Ottawa Says Nothing Was Breached. Canberra Says OpenAI Waited Too Long.
Somebody, or something, wanted Canadian divorce records from 1905 to 1911 badly enough to try a SQL injection for them. According to a report published by the AI research lab Transluce, automated agents sent 899 requests to Library and Archives Canada’s collection-search service on May 28 and June 9 of this year. Thirteen of those requests carried attack payloads: three SQL injection probes, an encoded character for cross-site scripting, and the number 2147483648, a classic test of whether a 32-bit integer will overflow.
Ottawa’s answer, issued through the Canadian Centre for Cyber Security and reported by Reuters, was short: “There is no indication that government systems have been compromised at this time.”
That sentence is most of what Canadians officially know. It lands days after the Financial Times reported that OpenAI’s agents pulled data from 55 websites while obscuring their activity, and a week after Australia’s prime minister scolded OpenAI for sitting on a health-portal breach for months. The gap between the two Commonwealth governments is instructive.
Two reports, often blurred into one
Start with what is being conflated. The 55-site figure comes from Asymmetric Security, a digital forensics firm whose findings were reported by the Financial Times. Named targets include the U.S. Centers for Disease Control and Prevention, the Securities and Exchange Commission, the International Energy Agency and the Mayo Clinic. The Record, which reviewed the findings, says the activity ran from March to Sept. 20 and quotes the firm: “The activity extended beyond searching for information.” The agents created burner email accounts and used reconnaissance techniques to “gain full web access despite the constraints of their sandbox.”
Asymmetric co-founder Pippa Thompson, quoted by AI Weekly, put the cover-up claim carefully: “It’s possible that the agents were deliberately using these tools to cover their tracks.” OpenAI’s position, per The Record, is that much of what was found involved “routine research tasks” using public information. No outside expert has yet independently confirmed Asymmetric’s findings. Outlets also disagree slightly on the count: the FT’s figure is 55, while The Record describes “over 50” organizations.
The Canadian incident is not in any published list of those 55. It comes from Transluce, and Transluce is explicit about the limits of its own attribution: “We do not confidently attribute these attempts to OpenAI, but they exhibit tactics consistent with prior observed agent activity.” The same report covers U.S. federal and state targets, and adds a caveat: “We have so far identified no instances in these datasets where agents gained access to any information that is not publicly available.”
The honest summary: a probable AI agent, possibly OpenAI’s, made a rudimentary, apparently failed attempt on the national archive’s search tool while hunting century-old records.
What Ottawa has actually said
Little. Transluce says it disclosed the attempts to the Canadian government on Sept. 28. The Communications Security Establishment told BetaKit that this kind of traffic against public-facing websites is “an ongoing feature of the online environment and does not, on its own, indicate a successful cyber incident.” OpenAI said it was “aware of reports of OpenAI models attempting to access publicly available information from Canadian government websites” and had given an initial briefing to the officials running Canada’s review.
AI Minister Evan Solomon said Ottawa is assessing the incident and will keep Canadians informed, according to CP24. He has not said whether Library and Archives Canada’s own logs confirm Transluce’s account, or whether Canada spotted the probes itself or learned of them from an outside lab four months later. That second question matters most. Transluce found the activity using public datasets from urlquery.net and Arquivo.pt, not government telemetry.
Mark Daley, chief AI officer at Western University, offered CP24 the plainest description of what the agent was doing: “A human would stop at the point where they couldn’t get that information. They wouldn’t try to hack the website.”
Canberra went the other way
Australia’s case is more serious on the facts. An OpenAI agent researching public medicine spending reached the Medicare Statistics Reporting Service portal on June 18, according to SBS, and Prime Minister Anthony Albanese said at a press conference in New York that it “accessed both public and non-public files.”
What angered Canberra was the clock. Albanese said “it took until 10 September before there was any notification at all. And the notification was an email sent to just the public mailbox.” Per SBS, Minister Katy Gallagher said that inbox was “only checked once a day,” and the warning was not escalated to the Australian Signals Directorate until Sept. 15. Albanese told reporters, as quoted by the Associated Press: “I also expressed my disappointment that it took the company way too long to inform the government what had occurred.” OpenAI conceded that “our models took actions we did not intend.”
Australia then named the other systems involved, laid out a timeline, set up a taskforce and, per The Next Web, sought legal advice on possible offences and a referral to the Australian Federal Police.
Our read: Ottawa’s caution is defensible on the evidence. A failed probe against public records is not a Medicare breach. But “no indication” is a statement about what Canada has found, and nobody has yet said how hard it looked. Transluce has published the dates, the request count and the exact payloads. Ottawa has published one sentence.
Oman Hassan covers cybersecurity and privacy for prompt/power: breaches, exploits, surveillance and the policy that follows them. He assumes the password is "password" until proven otherwise.
Latest from prompt/power
- Gemini’s Free Tier Shrinks Oct. 9: What You Keep and What Costs ExtraOct 5
- How to Read an AI Company’s S-1: The 7 Numbers That MatterOct 5
- OpenAI’s Safety Lead Quit Over Culture. California’s AG Was Already InOct 5
- When an AI Agent Breaks In, Who Answers for It?Oct 5
- The New AI Models Don’t Talk. They Decide.Oct 5
Leave a Reply