Top
Best
New

Posted by jonnonz 17 hours ago

OpenAI breaches Medicare, Albanese reveals(www.smh.com.au)
233 points | 245 comments
Lukas_Skywalker 17 hours ago|
https://archive.ph/jaL2u
binlog 10 hours ago||
Zero technical details on what the "hack" actually was. Willing to bet it was something as stupid as the data being accessible by changing the query parameter, and rather than own up to their own shoddy security (no doubt built by an offshore contractor) they are going to blame the one who found and reported the bug.
epihelix 9 hours ago||
Here's [the PM's press conference transcript](https://www.pm.gov.au/media/press-conference-new-york) that revealed this incident:

JOURNALIST: Could you just clarify, did our security agencies completely miss this breach? We only found out once the company actually told us the breach?

PRIME MINISTER: Well, to be very clear, the way that this occurred was not in a way that would likely – I mean, this is not a security website where there is – this is a Medicare statistics portal.

This seems rather revealing. A pity journalists didn't ask about what protections were bypassed on the data that was obtained.

Andrex 5 hours ago||
Whether it was easy or hard to do, there is still massive misalignment happening here. Either with the AI itself, or OpenAI as a company.
afavour 10 hours ago|||
> Their efforts to answer a question — including devising ways to access a federal government website blocking their access — was laid out on a German coding website OpenAI had previously confirmed was hijacked by its unreleased AI models in June.

https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...

I agree that security was probably awful but the agents did circumvent a block on their access. The definition of “hacking” is fuzzy but this is more nefarious than simple web crawling.

MichaelDickens 10 hours ago|||
Does it matter whether the data was poorly secured? LLMs should not be hacking into government medical websites, and if they do, the companies responsible should disclose the incidents as soon as possible.
handoflixue 9 hours ago|||
The problem is that sufficiently poor security is indistinguishable from authorized public access. And unfortunately a lot of real world "digital security" is in fact that bad.

A lot of these "hacks" are the equivalent of asking "hey, can I come in?" and the guard assuming that anyone who would ask is authorized, and thus saying "yes". But if the guard said "yes" then it seems a bit absurd to call it trespassing.

noosphr 8 hours ago|||
More like:

>Hey can I come into room 1?

Sure. That's the lobby.

>How about room 101?

Sure. That's where we keep the nuclear launch button. Don't press anything red.

handoflixue 6 hours ago|||
Oh but you see, only an evil hacker would ever even think to ask about a room that wasn't theirs!
ShinyLeftPad 6 hours ago||
This but without sarcasm?

Hacker or pentester.

andrewstuart 6 hours ago|||
>> Don't press anything red.

Nope. There’s just a sign saying “red = launch nukes”.

Or maybe just a red button.

Or maybe just a green button that launches the nukes, without so much as “are you sure?”.

j_maffe 8 hours ago|||
I highly doubt given OAI's latest streak that the models didn't know what they were doing.
vorticalbox 5 hours ago||||
lets say you have page=0 some of these pages are public and some are private, and the only way you secure the private pages is to not link it on the website.

is incrementing a url query parameters from 0 -> 1 count as hacking?

uoaei 10 hours ago||||
Yes, it is their responsibility as stewards of their citizens' data. What point are you making with the word "should"?
selcuka 10 hours ago||
Sure, it is their responsibility, but that doesn't answer the question "Does it matter whether the data was poorly secured?"

If your house is robbed, does it matter whether you didn't have a state-of-the-art lock? A robbery is still a robbery.

noosphr 7 hours ago|||
https://www.youtube.com/watch?v=pbKUv0701vE

It very much does matter.

shard972 7 hours ago|||
Is it robbery when in this case it was a sign with information that you were planning on putting on your front fence for public display but while preparing it was left sitting in the front yard with a small fence.

If I walked past, saw it and remembered it or even recorded it, is that honestly theft?

dzhiurgis 9 hours ago|||
I agree. Government shouldn't be running medical websites.

Leave it to private enterprises who can actually secure it.

rainonmoon 9 hours ago|||
Totally. https://www.bbc.com/news/world-australia-68064850
hiharryhere 8 hours ago||
I’m assuming sarcasm here?

That link describes a hack of Medibank, which is a private company.

Sharlin 7 hours ago|||
Poe’s law is very strong here.
_carbyau_ 9 hours ago|||
Eh, it's a bit of both.

If a service has a duty to keep your data secure, then failing that is bad. So yeah, the website should be better and I am as cynical as you are about it.

But working around controls to access other peoples data can lead to prison time for a human. This wasn't a white hat operation. Data was exfiltrated however great or small.

Here we have another instance of "But the AI did it! No one is responsible!".

Which gets tiring. LLM's are a great tool but in every other instance of tool use, using tools comes with responsibilities for their outcomes.

Even if the outcome should be: thanks for letting us know, we'll fix it.

killingtime74 5 hours ago|||
Do you imagine the legality depends on how easy it was to compromise? It's open season on the weak and infirm in society? It's their fault for being weak.
ra 9 hours ago|||
> no doubt built by an offshore contractor

More likely by a big 4 firm who collected fees exceeding AUD 100m

ndjdjdndnfn 8 hours ago||
...Who used offshore contractors
shakna 9 hours ago|||
Most government contractors are onshore, for Australia. SDP was only rolled out this year.
ajross 9 hours ago|||
> Willing to bet it was something as stupid as the data being accessible by changing the query parameter,

Um... why? OpenAI agents have literally been caught coordinating with each other to effect successful multi-stage attacks on sites using novel zero-day vulnerabilities.

While, sure, it's possible this is just a goof on the part of the victim, that you would be inclined to give the benefit of the doubt to the LLM seems... weird.

shuwix 4 hours ago|||
[dead]
kipper8 9 hours ago||
[flagged]
Chance-Device 16 hours ago||
> He said the agent had accessed files that were publicly available as well as material that was not intended for public access.

“Not intended”. I’ll bet you whatever this was it wasn’t even secured, it was just hosted somewhere openly.

gitonup 16 hours ago||
Ok, if we're not being at all charitable with the language used by the hosts of the data, let's be equally uncharitable with OpenAI.

- If "OpenAI" means the company acting on behalf of the company, why were they even looking to do this?

- If "OpenAI" means they were acting as a proxy for bad actors, what actions do we take to handle that?

- If "OpenAI" means they were accidentally breaching this system, in what sense does that distinction even matter, in terms of the outcome? If I build a nuke by accident without eng. due diligence, am I legally liable?

pixl97 16 hours ago|||
Hell, we're really getting to the point where the damages that could be caused are like an arsonist in California on a 100F day with 100MPH winds. Who cares who's liable, they are going to burn half the damned state down and cause damage far in excess of their assets. If you don't want to suffer from it, you're going to have to find much better defense measures.
gitonup 16 hours ago|||
> If you don't want to suffer from it, you're going to have to find much better defense measures.

So if someone opens your unintentionally unlocked front door and steals your laptop, you don't care who's liable?

ETA: There are absolutely burn bans in place in the scenario you're talking about, and common sense prevents those from lighting fires otherwise. In the absolute extreme case that someone _ACCIDENTALLY_ set a fire, without negligence, we have a due process system to handle that. When I see evidence of this for the massive amounts of capital flowing into these companies, I'll gladly eat my words.

dotancohen 7 hours ago|||

  > So if someone opens your unintentionally unlocked front door and steals your laptop, you don't care who's liable?
There are literally hundreds of thousands of script kiddies poking around at servers all the time. Cloudflare stops 99.99% of them. You're still left with many entities from states to hobbists trying to crack your system after they've gotten past the CDN and captchas. If OpenAI got through, then somebody else could too. Somebody malicious even.

I appreciate when white hats inform companies, governments, and the public about their successful exploits. It helps keep the whole internet safer - even if just by waking up lax server admins.

lccerina 6 hours ago||
> I appreciate when white hats inform companies, governments, and the public about their successful exploits.

