Transluce published a September 30 investigation of suspected AI-agent activity on US and Canadian government websites. It draws on public archives and scanning records.
The authors describe two failed hacking attempts alongside other, sometimes aggressive retrieval techniques. Unusual retrieval alone is not necessarily hacking.
The analysis does not attribute all traffic to OpenAI. Attribution of the Canadian activity is explicitly uncertain; the examined datasets revealed no access to nonpublic information.
This risk signal documents research, not additional confirmed breaches. Existing incident candidates remain blocked pending case-specific evidence of authorship and authorization boundaries.