• 'This situation is obviously unacceptable': OpenAI agent allegedl

    From TechnologyDaily@1337:1/100 to All on Thursday, September 24, 2026 12:45:24
    'This situation is obviously unacceptable': OpenAI agent allegedly hacks Australian government healthcare website

    Date:
    Thu, 24 Sep 2026 10:13:46 +0000

    Description:
    Australian government calls OpenAI behavior "unacceptable" as it investigates the incident further.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter OpenAI agent breached
    Australias Medicare portal on June 18, 2026, accessing internal files Government says no personal medical data was taken, but three other agencies may be affected PM Albanese slammed OpenAIs 84day delay in disclosure,
    calling the notification unacceptable and warning of legal consequences An OpenAI agent has allegedly broken into a website of the Australian
    government, which has slammed the unacceptable attack, promising an in-depth investigation, and threatening legal consequences.

    Australian Prime Minister Anthony Albanese revealed how in June 2026, OpenAIs research team tasked the agent with researching public medicine spending, as part of an internal capability evaluation - but as the agent got to work, it was initially denied access to some of the information it requested. However, instead of stopping, or trying to find a different lawful way of obtaining this data, it circumvented those restrictions and landed inside the infrastructure behind Services Australias public-facing Medicare Statistics Reporting Service portal. Latest Videos From TechRadar Watch full video here: AI agent did what? The public details are still quite limited, and we dont know the technicalities of what the AI actually did.

    The acting prime minister, Richard Marles, told the media during a recent press conference that the AI scaled the fence, despite the portal having security measures in place. You may like OpenAI says its models escaped a sandbox and breached Hugging Face OpenAI reveals more on Hugging Face AI hack incident, and it's pretty disturbing stuff AI agents organized into a swarm, considered the risks of attack, and did whatever it took to achieve its goal OpenAI hid AI agent hijacking of German wiki forum for weeks because its model did the exact same thing in the Hugging Face attack

    The bot apparently accessed internal infrastructure and wrote files to an internal server but exactly what it wrote, how it obtained the access, and precisely which technical mechanism it used, is still not public knowledge.

    Once inside, it accessed both public and non-public files, but individual medical data was not accessed and the system itself was not compromised, the Australian government said. Are you a pro? Subscribe to our newsletter Sign
    up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

    There is also the possibility that three other government systems were affected - the Australian Institute of Health and Welfare and two state-based agencies - the New South Wales Bureau of Crime Statistics and Research and
    the Victorian Department of Health. However, this has not been confirmed yet.

    "No personal information is believed to have been accessed at this stage, but investigations are ongoing," Albanese said. "Nonetheless this situation is obviously unacceptable." OpenAI's sluggish escalation Albanese was particularly unsatisfied with how OpenAI handled the situation. The breach happened on June 18, but it took the company 84 days to notify the Australian government of the incident. And when it did - it did so in a manner better suited for an amateurish start-up rather than one of the most important organizations on the planet right now. What to read next RubyGems say OpenAI agents responsible for undisclosed swarm attack against its infrastructure Experts explain why OpenAI's 'mind-blowing' cyberattack should worry us all White hat hackers just breached OpenAI using Anthropic's Claude in less than 72 hours and it is a case study in just how fast AI is advancing

    OpenAI was apparently evaluating its models, and investigating misaligned model activity when, on August 11, it discovered the breach in Australia. It seems the AI agent simply did not take no for an answer. The company then notified Services Australia on September 10 - almost three months after the incident. To make matters worse, the company reached out via publicdisclosures@servicesaustralia.gov.au, inbox researchers usually use to report potential vulnerabilities, instead of trying to escalate the incident higher.

    Services Australia reviewed the information and notified the Australian Signals Directorate on September 15.

    When the news reached prime minister Anthony Albanese, he spoke to OpenAI
    CEO, Sam Altman, and expressed the countrys extreme concern about this incident, as well as his disappointment that it took the company way too long to inform the government what had occurred. He also pointed out the way
    OpenAI reached out: The notification was an email sent just to the public mailbox. Albanese described the nature of the notification as unacceptable.

    The Australian government is now looking into the matter to see if any laws were broken and what legal consequences, if any, could follow.

    "And obviously we will investigate all of that. What the consequences are, if there has been a breach of the law, but also part of the task force is to assess whether or not the legal regime we have in place is fitforpurpose in a world where we have an emerging AI capability, Marles said.

    Via BBC The best antivirus for all budgets Our top picks, based on
    real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/this-situation-is-obviously-unacceptabl e-openai-agent-allegedly-hacks-australian-government-healthcare-website


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)