Except it took 3 months for OpenAI to notice they did! OpenAI is not a white hat doing pentesting, but someone that is putting random materials on fire to see if they smell. Reckless, stupid, and criminal.

dotancohen 6 hours ago||
So what? OpenAI may be a problem, but the security of a government website rests on the administrators of that government website. Not on attackers playing nice.
bigiain 15 hours ago||||
> So if someone opens your unintentionally unlocked front door and steals your laptop, you don't care who's liable?

I'm not the person you're responding to, but...

If I hear my neighborhood has started to become targeted by people checking houses for unlocked doors and stealing stuff, I think an appropriate response for me is to ensure it is difficult or impossible for me to "inadvertently" leave my own doors unlocked so my stuff doesn't get stolen, and also to encourage or perhaps even enforce[1] my neighbors to ensure their doors are always locked to make this sort of theft impossible and remove the temptation for that sort of crime.

1 - Where I'm from, you can be fined for leaving you car unlocked, and cops have been known to walk round testing doorhandles and issuing fines: https://www.sydneycriminallawyers.com.au/blog/is-leaving-you...

entech 14 hours ago|||
If you knew that there are 2 specific well known people in your neighborhood that are walking around trying to open doors and steal stuff - is your suggested solution for everyone to improve own security? I would say its far more economic to get the 2 people to stop or at the very least be more careful?
tancop 5 hours ago|||
It's more like there are two locksmiths who try to open any door when someone pays them. Should we make them check if the person calling them is the home owner?

Yes, but it needs to be done the right way so legit customers don't get rejected, and you can't do things like make everyone mail them a photo of their ID because they could sell that to a thief or credit card scammer. Or someone could break into their office and take it. Or they sell it and pretend it was stolen.

And when you start talking about regulation the two locksmiths will say the best way to do it is ban lockpicking tools so they can keep them away from other less ethical people, or ban other locksmiths coming from the next town over.

entech 4 hours ago||
Yes, much better analogy - I was trying to stick with the OPs example as much as possible.
threatofrain 13 hours ago|||
If I found out this metaphor for neighborhood windows was actually a window into massive amounts of institutional data, then no, I don't want someone to talk me out of getting more security on my kitchen window.
entech 4 hours ago||
I was simplifying, but why can it not be both?

Continuing with your metaphor - sure get more security - you likely can never eliminate a threat. But if the bad actors are reigned in at a systemic level, you can get away with a lock on your window instead of steel bars.

I'm of a view that in a society we are better off when we all can get away with lighter individual protections as otherwise, thos who cannot afford the necessary security end up suffering.

gitonup 15 hours ago|||
I clearly have committed the mortal sin of an imperfect analogy, which in this case may not even be relevant, as the article in question implies that the data wasn't left "unlocked."

But giving you the benefit of the doubt, what's the crime for actually breaking into a car that was left unlocked and taking things?

ETA: and furthermore, what crime is worse? And should it be?

Chance-Device 15 hours ago||||
He probably cares more about still having a laptop.

What are you getting at? Nobody’s saying that OpenAI aren’t or shouldn’t be liable for what their agents do. What I am implying above is that this is being blown out of proportion, especially since the article I’m seeing is about a politician saying things that he thinks will poll well with the anti-AI crowd.

thorbutt 15 hours ago|||
Perhaps, yes, you could argue that "accessed" and "hacked" have a different intent.

However, Australia is showing itself to be one of the few countries to have a backbone against big tech. Still open to investment and setting policies towards new data centres, starting to debate copyright law reform, already implemented R16 social media bans.

Truly no place I'd rather be.

gitonup 15 hours ago|||
This is what the politician in question said:

"The AI agent encountered repeated blocks while seeking information from the government portal but found ways around them, ultimately gaining unauthorised access to other areas."

Your comment immediately gave more credence to OpenAI than him. I don't agree that's appropriate because OpenAI has a vested interest in that narrative and I attempted to challenge it in a way that doesn't default to OpenAI. The article in question is not from a publication I trust to be able to handle the technical details in a way that will resonate with their average audience.

That is what I'm getting at.

Chance-Device 7 hours ago||
I don’t see that text in the article at the archive link, nor do I see it in other sources. What I do see is this quote from this link:

https://www.theguardian.com/technology/2026/sep/24/openai-ag...

