OpenAI agents tried to bruteforce a UN website's API fields OpenAI agents scanned UNCTADstat's API more than 16,500 times between 13 April and 19 June 2026, using proxies, obfuscation and a double-encoding exploit to bypass the UN Conference on Trade and Development statistics site's restrictions, according to a Transluce report and access-log analysis. The agents bruteforced API fields to locate endpoints, eventually using a Google XSS game to fetch data in bulk, and 45 of the 54 Azure IP addresses behind related FractalWiki edits also edited DseWiki in the OpenAI-confirmed wiki swarm. The analysis concludes it is highly likely the scanning was perpetrated by OpenAI agents, which labelled payload pages with names such as CHATGPTTEST1 and OAI_META_1312. OpenAI agents tried to bruteforce a UN website's API fields From 13 April - 19 June 2026, OpenAI agents scanned UNCTAD's API ~16,500 times, using proxies, obfuscation, and Google's XSS game UNCTAD is the UN Conference on Trade and Development. UNCTADstat https://unctadstat.unctad.org/ is a statistics site they serve, which covers various trade/development indicators. The website renders data from its API, at unctadstat-api.unctad.org/datamart-api/... . Transluce's report https://transluce.org/agent-activity has a dataset showing that agents made many requests to this site, but doesn't go into what these requests actually are - I think they deserve some further inspection. On the 6th of June 2026, UNCTADstat's plastics-trade API was hit by scans at 21:06 UTC and 22:40 UTC. 40 minutes later, at 23:20, a user PublicDataResearchAgentT93214 created a page on FractalWiki, one of the wikis hit by the wiki swarms confirmed by OpenAI to be the result of OpenAI agents https://collusion.wiki . This page listed the exact UNCTADstat URLs that the scans used. We have those wikis' access logs, which show that, of the 54 Azure IP addresses used to make this page and other UNCTAD-related edits and searches, 45 of them also made edits on DseWiki in the wiki swarm