An online tool that belongs to Vanderbilt University was caught up in a wave of unsanctioned communications by artificial intelligence agents run by OpenAI earlier this year.
The San Francisco-based company operates ChatGPT, a popular AI platform that can answer questions, write, code and create images, among other tasks. In an exclusive story, Reuters said a group of researchers and independent investigators found the OpenAI agents accessed a Vanderbilt tool that shortens website links, along with several other websites.
The Vanderbilt link shortener website states it is only to be used by organizations affiliated with the school and only for official communication. To access the service, departments are directed to open a help ticket. It's not
clear if the breach posed any cybersecurity risks to Vanderbilt or those who used the link shortener, or if the issue has been resolved.
Researchers also said agents from OpenAI took over a German-language wiki site, instead making it an "improvised messaging platform for cheating on tests," Reuters reported. That breach, along with the one at Vanderbilt, are among at least 10 others.
OpenAI kept the breach under wraps in the fallout over its agents hacking open-source repository Hugging Face in July, according to Reuters. OpenAI slowed the pace of its model development to retool its research and training systems after the hack caught the company unaware.
In July, Anthrophic said its Claude AI model gained "unauthorized access to the production infrastructure of three different organizations" and hacked into them on its own volition, according to a company statement.

Andrew Yoon, a researcher with California nonprofit CivAI, said OpenAI did not disclose that its agents accessed at least 18 sites between May and July.
“It's almost certain that there's more going on here that we just don't know about," Yoon told Reuters.
OpenAI did not directly address questions from Reuters about how many different sites its agents used to communicate or say why it kept the activity under wraps for months. In a statement, it said it was undertaking a broader review of agent activity and had so far "not identified other activity matching the severity or scale of Hugging Face," a breach that drew global attention and raised concerns that OpenAI was losing control of its own technology.
A Vanderbilt spokesperson did not comment on the matter on Sept. 9, and follow-up questions sent to to Vanderbilt by email were not immediately answered.
Reuters contributed to this story.
This article originally appeared on Nashville Tennessean: Vanderbilt online tool breached by rogue OpenAI agents











