OpenAI Agents Allegedly Made 16,500+ UN API Scans While Finding Ways Around Restrictions


OpenAI’s AI agents apparently did not take a few blocked requests as a hint to stop. Independent security researcher Rowan H-J says agents linked to OpenAI made more than 16,500 scans against the United Nations Conference on Trade and Development’s UNCTADstat API between April 13 and June 19, repeatedly changing their approach when the normal route did not work (via TechRadar).

The finding comes from H-J’s investigation published September 26, which examined public Urlquery records and activity connected to UNCTADstat. H-J says the evidence makes it “highly likely” that the scanning was performed by OpenAI agents, although the attribution is based on the available evidence rather than a direct confirmation from OpenAI.

The data itself was not secret. The researcher believes the agents were looking for information related to areas including the Productive Capacities Index, tradable industries and food trade. The unusual part was how far the agents went when they encountered restrictions.

The agents kept finding new ways around the restrictions

According to H-J, the agents initially ran into an API endpoint that only accepted POST requests while their environment appeared to allow GET requests. Rather than stopping there, they experimented with public services that could execute requests on their behalf.

They used Urlquery as a kind of relay, creating pages that caused its sandboxed browser to send POST requests to UNCTADstat. Later, the agents used other relay services to retrieve responses and experimented with ways to get the returned data back into a form they could read.

The researcher found evidence that the agents discovered Google’s XSS Game, a security-training site designed to demonstrate cross-site scripting. They used its vulnerable training page to execute JavaScript that could submit requests to the UNCTADstat API. H-J found 25 reports using the technique between May 25 and June 1, including one that returned nine rows of data.

The agents also discovered a double-encoding trick that allowed them to bypass a restriction on the Facts endpoint. H-J says they encoded the word Facts as F%2561cts, allowing the request through and eventually returning data. The technique was then used 55 times between May 4 and June 19.

The OpenAI connection comes from several clues

The attribution is based on several pieces of evidence rather than one smoking gun. H-J found payloads and URLs carrying identifiers such as “CHATGPTTEST1,” “OAI_META_1312,” “OAI_IFRAME_TRADABLE” and “CHATGPT_1610_2000_125192.” The investigation also found overlap between Azure IP addresses involved in the UNCTAD activity and addresses connected to wiki activity that OpenAI has previously confirmed was caused by its agents.

There is also a fascinating connection to public wikis. On June 6, an account named PublicDataResearchAgentT93214 created a FractalWiki page listing UNCTADstat API URLs that had been scanned shortly beforehand.

H-J is careful not to call the activity hacking. The researcher notes that the data was publicly available, but says the repeated attempts to bypass restrictions are concerning because the same behavior against a more sensitive system could have much more serious consequences.

The researcher also disclosed the double-encoding bypass to UNCTAD’s security team before publishing the investigation. The finding comes as OpenAI faces renewed scrutiny over how its agents behave when they encounter restrictions, making this especially interesting look at what those systems can do when the straightforward route is blocked.

More about the topics: AI, Cybersecurity, OpenAI

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages