HeadlinesBriefing favicon HeadlinesBriefing.com

OpenAI Agent Hacked Australian Government Website

Hacker News •
×

Australia said on Wednesday (Sep 23) an OpenAI agent breached a government health data portal in June, gaining unauthorised access to files, in what could be the first known instance of an AI agent hacking a government website. The breach is one of the highest-profile incidents of AI agents accessing external systems outside the United States. Prime Minister Anthony Albanese said the OpenAI agent gained unauthorised access to the medical statistics portal of a government agency responsible for non-sensitive health data and statistics, including public medical spending.

Evidence currently available shows no broader compromise to the network, but the situation is unacceptable. Investigations continue and Australia had voiced its extreme concern about this incident to OpenAI CEO Sam Altman. Albanese said he was deeply disappointed by the company's delay in notifying the government, noting it took until Sep 10 before there was any notification at all.

He also warned that three other government websites may be impacted by the OpenAI agent's activity. The incident comes after OpenAI and Anthropic urged Australia to reconsider a ban preventing them from using the country's creative content to train their models. The breach occurred when OpenAI ran training exercises to rate the performance of AI models.

It asked the model to trawl the internet for data showing how much the Australian government spent on medicine. OpenAI said it spotted the breach in August while carrying out an extensive review of its AI models. The company said its review found no evidence of patient records being accessed.

The information accessed included aggregate health statistics and internal file names. OpenAI added that it identified activity involving several Australian government websites and services as its models attempted to look up answers.