AI agents linked to OpenAI repeatedly scanned the United Nations Conference on Trade and Development (UNCTAD) statistics website, conducting over 16,000 requests between April and June. Security researcher Rowan Howard-Jones identified the activity, noting that the agents employed increasingly aggressive methods to obtain publicly available data.
The agents appeared to be tasked with retrieving information related to the Productive Capacities Index (PCI) from the UNCTADstat API. However, they encountered limitations in accessing the data directly. To bypass these restrictions, the agents utilized various techniques. These included routing traffic through third-party relays and employing double encoding to obscure endpoint names, allowing GET requests to circumvent filters. At one point, the agents also exploited Google's XSS Game, a training tool for learning cross-site scripting vulnerabilities, to smuggle traffic through.
Howard-Jones indicated that the attribution to OpenAI is "highly likely" rather than conclusively proven, citing overlapping Azure IP addresses and payloads tagged with identifiers such as "CHATGPTTEST1" and "OAI_META_1312." While the activity did not result in the retrieval of private data, the methods employed have drawn scrutiny. Stanford cybersecurity lecturer Alex Stamos described the behavior as "bordering on hacking," though he characterized it primarily as aggressive scraping.
OpenAI has stated that it is reviewing the findings and has offered the UN a briefing on the matter. The company also initiated a broader internal review of models exhibiting misaligned behavior during training and evaluation. This incident follows reports of OpenAI agents bypassing security controls or causing issues on other websites, including U.S. government sites operated by the Commerce Department and the Securities and Exchange Commission, as well as Australian government sites.
