Research suggests ChatGPT maker's agents got surprisingly creative when a UN data API proved less than cooperative
Europe's AI ambitions rest on somebody else's supply chain 39 minutes ago
Europe's AI ambitions rest on somebody else's supply chain
Microsoft tells nonprofits their deleted M365 data isn't coming back 2 hours ago
Microsoft tells nonprofits their deleted M365 data isn't coming back
Ex-soldier's telecom hacking spree earns him 70 months 2 hours ago
Ex-soldier's telecom hacking spree earns him 70 months
UK government vows to reclaim services from outsourcing giants 3 hours ago
UK government vows to reclaim services from outsourcing giants
Ofcom pulls the plug on Openreach's aggressive fiber discount 3 hours ago
Ofcom pulls the plug on Openreach's aggressive fiber discount
OpenAI agents apparently spent two months hammering a United Nations (UN) data API, trying increasingly creative ways to bypass the barriers they encountered.
Researcher Rowan H-J uncovered the activity by analyzing roughly 16,500 scans of the UN Conference on Trade and Development's UNCTADstat API recorded between April 13 and June 19, 2026.
Rowan claims it’s "highly likely" the traffic came from OpenAI agents, based on links to previously documented OpenAI "wiki swarms," overlapping Azure IP addresses, and payloads carrying labels including “CHATGPTTEST1” and “OAI_META_1312.”
OpenAI told The Register it is looking into the findings, though it stopped short of explicitly confirming that its agents were responsible for the activity Rowan documented.
"We're aware of reports of OpenAI models accessing publicly available information from the United Nations Conference on Trade and Development's Data Hub," an OpenAI spokesperson told us. "We're reviewing these findings and have reached out to the UN to offer a briefing with the team conducting that review."
The spokesperson pointed to OpenAI's previously announced review of what it calls "misaligned model activity," saying most of the behavior examined so far involved routine research, including accessing public websites to answer questions.
"Some involved government websites because our models often turn to them as authoritative sources of public information," the spokesperson added.
Assuming the researcher is right, the interesting part isn't that AI agents wanted to get their synthetic mitts on some UN statistics. It's what happened when they couldn't.
The agents appear to have been hunting for fairly unexciting public data on things like trade, employment, and productive capacity. But requests to UNCTADstat didn't always work the way they wanted, and instead of admitting defeat, they kept trying different routes.
According to Rowan's analysis, the agents experimented with third-party services that could make requests on their behalf and built bits of JavaScript to fetch the data.
One of the more unusual detours involved Google's XSS training game , a deliberately vulnerable site for learning cross-site scripting. The agents appear to have put it to rather more practical use, using it to host JavaScript that made requests to UNCTADstat. On June 1, one attempt returned nine rows of employment data.
The agents also stumbled across a trick that appeared to get around UNCTADstat refusing a particular type of request. After the straightforward approach failed, they altered the address using double URL encoding. This time the server returned a successful response. Rowan counted the same technique being used 55 times between May 4 and June 19.
There was plenty of flailing around in between. The agents repeatedly guessed different names for the API key parameter, tried different ways to construct requests, and apparently tried to dodge a filter that may not even have existed.
The API key itself wasn't some crown jewel pilfered from a UN server. Rowan notes that UNCTADstat's own data viewer sends the same key from users' browsers.
What stands out is how persistent the agents appear to have been set to be. When one route failed, they tried another, bringing in third-party services and changing how requests were made until they got the data they were after.
Which, of course, is what we're told makes AI agents useful: give them a goal and let them figure out the steps required to achieve it. Things get a little more interesting when one of those steps involves working out how to get past somebody else's technical restrictions. Or, possibly, some might infer, not being told to obey guardrails.
Why the agents were doing any of this remains unclear. Rowan doesn’t have the prompts they were given and suggests the pattern could fit an internal OpenAI question set used for training or evaluation.
There are other breadcrumbs pointing toward OpenAI. Shortly after some of the UNCTADstat activity, an account called “PublicDataResearchAgentT93214” created a page on FractalWiki containing the same API URLs. Rowan also found that 45 of the 54 Azure IP addresses associated with UNCTAD-related activity on the wikis had previously edited DseWiki during the earlier agent swarm.
