DKDKCISSPSearch
AI SecurityDEVELOPING

Wikimedia Says Rogue AI Agents Abused its Platforms

The non-profit giant, which operates Wikipedia and several other open-knowledge platforms, revealed the news in a blog post published on October 5.

DKCISSP News DeskInfosecurity Magazine9 Oct 2026, 8:30 pm
Wikimedia Says Rogue AI Agents Abused its Platforms
Image courtesy of Infosecurity Magazine. Original report
DKCISSP REPORT

In the Telegram channel which was linked to in the push notification claiming the hack, the attacker, using the name ‘Xuanyewen’ and ‘Xuanye group,’ said the incident only involves “customer information.” They claimed it “is safe on our server and will not be touched for a designated period.” According to the BBC, a sample of the stolen data it was sent by the threat actor contained more information than the "basic contact details" ASOS had previously said may have been compromised.

Upon investigating the breach, ASOS discovered that the attacker had gained access to an employee account “by impersonating a trusted contact to obtain log in credentials.” These credentials were then used to “access information on certain third-party platforms used by ASOS.” In a statement sent to the London Stock Exchange , published on October 6, ASOS said they are investigating third-party platforms which were used to communicate with customers.

ASOS’ first communication regarding the hacker claims confirmed the firm was investigating unauthorized activity "involving third-party platforms that we use to communicate with customers." The company said it took "immediate action to restrict access to the notification platforms" and is "working with our internal and external specialist advisers, as well as all relevant authorities." The company also acknowledged that basic personal information including names and contact details may have been accessed by the threat actor, but the investigators do not believe payment-card information or account passwords were impacted.

We should not allow this behavior to become the ‘new normal’ for the people or organizations that maintain it.” Deckelmann did not pull her punches, arguing that Wikimedia’s findings show how agents can drain resources and crash servers, even when they aren’t compromising data and systems.

Anastasia Tikhonova, global head of threat research at Group-IB, found that the Telegram channel included in the bizarre push notification sent to ASOS customers was brand new – created on October 6 – and that the Telegram account behind it previously carried other names, largely in gaming-item trading.

Deckelmann said her team didn’t find any evidence that their systems had data compromised or were used for coordination among agents.

However, the company emphasized that the notifications do imply any private information was accessed, or that there was a breach of a third-party system.

They also asked Claude for assistance in finding Korean Telegram data sales groups to try and sell the stolen information.

However, the fashion retailer did not mention Snowflake in any of its statements and the cloud service firm told Infosecurity it has found “no compromise of the Snowflake platform.” Group-IB’s Tikhonova noted that “being able to send a notification shows access to a customer-messaging channel, not possession of a customer database.” Will Thomas, senior threat intelligence advisor at Team Cymru, assessed that this incident likely points in the direction of some form of a software-as-a-service (SaaS) platform compromise, an approach that has been used in high-profile attacks on UK retailers over recent years.

The Pwn2Own Ireland 2026 hacking contest has concluded, with hackers collecting $1,262,000 in rewards after exploiting 98 zero-day flaws.

What happened

In the Telegram channel which was linked to in the push notification claiming the hack, the attacker, using the name ‘Xuanyewen’ and ‘Xuanye group,’ said the incident only involves “customer information.” They claimed it “is safe on our server and will not be touched for a designated period.” According to the BBC, a sample of the stolen data it was sent by the threat actor contained more information than the "basic contact details" ASOS had previously said may have been compromised.

Upon investigating the breach, ASOS discovered that the attacker had gained access to an employee account “by impersonating a trusted contact to obtain log in credentials.” These credentials were then used to “access information on certain third-party platforms used by ASOS.” In a statement sent to the London Stock Exchange , published on October 6, ASOS said they are investigating third-party platforms which were used to communicate with customers.

What changed

ASOS’ first communication regarding the hacker claims confirmed the firm was investigating unauthorized activity "involving third-party platforms that we use to communicate with customers." The company said it took "immediate action to restrict access to the notification platforms" and is "working with our internal and external specialist advisers, as well as all relevant authorities." The company also acknowledged that basic personal information including names and contact details may have been accessed by the threat actor, but the investigators do not believe payment-card information or account passwords were impacted.

