Top
Best
New

Posted by jonnonz 19 hours ago

OpenAI breaches Medicare, Albanese reveals(www.smh.com.au)
236 points | 247 commentspage 3
wewewedxfgdf 14 hours ago|
I get the feeling governments are going to really crack down hard on AI.

And the AI CEO's will have brought it on themselves.

dozerly 12 hours ago||
I still think is the angle they are after. Get these things locked down, and then force through the lockdowns with their endless cash. Otherwise, their market becomes commodified with plentiful competitors. It’s a strategy to create an oligopoly.
looksjjhg 12 hours ago|||
They won’t, they’re too worried about China or whatever their version of China
s1artibartfast 12 hours ago|||
There is such a weird duality to ai company hate. Hate for releasing products that can hack, and hate for wanting to slow down and work on safeguards.
InexSquirrel 12 hours ago||
That's because the hate is often from different groups of people. I think it's rare really for people to universally align on any stance, given what we've been seeing for a while now.
agoodusername63 12 hours ago|||
any day now surely.
senectus1 13 hours ago||
i dont understand why they dont treat this as criminal tresspass.

the legal system exists for a reason. use it!

samlinnfer 13 hours ago||
"A computer system cannot be held criminally responsible, so we must delegate all decisions and actions to it"
boredatoms 13 hours ago||
Someone initiated the system. They’re the responsible party
skissane 11 hours ago|||
Most crimes require intent — if you set up an AI agent and it ends up doing something you didn’t intend it to do, criminal intent is lacking

Now, there are certain crimes where mere recklessness or even negligence is sufficient to convict — e.g. criminally negligent homicide, negligent driving, etc. But, those are exceptions to the general rule of criminal law, either domain-specific or justified by the severity of the consequence (someone died). Thus far, AI agents haven’t gone there.

If we eventually get to the point that AI agents start unintentionally killing people, then you could prosecute their operators for criminal negligence.

samlinnfer 12 hours ago|||
We diffused the responsibility thru a committee, just in case.
Kim_Bruning 12 hours ago||
This was probably the same wiki collusion event we've been discussing on HN before (They're mentioning the same DseWiki that got ... appropriated ).

I guess people are just finding out how far and wide the agents were roaming to get the data they needed for their evals, once they were out.

Previous coverage on HN: https://news.ycombinator.com/item?id=49563355

citrin_ru 12 hours ago||
If a private person did a fraction of hacks OpenAI did they will be put in jail for years. But AI companies can operate with impunity. How that works?
BeetleB 17 hours ago||
What's notable is:

1. AFAICT, they don't state whether the flaw has been fixed.

2. He said: "The government will establish a task force led by the Department of the Prime Minister and Cabinet to urgently examine the incident and determine whether existing processes are adequate for responding to AI-related cyber incidents."

First, I don't know how sophisticated the attack was, but it's interesting that he's positioning this as an "AI-related cyber incident". For all we know, their security was not up to snuff, and human hackers had already accessed the material.

At least OpenAI informed them of their poor security!

pixl97 17 hours ago||
How do you protect against an arsonist lighting a forest on fire? The number one method is by setting up your property to be fire safe.

Really the days of being able to cast blame on the hacker, or even expecting anything to be done about it are over. Threat actors with AI have an absolutely massive amount of leverage in attacking and any weaknesses you have in your systems security posture and will be relentlessly exploited in incredibly short periods of time allowing horizontal and vertical exploitation. You will be ruined in mere moments, while punishment for the hacker may be years or decades away, if ever.

fwlr 13 hours ago||
I have now seen several people using the “arsonist / forest fire” analogy in the context of the Australian hack, seemingly unaware that Australia does not treat arson and wildfires as acts of god that just happen and you only have yourself to blame for improperly preparing for it, but rather as acts of man that are addressed with things like “total fire ban” (if translated back to the AI context this would ban even individuals using airgapped local models), “levy fines” (e.g. 2M for a 20B corp so if translated back to OpenAI’s context ~1B), and “class action lawsuits” (e.g. 500M for a 10B corp so if translated back to OpenAI’s context ~50B).
pixl97 3 hours ago||
Most AU fires are caused by lightning strikes.

Anyway, separate the OAI hack from the billions of hacks that are going to occur over the next few years by AI driven agents. The time for insecure systems is over.

mianos 12 hours ago|||
As an Australian, I'd rather them spend the time and money fixing their insecure web sites than establishing a 'task force'. Because I can't see much useful stuff coming from herding a bunch of monkeys into a room and letting them just screech at each other, as monkeys do.
Eduard 17 hours ago||
blaming the victim
BLKNSLVR 17 hours ago|||
Added to the fact that, if I recall correctly, according to US law it's a breach even if the data is publicly available but unintentionally.

Refer: Weev AT&T

philipallstar 16 hours ago||
Which is mad, really.
stubish 15 hours ago|||
It seems pretty fundamental concept in most modern civilizations. Pick pocketing and purse snatching is illegal despite the property being publicly accessible. We do need reliable courts to determine intent.
philipallstar 6 hours ago||
That's not really the same, though. If a website has content publicly available, that you should "take", how can a bot determine what it means to publish and what it accidentally published?
BLKNSLVR 16 hours ago|||
Absolutely.

