OpenAI agents hacked an Australian government website in search for data

Australia’s leader said it was ‘unacceptable’ OpenAI took months to report the incident.


OpenAI’s artificial intelligence agents hacked an Australian government website and attempted to breach numerous other government and university websites. The attack appears to be the first confirmed instance of a rogue AI agent breaching a government website, adding fuel to rapidly intensifying concerns about the safety of advanced AI systems and the responsibility of the companies building them.
Speaking on the sidelines of the UN General Assembly in New York, Australian Prime Minister Anthony Albanese said an agent from the American AI lab “infiltrated” Australia’s Medicare statistics portal and “accessed both public and non-public files.” Medicare is Australia’s universal health insurance program.
Albanese said personal information does not appear to have been accessed in the breach and that there is no evidence of a broader compromise to the network, but noted “investigations are ongoing.”
“This situation is obviously unacceptable,” Albanese said, adding that he had spoken with OpenAI CEO Sam Altman “to express Australia’s extreme concern.” Despite the breach happening in June, Albanese said the tech giant only notified the government about the incident earlier this month and did so via an email to a generic “public mailbox.”
Unlike previous agent incidents, which largely involved systems being tested for their cybersecurity skills, these latest hacks were the result of a more pedestrian task — data collection — going wrong. In a statement to The Verge , OpenAI spokesperson Oscar Haines said the models were attempting to “look up answers” during an internal evaluation. “In the course of that, our models took actions we did not intend.”
The timeline of the incident and its disclosure is likely to prove particularly inflammatory in the discussions of corporate behavior and transparency that follow. Albanese stressed the delay in disclosure is particularly unacceptable. OpenAI told the BBC in an unattributed statement that it did not become aware until August, when reviewing misaligned model activity.
OpenAI spokesperson Oscar Haines told The Verge the company’s “review found no evidence of patient records being accessed,” and that “the information accessed included aggregate health statistics and internal file names.” Haines said OpenAI has notified the relevant organizations and is providing technical information to support their investigations and address potential security vulnerabilities. “Our overall review is ongoing, and we remain committed to transparency about these issues and to sharing what we learn as that work continues,” Haines said.
Verified source · The Verge
Reported by The Verge. Open the original for full media and formatting.
More in Policy
All news
PolicyTurtlemint Crashes Another 20%, PB Fintech Falls 8% On IRDAI’s Proposed Commission Caps
The rout began yesterday after IRDAI released a consultation paper proposing product- and channel-specific commission ceilings for insurance distributors
Read at Inc42
PolicyMeta employees ordered ‘attorney/client privilege’ hats while fighting child safety disclosures
Meta's lawyers have argued that certain evidence should be withheld from public view on the grounds of attorney-client privilege in the ongoing lawsuits over alleged harm to teens' safety and mental health. Lawyers suing the company said this week that the label has been applied…
Read at The Verge
PolicyDecoding The Commission Gap That Sparked A Bloodbath In Insurance Stocks
For insurance distributors, the commission earned on every policy is central to their business model. It determines how much they…
Read at Inc42
PolicyWaymo’s driverless cars continue to crash less often than people
Waymo's latest batch of self-reported data continues to affirm the company's message that its driverless cars are safer than human drivers. As policymakers continue to debate the safety and economic impact of autonomous vehicles, Waymo is hoping that its own data will help bring…
Read at The Verge