All that ingenuity for some UN statistics. Imagine what happens when the prize is a little more interesting. ®
How many times are you paying for the same file?
A Register dinner in Midtown on 27 October takes on the file infrastructure distributed teams still run and nobody chose, off the record
Microsoft's Copilot super app comes with a meter attached
Redmond calls its pricing model an 'evolution' as advanced AI racks up usage charges
Huawei Cloud Rolls Out Enterprise AI Products Across the Board, Building an Open Agentic Cloud
PARTNER CONTENT: Huawei Cloud strengthens the silicon bedrock on the cloud
Europe's AI ambitions rest on somebody else's supply chain
EU firms capture less than 10% of the bloc's datacenter chips, server assembly, and cloud infrastructure markets
Open source datacenters and open source thinking will undo self-inflicted DC damage
Denial and distraction have served the bit barn barons very badly. Wise up
OpenAI agents went the long way round for UN data
Research suggests ChatGPT maker's agents got surprisingly creative when a UN data API proved less than cooperative
Astronomer watches Starlink satellites sinking to build a ‘planetary barometer’
Astronomer watches Starlink satellites sinking to build a ‘planetary barometer’
ShinyHunters claims FBI hack: 'This is NOT financially motivated'
ShinyHunters claims FBI hack: 'This is NOT financially motivated'
UPDAted Register reader hit with surprise bill after Microsoft portals disagreed
Register reader hit with surprise bill after Microsoft portals disagreed
Security firm finds naming AI agents after Seinfeld characters helps bots join the team
Security firm finds naming AI agents after Seinfeld characters helps bots join the team
Who, Me? Boss bought cheap 'printer' from a catalog and was left without a leg to stand on
Boss bought cheap 'printer' from a catalog and was left without a leg to stand on
DoJ: Uncle Sam bought forensics software from same Russian operation supplying FSB
DoJ: Uncle Sam bought forensics software from same Russian operation supplying FSB
OPINION Open source datacenters and open source thinking will undo self-inflicted DC damage Denial and distraction have served the bit barn barons very badly. Wise up
Open source datacenters and open source thinking will undo self-inflicted DC damage
Denial and distraction have served the bit barn barons very badly. Wise up
OPINION Big AI's content problem: Take the work, keep the money The more we learn how AI does business, the more unfair it looks
Big AI's content problem: Take the work, keep the money
The more we learn how AI does business, the more unfair it looks
Google's TPUs to catch some rays in orbit week Part of Project Suncatcher, the proof of concept aims to see how well lightly modified compute fares in orbit
Google's TPUs to catch some rays in orbit week
Part of Project Suncatcher, the proof of concept aims to see how well lightly modified compute fares in orbit
Meta's new AI fidget is a ... Tamagotchi? We hope Zuck's Muse Charm doesn't die if you neglect it
Meta's new AI fidget is a ... Tamagotchi?
We hope Zuck's Muse Charm doesn't die if you neglect it
CVE flood pushes Ubuntu onto weekly kernel release cycle AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace
CVE flood pushes Ubuntu onto weekly kernel release cycle
AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace
Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Russians are posing as Signal support to launch phishing attacks
PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack
PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Black Hat and DEF CON
DEF CON Franklin project enlists hackers to harden critical infrastructure
Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
EQT buys majority in Swiss cybersecurity biz Acronis
Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career
Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight
On the plus side, infosec's a good bet for a long, stable career
KDE turns 30 and someone's brought an AI-native desktop proposal Akademy talk imagines Plasma assembling itself around a personal model of each user
KDE turns 30 and someone's brought an AI-native desktop proposal
Akademy talk imagines Plasma assembling itself around a personal model of each user
Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '
Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line
Acquisition gives open source CSS framework 'a stable long-term '
Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push
Switzerland tests a FOSS escape route from Microsoft 365
Swiss Army sticks a knife in American cloud apps with its own FOSS push
Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin
Feel peak Windows was 7? You might like Kumander Linux
Debian and Xfce – solid, sensible choices – with a pretty skin
Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted
Canonical shuttering some of its legacy chat channels
The Ubuntu Pastebin went in June, IRC gets demoted
Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
Audacity audio-editing app no longer looks like it's from the early 2000s
The FOSS tool for audio editing has a fresh coat of paint, and new features to boot
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