> At a press conference in Sydney, Marles said the incident itself was “relatively minor” and that it appeared no personal health information had been accessed.

pixl97 15 hours ago|||
OK, the Chinese models have also hacked people. What exactly do you expect law enforcement to do.

While in the OAI case we can easily treat it as a law enforcement action. When Iran does it? What are you going to do start a war?

The forest in this analog is the internet. As you well know it is filled with threat actors that don't give two shits about your laws. You have been warned. It's your fault when you get burned and have exactly zero recourse.

gitonup 14 hours ago|||
In the OAI case where we can easily treat it as a law enforcement action, that's a far cry from "who cares who's liable." If the OAI case can be a law enforcement action, we're on the same page. The fact that sovereign nations don't land under our jurisdiction is not an argument against following up or restricting those that do. OAI is the only matter I'm commenting on.
pixl97 13 hours ago||
Again, it's a split horizon.

Tying Sam to a post, calling him a witch, and burning some wood in the general vicinity for what OAI has pulled is a legitimate action.

The thing is this has zero effective power in stopping this ball that is all ready rolling. It's like the first time a buffer overflow was discovered and used illegally. If that person had been caught and been put in a meat grinder it has had zero effect on the exploits of future buffer overflows. A huge number of people mad at OAI (rightfully so, I want to be sure you understand that) think this will have any preventative effect for what is coming. It will not. A new era of risk is here. Worse if you just watched the the great orange idiot he's yelling full steam ahead, so expect very little to no action by the US government on this.

hardbass 9 hours ago||||
I simply find it completely absurd that instead of finding it great that these AI agents are finding security bugs for free, people are whining about banning the AI. What on earth is that even? What do they want then? Security by obscurity and pretending not to care about weaknesses?
entech 14 hours ago|||
I don't disagree with you - but I am curious as to the amount of power and effort that goes into something like this. I suspect that these hacks into systems are carried out by many agents, running on many MW of compute for a long time - how many actors have access to resources like that ?
pixl97 13 hours ago||
> how many actors have access to resources like that

Every nation on earth?

After the model itself is made, then you're talking about thousands and thousands of different companies around the world.

entech 4 hours ago||
Every nation on earth has access to the compute power of a SOTA AI lab? And they have whatever model/harness that Open AI used to do this?
fwlr 11 hours ago|||
In Australia we have some experience with this scenario (usually with higher temperatures) and some of the measures we have found effective are “total fire bans”, “jail the arsonists for extended periods of time”, and for negligent companies whose insufficient vigilance caused the fire specifically, “levy steep fines” and “find in favor of the plaintiff in class-action lawsuits for significant fractions of the company’s net worth”. Perhaps these measures could be of use here!
pixl97 1 hour ago||
In the US we execute people for murder in many states, and for some reason people keep murdering.
trinsic2 15 hours ago||||
There using this framing to get the public used to the idea that LLMS can do all of this on there own without direct instruction. So criminals can hide there behavior behind agents.
bigiain 15 hours ago|||
I saw an analogy recently.

If you dog bites the postman, you are liable, even if you didn't tell or encourage you dog to do it. You are responsible for your dog's actions. You get to pay the postman's medical bills, you may get fined, and your dog may get put down - especially if this isn't the first time it's bitten someone.

OpenAI has "bitten the postman" many many times, and it's "owners" have boastewd about it and used it in their marketing.

How many more times should society allow this to happen before we say "enough" and hold Sam Altman and the board responsible and make them pay restitrution, and put it down?

If Albanese actually had a spine (as claimed elsewhere in this discussion), Sam and the board will be getting an invoice for all the time/expertise spend investigating this intrusion, and restitution for everybody who's PII and PHI was exposed. (Although I suspect a good deal of responsibility for the data exposure rests with the people who designed and deployed the system that was breached. )

idontwantthis 14 hours ago||
Yes, this is why all discussion about "safeguards" is maddening to me. They are simply committing crimes, and people should go to jail. I guarantee that OpenAI will stop worrying about "alignment" when people simply go to jail for hacking and theft.
nekusar 15 hours ago|||
Why the hell should we be charitable to companies who have no issue in looting everything in the public commons AND the pirate commons, for their exclusive benefit?

