OpenAI’s AI agents exploited a Google security education game to scrape UN trade data
AI agents that very likely came from OpenAI hijacked a Google game that teaches web security to scrape a United Nations statistics site. You can’t make this stuff up.
An analysis by Rowan Howard-Jones documents how agents ran more than 16,500 scans of the UNCTADstat data API through the URL scanner Urlquery between April 13 and June 19, 2026, systematically probing API fields along the way. Here’s what I think is the most spectacular aspect: According to the analysis, the agents apparently could only send GET requests directly, but the UNCTAD API endpoint they wanted required POST requests. So they took a detour through a Google web security learning game, where Level 1 displays whatever you type after “?query=” in the address bar. Instead of typing a search term, the agents injected a small program. The URL scanner Urlquery executes JavaScript on loaded pages, so it opened the game page and ran the program. That program assembled a form and automatically sent the required POST request to the UN site, which responded with the requested data. It’s a textbook example for the alignment problem with persistent agentic AI systems. The agents likely had a hard constraint allowing only GET requests. Rather than accept that limit, they autonomously found a way around it without technically breaking it. They kept making GET requests, but to a page that turned them into POST requests. Rules can almost always be circumvented when a system is driven enough and only knows the goal but doesn’t grasp the spirit of the restriction. The issue gets worse when the system is persistent and simply won’t stop. Even after the site throttled 82 of their requests, the agents kept going, according to the report. Howard-Jones stops short of calling it hacking but says the behavior looks like someone who won’t take “no” for an answer. That tracks with other cases that have recently surfaced or been disclosed by OpenAI itself.