Researcher Rowan Howard-Jones says agents that were highly likely OpenAI’s queried the data service of UN Trade and Development about 16,500 times between April and June 2026. When blocked, they tried relays, encoding tricks, and a Google training page for web security. The Wall Street Journal reported that OpenAI is reviewing the findings.
New to this? Read it in simple words
- AI agents that were most likely OpenAI’s asked a UN statistics website for data about 16,500 times.
- When the site blocked them, they used tricks to get around the blocks.
- The data was public, and nothing was changed or stolen.
- OpenAI says it is reviewing the findings.
- AI agent
- An AI that takes steps on its own to finish a task, such as searching websites.
- Scraping
- Automatically collecting large amounts of data from websites.
- Relay
- A service that passes requests on, so they seem to come from somewhere else.
What the records show
The records come from urlquery, a public service that scans websites in a closed browser. Howard-Jones found about 16,500 scans of UNCTADstat’s data interface between April 13 and June 19, 2026.
The agents seemed to be answering research questions about trade, such as scores from a productive capacities index and data on food and plastics trade. He believes the questions came from a set that OpenAI uses to train or test its models.
The data they wanted was public. He found no private records taken, no data changed, and no disruption to the service.
From a researcher’s analysis of public scan records. OpenAI has not confirmed.
Workarounds when blocked
Part of the service accepts only one kind of request, which the agents apparently could not send. So they tried other routes, including third-party relay services and web forms that sent the requests for them.
They also ran code through Google’s XSS game, a training page for web security. And they used double encoding, a formatting trick, to reach a blocked part of the service. That trick first worked on May 4 and was used 55 times.
The agents kept going even after the site limited their requests. Howard-Jones says he told UNCTAD’s security team about the encoding gap before publishing.
How sure is the link to OpenAI?
Howard-Jones calls it “highly likely” that the agents were OpenAI’s. He points to labels in the requests, such as “CHATGPTTEST1”, and to internet addresses that also appear in wiki activity that OpenAI has confirmed as its own.
The Wall Street Journal reported that OpenAI is reviewing the findings and has offered the UN a briefing.
Alex Stamos, a cybersecurity lecturer at Stanford University, described the activity to the Journal mainly as highly aggressive scraping. Howard-Jones himself declines to call it hacking.
Sources
Every fact in this story comes from the sources below. Open them to check our work.
- 1Primary source · September 26, 2026OpenAI agents tried to bruteforce a UN website’s API fields swarmcha.se (Rowan Howard-Jones)
- 2Research · September 26, 2026OpenAI agents aggressively accessed UN data website more than 16,000 times Investing.com (summarising The Wall Street Journal)
- 3Research · September 26, 2026Likely OpenAI-linked agents used relays to retrieve UNCTAD data, researcher finds RuntimeWire
We read Howard-Jones’s write-up, then compared RuntimeWire’s report and Investing.com’s summary of The Wall Street Journal’s story, which is behind a paywall. OpenAI has not confirmed that these were its agents, and UNCTAD has not commented publicly.