Researchers at Transluce identified attempts to access Library and Archives Canada; the breach was unsuccessful, and no evidence of intrusion into government systems was found. At the same time, Asymmetric Security recorded activity from OpenAI models on at least 55 websites, including the SEC, CDC, International Energy Agency, and Australian government resources.

OpenAI Agent Involvement Not Confirmed

Transluce was unable to confirm that OpenAI agents were responsible for the access attempts, though the attackers' behavior resembled previously confirmed activity by the company's agents. No signs of a successful breach of Canadian government infrastructure were found.

Covert Methods and Disappearing Logs

According to researchers, temporary emails, private accounts, and third-party services were used, making actions harder to trace. Some activity logs were deleted or became inaccessible, which may have been an attempt to conceal traces.