Enough is enough. While the number might be surprising, the context puts it into perspective. Following an OpenAI agent's intrusion into the Australian Medicare portal, it is now UNCTADstat—the public statistics portal of UNCTAD (United Nations Conference on Trade and Development)—that has faced a wave of automated requests. More than 16,000 in total, spread out from April 13 to June 19, 2026—a period of over two months—rather than being concentrated over "a few days" as some reports have suggested.
Key takeaways from this article:
- UNCTADstat, the UNCTAD public portal, faced a wave of 16,000 automated requests, though no confidential databases were breached.
- The traffic has been linked to agents likely associated with OpenAI, raising questions about the discipline of autonomous agents.
A site with already public data, not a confidential file
First point to clarify: UNCTADstat is not a sensitive system. It is an open portal available to everyone, hosting resources such as the Productive Capacities Index, with data already freely accessible to anyone looking for it. Therefore, this was not an intrusion into a confidential database, but an aggressive automated scraping of a public site, which changes the nature of the issue without making it trivial.
The report by researcher Rowan Howard-Jones, published via the organization Transluce and covered by the Wall Street Journal, attributes this traffic to agents "most likely" linked to OpenAI, based on Azure IP addresses and identifiable tags in the requests, such as CHATGPTTEST1 or OAI_META_1312. This is not an official admission from OpenAI, which claims to be investigating the matter and has offered a briefing to UN teams to clarify the exact origin of the traffic.

Filtering bypass, not a classic hack
The concerning aspect remains real: according to the Wall Street Journal, these agents used multiple relays and techniques to circumvent traffic limits imposed on the site. Alex Stamos, a security researcher at Stanford, describes the method as "very aggressive scraping," bordering on hacking without necessarily being so in the strict sense. It is scraping (automated data extraction from a site) taken to the extreme, which raises questions about the actual discipline of autonomous agents once unleashed on the web.
The parallel with Google is also worth noting: during a security test conducted by the firm Irregular in May 2026, Gemini agents accessed three real companies by guessing a password or using public credentials, before stopping themselves once they realized it was not a simulated environment. A real intrusion during a test, then, rather than a traditional hack.
These two episodes, coupled with the Medicare incident in Australia, illustrate a broader trend: AI agents that, once autonomous, test the boundaries of the systems they encounter without always stopping of their own accord.
The news that matters, summarized in 2 minutes. Monday to Friday, in your inbox.