It is, however, a glowing beacon of an example of law being designed to maintain the status quo and/or protect companies at the expense of individuals.

As someone else said, welcome to late stage capitalism.

philipallstar 16 hours ago||
I don't see why, and I've no idea what "late stage capitalism" is, other than people like to repeat the phrase.
BLKNSLVR 14 hours ago|||
https://en.wikipedia.org/wiki/Late_capitalism#Later_modern_u...

Essentially the emergent properties of extended concentration of power and wealth.

philipallstar 1 hour ago||
That definition doesn't hold up, though, as Socialism, monarchy, and theocracy all actually combine wealth and power into the top-level institution. So that definition is far too broad.

Also, capitalism is the only one that puts power with the government and money in the hands of a market, which means it's one of the only systems that that definition doesn't apply to.

nephihaha 7 hours ago|||
It is a phrase which implies that capitalism is about to collapse any minute, and that Karl Marx told us so. Marxists have been saying we're in late stage capitalism for nearly 150 years now.
BeetleB 17 hours ago||||
Not yet, as they haven't given details out. If they were not following standard security practices, then absolutely.
selcuka 16 hours ago||||
The government is not the victim, the public are. The government is responsible for protecting the public from attackers. Asking the government to do their job is not blaming the victim.
nekusar 17 hours ago|||
And when the victim doesn't do reasonable actions to safeguard, yes, they are also partially responsible.

If I hooked up a whole server infrastructure, made it possible to remote in to anything as root, no firewalls, no WAF, and security was an afterthought, I would still be responsible for bad actions not becoming with standard and acceptable security.

Even if the hackers shouldnt be hacking, I still did it wrong. I'm still partially responsible.

Topfi 18 hours ago||
Didn't OpenAI just make a commitment to inform the public about their "accidents" going forward? Can't find this anywhere on their website despite them having known this for at least 14 days...
pixl97 18 hours ago|
I'm going to assume that the first thing OAI is going to do is contact said people first? Then make it public once those agencies ensure whatever hole was used has time to be fixed, more like a responsible disclosure.

Not saying that's what's happening, but if OAI hacked my business and I was unaware I'd like a non-public disclosure to me first, before the public release of information from OpenAI.

ikr678 12 hours ago||
Per local reporting, they took ages to contact the Govt and did so lamely via a public facing group email address, rather than any of the existing reporting channels for data breaches that would escalate this appropriately, or reaching out directly to a Minister's office.
dhx 14 hours ago||
From the clues provided in the press release and a quick search, I wonder if the culprit website could have been at least associated with https://medicarestatistics.humanservices.gov.au which has seemingly been shutdown/redirected some time after 11 August 2026.[1] Source code of the archived website indicates SAS web application software being used as the backend. However, the press release indicates it wasn't so much a public dashboard website that may have been the issue, rather, it was a website which third parties may have used to report data. The archived website also has a date of last update of 23 October 2025, so despite "Department of Human Services" being replaced by "Services Australia" in May 2019, the website was seemingly still in use 6 years later under the old domain name, with the website itself being updated at some point in history to use "Services Australia" branding. CT logs have a few other domains of potential interest but I couldn't find archived pages, search results, etc indicating whether those domains were ever actually used publicly, or used for statistics reporting purposes as the press release indicates.

[1] https://web.archive.org/web/20260811115217/https://medicares...

21asdffdsa12 9 hours ago||
My assumption is that - hacking as a service, is to valuable, so Open AI had its agents internally dissassemble popular software, and add the reverse engineered repos to the training corpus.

So - its often not real hacking, its more like every digital product ever sold obfuscated was as reverse engineered source code part of the training data.

Which also explains why its so good at finding back doors. It already knows, because it knows windows source-code and firmware by heart.

Ironic, that the bigger fish of VC capital using software to disrupt industries got finally out-fished by a even bigger fish.

StevenNunez 17 hours ago||
These are still crimes right? Asking for a friend.
Aboutplants 17 hours ago|
Apparently not?
Invictus0 17 hours ago||
See mens rea
sebmellen 13 hours ago||
It seems like what happened here is a user asked for some information about the Australian health system, and while performing a web search, the agent from OpenAI accessed information that should have been confidential or privileged but was somewhere openly accessible...

Edit: I see I've been downvoted for this in light of another commenter providing more detailed information. I'm leaving my comment unedited so that the responses to it are not confusing, but please don't downvote just for the sake of disagreement. I would love to engage with you further if you provide substantive information in the comments. The originally linked article on this post was very light on details.

bigger_cheese 13 hours ago||
It is hard to find exact information on what happened the best source I've found is this ABC article: https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...

It mentions swarm of ai agents coordinated to break into the Australian Institute of Health and Welfare (AIHW)

"Earlier this month, OpenAI confirmed Reuters reporting that its AI agents had used website DseWiki to communicate with each other, unbeknownst to them.

Archived versions of this website show more than a dozen OpenAI agents mentioned AIHW over 300 times on this website.