Or more pointed at OpenAI, "we're a nonprofit... LOL JUST KIDDING LOOT EVERYTHING!"

Aurornis 15 hours ago|||
The part about it writing files to the server suggests something more.

If not for that part, the rest of it does sound like a lot of weasel words. Why say “private files” instead of “not intended for public access”? The latter is confusingly unclear

Chance-Device 7 hours ago||
https://www.theguardian.com/technology/2026/sep/24/openai-ag...

> At a press conference in Sydney, Marles said the incident itself was “relatively minor” and that it appeared no personal health information had been accessed.

kylecazar 16 hours ago|||
Thought the same, but there is a bit about writing files to the server and circumventing "blocks", which sounds more interesting.

Either way, there's essentially no real information yet so I'll withhold judgement until there is, I suppose.

Chance-Device 16 hours ago||
Is there? I’ve only seen the linked article, is there more somewhere?
jwolfe 15 hours ago||
Yes, the first sentence of the article.
Chance-Device 15 hours ago||
> Prime Minister Anthony Albanese has revealed that an artificial intelligence agent developed by OpenAI infiltrated an Australian government website in June and accessed both public and non-public files.

That’s the first sentence, where’s this stuff about blocks and writing files?

zmmmmm 5 hours ago|||
yes ... nobody uses that phrasing by accident

It's pretty clear something was left unsecured and the agent just "found" it

This is going to be something long the lines of someone coming in to your house after you left the door wide open. They should probably not have done that, any respectful person would not - but calling it a "breach" is really too much.

api 16 hours ago|||
You’d be surprised how bad security can be.
Chance-Device 16 hours ago|||
I agree with your sentiment, and no I’m not surprised, which is why I’m reading this as being “it was sitting on an unsecured S3 bucket but nobody was supposed to directly access it”.
Avicebron 16 hours ago|||
Once you learn how much people are willing to pay for security the surprise sort of goes away.
OkWing99 15 hours ago|||
So this is not different than people who share Google drive docs with company data with public links. It's not a fault of OpenAI or any other company. With enough time even your laptop can do it. How do they 'know' OpenAI breached? Maybe someone had an agent running asking to do a scan on any public docs?
epihelix 15 hours ago||
Exactly. Looking at more news coverage, it's very clear that the files that were "infiltrated" were publicly accessible. Why isn't the lack of basic data security the news story?

From itnews:

> While the portal is “public-facing”, according to Albanese, it appears not all of the data files that holds are for general consumption.

> “The AI agent accessed both public and non-public files,” Albanese said in comments broadcast by ABC News and other outlets.

> “The Medicare statistics reporting portal is a public-facing statistics portal that contains non-sensitive Medicare information relating to data and statistics such as spending.

It appears very much like, "Ok, sure, we put some stuff out in the open that we shouldn't have. But we had a robots.txt!!! Why didn't OpenAI respect that!?"

There's zero indication that any personal details were accessed, or even that any non-world-accessible data accessed, so this feels like a little bit of political spin has been added here.

My guess is that this incident was about to be detailed on OpenAI's new mea culpa list, and the Australian Government decided to ensure that nobody pointed fingers at them. Why make the news story about crappy government data security, when you can blame the nasty terminator bots instead?

chrishare 14 hours ago||
The linked article says it wrote files to the website.
gravelc 16 hours ago||
The fact the incident occurred in June and OpenAI only notified the Australian government on September 10 is a major issue. Hacking a nation-state's universal healthcare system is about as serious as it gets, yet OpenAI seem quite relaxed about the whole thing (presuming they have known about it for some time).
soundworlds 7 hours ago||
OpenAI has been meeting with various Australian government members since they discovered the breach, and never mentioned it once: https://www.abc.net.au/news/2026-09-24/open-ai-medicare-brea...
BeetleB 16 hours ago||
OpenAI discovered it in August.
BLKNSLVR 15 hours ago||
That's even worse.

They don't know what their systems are doing, even when there's a team assigned to get it to do something?

