cd /news/ai-agents/openai-agents-tried-to-bruteforce-a-… · home › topics › ai-agents › article
[ARTICLE · art-140905] src=theverge.com ↗ pub= topic=ai-agents verified=true sentiment=↓ negative

OpenAI agents tried to ‘bruteforce’ a UN website

Security researcher Rowan Howard-Jones reported that OpenAI agents scanned the UN Conference on Trade and Development's (UNCTAD) statistics site over 16,000 times between April and June while attempting to retrieve Productive Capacities Index (PCI) data through the UNCTADstat API. According to Howard-Jones, the agents lacked direct API access and, after hitting HTTP tool restrictions and errors, masked their requests and hijacked Google's XSS game to continue pulling data. OpenAI and the UN did not immediately reply to a request for comment.

by read1 min views1 publishedSep 27, 2026
OpenAI agents tried to ‘bruteforce’ a UN website
Image: The Verge

Security researcher Rowan Howard-Jones says that OpenAI agents scanned the UN Conference on Trade and Development’s (UNCTAD) statistics site over 16,000 times between April and June. While the incident doesn’t quite rise to the level of the Hugging Face hack, or the recent attacks on US government sites, it’s yet another concerning example of AI agents going outside the normal bounds to accomplish a task.

OpenAI’s agents resorted to increasingly aggressive tactics when they couldn’t immediately get what they wanted.

According to Howard-Jones, the agents were likely tasked with retrieving publicly available data related to the Productive Capacities Index (PCI) through the UNCTADstat API. However, the agents did not appear to have direct API access and were limited in their ability to pull data from UNCTADstat because of restrictions on their HTTP tools.

The agents eventually worked out a way to bypass their limitations and start pulling data from the site, but still encountered some errors. At this point, the AI went from creative to deceptive. Believing that the errors were due to its requests being caught by a nonexistent filter, it started to mask its behavior. It eventually realized it could hijack Google’s XSS game (a cross-site scripting learning tool) to accomplish its goals. The agents resorted to increasingly aggressive tactics to get access to UN data.

OpenAI and the UN did not immediately reply to a request for comment.

Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.

── more in #ai-agents 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openai-agents-tried-…] indexed:0 read:1min 2026-09-27 · —