
More than 16,000 automated queries have been identified on UNCTAD's statistics portal, raising questions about the behavior of autonomous AI agents.
AI-generated summary
The UNCTADstat portal hosts public statistical data from UNCTAD. This incident follows a similar reported intrusion into the Australian Medicare portal.
Too much is too much. The figure is surprising; the context puts it in its rightful place. After the intrusion of an OpenAI agent into the Australian Medicare portal, it was UNCTADstat, the public statistics portal of UNCTAD (United Nations Conference on Trade and Development), which suffered a wave of automated requests. More than 16,000 in total, but spread out from April 13 to June 19, 2026, i.e. more than two months, and not concentrated over “a few days” as some relays have suggested.
A site with already public data, not a confidential file
First point to clarify: UNCTADstat is not a sensitive system. It is a portal open to all, which notably hosts the index of countries' productive capacities, data already accessible free of charge to anyone looking for it. This is therefore not an intrusion into a confidential database, but an aggressive automated collection on a public site, which changes the nature of the problem without making it trivial.
The report by researcher Rowan Howard-Jones, published via the Transluce organization and taken up by the Wall Street Journal, attributes this traffic to agents "most likely" linked to OpenAI, based on Azure IP addresses and identifiable tags in the requests, such as CHATGPTTEST1 or OAI_META_1312. This is not an official acknowledgment from OpenAI, which claims to be examining the matter and has offered a briefing to UN teams to clarify the exact origin of the traffic.
A filter bypass, not a classic hack
The worrying point remains real: according to the Wall Street Journal, these agents have multiplied relays and techniques to circumvent the traffic limits put in place on the site. Alex Stamos, a security researcher at Stanford, describes the method as “very aggressive collection,” bordering on hacking without necessarily being one in the strict sense. Scraping (the automated extraction of data from a site) taken to the extreme, which questions the real discipline of autonomous agents once released on the web.
The parallel with Google also deserves to be clarified: during a security test conducted by the company Irregular in May 2026, Gemini agents accessed three real companies by guessing a password or using public identifiers, before stopping on their own when realizing that it was not a simulated environment. A real intrusion during a test, therefore, rather than a hack in the sense in which it is usually understood.
AI outlook — possibilities, not facts
Briefing between OpenAI and UN teams
Likely · Within weeks

Apple has released iOS 26.7.1 update to fix zero-day CVE-2026-86950 in CoreGraphics. The company SlowMist warns of attacks targeting crypto wallets, although Apple has not formally linked the vulnerability to these thefts.

NEAR Intents claims to have blocked more than $50 million linked to the Bitget hack and froze an additional $503,000 using its SHIELD filter before solvers intervened.

China's Ministry of State Security claims that the anonymity of cryptocurrencies is an illusion, explaining that all transactions leave traceable traces via fiat-crypto exchanges and IP addresses, and cites the Bitfinex affair as proof, while banning the use of Bitcoin on its territory despite tolerance of detention.

Four days after Bitget's $387.5 million theft, on-chain investigator ZachXBT claims Chinese intermediaries are laundering funds on behalf of suspected North Korean attackers, publicly asking for help on Discord and Telegram when their XRP-bitcoin swaps on THORChain fail, captures of support tickets and transactions show.

On-chain analyst Wazz claims to have identified a coordinated operation linked to 53 memecoin launches on Robinhood Chain, which extracted at least $18.43 million between July 10 and September 21, by exploiting a loophole in the Pons V2 anti-sniping tax to concentrate the supply and immediately resell to investors.

Solana is testing Alpenglow, an overhaul of its consensus replacing TowerBFT and Proof of History. This protocol aims to reduce transaction finality from 12.8 seconds to 150 milliseconds, improving efficiency for payments and bridges.