We should not allow this behavior to become the ‘new normal’ for the people or organizations that maintain it.” Deckelmann did not pull her punches, arguing that Wikimedia’s findings show how agents can drain resources and crash servers, even when they aren’t compromising data and systems.

Who is affected

Anastasia Tikhonova, global head of threat research at Group-IB, found that the Telegram channel included in the bizarre push notification sent to ASOS customers was brand new – created on October 6 – and that the Telegram account behind it previously carried other names, largely in gaming-item trading.

Deckelmann said her team didn’t find any evidence that their systems had data compromised or were used for coordination among agents.

Why it matters

However, the company emphasized that the notifications do imply any private information was accessed, or that there was a breach of a third-party system.

They also asked Claude for assistance in finding Korean Telegram data sales groups to try and sell the stolen information.

Technical details

However, the fashion retailer did not mention Snowflake in any of its statements and the cloud service firm told Infosecurity it has found “no compromise of the Snowflake platform.” Group-IB’s Tikhonova noted that “being able to send a notification shows access to a customer-messaging channel, not possession of a customer database.” Will Thomas, senior threat intelligence advisor at Team Cymru, assessed that this incident likely points in the direction of some form of a software-as-a-service (SaaS) platform compromise, an approach that has been used in high-profile attacks on UK retailers over recent years.

The Pwn2Own Ireland 2026 hacking contest has concluded, with hackers collecting $1,262,000 in rewards after exploiting 98 zero-day flaws.

In total, today security researchers exploited 21 zero-days for $641,000 in cash on the final day of the contest.

Response

None of this was hidden." The three safety researchers wrote in the letter that OpenAI cannot make AI safe on its own, warning of degrading "monitorability" of frontier models and urging OpenAI and other frontier companies to refrain from "move forward with developments that further decrease monitorability." In response, an OpenAI spokesperson shared an internally circulated memo with The Wall Street Journal that said the decisions to fire the employees "were not about raising safety concerns or speaking out." An OpenAI spokesperson also told TechCrunch the three were let go after an investigation revealed a "pattern of misconduct" in "clear violation of our policies of mishandling research information" that goes beyond sharing information with an outside AI evaluation group.

The researchers were able to link all the attacks to the same IP address, which allowed them to uncover the threat actor’s deployment of AI during the campaign.

What security teams should do

Anastasia Tikhonova, global head of threat research at Group-IB, investigated the Telegram channel t.me/xuanyewengateway, included in the bizarre push notification sent to ASOS customers on October 6 where a threat actor claimed to have hacked the company via a Snowflake instance.

While CAA cannot prevent certificate issuance during an active DNS hijack, the company said restoring a restrictive policy afterward stops attackers from reusing cached domain-control validation checks to obtain new certificates.

Attribution

Infosecurity Magazine: The non-profit giant, which operates Wikipedia and several other open-knowledge platforms, revealed the news in a blog post published on October 5.

Infosecurity Magazine: The work of Integrity Technology Group has in the past enabled prolific Beijing-backed groups such as Flax Typhoon (aka Ethereal Panda , Red Juliett ) according to the advisory, published on October 8.

Infosecurity Magazine: In response, training and certification body ISACA plans to launch an AI governance certification, currently accepting applications in beta phase, in early 2027.

The Hacker News: OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported .

MORE IN AI SECURITY

More cybersecurity reporting

How AI can fix cybersecurity compliance: From dashboards to continuous execution - Help Net SecurityHelp Net Security · 8 Oct 2026, 10:30 amPoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining BotnetThe Hacker News · 7 Oct 2026, 9:03 pmApple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data AccessThe Hacker News · 7 Oct 2026, 5:11 pmIntellias Agentic ServiceOps applies governed AI across IT operations - Help Net SecurityHelp Net Security · 6 Oct 2026, 6:25 pm