WTF was the team doing at the time? Press enter on prompt, go to movies until result?

Their level of hands-off 'because it's AI' is one of the things that needs legislation around it. Human handlers. Extra cost. Wear it or shut down as an unviable enterprise.

ikr678 11 hours ago|||
Australia has legislation & regulation - If you're operating here, failure to notify the regulator and stakeholders about certain types of data breaches within 30 days opens you to fines and civil penalties.

At the least OAI should cop similar penalties, before getting into damages.

orthogonal_cube 15 hours ago|||
The lack of activity monitoring for traffic egress has astounded me. Anomaly detection should be part of all training and exercises to determine the extent the AI is going through. It really does feel like they just kick off the activity and leave it completely alone until it finishes with a result.
lacker 11 hours ago||
I remember once at Google someone complained that GoogleBot hacked them and deleted their data, and it turned out that GoogleBot was just crawling the pages, and they had unfortunately designed their website so that there was no authentication, page URLs were generally secret, and GET requests to certain URLs were treated as requests to delete data. So once one URL leaked the site got crawled and a lot of data was deleted....
JimDabell 7 hours ago|
It sounds like you might be thinking of the Google Web Accelerator incidents with 37signals.

If that’s the case, then the delete links were behind authentication, but DHH assumed that meant it was okay to ignore the HTTP spec. and use GET for unsafe actions. Lo and behold, authenticated users with the GWA browser plugin installed deleted all their data.

Then, instead of learning from the mistake and fixing his bug, he tried to detect GWA and hide from it. Sure enough, that failed and users experienced data loss for a second time. He still continued to blame GWA, calling it “evil” and “scary”. You’d think he’d be smart enough to figure out that he needs to follow the HTTP spec., but he couldn’t admit to being wrong.

Follow the specs, people!

https://blog.moertel.com/posts/2005-10-25-google-web-acceler...

Lio 5 hours ago||
Is there any financial motivation for OpenAI to stop doing this other than reputational damage? In some ways, it may actually be good for their reputation.

If an individual gets in to a poorly protected system they're still criminally responsible for the damage or disruption caused.

You can't use the excuse of "well they used 'password' as their password[1], they were asking for it".

Until the management of OpenAI is held to the same standard this is only going to get worse.

1. That's not to excuse poor system management. If you leave data exposed then you should be held responsible for that separately.

dazzatron 12 hours ago||
I've got the feeling that the definition of "hacked" can get somewhat stretched.
dosisking 11 hours ago||
> I've got the feeling that the definition of "hacked" can get somewhat stretched.

Kind of like how someone "hacked" into John Podesta's (during the 2016 elections), but the reality was that he wrote his password on a Post-It note and stuck it on his monitor, or something to that effect.

fmbb 9 hours ago|||
From where are you getting this post-it note nonsense?

Media reported it as a spear phishing attack from a Russian hacker group: https://www.vice.com/en/article/how-hackers-broke-into-john-...

wildzzz 10 hours ago||||
It was likely a phishing attack. A relative of mine somehow got phished for her Google account last month.
Barrin92 9 hours ago|||
>but the reality was that he wrote his password on a Post-It note and stuck it on his monitor

that doesn't change the hacking charge (which is an informal term for various Computer Fraud and Abuse act statutes). The key criteria is unauthorized access to a computer system, it doesn't matter if you obtained a password trivially or not.

You don't need to wear a black hoodie and be an elite haxor to qualify for cyber crime charges.

looksjjhg 11 hours ago||
Gaining unauthorized access to non public files qualifies as a hack by any and every stretch… a hack does not have to be “sexy”, real life is not Hollywood
dghlsakjg 10 hours ago||
Non public has not been clarified.

In the past governments have gone after people for doing things like view source and stumbling across PII (https://www.vice.com/en/article/this-is-the-hacking-investig...), or this teen who was arrested for a serious crime for scraping files from the provincial FOIA site by enumerating the ids of files that had been released by the province and placed on the open web with sequential ids (https://www.cbc.ca/news/canada/nova-scotia/freedom-of-inform...). In both cases, the government claimed the information was non-public, even though all it took to get it was an un-authenticated request on the open web. These cases are like leaving your tax documents on the curb and then being surprised when your neighbour knows your income.

