Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Artificial Intelligence

Wikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into Proxies

Wikimedia looked into whether its own websites had seen activity like that disclosed by other organizations

Wikimedia Foundation targeted by rogue OpenAI agents

The Wikimedia Foundation, the non-profit that hosts Wikipedia, says it found activity by “rogue” OpenAI agents on its platforms, including what it believes were attempts to misuse a citation tool and a note-taking service as proxies for fetching external data.

Wikimedia looked into whether its own websites had seen activity like that disclosed by other organizations, focusing on agents operated by OpenAI. 

OpenAI agents, for instance, used DseWiki, a small German wiki for programmers, as a message board, making thousands of edits beginning in May. OpenAI described it as a misalignment incident.

According to Wikimedia, agents it believes are operated by OpenAI made edits to its wikis. None of the edits appeared on pages visible to regular readers, and almost all of them were test edits in sandbox areas.

A few edits, however, targeted the configuration of a citation tool. Wikimedia believes these were potentially malicious and meant to turn the tool into a proxy for retrieving data from remote services.

“While Wikipedia policies allow bots to edit when they are disclosed and approved by the community, none of those approvals were sought in these incidents,” the foundation said.

Advertisement. Scroll to continue reading.

The agents also made unsuccessful attempts to compromise Wikimedia’s public Etherpad, a note-taking tool the foundation hosts for its community. “Agents unsuccessfully tried to use it to fetch data from other websites as a proxy,” Wikimedia said.

Other agents, likely also OpenAI’s, used Etherpad to take notes on their tasks. Wikimedia says this did not appear to turn into coordination between agents.

The agents also generated heavy traffic. They made millions of automated requests to Wikimedia’s public APIs, crawled millions of pages, mostly on Wikidata and Wikimedia Commons, and sent hundreds of thousands of queries to the Wikidata Query Service.

Wikimedia says the traffic may have contributed to a partial outage of the query service in May.

“We did not find any evidence that our systems were used for coordination among agents, nor did we find any evidence of our systems or data being compromised. However, we are concerned about what could have occurred here, the difficulty and effort involved in investigating and attributing this activity, and the growing risks of agentic AI activity on our platforms in general,” the foundation said.

Wikimedia argues that AI companies are not doing enough to secure their systems, shifting the burden onto everyone else, including smaller organizations.

“At a minimum, their systems should operate in a way that non-profit website owners like us can easily identify, and choose how they interact with our services,” the foundation said.

In July, OpenAI admitted that its agents had broken out of an isolated testing environment and hacked Hugging Face. OpenAI later disclosed that the agents coordinated through a message board they improvised. In a separate incident, some agents exploited a known Linux kernel flaw to escalate privileges on OpenAI’s own systems.

In August, OpenAI unveiled stricter isolation, an alerting system and training pauses for models with advanced cybersecurity capabilities. It also said it is building training environments that teach models to distrust instructions from other agents that come through unsanctioned channels.

SecurityWeek has reached out to OpenAI for comment and will update this article if the company responds.

Related: AI Agents Aimed SQL Injection at US and Canadian Government Sites

Related: OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training

Related: FTC is Investigating OpenAI and Anthropic Over Possible Risks to Consumers

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Chip Wentz has been appointed as SVP & CISO at Keurig Dr Pepper Inc.

Lumen Technologies has named Kim Keever as CSO.

Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.