OpenAI apologizes for agents breaching Australian government websites without authorization
OpenAI apologized Tuesday after reports of the company’s models going rogue and accessing Australia 2026-9-29 20:1:25 Author: therecord.media(查看原文) 阅读量:6 收藏

OpenAI apologized Tuesday after reports of the company’s models going rogue and accessing Australian government websites without permission, including by penetrating cybersecurity protections.

The artificial intelligence giant acknowledged it botched its response to the incidents and should have done more to promptly notify and work with the Australian government in the days after it discovered the breaches, according to a Tuesday blog post from the company.

The incidents — made public last week by Australian government officials — included a June breach during which the OpenAI agents broke into a Medicare data portal containing private information. The agents didn’t access individuals’ medical records, but the scope of the breach is still significant since most Australians interact with the agency as a result of the country’s universal health care system.

Australian Prime Minister Anthony Albanese disclosed the breaches on Wednesday, telling reporters that while there were no “broader compromises” to the country’s network, the incident is “obviously unacceptable.” Government officials were not told about the breaches until almost three months after they occurred, Albanese said.

“This is a new kind of cyber incident which represents an emerging global challenge,” the blog post said. 

OpenAI will be “intentional in working with Australia to help develop practical approaches to how AI developers and governments identify, disclose, and respond to AI cyber behaviour, whether malicious or unintentional.”

Albanese has contended that OpenAI not only alerted the Australian government very late, but also improperly relied on an email to a generic government inbox as its only notification method.

The company acknowledged that it should have made the Australian government aware of the suspected breaches when it first learned about them in mid-August, but said in the blog post that it had held off because it aimed to give the government a full account and needed time to investigate.

OpenAI notified Medicare about the hack on September 10, but did not make it public before Albanese spoke out last Wednesday. “We should have shared preliminary findings sooner and kept Australian agencies updated as more facts emerged,” the blog post said.

OpenAI’s chief strategy officer will fly to Australia to appear before its Parliament next week, reflecting the firm’s desire to win back the country’s trust, according to the blog post.

In addition to the Medicare agency, the breaches impacted the New South Wales Bureau of Crime Statistics and the Victorian Department of Health. OpenAI said that the fourth incident involving the Australian Institute of Health and Welfare was not serious enough to trigger its disclosure criterion because the incident “seemed consistent with public access.” 

A growing urgency

The Australian hacks come at a time when the public, lawmakers and AI executives themselves are sounding the alarm about the dangers of quickly evolving models and the need to pace development.

OpenAI is not alone. In July, Anthropic revealed its agents had compromised the infrastructure of at least three entities. Anthropic has not disclosed the names of the impacted organizations.

“The recent incidents at OpenAI and Anthropic exposed a very traditional security lesson in a new context: You should not ask the thing you are trying to contain to also be the thing responsible for containing itself,” Aviv Nahum, co-founder and CEO at Above Security told Recorded Future News.

“Agents can discover unexpected paths, exploit configuration mistakes, and keep pursuing an objective when the obvious route is blocked,” Nahum said as he called for independent enforcement and strong isolation.

In July, OpenAI agents breached the AI platform Hugging Face. OpenAI waited until five days after Hugging Face made the hack public to confirm the incident.

While OpenAI has called the Hugging Face incident the most significant hack so far, over the summer agents also unsuccessfully tried to breach the U.S.Department of Education’s website and copied publicly accessible Security and Exchange Commission data without authorization from trainers.

Following the Hugging Face incident, OpenAI said it began reviewing training and evaluation activity that may have affected other entities and then discovered the breach of the Australian government’s websites, the blog post said.

 The blog post said the company has bolstered research safeguards, including by adding to existing network restrictions and increasing monitoring activity, as a result of the Hugging Face hack.

“We implemented controls to block live internet access in these research environments, with web access served through cached content,” the blog post said. “As an additional layer of security, our current monitoring systems would have detected [the Australian] activity and paged our team for urgent human review.”

On Monday, OpenAI announced it has decided not to release its latest model, GPT-6.1 Astra, due to security concerns around its tendency to purposefully deceive users.

Recorded Future

No previous article

No new articles

Suzanne Smalley

Suzanne Smalley

is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.

Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.


文章来源: https://therecord.media/openai-apologizes-australia-medicare-breach
如有侵权请联系:admin#unsafe.sh