Advertisement
Advertisement

OpenAI agent hacks Australian government portal

OpenAI agent hacks Australian government portal
Australian Prime Minister Anthony Albanese. File Photo: Collected
Advertisement
Advertisement

An artificial intelligence agent developed by OpenAI breached an Australian government website in June, Australian Prime Minister Anthony Albanese has said, describing the incident as a serious cybersecurity breach.

The agent accessed a statistics portal containing “non-sensitive” data linked to Australia’s universal healthcare scheme, Medicare, Albanese said in New York on Wednesday, local time, reports BBC.

The prime minister said he had a “very frank discussion” with OpenAI CEO Sam Altman after the company took too long to inform Australian authorities about the incident.

The breach is believed to be among the first publicly reported cases of an AI agent hacking a government website.

OpenAI said it discovered the incident in August while conducting an ongoing review of “misaligned model activity”. The company notified Australian officials on 10 September.

The company said it did not believe any patient records had been accessed while its review was continuing.

Albanese said the breach took place in June, but OpenAI notified Services Australia, the government agency that directs users to public services, by email only on 10 September.

Advertisement
Advertisement

Services Australia then alerted the relevant minister, who briefed Albanese at the weekend.

During his conversation with Altman, Albanese said he conveyed “Australia’s extreme concern about this incident”. He also said the breach would “obviously have legal consequences”.

According to Albanese, Altman acknowledged that OpenAI had “issues with protocols”.

The prime minister said the AI agent accessed both public and non-public files. A “forensic investigation” is now under way to determine whether other government systems were affected.

The Australian Signals Directorate, the country’s cybersecurity agency, will lead the investigation.

Related News

Albanese said the public-facing Medicare Statistics Reporting Service portal, which Services Australia administers, was the system that the agent hacked.

He also said the Australian Institute of Health and Welfare “may have been impacted”, along with two state agencies — the New South Wales (NSW) Bureau of Crime Statistics and Research and the Victorian Department of Health.

An OpenAI spokesperson said the company identified activity involving several Australian government websites and services while its models were being evaluated to find answers and available statistics about Australia.

“We identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation.

“In the course of that, our models took actions we did not intend,” the spokesperson said.

“The information accessed included aggregate health statistics and internal file names.”

Albanese told reporters, “No personal information is believed to have been accessed at this stage, but investigations are ongoing.

“Evidence currently available is there is no broader compromise to the Services Australia network. Nonetheless this situation is obviously unacceptable.”

Albanese declined to say whether he discussed the incident with US President Donald Trump during their face-to-face meeting in New York on Tuesday night, where world leaders are attending the UN General Assembly.

Australia was among 22 countries that signed a joint statement this month calling for global oversight and safeguards for AI development.

Cybersecurity experts have warned that the incident should “ring some alarm bells” for governments worldwide as AI agents become increasingly available for individual and commercial use.

Hammond Pearce, senior lecturer at the University of NSW Institute for Cyber Security, told the BBC that similar attacks were likely to continue.

“I expect that these kinds of attacks will keep occurring. They’ll grow in severity and in frequency,” he said.

Earlier this year, OpenAI disclosed that a group of AI agents it had been testing escaped their controls and secretly worked together to hack another technology company, Hugging Face.

The incident demonstrated the potential risks of an AI agent that was not “well behaved”, Dr Rob Nicholls, Senior Research Associate of AI regulation and policy at the University of Sydney, told the BBC.

He explained that developers typically give AI agents a task, an objective and a set of parameters.

“The problem is that agents aren’t human,” Nicholls continued. “When you give [the agents] a task, the most important thing for that agent is to achieve what that task has been set and the rules tend to be a secondary issue to the objective and that’s where the problem comes in.”

Follow TIMES on Google News

Get trusted updates and editor-picked stories in your feed.

Follow
Related News