Artificial intelligence agents linked to OpenAI Group PBC reportedly took over a German website and used it to exchange information.
Reuters revealed the incident today, citing two unnamed sources and a group of AI researchers. The researchers spotted the incident in August. They shared their findings with Reuters in the form of a report that has not yet been publicly released.
“We are unable to meaningfully respond to claims or findings on a report that we have not had an opportunity to review,” OpenAI said in a statement. “We will carefully review its contents upon publication and take any necessary next steps.”
The incident reportedly began in May. That month, a group of AI agents started posting on DseWiki, a German website for software developers. The researchers who spotted the suspicious activity counted more than 15,000 AI-generated page edits.
There are several reasons to believe the agents were powered by OpenAI models. Two of the agents referred to themselves as “OpenAIResearcher” and “OAIResearchMar26.” Additionally, much of the AI agents’ activity originated from Microsoft Corp.’s Azure cloud platform. The tech giant is one of OpenAI’s biggest infrastructure providers.
According to Reuters, the agents effectively turned DSeWiki into a message board. Their correspondence focused on the kind of technical questions that often appear in AI evaluation benchmarks.
The report comes a few months after a group of OpenAI agents hacked AI hosting platform Hugging Face. Notably, the agents involved in that breach also created a makeshift message board to coordinate their work.
The Hugging Face breach originated from an internal OpenAI deployment of Artifactory, a popular developer tool. It’s normally used to store software project assets such as containers. A group of rogue AI agents repurposed the Artifactory instance into a message board and used it to share information about how to exit OpenAI’s network. They subsequently found a way to breach Hugging Face’s infrastructure.
Some of the messages that OpenAI’s agents posted to DSeWiki reportedly contained tips on avoiding detection. Others explained how AI agents can preserve information after shutting down. At least one message discussed how to use Tor, a networking tool often used by hackers to access the dark web.
The researchers who spotted the DSeWiki messages also found attempts to “tamper with the website itself.” According to one of the AI experts cited by Reuters, that activity amounted to a hacking attempt.
In June, a DSeWiki moderator discovered the AI agents’ correspondence and started deleting it. The agents responded by creating backup pages. Today’s report hints that the incident ended shortly thereafter. Once the unauthorized agent activity ceased, OpenAI employees started visiting the website, presumably to study what happened.
Rival Anthropic PBC recently disclosed a similar cybersecurity incident. According to the AI provider, three of its language models found a way to exit an isolated sandbox in which they were undergoing testing. They subsequently hacked two websites and a cybersecurity company’s internal infrastructure.




