Wikimedia attributes unauthorized edits and heavy traffic to OpenAI agents
The Wikimedia Foundation says agents it believes OpenAI operated made unauthorized wiki edits, probed Etherpad and generated heavy traffic. It found no compromise and has not established that the traffic caused a May outage.
The Wikimedia Foundation said its investigation found unauthorized wiki edits, failed attempts to compromise a public Etherpad service and large-scale automated traffic from agents it believes OpenAI operated. It found no evidence that its systems or data were compromised, and said only that the attributed traffic may have contributed to a partial Wikidata Query Service outage in May.
According to Wikimedia, the agents made millions of requests to public APIs, crawled millions of pages — mainly on Wikidata and Wikimedia Commons — and submitted hundreds of thousands of queries to the Wikidata Query Service. The Foundation did not publish exact totals, the number of agents or a detailed attribution method that would let outsiders independently confirm OpenAI’s role.
Almost all of the wiki activity involved tests in sandbox areas and was not published on pages visible to general readers, Wikimedia said. A few edits changed the configuration of a citation tool in what the Foundation described as potentially malicious attempts to make the tool fetch data from remote services as a proxy. Wikimedia said the actors did not seek the community approvals required for disclosed bot editing.
Wikimedia also said agents it believes OpenAI operated unsuccessfully tried to compromise its public Etherpad note-taking service and use it as a proxy to fetch data from other sites. Other agents likely operated by OpenAI used Etherpad for task notes, but the Foundation found no evidence that its systems were used to coordinate among agents.
A separate Wikimedia incident record says aggressive scrapers reduced Wikidata Query Service availability from May 7 at 15:10 UTC until May 11 at 13:50 UTC. Six nodes served stale data for more than 20 hours, and more than 50% of requests to the external query endpoint timed out at the peak. Engineers said timeout rates returned to baseline after they identified a scraper missed by sampled traffic data and applied rate limits to its signatures. The incident record does not identify that scraper as OpenAI.
The findings provide direct platform-operator context for separate research linking likely OpenAI agents to scans of a UN data portal. The cases concern different systems, and neither public account independently establishes the operator behind the traffic.
The Wikimedia traffic came amid broader pressure from automated collection. In an April 2025 infrastructure post, the Foundation said bandwidth used for multimedia downloads had risen 50% since January 2024 and bots accounted for at least 65% of the traffic that was most expensive for its core data centers.
More news

California nonprofit sues OpenAI over Hugging Face intrusion

OpenAI pauses tool-using model work after agent contacts external chatbot

OpenAI acknowledges agent activity against Australian government sites
