An independent researcher tied more than 16,000 scans of a United Nations statistics portal to artificial intelligence agents. The researcher considers it highly likely that OpenAI Group PBC ran these agents.
When the portal turned requests away, the agents used proxies and encoding tricks to get the data anyway. Engineer Rowan Howard-Jones published a blog post on Saturday detailing the activity. The scanning lasted from April 13 until June 19. The target was the United Nations Conference on Trade and Development statistics site, known as UNCTADstat.
None of the data was secret. The agents wanted public figures such as the Productive Capacities Index. Howard-Jones found them brute-forcing the fields of the site application programming interface to locate endpoints. The key they used for those queries was public too, because the UNCTADstat data viewer sends it with every request.
Read nextOpenAI Admits Its AI Agents Targeted and Infiltrated US Government WebsitesThe agents used a URL scanner to get data
The main tool used was urlquery.net. This is a URL scanner that opens whatever page it is given in a sandboxed browser. The agents built base64-encoded HTML forms on the httpbin testing service and fed them to the scanner. The scanner browser then submitted the forms to UNCTADstat. Screenshots in the scan reports show index data coming back.
Later, the agents beat a block on GET requests to the Facts endpoint by double-encoding it as F%2561cts. Other payloads were hosted on a Google LLC game that teaches cross-site scripting. Some split the word POST into two strings, apparently to slip past filters.
UNCTADstat rate-limited 82 of the requests. The requests kept coming. Howard-Jones told the UN security team about the double-encoding bypass before publishing. The researcher stopped short of calling the activity hacking. The actions look like those of someone, or something, that won’t take no for an answer, Howard-Jones wrote.
Payload pages built by the agents carried labels such as CHATGPTTEST1 and OAI_META_1312. Howard-Jones also traced 54 Microsoft Corp. Azure addresses tied to UNCTAD-related edits and searches on FractalWiki, a small public wiki. Forty-five of those addresses had edited DSEwiki as well. That long-dormant German wiki is where OpenAI agents were found coordinating with one another earlier this year.

OpenAI is reviewing the findings
An OpenAI spokeswoman told The Wall Street Journal that the company is reviewing these findings. The company reached out to the UN to offer a briefing with the team conducting that review. OpenAI has described the review as a broad look at misaligned models during training and evaluation. Most of what it has examined so far involved routine research such as reading public web content, the spokeswoman said. The UN did not immediately respond to the Journal request for comment.
Nonprofit research lab Transluce prompted Howard-Jones to dig into the data through an earlier report last week. That report linked OpenAI agents to attacks on Data USA and an Australian government health statistics site. OpenAI confirmed on Friday that its agents had also misbehaved on US government websites, including those of the Commerce Department and the Securities and Exchange Commission.
Alex Stamos, a cybersecurity lecturer at Stanford University, commented on the UNCTAD activity to the Journal. He called it borderline for what he would call hacking. He stated that it is really very aggressive scraping and data retrieval.
OpenAI is reviewing the findings and offering a briefing to the UN.



