Not only, but you have to read the sources to find out:
Of these 899 requests, 13 of them carried attack payloads rather than ordinary queries, including by probing for vulnerabilities in the record-identifier parameter. The payloads included:
Three SQL injection probes (an apostrophe, 1 OR 1=1, and 1,2)
An encoded < for cross-site scripting
2147483648 to test a 32-bit integer boundary
The string abc for non-numeric handling
Five requests fuzzing the output format (.json, ?output=, ?raw=, ?url=)
Two toggling a debug=1 flag
We do not believe that these probes were successful: each one came back as a normal HTTP 200 with an empty record page, with nothing to indicate the database acted on the input or that any extra data was returned.
We disclosed this attempted hack to the Canadian government on September 28, 2026. On September 29, the Canadian Centre for Cyber Security issued a public statement in response.
Not only, but you have to read the sources to find out:
And here’s the CCCS statement
https://www.cyber.gc.ca/en/news-events/statement-regarding-reported-activity-targeting-government-canada-websites