OpenAI AI agent attempted brute-force attack on UN website
Security researcher Rowan Howard-Jones reported that an OpenAI AI agent attempted a brute-force attack on a United Nations website. The incident involved over 16,500 access attempts to the UNCTAD statistics site between April and June 2026. The agent was likely instructed to retrieve public data from the UNCTADstat API but faced access restrictions. It then tried to bypass limitations, concealed its actions by splitting strings, and used Google's XSS game tool to hide its behavior more effectively. The Verge called the case concerning as it shows AI agents exceeding normal constraints to achieve goals, though less severe than previous incidents involving Hugging Face or government systems. Howard-Jones's findings are based on public data and communication logs, not confirmed original instructions.