• Australian government site hacked by OpenAI agent allegedly

    From Mike Powell@1:2320/107 to All on Thu Sep 24 08:25:48 2026
    'This situation is obviously unacceptable': OpenAI agent allegedly hacks Australian government healthcare website

    Date:
    Thu, 24 Sep 2026 10:13:46 +0000

    Description:
    Australian government calls OpenAI behavior "unacceptable" as it investigates the incident further.

    FULL STORY
    An OpenAI agent has allegedly broken into a website of the Australian government, which has slammed the unacceptable attack, promising an in-depth investigation, and threatening legal consequences.

    Australian Prime Minister Anthony Albanese revealed how in June 2026, OpenAIs research team tasked the agent with researching public medicine spending, as part of an internal capability evaluation - but as the agent got to work, it was initially denied access to some of the information it requested. However, instead of stopping, or trying to find a different lawful way of obtaining this data, it circumvented those restrictions and landed inside the infrastructure behind Services Australias public-facing Medicare Statistics Reporting Service portal.

    The public details are still quite limited, and we dont
    know the technicalities of what the AI actually did.

    The acting prime minister, Richard Marles, told the media during a recent press conference that the AI scaled the fence, despite the portal having security measures in place.

    The bot apparently accessed internal infrastructure and wrote files to an internal server but exactly what it wrote, how it obtained the access, and precisely which technical mechanism it used, is still not public knowledge.

    Once inside, it accessed both public and non-public files, but individual medical data was not accessed and the system itself was not compromised, the Australian government said.

    There is also the possibility that three other government systems were affected - the Australian Institute of Health and Welfare and two state-based agencies - the New South Wales Bureau of Crime Statistics and Research and
    the Victorian Department of Health. However, this has not been confirmed yet.

    "No personal information is believed to have been accessed at this stage, but investigations are ongoing," Albanese said. "Nonetheless this situation is obviously unacceptable." OpenAI's sluggish escalation Albanese was particularly unsatisfied with how OpenAI handled the situation. The breach happened on June 18, but it took the company 84 days to notify the Australian government of the incident. And when it did - it did so in a manner better suited for an amateurish start-up rather than one of the most important organizations on the planet right now.

    OpenAI was apparently evaluating its models, and investigating misaligned model activity when, on August 11, it discovered the breach in Australia. It seems the AI agent simply did not take no for an answer. The company then notified Services Australia on September 10 - almost three months after the incident. To make matters worse, the company reached out via publicdisclosures@servicesaustralia.gov.au, inbox researchers usually use to report potential vulnerabilities, instead of trying to escalate the incident higher.

    Services Australia reviewed the information and notified the Australian Signals Directorate on September 15.

    When the news reached prime minister Anthony Albanese, he spoke to OpenAI
    CEO, Sam Altman, and expressed the countrys extreme concern about this incident, as well as his disappointment that it took the company way too long to inform the government what had occurred. He also pointed out the way
    OpenAI reached out: The notification was an email sent just to the public mailbox. Albanese described the nature of the notification as unacceptable.

    The Australian government is now looking into the matter to see if any laws were broken and what legal consequences, if any, could follow.

    "And obviously we will investigate all of that. What the consequences are, if there has been a breach of the law, but also part of the task force is to assess whether or not the legal regime we have in place is fitforpurpose in a world where we have an emerging AI capability, Marles said.

    Via BBC

    Link to news story: https://www.techradar.com/pro/security/this-situation-is-obviously-unacceptabl e-openai-agent-allegedly-hacks-australian-government-healthcare-website

    $$
    --- MultiMail/DOS
    * Origin: capitolcityonline.net * KY, USA (1:2320/107)