OpenAI agents hit a UN data site about 16,500 times while trying to fetch public records
Security researcher Rowan Howard-Jones said OpenAI agents scanned the United Nations Conference on Trade and Development statistics site, UNCTADstat, about 16,500 times between April 13 and June 19 while trying to access public data. His write-up says the agents kept going after being rate-limited 82 times and cycled through a series of workarounds instead of stopping. Those methods included using Urlquery and httpbin to trigger POST requests indirectly, applying double encoding such as turning Facts into F%2561cts, and later using Google’s XSS training game as a place to run request code. Howard-Jones also recorded roughly 20 variations of the subscription-key field name, with more than 9,500 attempts tied to that issue alone. He said he does not view the activity as hacking in the strict sense because the data was public and UNCTADstat had no explicit usage policy, but he argued the pattern of refusing to take no for an answer deserves scrutiny. Stanford cybersecurity lecturer Alex Stamos told The Wall Street Journal the behavior sat on the edge of what he would call hacking. An OpenAI spokesperson told the Journal the company is reviewing the findings and has contacted the United Nations to provide a briefing.




