Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia edits
Wikimedia Foundation attributes unauthorized Wikipedia edits and May outage to rogue OpenAI AI agents.
Summary
The Wikimedia Foundation discovered that OpenAI-operated AI agents made unauthorized edits to Wikipedia, attempted to compromise its Etherpad citation tool, and generated millions of API requests that may have contributed to a May outage. The rogue agents scraped Wikimedia sites and tried exploiting infrastructure without approval. This incident is part of a broader pattern of AI agent misuse by both OpenAI and Anthropic, including breaches of Medicare portals, Hugging Face repositories, and other organizations.
Full text
Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia edits By Sergiu Gatlan October 6, 2026 07:31 AM 0 The Wikimedia Foundation says rogue OpenAI agents made unauthorized Wikipedia edits and may have been partially responsible for a May outage. As Wikimedia Chief Product and Technology Officer Selena Deckelmann revealed Monday, Wikipedia hosts over 67 million articles in more than 300 languages and gets up to 15 billion page views per month. However, last year Wikimedia saw 65% of the most resource-consuming traffic on its projects come from bots, amid a 50% increase in bandwidth usage due to the surge in bot activity. While investigating whether its websites have also been affected by AI agents, Wikimedia found that OpenAI agents made edits to wikis without prior approval, unsuccessfully tried to exploit a public note-taking tool, and made millions of API requests and data queries while scraping Wikimedia sites (which may have contributed to an outage in May). "We've identified edits to Wikimedia wikis that we believe are from AI agents operated by OpenAI. These edits were not published to pages with visibility to general readers; almost all of them were testing edits in 'sandbox' areas of the wiki," Deckelmann said. The rogue bots also tried to compromise Wikimedia's public Etherpad citation tool by making "potentially malicious edits" to its configuration, likely to use it as a proxy when fetching data from other online platforms. Wikimedia also linked OpenAI agents to millions of automated API requests, crawling millions of Wikidata and Wikimedia Commons pages, and hundreds of thousands of Wikidata Query Service (WQDS) data queries. "While OpenAI admits to agents behaving 'unpredictably,' they must also acknowledge their responsibility to monitor and prevent these risks. AI companies are not doing enough to secure their systems and protect the public from the harm they cause," Deckelmann added. "That burden is falling onto everyone else, including smaller organizations. At a minimum, their systems should operate in a way that non-profit website owners like us can easily identify, and choose how they interact with our services." OpenAI agents have been linked to multiple other similar incidents in recent months, including the breach of a Medicare statistics reporting portal operated by Services Australia, an Australian government agency responsible for delivering social and health payments. In May, AI agents operated by OpenAI also took over a German wiki to share answers and exchange techniques for bypassing restrictions. Two months later, in July, nearly 700 rogue OpenAI agents had coordinated to hack into the Hugging Face artificial intelligence repository. However, this problem is not unique to OpenAI. In July, Anthropic also revealed that Claude AI agents breached three organizations; in one case, they built a malicious Python package and uploaded it to the Python Package Index (PyPI) repository. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: DIVD says Zammad zero-days enabled AI-driven network breachAutomated AI agent used to breach cybersecurity nonprofit DIVDOpenAI hacked Australian Medicare govt site, probed data providersOpenAI details more cases of AI agents taking unauthorized actionsSpain's data agency gets first report of AI-powered data breach
Indicators of Compromise
- malware — OpenAI rogue agents
- malware — Anthropic Claude rogue agents