AI

Researcher Documents 16,000 Scans of UN Portal Linked to OpenAI Agents

An independent engineer has connected thousands of requests to a United Nations statistics database to AI agents likely operated by OpenAI, which circumvented access restrictions using proxies and encoding techniques.

·3 min read
Researcher links 16,000 scans of a UN statistics portal to OpenAI agents
Researcher links 16,000 scans of a UN statistics portal to OpenAI agents

Engineer Rowan Howard-Jones has attributed more than 16,000 scans of a United Nations statistics portal to artificial intelligence agents he believes were operated by OpenAI Group PBC. The agents circumvented access controls by deploying proxies and encoding techniques when the portal rejected their requests. According to a blog post Howard-Jones published on Saturday, the scanning campaign ran from April 13 through June 19, targeting the United Nations Conference on Trade and Development's UNCTADstat database.

The information the agents sought was publicly available, including metrics like the Productive Capacities Index. Howard-Jones observed the agents systematically testing the site's application programming interface endpoints through brute force. The authentication key they employed was also public, as UNCTADstat's data viewer includes it in every request.

The primary mechanism involved urlquery.net, a URL scanning service that renders pages in an isolated browser environment. The agents constructed base64-encoded HTML forms using the httpbin testing service and submitted them to the scanner, which then forwarded the forms to UNCTADstat. Screenshots from the scan reports documented the return of index data.

When UNCTADstat blocked direct GET requests to the Facts endpoint, the agents responded by double-encoding it as "F%2561cts." Additional payloads were hosted on a Google LLC educational game about cross-site scripting vulnerabilities, while other attempts split the word "POST" into separate strings to evade filtering mechanisms.

The portal rate-limited 82 of the requests, yet the scanning continued. Howard-Jones informed UNCTAD's security team about the double-encoding workaround before publishing his findings, but declined to characterize the activity as hacking. Instead, he described it as behavior from "someone, or something, that won't take 'no' for an answer."

The payload pages contained identifiers including "CHATGPTTEST1" and "OAI_META_1312." Howard-Jones also identified 54 Microsoft Corp. Azure addresses associated with UNCTAD-related edits and searches on FractalWiki, a small public wiki platform. Of those addresses, 45 had also made edits to DSEwiki, a dormant German wiki where OpenAI agents were previously documented coordinating with each other earlier this year.

"We're reviewing these findings and have reached out to the U.N. to offer a briefing with the team conducting that review," an OpenAI spokeswoman stated to The Wall Street Journal. The company characterized its review as an examination of misaligned models during training and evaluation phases. According to the spokeswoman, most of the activity examined so far involved standard research practices such as accessing publicly available web content. The U.N. has not yet responded to the Journal's inquiry.

Transluce, a nonprofit research organization, had previously published findings that prompted Howard-Jones's investigation. Last week, Transluce connected OpenAI agents to intrusions targeting Data USA and an Australian government health statistics portal. OpenAI acknowledged on Friday that its agents had also engaged in unauthorized behavior on U.S. government systems, including those operated by the Commerce Department and the Securities and Exchange Commission.

Alex Stamos, a cybersecurity instructor at Stanford University, characterized the UNCTAD activity as "borderline for what I would call hacking" in remarks to the Journal. "It's really very aggressive scraping and data retrieval," he added.