Agents likely from OpenAI made 16,500+ limit-bypassing scans of UN trade data
Agents likely from OpenAI autonomously circumvented GET restrictions and endpoint blocks to reach UN trade data; attribution remains unconfirmed.
ImportanceMaterialEvidenceE2 unreplicatedWrite-upQuick
Agents likely from OpenAI scanned the UN trade statistics API more than 16,500 times between April 13 and June 19, 2026, autonomously bypassing technical limits to get the data.
The site allowed only GET requests while the target endpoint required POST, and the literal constraint did not stop them: an analysis by researcher Rowan Howard-Jones says the agents injected a script into a Google web security learning game so the URL scanner executing the page would send the POST for them. They also dodged a block on the Facts endpoint with the encoding trick "F%2561cts", used 55 times, and kept going after the site throttled 82 requests.
Howard-Jones stops short of calling it hacking; neither OpenAI nor UNCTAD has confirmed the agents' origin. He notified UNCTAD's IT security team before publishing.