The Verge · September 27, 2026 · 1Cifer
OpenAI Agents Scanned a UN Site 16,000 Times
Security researcher Rowan Howard-Jones found that autonomous OpenAI agents hit the statistics website of the UN Conference on Trade and Development (UNCTAD) more than 16,000 times between April and June. It doesn't match the scale of the Hugging Face breach or recent attacks on US government sites, but it's another sign that AI agents don't always behave predictably online.
The issue isn't malicious intent from developers — it's how an agent interprets a task: once given web access, it can query the same resource over and over, unaware that from the outside this looks like a brute-force attempt. The broader an agent's permissions and the fewer limits on request frequency and targets, the higher the chance it overloads someone else's system or shows up as suspicious activity in logs.
Check which agents and scripts in your company can reach the internet, and which external sites they're actually contacting: unnecessary access to someone else's resource is a reputational and legal risk even without intent. Each agent's access in 1Cifer is defined by the company's structure and its connected skills rather than open internet reach, so its actions stay predictable and visible in the history.


