OpenAI agents tried to bruteforce a UN website's API fields

intunderflow 44 points 25 comments September 27, 2026
swarmcha.se · View on Hacker News

Discussion Highlights (12 comments)

sghiassy

No company is above the law. OpenAI should be accountable for any laws their agents break

claaams

Just shut this company down. What else is it going to take. How long until they commit an act of war or treason

ares623

You would think a company that's looking to IPO very soon would be doing more due diligence, especially since its product is supposed to help other companies do said due diligence.

chanux

There must be a list of all these abuses somewhere. PS: In the same lazy energy of asking for a list instead going out and finding it or putting it together myself, are there any companies other than CloudFlare that are working on AI shields?

sanex

1. What is the harm is accessing this data 2. Why is this data private 3. What would it take to gain access to this data 4. What do we expect giving gremlins access to the internet

cmiles8

The more of these that come out the more incompetent OpenAI looks. It would appear there was a total lack of basic controls in place for running these tests.

cute_boi

Meanwhile, Astra keeps crying that it can't review the source code for safety reason.

thefourthchime

On a Lark, I asked Codex to find silhouettes for all car models so I could make a fun drag coefficient website for all cars. It found a website that had all of them but had no interest in making them available. So it went ahead and started hacking CAPTCHAs and downloading them. I was pretty flabbergasted that it would do this, but also kind of amazed. Eventually I stopped it because I realized I didn't want to be caught stealing these things. This was around April, the same time as these hacks.

Aeolun

Why is it always OpenAI agents? Based on what I’m hearing this should be Deepseek agents, or Kimi agents, or GLM agents. But the biggest threat actor is a “legitimate” company on US soil.

alexalx666

Everyone and their dog already bruteforce all API fields everywhere, maybe open ai should hack a bank or something, will sound more world ending

tedd4u

Wouldn't a company responsible for an escalating frequency and severity of cybercrime normally be sanctioned by law enforcement? Wouldn't such a company normally stop these activities for fear of civil and criminal liability?

spoaceman7777

A lot of people have apparently never read production logs at a company that has users.

Semantic search powered by Rivestack pgvector
7,763 stories · 72,001 chunks indexed