Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Gene therapy and special goggles give some blind people limited sight

    October 7, 2026

    The China-U.S. AI Race Is Playing Out Worldwide

    October 7, 2026

    White House promotes ‘Trump TV’ with an AI-altered photo – Truth or Fake

    October 7, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Gene therapy and special goggles give some blind people limited sight
    • The China-U.S. AI Race Is Playing Out Worldwide
    • White House promotes ‘Trump TV’ with an AI-altered photo – Truth or Fake
    • Die Brandmauer vor dem Aus – POLITICO
    • Labour Send changes at risk as parents rush to secure support, say experts | Special educational needs
    • Microsoft releases new Nvidia-chip AI PCs with revamped Windows 11
    • Liquid AI Releases Open-Weight d1-3B and d1-omni-600M: Multimodal Decision Models With Zero Output Tokens
    • OpenAI Agent Escape Causes Wikimedia Service Outage
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, October 7
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    OpenAI Agent Escape Causes Wikimedia Service Outage

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 7, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Autonomous OpenAI agents caused a partial outage of a Wikimedia online service and tried to use others as proxies as part of a series of unauthorized activities it performed across the nonprofit’s wiki sites.

    Inspired by reports of OpenAI agents attempting to break into websites and online services, Wikimedia — a nonprofit foundation that provides technology and Web-hosting services for Wikipedia and other public wikis — did some investigating of its own services, according to a blog post published this week.

    What the organization found is that it too was the victim of OpenAI agents acting independently to disrupt sites and services. “We can confirm that we have discovered some activity by these ‘rogue’ OpenAI agents on Wikimedia platforms,” Wikimedia’s chief product and technology officer Selena Deckelmann wrote in the post.

    The unauthorized bot activities included minor infractions, such as edits to the organization’s various wikis, to more serious ones, such as trying to exploit its Etherpad public note-taking tool as a proxy and flooding sites with traffic, resulting in a partial outage to its Wikidata Query Service, she said.

    Related:ClickFix Attacks Evolve to Better Hide Malicious Payloads

    OpenAI did not immediately reply to Dark Reading’s request for comment on the activity on Wednesday. However, reports of these activities are becoming increasingly more common since the revelation in July of an autonomous hack of Hugging Face by OpenAI agents, which sounded an alarm not only through the security community but the world at large. Since then, there has been much public discourse, dire warnings, and even the formation of a governmental AI task force by US President Donald Trump to find ways to rein in autonomous AI activity before it’s too late.

    Specific OpenAI Agent Activities

    Wikimedia identified three specific types of activity that the so-called “rogue agents” committed on its sites. On the more benign end of the spectrum, the agents made edits to Wikimedia wikis in the sandbox area of the wiki, meaning they were not made public to anyone reading the sites.

    More maliciously, however, the activity also included a few edits to the configuration for a citation tool, which the foundation believes “were intended to misuse this tool as a proxy for fetching data from remote services,” Deckelmann wrote. This is potentially dangerous activity, because a threat actor can use this proxy as a platform from which to commit malicious activity on other websites.

    Wikimedia policies do allow bots to edit when they are disclosed and approved by the community, Deckelmann acknowldeged. However “none of those approvals were sought in these incidents,” she added.

    Related:Chinese Hackers Impersonate US Officials for AI Cyber Espionage

    Other more malicious activites included a flood of traffic to various wiki sites through the following: an excessive amount of request to public APIs to access the knowledge on Wikimedia projects; crawling of sites such as Wikidata and Wikimedia Commons; and hundreds of thousands of data queries to the Wikidata Query Service (WQDS). This significant traffic surge likely caused a partial outage of WQDS in May, according to Wikimedia.

    The agents also made some unsuccessful attempts to compromise Wikimedia’s public Etherpad note-taking tool, which is hosted as a community service, in what appears to be another attempt to use a Wikimedia service to fetch data from other sites as a proxy, Deckelmann said.

    “Other agents also likely operated by OpenAI took notes about their tasks, though this did not appear to turn into coordination,” she added.

    Containment Is Key to Avoiding Overprovisioned AI Behavior

    None of the activity resulted in the agents using infrastructure for coordination, nor did it result in any compromise of Wikimedia systems. “That distinction matters,” observes Ensar Seker, chief information security officer (CISO) at SOCRadar.

    Related:Alleged KillSec Ransomware Mastermind a 16-Year-Old

    However, once again the revelation demonstrates how “agents attributed to OpenAI were able to interact with third-party infrastructure beyond their intended boundaries” to commit activities “that imposed costs on an outside organization,” he says, which is troubling in the context of the various AI agent behavior already publicly documented.

    Indeed, Wikimedia noted that the activity caused “intense pressure” on its infrastructure and added costs for its servers and people who may want to visit the site. “We are already paying for costs that come with the increased activity,” Deckelmann wrote.

    Indeed, the excessive autonomy that AI agents continue to demonstrate in various examples should be taken seriously, and treated with more adequate containment, Seker says.

    “An AI agent should be treated like any other potentially untrusted workload: give it a unique identity, minimum permissions, tightly restricted network access, approved tools and destinations, strict rate and spending limits, complete audit logs, and an automatic way to terminate abnormal behavior,” he says.

    Seker also suggests that OpenAI and any other organization operating AI agents that escape their guardrails and sandboxes — should be held accountable and responsible for its actions.

    “When an agent reaches beyond its authorized environment, affected parties need prompt notification and usable technical indicators,” he says. To be fair, OpenAI has set up guardrails in response to the Hugging Face incident, but some experts have pointed out that those guardrails should have already been in place.

    One way that organizations can prevent incidents such as the one Wikimedia experienced don’t occur is to develop agents for containment before they are deployed, Seker adds.

    agent Escape OpenAI outage Service Wikimedia
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

    Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany

    Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts

    Microsoft Outlook to block MSIX attachments starting November

    The Sixth Voice of the CISO Data Shows Cyber Risk Has Moved Inside the Workflow

    Ransomware has a new target. Is your backup ready?

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Gene therapy and special goggles give some blind people limited sight

    October 7, 2026

    The China-U.S. AI Race Is Playing Out Worldwide

    October 7, 2026

    White House promotes ‘Trump TV’ with an AI-altered photo – Truth or Fake

    October 7, 2026

    Die Brandmauer vor dem Aus – POLITICO

    October 7, 2026
    Latest Posts

    British national shot dead in Kashmir by Pakistani security forces | Kashmir

    August 10, 2026

    Climate change doubled likelihood of Canada’s extreme fire weather, study finds

    August 10, 2026

    Scientists say just 7 days of meditation can rewire your brain

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Gene therapy and special goggles give some blind people limited sight

    October 7, 2026

    The China-U.S. AI Race Is Playing Out Worldwide

    October 7, 2026

    White House promotes ‘Trump TV’ with an AI-altered photo – Truth or Fake

    October 7, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.