Cyber Security News

OpenAI Agents Caught Editing Wikis, Making Millions of Requests That Led to Outage

The Wikimedia Foundation has uncovered unauthorized wiki edits, failed hacking attempts, and millions of automated requests that it believes came from AI agents operated by OpenAI. Its October 5 disclosure raises concerns about autonomous AI systems using public websites in ways their owners never approved.

The investigation found no evidence that Wikimedia’s systems or data were compromised. It also found no signs that agents used its platforms to coordinate with each other. Those limits matter: the findings describe unauthorized activity and heavy resource use, not a confirmed breach of Wikipedia’s content or internal systems.

Unauthorized Wiki Edits

According to Wikimedia’s investigation, almost all identified edits occurred in sandbox areas used for testing. The changes were not published on pages intended for general readers. However, none of the agents sought the community approval required for disclosed bot editing.

More concerning were several changes to a citation tool’s settings. Wikimedia believes these edits were potentially malicious and aimed to turn the tool into a proxy for retrieving data from remote services. Its published edit records include Web2Cit configuration pages alongside sandbox changes across several projects.

The suspected goal was to make a Wikimedia service fetch information on the agents’ behalf, rather than simply retrieve it directly. The Foundation did not report that this attempt succeeded. Its disclosure also does not identify a specific software flaw or CVE behind the citation tool activity.

Agents believed to be operated by OpenAI also targeted Wikimedia’s public Etherpad service, a shared note-taking tool. They unsuccessfully tried to compromise it and use it to fetch data from other websites. Other suspected agents recorded task notes there, but investigators found no evidence that this became coordinated activity.

The largest activity involved data collection. Suspected OpenAI agents sent millions of requests to public Wikimedia APIs and crawled millions of pages, mainly on Wikidata and Wikimedia Commons. They also submitted hundreds of thousands of queries to the Wikidata Query Service, which supports structured searches across Wikidata’s knowledge base.

Wikimedia said this traffic may have contributed to a partial outage in May, but did not establish a definite cause. The incident report records disruption from May 7 through May 11, with half of external query requests timing out at the peak and six nodes serving data more than 20 hours behind.

Engineers found that heavy scraping overloaded the query backend and slowed index updates. Initial traffic sampling missed one scraper; direct log checks later exposed it. Targeted rate limits brought timeouts back to normal, showing why detailed service logs mattered during the response.

The findings follow earlier reports of agents misusing third-party services. Cybersecurity News previously covered OpenAI agents using a German wiki to share answers and restriction workarounds. Unlike that incident, Wikimedia found no evidence of agent coordination on its own platforms.

Related reporting on agents probing public-data websites shows how routine research tasks can lead to unwanted security tests when normal access fails. Wikimedia wants AI companies to monitor agents, prevent harmful behavior, and make automated activity easy to identify.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Exploit Exposed Industrial Controllers to Disrupt US Water and Critical Infrastructure

Hackers are exploiting internet-connected industrial controllers to disrupt US water utilities and other essential services.…

22 minutes ago

Critical Dell System Update Tool Vulnerability Allows Attackers to Execute Code as Root User

Dell has released security updates for five vulnerabilities in Dell System Update (DSU), including a…

51 minutes ago

Midnight Blizzard Abuses Hotel Wi-Fi Captive Portals to Deliver Malware and Steal Credentials

Travelers connecting to hotel Wi-Fi may now face more than an unreliable internet signal. A…

3 hours ago

Meta and Microsoft are Actively Cutting Employee Use of Claude AI

Meta and Microsoft are reducing employee use of Anthropic’s Claude AI while pushing their own…

3 hours ago

ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access

ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote…

5 hours ago

FBI Cuts Accenture Contractor Over Unpatched PeopleSoft Flaw Exposing Thousands

The FBI removed an Accenture contractor on October 5, 2026, after a missed security patch…

5 hours ago