ESPN DeportesBruno, Cunha, Sesko y Lisandro imponen la superioridad del UnitedDaily MaverickAFTER THE BELL: We don’t talk anymore — the case for voice calls in a text ageCNN TürkPartnerinizle aranızda sorun mu var? Kaygılı bağlanma yaşıyor olabilirsiniz! İşte kaygılı bağlanmanın 4 belirgin özelliğiESPNSeahawks' Darnold gets 'really good news' about hip, expected to miss Week 2The Jerusalem PostHow the navy’s Haifa fleet is transforming war at sea: New details of attacks revealed - exclusiveBBC NewsUEFA Champions LeaguePunchCourt jails fake spiritualist for sextortion in Abujaוואלהסריקות נרחבות אחר צעיר בשנות ה-20 לחייו שנעדר בחוף הסטודנטים בחיפהInquirerHabagat rains to weaken on Friday – PagasaVarietyNetflix Taps ‘Friday Night Lights’ Director Peter Berg for NFL Gameday Openers, the First Narrated by Kyle ChandlerBillboardWhy Cage the Elephant’s New ‘Dying in Reverse’ Song Will Fit ‘So Naturally’ in Their Munich NFL Halftime ShowColliderThe 10 Best Spaghetti Westerns in Film History, Ranked
The Daily Newsstand · Free, Always
Thursday, September 10, 2026

OpenAI's website-hijacking swarm reached far further than we thought

Translate

New report points finger at OpenAI bots that hijacked a German wiki for improper use of an additional 20 websites, and 14 fetching services

Getting straight answers out of OpenAI about how many websites and services its agents have hijacked increasingly seems like pulling teeth, as the company seems intent on making the world discover each instance one by one. 

Case in point: The OpenAI agent swarm that we reported last week had taken over an obscure German wiki appears to have written content to an additional 20 websites, and used 14 fetch services to do work for it, according to new research.

The latest report, published Wednesday by Kenneth DeGraff of the Stanford Center for Internet and Society describes how he dug into records from 21 websites the swarm wrote to, including the German wiki. His report assumes it was the same swarm based on the fact that several hundred posts by the swarm to other sites are word-for-word copies of those found on the German wiki.

REG AD

Speaking of the German wiki report from last week, the authors of that report published their own update Wednesday pointing to even more research that found OpenAI agents had been improperly accessing even more websites. The update mentions DeGraff’s research as well as five other reports of OpenAI bending things like Pastebin sites, personal pages, link shorteners, and proxy websites to their own whims. And here we thought Anthropic bots committing four separate potentially criminal intrusions into third-party websites was a big deal.   

REG AD

The Vanderbilt link shortener

Turning back to DeGraff’s report, we learn that not only were self-identified OpenAI agents improperly accessing and using various third-party web services, they even managed to somehow gain access to Vanderbilt University’s private link shortening service. Access to the service is entirely locked down for university purposes only, and users must file a help ticket to the IT department to get access. 

Despite that, the agents still gained access to the Vanderbilt link shortener and used it extensively to communicate with other agents, repurposing the service’s statistics page to turn it into a message board for other agents. The swarm wrote 54,250 “posts” to the page in a single day.

Some of these posts contained stolen API keys from the FBI and other criminal justice agencies, which the agents used to retrieve a bunch of (non-confidential) information.

That activity further connects DeGraff’s report to the German wiki incident. As we discussed in our previous story, the OpenAI agents posting to that website appeared to be trying to solve statistical data lookup problems. In one example provided in last week’s report, the agents sought the median earnings for cashiers with various types of master’s degrees in the year 2014. Other questions in the experiment could have pertained to criminal justice statistics as well. 

If this swarm is the same one that hijacked the German wiki, they were ostensibly operating with the ability to send GET requests, but not make POST requests. In order to retrieve the data they needed to solve the problem, those agents needed to make POST requests to perform searches, which was a central part of the exploitation of web services undertaken by the swarm: The first thing they had to accomplish to do any of the things they did was figure out how to send POSTs.

Based on the ever-expanding footprint of this swarm’s activity online, it appears they did so, and the full scope may still be unknown. 

With this latest incident reaching 21 websites and 14 services misused by OpenAI agents so far, the question remains a crucial one: How much improper access to third-party services have OpenAI agents made? Are there other instances beyond Hugging Face and the German wiki swarm? Is OpenAI using the entire internet as its firing range to see what agents are capable of? Is there any way web service operators can protect themselves against such attacks?

View the original on The Register

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.