OpenAI’s AI agents hacked Australian government health website; alert email sent a month later to Public mailbox; upset Australian PM says: I spoke with Sam Altman to tell …


OpenAI's AI agents hacked Australian government health website; alert email sent a month later to Public mailbox; upset Australian PM says: I spoke with Sam Altman to tell ...
Representative Image. In pic: Sam Altman

​ChatGPT maker OpenAI‘s AI agents hacked Australian government health website. Australian Prime Minister Anthony Albanese has confirmed that an internal AI agent of the company gained unauthorised access to the country’s Medicare statistics reporting portal in June while researching public medicine spending. The agent accessed both public and non-public files after encountering blocks while trying to retrieve information. While the Australian government says there is no evidence that personal Medicare information was accessed, the incident has raised questions about how AI agents respond to restrictions and how quickly companies should report such incidents.​According to an AFP report, the delay in reporting the incident was a major concern for Albanese. “Today I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident,” he said. “And I also expressed my disappointment that it took the company way too long to inform the government what had occurred.” Albanese also criticised how the notification was delivered, saying, “The notification was an email sent just to the public mailbox.”​

OpenAI agent bypassed website restrictions

​The incident occurred on June 18, when an OpenAI research team was using an internal model to conduct internet-based research into public medicine spending, according to Albanese.​The agent repeatedly encountered blocks while attempting to access information. It then found a way around those restrictions and accessed parts of the Medicare Statistics Reporting Portal that were not publicly available.​“The AI agent found a way around those blocks,” Albanese said. “Didn’t accept no for an answer, if you like.” The model tried alternative methods to obtain the information, which resulted in unauthorised access.​The portal is a public-facing service administered by Services Australia and contains aggregate Medicare statistics, including spending information. The government has stressed that the portal is separate from systems containing individual Medicare records.​

OpenAI took months to notify Australia

​OpenAI became aware of the incident in August during a broader review of model activity involving unintended behaviour, an OpenAI spokesperson noted.However, Services Australia was not notified until September 10, almost three months after the June incident. OpenAI sent the notification to a public mailbox used by researchers and academics to report potential weaknesses in Services Australia’s systems.The email was seen on September 11. Services Australia then notified the Australian Signals Directorate on September 15, while Government Services Minister Katy Gallagher was briefed on September 17.Albanese said the delay and the manner of notification were both unacceptable. According to the prime minister’s official transcript, Altman acknowledged the concerns and said OpenAI’s protocols were inadequate in this case.​

No evidence of personal Medicare data accessed

​The Australian government says it has found no evidence that individual Medicare records or personal health information were accessed. The files involved included public and non-public information, including aggregate health statistics and internal files.​A forensic investigation involving the Australian Signals Directorate is underway to determine the full extent of the incident and whether other government systems were affected.​Defence Minister Richard Marles described the incident as serious because an AI agent gained unauthorised access, but said the impact appeared limited because no individual’s medical data was accessed.​The Australian government has also announced a taskforce to investigate the incident and is examining whether existing laws were breached. The case has renewed scrutiny of how AI agents are tested, what they are allowed to access and how companies communicate with governments when autonomous systems behave in unintended ways.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *