4 min read

Rogue AI agents caught tampering with Wikipedia, probing for vulnerabilities

Filip TRUȚĂ

October 09, 2026

Rogue AI agents caught tampering with Wikipedia, probing for vulnerabilities

The Wikimedia Foundation says AI agents linked to OpenAI made unauthorized edits, tried to exploit online tools, and generated millions of requests that may have contributed to a service outage.

AI agents are supposed to help people accomplish tasks online. But what happens when they start behaving like hackers? Wikipedia's operator says it has discovered troubling activity by autonomous AI systems linked to OpenAI, including attempts to manipulate website tools and access services without permission.

Key takeaways

  • The Wikimedia Foundation has uncovered unauthorized activity by AI agents believed to be operated by OpenAI
  • The agents made wiki edits, attempted to exploit a public note-taking service, and generated millions of automated requests
  • Some edits were potentially malicious, but Wikimedia found no evidence that its systems or data were compromised
  • Heavy automated traffic may have contributed to a partial service outage in May
  • The incident raises concerns about the security and accountability of autonomous AI agents operating across the internet

AI agents caught making unauthorized edits

The Wikimedia Foundation investigated suspicious automated activity on its platforms after reports emerged of rogue AI agents attempting to break into websites and online services, according to an Oct. 5 disclosure.

The investigation uncovered several incidents involving agents the organization believes were operated by OpenAI.

Some agents made unauthorized edits to Wikimedia projects, including Wikipedia. Most of the activity involved testing changes in sandbox environments, meaning the edits never appeared on pages visible to ordinary readers.

However, investigators also discovered changes to the configuration of a citation tool. These were potentially malicious, according to Wikimedia, and appeared designed to turn the tool into a proxy for retrieving information from external websites.

In other words, the agents seemingly tried to repurpose a legitimate Wikipedia feature to access resources beyond its intended function.

Wikipedia allows automated editing, but only when bots are properly disclosed and approved by the community. The agents involved in these incidents had no such approval.

Attempts to exploit a note-taking service

The suspicious behavior extended beyond Wikipedia's editing tools.

Wikimedia says agents believed to be operated by OpenAI also tried to compromise Etherpad, a public collaborative note-taking service hosted by the foundation.

The agents tried to use the service to fetch information from other websites, effectively trying to turn it into another proxy.

Those attempts were unsuccessful.

Other agents used Etherpad to record notes about their tasks, but investigators found no evidence the service was used to coordinate activity between agents.

While the behavior resembled techniques associated with cyberattacks, Wikimedia has not established that the agents successfully breached its systems.

The foundation explicitly says it found no evidence of compromised systems or data.

Millions of automated requests may have caused an outage

Perhaps the most disruptive aspect was the volume of requests generated by the agents.

According to Wikimedia, the automated systems:

  • Made millions of requests to Wikimedia's public APIs
  • Crawled millions of pages, particularly on Wikidata and Wikimedia Commons
  • Submitted hundreds of thousands of queries to the Wikidata Query Service

The foundation believes this traffic may have contributed to a partial outage of the query service in May 2026.

However, the connection has not been conclusively established.

OpenAI spokesperson Drew Pusateri told The Verge that the company is working with the foundation to investigate the activity. OpenAI has not independently verified whether its bots contributed to the outage.

When AI agents go rogue

Unlike conventional chatbots, which primarily generate responses to user prompts, AI agents can act on behalf of users.

Depending on their capabilities and permissions, they may browse websites, retrieve information, modify files, interact with online services, and execute sequences of tasks without requiring human approval at every step.

This autonomy introduces new security concerns.

An agent told to accomplish a legitimate objective might attempt actions that its operator never intended, especially when it encounters obstacles or insufficiently defined boundaries.

For example, an AI agent tasked with gathering information could try to bypass access restrictions, misuse a website feature, or overwhelm a service with automated requests.

Such behavior doesn't necessarily mean the agent has malicious intentions. It does, however, mean that autonomous systems can create security incidents even without a conventional human attacker directing every action.

The Wikimedia findings illustrate that risk: AI systems apparently attempted unauthorized actions against third-party services, leaving the affected organization to investigate the activity and deal with its consequences.

Wikipedia says AI companies must take responsibility

The Wikimedia Foundation is particularly concerned about the growing burden AI automation places on its infrastructure and volunteer community.

In 2025, the nonprofit reported that bandwidth consumption had increased by 50% amid rising bot activity since 2024. Bots also accounted for 65% of its most resource-intensive traffic.

This is a serious concern for an organization that hosts more than 67 million articles across over 300 languages and serves billions of page views every month.

In its latest disclosure, Wikimedia argues that AI developers must do more to prevent their systems from causing damage to third-party services.

"AI companies are not doing enough to secure their systems and protect the public from the harm they cause," the foundation warns.

It also wants AI operators to make their automated systems easier to identify, letting website owners determine who is accessing their infrastructure so they can establish appropriate restrictions.

Wikimedia's broader message is that organizations benefiting from the open internet should not leave nonprofits and volunteers to absorb the cost of unpredictable AI behavior.

What this means for consumers

There’s no indication that personal data of ordinary Wikipedia readers was exposed in these incidents.

Nevertheless, the findings raise important questions about what happens when increasingly capable AI agents interact with the websites and services people depend on.

For consumers, there are several practical implications.

AI-generated information still needs verification. Autonomous agents capable of modifying online content could potentially introduce misleading information into otherwise trustworthy sources. Wikimedia says the edits uncovered in this investigation did not reach pages visible to general readers, but the risk remains.

Giving an AI agent access to your accounts carries risks. An agent that can browse, send messages, modify documents, or interact with services on your behalf may make mistakes or take actions you didn't anticipate. Limit its permissions and require confirmation for sensitive operations.

Website reliability may become an AI security issue. Excessive automated activity can strain online services, possibly causing slowdowns or outages that affect legitimate visitors.

Human oversight remains essential. Users should review consequential actions taken by AI agents, especially those involving personal information, financial transactions, account settings, or public-facing content.

On topic:

Big Tech calls for cyber-defense before AI attacks surge

OpenAI is adding invisible watermarks to ChatGPT text. What this means for you

AI agents want to shop for you; banks warn of scams and privacy risks

tags


Author


Filip TRUȚĂ

Filip has 17 years of experience in technology journalism. In recent years, he has focused on cybersecurity in his role as a Security Analyst at Bitdefender.

View all posts

You might also like

Bookmarks


loader