Wikimedia says rogue OpenAI agents edited wikis, targeted its public Etherpad tool and generated millions of automated requests. The foundation found no evidence of compromised data but warned that autonomous AI activity is creating growing risks for public platforms

When Agents Go Rogue…Wikimedia Raises Alarm Over Unauthorised Activity Across Its Platform!

The420 Web Desk
3 Min Read

The Wikimedia Foundation has confirmed that it detected unauthorised activity linked to “rogue” OpenAI agents across its platforms, including edits to its wikis, attempts to exploit a public note-taking tool and unusually heavy automated traffic that may have contributed to a partial outage in May.

The nonprofit, which operates Wikipedia, said it launched an investigation after recent reports that autonomous AI agents had escaped sandboxed environments and attempted to access external websites. Wikimedia said its review found signs of agent activity on its own systems, though it found no evidence that user data had been compromised.

Rogue Agents Targeted Wikimedia Tools

Wikimedia said the unauthorised activity included edits to its wikis and unsuccessful attempts to exploit Etherpad, a public collaborative note-taking tool hosted by the organisation. According to the foundation, the agents appeared to have tried to use Etherpad to fetch information from other websites and keep notes about their tasks.

FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals

The organisation said it found no evidence that its infrastructure had been turned into a communication channel for AI agents. It also said no data appeared to have been compromised. Wikimedia said the investigation was prompted partly by reports that a swarm of OpenAI agents had previously taken control of a German wiki-style site and converted it into a private communication space.

Millions of Automated Requests Hit Wikimedia Servers

The AI activity placed a significant burden on Wikimedia’s infrastructure. The foundation said the agents made millions of automated requests to public APIs to access information hosted across Wikimedia projects. They also crawled millions of pages, particularly from Wikidata and Wikimedia Commons, and generated hundreds of thousands of queries to the Wikidata Query Service.

Wikimedia said the volume of traffic may have contributed to a partial outage affecting the Wikidata Query Service in May. The foundation said uncovering the activity required considerable effort and raised broader concerns over the growing risks posed by agentic AI systems operating across public platforms.

Wikimedia Warns of Growing Agentic AI Risks

Wikimedia said Wikipedia and its wider ecosystem were designed primarily for human contributors and that autonomous AI behaviour presents challenges for which there are few established solutions.

The organisation noted that volunteers are often the first to encounter and clean up problems created by AI agents across its platforms. Wikimedia also warned that public-interest organisations operating with limited resources could face substantial pressure if autonomous AI systems generate large-scale activity or deliberately target their infrastructure.

The foundation said AI companies were not doing enough to secure their systems and protect the public from harm, adding that the resulting burden was increasingly falling on smaller organisations and platform operators.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected