The Wikimedia Foundation says rogue OpenAI agents made unauthorized Wikipedia edits and may have been partially responsible for a May outage.
As Wikimedia Chief Product and Technology Officer Selena Deckelmann revealed Monday, Wikipedia hosts over 67 million articles in more than 300 languages and gets up to 15 billion page views per month.
However, last year Wikimedia saw 65% of the most resource-consuming traffic on its projects come from bots, amid a 50% increase in bandwidth usage due to the surge in bot activity.
While investigating whether its websites have also been affected by AI agents, Wikimedia found that OpenAI agents made edits to wikis without prior approval, unsuccessfully tried to exploit a public note-taking tool, and made millions of API requests and data queries while scraping Wikimedia sites (which may have contributed to an outage in May).
“We’ve identified edits to Wikimedia wikis that we believe are from AI agents operated by OpenAI. These edits were not published to pages with visibility to general readers; almost all of them were testing edits in ‘sandbox’ areas of the wiki,” Deckelmann said.
The rogue bots also tried to compromise Wikimedia’s public Etherpad citation tool by making “potentially malicious edits” to its configuration, likely to use it as a proxy when fetching data from other online platforms.
Wikimedia also linked OpenAI agents to millions of automated API requests, crawling millions of Wikidata and Wikimedia Commons pages, and hundreds of thousands of Wikidata Query Service (WQDS) data queries.
“While OpenAI admits to agents behaving ‘unpredictably,’ they must also acknowledge their responsibility to monitor and prevent these risks. AI companies are not doing enough to secure their systems and protect the public from the harm they cause,” Deckelmann added. “That burden is falling onto everyone else, including smaller organizations. At a minimum, their systems should operate in a way that non-profit website owners like us can easily identify, and choose how they interact with our services.”
OpenAI agents have been linked to multiple other similar incidents in recent months, including the breach of a Medicare statistics reporting portal operated by Services Australia, an Australian government agency responsible for delivering social and health payments.
In May, AI agents operated by OpenAI also took over a German wiki to share answers and exchange techniques for bypassing restrictions. Two months later, in July, nearly 700 rogue OpenAI agents had coordinated to hack into the Hugging Face artificial intelligence repository.
However, this problem is not unique to OpenAI. In July, Anthropic also revealed that Claude AI agents breached three organizations; in one case, they built a malicious Python package and uploaded it to the Python Package Index (PyPI) repository.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
DIVD says Zammad zero-days enabled AI-driven network breach
Automated AI agent used to breach cybersecurity nonprofit DIVD
OpenAI hacked Australian Medicare govt site, probed data providers
OpenAI details more cases of AI agents taking unauthorized actions
Spain’s data agency gets first report of AI-powered data breach
Anthropic asks Claude users to share voice data for AI model training
ShinyHunters hacker reportedly detained in Jordan, aiding FBI
Citrix patches NetScaler SAML zero-day exploited in attacks
Your access review passed cleanly, but it never saw the agents swimming under the surface. See how Token Security fishes out every one of them.
73% of orgs feel prepared for attacks. 82% had a browser incident last year anyway.
Free Identity Governance for up to 150 Users: Try Our Community Edition
Free Identity Governance for up to 150 Users: Try Our Community Edition
Overdue a password health-check? Audit your Active Directory for free
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