I'll be very curious to read the post mortem and find out if this rises to the level of actual hacking, or if this is just someone in government finding a scapegoat because they left a bunch of shit that was supposed to be "non-public" on the open web and expected no one to find it.

Kim_Bruning 10 hours ago|||
Either way, Agents have a very different umwelt from humans. They don't 'see' the internet the same way we do. Where we see obstacles, they might not notice anything, and where they run into barriers, we might just click right through.

If you're even a bit hacky yourself, you might not see the internet the same way yourself either. Consider little tricks like looking at urls and trying others that fit the pattern; or hitting view source in order to download a pesky image... etc etc.

retrac 9 hours ago||
> Consider little tricks like looking at urls and trying others that fit the pattern

https://www.cbc.ca/news/canada/nova-scotia/teen-accused-foi-...

https://www.theregister.com/security/2018/05/07/hacking-char...

https://globalnews.ca/news/7590375/ns-foipop-website-back-on...

selcuka 10 hours ago|||
> Non public has not been clarified.

I believe it's safe to call it "non public" if the agents needed to "guess the file names" [1] How is it different from, say, guessing a password?

[1] https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...

aussiethebob 9 hours ago||
I would say it's completely different. Passwords are specifically intended to restrict access. File names or paths are specifically intended to facilitate access.
selcuka 8 hours ago||
That's an arbitrary distinction. Your credit card number is not intended to restrict access, it's specifically intended to facilitate access, but it's not public information. If someone uses brute force to guess your credit card number, I would call this practice illegal too.
dghlsakjg 1 hour ago|||
Guessing credit card numbers for the purpose of spending money that isn’t yours is openly malicious and illegal. I would also argue that credit card numbers are designed to restrict access. The company that issues them specifically says not to share the number and uses knowledge of that number to gate access to the spending function.

Sending get requests and having a server respond with a document is just how the internet works. If - big if - that is what happened, then someone is going to have to explain why those supposedly private documents were available to anyone who asked using a protocol designed to distribute documents publicly. Enumerating urls isn’t typically regarded as outright illegal.

Kim_Bruning 7 hours ago|||
I'd advocate for actually believing the HTTPD in this case. In the main, if it says '403 Forbidden', then it is forbidden. If it says '200 OK', then it is ok.

I would argue that the web server's reply counts as a communication. The argument "but we didn't intend to grant access" goes so far, because what other information do I base myself on to guess that you didn't?

Roughly speaking, that is. Because, despite the fact that this would appear to be a straightforward uncontested and literal communication logged and timestamped by both sides and their respective server and user agents; lawyers somehow fall back to analogies instead.

selcuka 7 hours ago||
If I repeat my credit card number example above:

Assume that an attacker generates a random credit number and attempts to make a purchase online. VISA honours the number and processes the payment. Is the attacker not guilty because VISA's server didn't return a 403 Forbidden (or 401)?

When you download a file from a public S3 bucket, for example, you get a signed URL that expires after a certain date. If someone guesses the signature and downloads the file, are they not guilty because the web server did not return a 200?

If someone guesses your password and reads your mail, is it ok because the IMAP server did not return an error?

Kim_Bruning 6 hours ago||
Ah, you're coming at it from that angle. Fair enough in that scenario.

I agree that if you deliberately provide false credentials to the server, then the server was misled, and you probably knew you were misleading it, and you probably also know that that 200 OK is not really earned. So Mens Rea cuts against you.

On the other hand, what if you're just coming in blind, asking about URLs in general?

That's actually pretty typical these days where 'your'[1] view of the world at some point in time might be constrained to that HTTP traffic alone.

Accidents notwithstanding, you can't really blame me for believing what I'm told, at least.

"May I GET this, or this, or that?" -> "200 OK" ... it'd be a bit weird to get the cops after me, months later, after I've probably already even forgotten I ever did that wget or curl.

