• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Tennessee linebacker Arion Carter was suspended over a $427 flight—now he's donating that amount to charity for every tackle he makes this season

2

Current price of silver as of Monday, September 8, 2026

3

How Canada decided to hurt its own economy, raise its inflation—and most Canadians approved because they're so angry at Trump

1

Tennessee linebacker Arion Carter was suspended over a $427 flight—now he's donating that amount to charity for every tackle he makes this season

2

Current price of silver as of Monday, September 8, 2026

3

How Canada decided to hurt its own economy, raise its inflation—and most Canadians approved because they're so angry at Trump
AIOpenAI

OpenAI’s rogue AI agents reached at least 12 more websites, researchers say

By
Beatrice Nolan
Beatrice Nolan
Tech Reporter
Down Arrow Button Icon
By
Beatrice Nolan
Beatrice Nolan
Tech Reporter
Down Arrow Button Icon
September 9, 2026, 5:31 PM ET
Sam Altman talking
OpenAI CEO Sam Altman.Photo by Matt RAMEY / AFP via Getty Images
Google source logo
Add Fortune on Google for similar content.

Independent researchers have identified multiple new websites where AI agents seemingly built by OpenAI took unauthorized actions, such as accessing websites, posting messages, and sharing data to communicate with each other.

Recommended Video

The latest revelations, discovered by a group of independent researchers known as the Nightingale collective, add to growing concerns that AI companies are struggling to control the agentic AI technology they’ve created. In August, a swarm of OpenAI’s AI agents hacked the Hugging Face website, and last week the Nightingale collective identified a swarm of rogue AI agents surreptitiously posting messages to an obscure German Wiki page.

Now, as more researchers search the web for traces of the agents, the list of affected sites continues to grow. Researchers believe the newly discovered incidents are the work of a separate swarm of AI agents than those involved in the Hugging Face breach, since these agents were authorized to access the web whereas the Hugging Face attackers had managed to escape a special a sandbox.

Although the latest crop of rogue agents did not need to escape a sandbox to perform their misdeeds, researchers said their behavior was just as alarming.

“These additional findings show that the agents involved were even more persistent and clever in finding ways to collude with each other than originally known,” Cormac Slade Byrd, one of the researchers in the Nightingale Collective, told Fortune. “They tried a variety of venues. They tried many different approaches. The new findings point towards agent activity both before and after the time window in our original report.”

Researcher Kenneth DeGraff found that the agents were trawling the open web for exposed API keys—digital passcodes that let software access online accounts and databases—then reusing those credentials to pull data from a U.S. crime‑statistics site run by the FBI. One of the passcodes had been left exposed on an obscure code-sharing page on GitHub, according to DeGraff. While the database was meant to publish public crime numbers rather than sensitive records, it underlines how easily autonomous systems can scoop up and reuse information that humans forget to lock.

“The agents did not hack a private FBI database, only circumvent anti-bot restrictions,” the researchers said of the incident. “Almost anyone could acquire these API keys, and some people with API keys did not guard them well.”

Researchers also found activity on a chemistry wiki built by a high school teacher, where agents made close to 30 edits between May and July, leaving links to help each other with tasks.

Other independent researchers traced the same swarm to simple text‑sharing sites, where the agents traded more than 100 messages that “involved agents coordinating to solve an Iowa cancer statistics task.” DeGraff also linked some of the activity to Vanderbilt University, whose public stats page showed agents hitting a single campus news URL tens of thousands of times and, in the process, writing their FBI crime‑data queries—and one user’s access key—into a log anyone could see.

The fresh data shows that the incidents of rogue agent behavior are more widespread than previously believed. OpenAI has so far only released the details of its agents’ attack on the open-source platform Hugging Face, although the company has acknowledged that additional sites were also targeted, albeit less seriously, by the escaped swarm of agents.

Representatives for OpenAI did not immediately respond to a request for comment from Fortune.

The growing list of affected sites is likely to fuel concern over whether the companies deploying them have proper oversight of what their systems get up to once let loose—especially when outside researchers, rather than the companies themselves, uncover and disclose the full scale of the problem. OpenAI has faced some criticism already over failing to disclose the German Wiki incident, with some experts calling for tighter regulation that would force companies to make such incidents public.

There has been growing concern among many in the industry over the recent unintended AI agent behavior, with several prominent researchers recently calling for a coordinated slowdown of AI development while risks are managed and assessed.

Fortune Daily breaks the traditional barrier between audience and newsroom. The show transforms Fortune’s trusted reporting into actionable, conversational, and entertaining insights for an emerging class of business leaders. Watch here.
About the Author
By Beatrice NolanTech Reporter
Twitter icon

Beatrice Nolan is a tech reporter on Fortune’s AI team, covering artificial intelligence and emerging technologies and their impact on work, industry, and culture. She's based in Fortune's London office and holds a bachelor’s degree in English from the University of York. You can reach her securely via Signal at beatricenolan.08

See full bioRight Arrow Button Icon
Google source logo
Add Fortune on Google for similar content.

Latest in AI


Most Popular

Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • TikTok icon
  • YouTube icon

    Latest in AI


    Most Popular

    © 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
    FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.