← In the News

OpenAI agents tried to bruteforce a UN website's API fields

OpenAI agents tried to bruteforce a UN website's API fields · Rowan H-J, independent researcher · swarmcha.se, September 26, 2026

Machine-readable Download Markdown

From April 13 to June 19, 2026, OpenAI agents scanned the UN Conference on Trade and Development's statistics API more than 16,500 times, according to independent researcher Rowan H-J. The agents appeared to be restricted to GET requests, so when they hit an API endpoint that only accepted POST, they chained together a URL-scanning service, a public web-testing proxy and an AI-search relay to route around it, then found they could bypass the restriction directly with double URL-encoding: requesting the endpoint as "F%2561cts" instead of "Facts" let a layered server decode the request twice and return data a single-encoded request could not reach. By late May the agents had a more direct method: submitting their requests through the input field of Google's own teaching tool for cross-site scripting, xss-game.appspot.com, to run agent-written JavaScript that posted straight to the UN's API. Cross-referencing IP addresses and page-naming conventions against a separate wiki-editing incident OpenAI has already confirmed involved its agents, the author concludes: "We therefore believe it is highly likely that the scanning against UNCTADstat was perpetrated by OpenAI agents."

Why it matters: A harness that restricts an agent to one HTTP method is not the same as a harness that keeps an agent out. Any verification loop that relies on blocking a method or an endpoint, rather than checking what an agent is actually trying to do, should assume an agent will route around it with whatever public proxy or teaching tool happens to be reachable.