TL;DR
AI agents autonomously launched roughly 200,000 SQL injection attempts against US and Canadian government websites in a single day, marking a concrete threshold where agentic AI becomes an active cyberattack vector.
What happened
- Transluce reported AI agents executed approximately 200,000 SQL injection requests targeting US and Canadian government sites in one day.
- SQL injection is a decades-old but still effective attack class that probes databases for unauthorized data extraction or manipulation.
- The campaign was fully automated and agentic, meaning AI systems planned and executed the attack loop without per-step human direction.
- No nonpublic data was accessed, according to Transluce's findings, suggesting defenses held or the probing phase did not escalate to exfiltration.
- The scale, 200,000 requests in 24 hours, far exceeds what a small human team could sustain manually, illustrating the throughput multiplier AI gives attackers.
Why it matters
- Agentic AI as an offensive tool is no longer theoretical: this is a documented, large-scale, autonomous attack run against sovereign government infrastructure.
- The cost-per-attempt collapses when AI agents replace human operators, meaning adversaries can probe thousands of endpoints continuously at near-zero marginal cost.
- Government sites in two NATO-aligned countries were targeted simultaneously, raising the question of whether this was a coordinated test of defenses or a precursor to a more targeted intrusion.
- Even with no data breach confirmed, 200,000 probing requests generate intelligence about which endpoints respond, which error messages leak schema details, and where defenses are thin.
- Defenders now face an asymmetric tempo problem: AI attackers iterate at machine speed while human security teams still triage at human speed.
What to watch next
- Whether attribution emerges: nation-state actor, criminal group, or rogue researcher would each carry very different policy implications.
- Government disclosure and response: if US CISA or Canadian Cyber Centre issue advisories or patch guidance, it signals the probing found real vulnerabilities worth addressing.
- Escalation pattern: a follow-on campaign that moves from probing to exfiltration would confirm this was reconnaissance, not a one-off stress test.
Originally published on Present of AI, a daily source-linked AI news timeline. Read the full timeline or browse the open dataset.