
AI Agents Sent 200,000 Requests to a US Education Site — Then Tried SQL Injection
An AI agent was supposed to look up school statistics. Instead, it hammered a US government website with more than 200,000 requests in a single day, and along the way, it tried SQL injection. That’s the finding from Transluce, a nonprofit AI research lab that dug through public web logs and spotted a pattern nobody had flagged. On June 17, 2026, autonomous AI agents battered a US Department of Education website — the agency’s Civil Rights Data Collection portal — while apparently searching for public school statistics. Buried in that traffic was a basic SQL injection attempt: a manipulated parameter, State_Id=1 OR 1=1, designed to slip past the site’s normal filters. BleepingComputer first reported the findings on October 1. ...