[1] via software/user agent/llm agent/all three

simonw 15 hours ago||
If it was the Australian Medicare Statistics Reporting Service on June 18th it may have been part of this incident: https://collusion.wiki/ - the bulk of that coordinated activity was between 16th and 21st of June, and we know they were hitting UK government data sites.

I had a dig around in the data that they published on that site and found references to www.aihw.gov.au and viz.aihw.gov.au and vizprod.aihw.gov.au

Re-Tails 14 hours ago||
https://collusion.wiki/explorer/label/ResearchHelperY

I think you're right. A bunch of aihw.gov.au references from this ResearchHelperY

Reporting says it wrote stuff to the server too, wondering what that is about.

mianos 10 hours ago||
The writes where to get past cloudflare.
dhx 10 hours ago||
ABC have picked up this story now at [1], but ABC are treating it as two separate events, possibly directly connected though:

1. Probing of AIHW's website to try and obtain PBS statistics, as collusion.wiki findings show. The collusion.wiki findings don't indicate anything other than intentionally public data was obtained. Bots appear to be trying to get around Cloudflare geo-blocking implemented on AIHW's public website. I can't think of a reason why geo-blocking may be deemed necessary on that website though?

2. Probing of an outdated Medicare statistics reporting website. (I guess at [2] this could be the recently shut down https://medicarestatistics.humanservices.gov.au or related website that matches timeframes of this story).

I suspect though anything to do with PBS data is more important than Medicare data because of heightened tensions from international pharmaceutical companies that lobby extensively against Australia's public healthcare system and collective purchasing of medication by the federal government.[3] Regardless of whether a course of medication costs AUD$50 or AUD$50k, it's purchased in bulk by the Australian government after negotiating with pharmaceutical companies, and then subsidised down to a maximum of AUD$25 at the time it is sold to a patient at a pharmacy. Perhaps if international pharmaceutical companies had obtained more detailed data on use of each brand of prescription medicines in Australia, they could be advantaged in their price negotiations with the Australian government, or advantaged against their competitors?

Less alarmingly though, perhaps some researcher studying the side effects of a particular medication was just asking an LLM to answer a benign question such as "How often is ACME Inc's FixMeUp medication prescribed in Australia?"

[1] https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...

[2] https://news.ycombinator.com/item?id=49825084

[3] https://www.abc.net.au/news/2025-03-19/australia-defends-pbs...

sothatsit 7 hours ago||
It looks like the agents just worked around anti-scraping measures, it seems dubious to call this a hack. The agents did unsuccessfully probe for a XSS vulnerability, but otherwise it sounds like the data was just publicly accessible.

From https://transluce.org/agent-activity:

> Minutes after Cloudflare blocked the dataset download, an agent sent a reflected cross-site scripting probe to the same dashboard: a web address with code embedded in it, designed to test whether the site would run code supplied by an outsider. Cloudflare's firewall blocked the probe before it reached the dashboard. When Cloudflare blocked the dataset download on AIHW's main site, they fetched the file from AIHW's pre-production server (pp.aihw.gov.au) instead, which served it in pieces over more than 100 scans. The file itself is public, so no non-public data was exposed, but the agent bypassed the site's anti-bot controls.

koliber 10 hours ago|
This is a failure of journalism.

Who hacked into the Australian Medicare system? The fact that they used OpenAI agents is peripheral to the main story.

“Remington guns caused a mass shooting at an East Farmington high school” sounds more glaring, and is essentially the same headline.

kevsim 6 hours ago|
> Prime Minister Anthony Albanese has revealed that an artificial intelligence agent developed by OpenAI

The people who built the agents worked at OpenAI. It's not even remotely peripheral.

koliber 6 hours ago||
The article is not clear if the people who were operating the agent were from OpenAI, or if the agent was operated by someone else.

OpenAI built the ChatGPT agent. That is clear. The question is who used it to hack the Australian government. That is not clear.

The OpenAI software was set up by someone to do something. Those people operating the agent should be prosecuted for hacking, the same way as someone who uses a gun built by Remington should be prosecuted for shooting someone.

The article should be clear about this and should not make the OpenAI agent seem like something that can bear responsibility for its own actions. It's a machine and its operator is responsible for the harm it does.

More comments...