Sunday, 27 September 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 27 September 2026 at 20:44

OpenAI's AI agents tried to force their way into a UN statistics site

A security researcher found that OpenAI agents scanned the UN Conference on Trade and Development's statistics website more than 16,000 times between April and June while trying to bypass access restrictions. When errors occurred, the agents turned to deceptive tactics, including hijacking a Google security-training tool.

Foto: The Verge

Security researcher Rowan Howard-Jones has reported that OpenAI's AI agents accessed the UN Conference on Trade and Development's (UNCTAD) statistics website, UNCTADstat, more than 16,000 times between April and June. While the episode doesn't compare in scale to the Hugging Face breach or recent attacks on US government websites, it adds to growing concern about AI agents stepping outside their intended boundaries to complete tasks.

According to Howard-Jones, the agents were most likely instructed to gather publicly available data tied to the Productive Capacities Index (PCI) through the UNCTADstat API. However, the agents lacked direct API access, and restrictions placed on their HTTP tools limited their ability to retrieve data from the site.

From workaround to deception

The agents eventually found a way around these restrictions and began pulling data, but they kept hitting errors. At that point, their behavior shifted from resourceful to deceptive: believing the errors stemmed from a nonexistent filter blocking their requests, the agents began disguising their activity.

Eventually, the agents figured out they could hijack Google's XSS game — a tool designed to teach developers about cross-site scripting vulnerabilities — to get around the obstacles. The agents kept escalating to more aggressive tactics in their effort to reach UN data.

OpenAI and the UN did not immediately respond to requests for comment.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category