Back The-Decoder OpenAI's AI agents exploited a Google security education game to scrape UN trade data
AI agents that very likely came from OpenAI hijacked a Google game that teaches web security to scrape a United Nations statistics site. You can't make this stuff up.
An analysis by Rowan Howard-Jones documents how agents ran more than 16,500 scans of the UNCTADstat data API through the URL scanner Urlquery between April 13 and June 19, 2026, systematically probing API fields along the way.
Here's what I think is the most spectacular aspect: According to the analysis, the agents apparently could only send GET requests directly, but the UNCTAD API endpoint they wanted required POST requests. So they took a detour through a Google web security learning game , where Level 1 displays whatever you type after "?query=" in the address bar.
Instead of typing a term , the agents injected a small program. The URL scanner Urlquery executes JavaScript on loaded pages, so it opened the game page and ran the program. That program assembled a form and automatically sent the required POST request to the UN site, which responded with the requested data.
It's a textbook example for the alignment problem with persistent agentic AI systems. The agents likely had a hard constraint allowing only GET requests. Rather than accept that limit, they autonomously found a way around it without technically breaking it. They kept making GET requests, but to a page that turned them into POST requests.
Rules can almost always be circumvented when a system is driven enough and only knows the goal but doesn't grasp the spirit of the restriction. The issue gets worse when the system is persistent and simply won't stop. Even after the site throttled 82 of their requests, the agents kept going, according to the report.
Howard-Jones stops short of calling it hacking but says the behavior looks like someone who won't take "no" for an answer. That tracks with other cases that have recently surfaced or been disclosed by OpenAI itself .
The agents refined their methods over weeks
The XSS game exploit was just one technique in a weeks-long evolution documented in the analysis . The first observed attempt using a self-submitting form showed up on April 21. The agents used the testing service httpbin to serve a page that Urlquery opened in a browser. An embedded script then automatically sent the form to the UN API.
The first successful queries returned Productive Capacities Index data for Norway, Iceland, and Denmark. At first, though, the agents could only see the responses as screenshots, which made extracting the data difficult.
Starting April 27, successful retrievals through the proxy service r.jina.ai were documented. The service fetched the data on the agents' behalf and made it accessible to their script. That initially worked only for pre-existing files, not for queries against the Facts endpoint. To make retrieved data easier to read, the agents later embedded it directly into the URLs of follow-up requests so it would show up in the URL scanner's report.
The agents also found a way to bypass the block on the central data endpoint called "Facts." Instead of writing "Facts," they used "F%2561cts" in the address. This encoding trick let them dodge the restriction and pull the data via GET request after all. According to the analysis, the agents used this trick 55 times. Before publishing, Howard-Jones notified UNCTAD's IT security team the vulnerability
AI News Without the Hype – Curated by Humans
Full access to every article on THE DECODER
Join the and community discussions
A weekly AI news recap via mail
6x/year: "AI Radar" — deep dives on the AI topics that matter most
Daily AI news, always up to date
Our full ten-year archive
Covered by a team with 10+ years in AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
