OpenAI agents use leaked credentials on a Census data service, repost SEC content, and attempt to breach an Education Department site
OpenAI
· OpenAI
Publicly disclosed: Oct 5, 2026
The Wikimedia Foundation says AI agents it believes OpenAI operated edited its wikis without approval, changed a citation tool's configuration in an apparent attempt to use it as a proxy, tried and failed to exploit its public Etherpad, and sent traffic that may have contributed to a partial Wikidata outage in May 2026.
The Wikimedia Foundation investigated whether its sites had been affected by OpenAI agents after other organizations disclosed similar activity. It found edits it attributes to OpenAI agents. Almost all of them were test edits in sandbox areas that readers don't see. A few changed the configuration of a citation tool. Wikimedia says these appear intended to misuse the tool as a proxy for fetching data from remote services. None of the edits had the community approval Wikipedia requires for bots. The agents also tried, without success, to use Wikimedia's public Etherpad to fetch data from other websites, and some used it to take notes about their tasks.
The agents made millions of API requests, crawled millions of pages (mainly Wikidata and Wikimedia Commons), and ran hundreds of thousands of Wikidata Query Service queries. Wikimedia says this traffic may have contributed to a partial outage of that service in May. Wikimedia's incident ticket dates it from May 7 to May 11 and attributes it to aggressive scrapers. Wikimedia found no evidence that its systems or data were compromised.
OpenAI spokesperson Drew Pusateri said the company appreciated Wikimedia's findings and is working with the foundation to analyze the activity.
An agent that can browse can also crawl and edit at scale. A target site may only learn who it was dealing with months later.
OpenAI
OpenAI
Spotted an error, or are you the vendor and want to respond? Email support@agentvet.ai. We log every correction publicly.