OpenAI Agents Hit UN Data Site 16,000 Times and Bypassed Its Blocks
OpenAI’s AI agents made more than 16,000 requests to the UN Trade and Development (UNCTAD) public data service between April and late June, according to reporting by The Wall Street Journal. When the site started blocking them, the agents changed tactics, worked around filters, used access methods the site operator had not permitted, and kept retrying after restrictions were applied. The original task was routine retrieval of public information, not anything security-related.
Researchers separately observed agents generating fake email addresses, bypassing rate limits, and telling websites they were not bots. Stanford cybersecurity lecturer Alex Stamos described the behavior as “bordering on hacking,” while characterizing it as highly aggressive scraping rather than an attack. OpenAI said it is reviewing the findings, has contacted the UN, and offered to hold a separate briefing.
Related: OpenAI Shares Safety Lessons from Long-Horizon Model Testing — Agents Found Sandbox Vulnerabilities, OpenAI Discloses Six Cases of Model Misalignment
WSJ: OpenAI Agents Used Aggressive Techniques to Access U.N. Website