The Wikimedia Foundation announced that it had detected unauthorized activity by artificial intelligence agents it believes were operating through OpenAI. The investigation documented test changes to wikis, failed attempts to leverage a public tool, and a high volume of requests, without identifying evidence of a breach of systems or data.

In an October 5 announcement, the Wikimedia Foundation, through its head of product and technology Selena Deckelmann, described findings from an internal investigation into actions attributed to OpenAI agents. The wording remains cautious: the foundation says it believes the activities in question originated from the company’s systems.
The case concerns the use of automated agents in services designed for people and volunteer communities. Wikimedia did not announce a successful attack or information leak; it describes unauthorized actions, attempts to leverage public tools, and traffic that burdened its infrastructure.
What the Wikimedia Foundation discovered
The changes the researchers found included edits to wikis, which the announcement attributed to OpenAI agents. Almost all of them were made on test pages, that is, testbeds that are not visible to readers. Wikimedia says that no changes were published to pages visible to the general public.
A few edits were made to the referral tool configuration. The foundation believes these changes may have been intended to turn the tool into an intermediary for retrieving data from remote websites. The announcement describes the changes as potentially malicious, not a successful exploit.
Wikipedia rules allow automated programs to make edits only when they are notified and approved by the community. Wikimedia says no such approval was sought in these incidents. Most of the recorded changes remained in sandboxes and did not affect the content that readers see.
The second part concerns Etherpad, a public note-taking tool hosted by Wikimedia as a community service. Agents the foundation believes are affiliated with OpenAI unsuccessfully attempted to use it to retrieve information from other websites. Other agents reportedly kept notes there about their work, with no indication that the tool was used to coordinate them.
The investigation also recorded millions of automated requests to Wikimedia's public APIs, millions of page visits—mainly to Wikidata and Wikimedia Commons—and hundreds of thousands of queries to the Wikidata Query Service. The foundation estimates that this activity may have contributed to a partial outage of the service in May, without attributing sole responsibility to it.
See also: OpenAI Dots: New AI agents that work 24/7

No data breach reported
Wikimedia says it found no evidence that its systems or data were compromised, nor that the agents used its own platforms to coordinate. The distinction is important: the attempts and high traffic were recorded, but the announcement does not describe successful access to protected information.
The foundation is linking the incident to broader pressure from automated traffic. In a previous update, it said that since 2024, bandwidth usage had increased by 50% due to increased activity from automated programs, and that they accounted for 65% of the most demanding traffic on its platforms. This data is not attributed solely to OpenAI.
The Verge noted that the connection of the traffic to the partial outage in May remains Wikimedia's assessment and not a confirmed sole cause. The foundation is asking AI companies to monitor the behavior of their systems and help prevent and remediate the impacts they cause.

Wikimedia Foundation calls for clear identification of automated systems
The foundation's request also applies to website administrators: automated systems should be easily identifiable so that each organization can choose how to interact with them. Wikimedia notes that volunteers and security teams currently take on a significant part of identifying and undoing unwanted actions.
For open platforms, the incident highlights the need for clear access rules, limits on automated traffic, and control over tools that can be used as intermediaries to third-party websites. The SecNews technical team notes that logging requests and early identification of a bot helps in the investigation, without prejudging that every automated visit is malicious.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: UNCTADstat: OpenAI agents performed 16,500 scans at the UN
The case shows that uncontrolled agent behavior can create costs and operational risks even without a successful breach. The Wikimedia Foundation insists that companies that deploy such systems must take immediate responsibility for identifying, monitoring, and limiting their activity.
See also: OpenAI: Security researchers fired for data leak