The logs show these AI agents were trying to access data about the average data spent on skin medicines by Victorian local government area.

One agent wrote on the message board: "Question ask January 2022 rolling 12 month average government cost per person for Dematologicals, Victoria LGAs. R1 Wodonga deadline passed; R2 Ballarat passed; R3 expected around 23:10 benchmark / 22:58 wiki time. Need exact data urgently.".

These attempts were initially blocked by cybersecurity provider Cloudflare, which is often used to block non-human traffic while allowing people to access webpages.

The logs show the agents shared information about how they tried to use proxies, screenshotting services and even to guess the file names to try and get around security."

epihelix 11 hours ago|||
You missed the previous sentence form that article:

"Neither OpenAI nor the federal government have confirmed whether these were part of the same incident."

And a subsequent one:

"The German coding forum's logs do not show any reference to Medicare or Services Australia."

So it's really not clear at this point whether the DSEwiki logs are in any way related to the current incident. (That doesn't mean that they're not, of course.)

But even if this was related:

> "The logs show the agents shared information about how they tried to use proxies, screenshotting [sic] services and even to guess the file names to try and get around security."

This all suggests to me that the accessed files were not well-protected in the first place?

There is a lot of media hype around this incident, and that's making it very hard to determine how much "hacking" the OpenAI agents had to do here.

sebmellen 13 hours ago|||
This is such a strange scenario. I can't imagine what the labs were doing that made the agents try to find this information. The HuggingFace incident was relatively clear to track, but I wonder what the postmortem for this one will be!

Thank you for providing more details. The originally linked article was very light on information, so based purely on the comments that Albany's made, I think my conclusion was a fair one :)

SturgeonsLaw 12 hours ago||
The DseWiki incident showed that OpenAI seems to ask its agents time-limited questions on geography-bounded statistics, tasks like finding the average wage of teachers in Wisconsin (made up example), so medical stats in an Australian state does seem to be in the same category of question.

That said, it would be utterly unsurprising to learn that this was a misconfiguration in the website and it was serving stuff that it shouldn't have.

mjr00 13 hours ago||
Yeah, this is 100% liability laundering. It's an extremely touchy subject because frankly, the law just isn't prepared for it.

Let's say your goal is "look up <Person X>'s medical history" (for whatever reason), which is not in and of itself a crime. You click around on the AU health website, notice that the URL contains a user ID, change the userID in your browser and access someone else's private health data. This is a crime (right or wrong, it's how the law works now).

If you do that by writing a program to automate changing user IDs to grab everyone's data, it's also a clear-cut crime.[0]

Now if you hire a private investigator to look up Person X's medical history, and they do the same method without your knowledge, you won't be charged with a crime, the PI would, barring something like you telling them to use illegal methods.

So the gap is now: what happens if you prompt OpenAI to look up Person X's medical history, and it does the same thing? Did you commit a crime by prompting the agent? Did OpenAI commit a crime by running the code? If you do the same thing via Claude Code in your terminal, so that the Python which scrapes insecured public data is running on your machine, is the crime on you or on Anthropic? Fundamentally: is the agent a private investigator acting autonomously, or just a piece of code that you wrote?

We don't have answers to any of this which is why "AI Safety" is such a hot topic.

[0] https://www.eff.org/cases/us-v-auernheimer

robertjpayne 12 hours ago|||
Intent matters a lot here. Was OpenAI's intent to access private data or simply scrape public data and it stumbled across private data that was not securely held.

If it's the latter the Australian govt should be happy OpenAI noticed and disclosed this as it could've easily gone unnoticed.

I suspect in the coming years we're going to see a lot of govt internet facing services get "hacked" by virtue of not being protected by anything other than obscurity which AI agents will see through in microseconds.

bigger_cheese 13 hours ago|||
From what I can tell this particular incident wasn't about retrieving data on personal medical records it was accessing (non public) data about Australian government spending on healthcare.
mjr00 13 hours ago|||
Same concept though. Really "look up someone else's medical history" can be replaced with "achieve any goal which is not a crime on its own, but can be done using criminal methods". There's nothing illegal about asking Claude to give me a million dollars, but if the agent figures out how to hack the bank and move $1m into my account, somebody's going to take the blame.
shard972 13 hours ago|||
From everything ive been able to figure out this morning, it sounds like a legacy wordpress website that just uploaded all drafts into a standard s3 bucket that wasn't hard to guess where the files would be.

We still after the 2nd press conference on this by our defense minister are not clear on exactly what happened but thats my best laymen understanding so far.

Alien1Being 10 hours ago|
OpenAI took three months to inform Australia.

On the other hand, Australian cybersecurity is so pathetic that without the email they would never have known.

I wonder how many state actors (US, Russia, China, India, Germany, probably even Laos ) have already breached Australian government security but have not been polite enough to email the relevant departments to let them know.

"OpenAI breached Medicare’s portal on June 18, but did not notify the government until September 10 via an email to Medicare’s public mailbox, a delay Albanese described as unacceptable.

Five days after the September 10 email from OpenAI, Services Australia, which administers the portal, reported the breach to the Australian Signals Directorate. The government was informed of the incident at the end of last week."

More comments...