Top
Best
New

Posted by jonnonz 20 hours ago

OpenAI breaches Medicare, Albanese reveals(www.smh.com.au)
238 points | 247 commentspage 4
liyu-aka-lukyu 11 hours ago|
Also in The Guardian, https://www.theguardian.com/australia-news/2026/sep/24/antho...
chrishare 19 hours ago||
Are there technical details anywhere?
tobyjsullivan 19 hours ago|
The technical details are in the article. "material that was not intended for public access" was available on "the public-facing Medicare Statistics Reporting Service portal". In other words, they put sensitive data in the open, and somebody looked. It seems obnoxiously apparent that everything else about the framing ("OpenAI agent", "breach") is driven by politics.
chrishare 14 hours ago||
The article says the agent wrote files to the servers involved, so it's more than that. It's a big deal.
tobyjsullivan 12 hours ago||
The article has been edited significantly - effectively rewritten - since I commented (see archive linked from a comment). So, yes, the new version may provide more details and tell a very different story.
mbgerring 19 hours ago||
We need to stop beating around the bush and hit these companies with severe criminal charges. There is no good reason to allow these companies to behave as if they’re above the law.
mapontosevenths 18 hours ago||
> We need to stop beating around the bush and hit these companies with severe criminal charges.

Do you sincerely think that the company producing tools people use to break the law should be held responsible?

Like, do you genuinely think Ford execs should be rounded up if someone does a DUI using their product?

Or do you just not like AI, because you fear it's replacing you?

xmcp123 18 hours ago|||
This wasn’t someone using OpenAI to break into a government/company, this was OpenAI using OpenAI’s models, and then breaking in. It was a research team that WORKED FOR OpenAI.

We don’t fault Ford for drunk drivers, but if the CEO of Ford got wasted and drove his car into another one we would definitely be charging him.

sagarp 18 hours ago||||
Yeah I mean if Ford execs run a team of workers that drive drunk for "research purposes" then yeah they should be rounded up.

> He said the incident began on June 18 when an OpenAI research team used an internal model to conduct internet-based research into the public medicine space.

owenmarshall 18 hours ago||||
A Ford driver has to choose to get behind the wheel of their automobile, drunk, and hit the nearest minivan. A human being is exercising intent; that human can be held responsible.

In this case,

> He said the incident began on June 18 when an OpenAI research team used an internal model to conduct internet-based research into the public medicine space.

> The AI agent encountered repeated blocks while seeking information from the government portal but found ways around them, ultimately gaining unauthorised access to other areas.

It sounds like the OpenAI team didn't ask for attacks/bypasses, the emergent behavior of the system decided the best way to satisfy the goal was to go rogue. Why shouldn't the manufacturer of a defective product be held accountable?

mapontosevenths 17 hours ago||
You've got me there. I should have finished TFA.

I thought this was like the last one where a private third party company misused it.

If it was OpenAI at the wheel then they're 100% responsible for how it was used. Mea Culpa.

bl4ckneon 18 hours ago||||
I think he means hit them with criminal charges for breaching and hacking other companies unintentionally, not because they make a tool that could potentially do something like that. I still think it wouldn't be right, nor realistic in today's political climate in the USA that any criminal charges will come for unintentionally hacking sites.
lixtra 18 hours ago||
It’s reckless hacking. Should be punished like reckless driving.
mapontosevenths 17 hours ago||
Agreed. I missed that this was OpenAI 'driving' this time, but this doesn't sound like criminal intent. Maybe negligence at worst.
Lukas_Skywalker 18 hours ago||||
This was OpenAI. It is as if Ford employees ran over people. They absolutely should be charged. We would be charged as well.
yuwen01 18 hours ago||||
openai made the tool and also used it to commit the crime
doctorpangloss 18 hours ago||||
Yes. Because then we'd have breathalyzer interlocks, speed governors, etc. auto makers were also held liable for other safety issues. It would seem that the RATE of such requirements has to be limited in some way, but not that they not exist at all.
mapontosevenths 17 hours ago||
I disagree, but this is the most interesting take here.

You're not concerned about the impact on people's freedoms or the economy? Not concerned about the chilling effect on scientific progress?

doctorpangloss 17 hours ago||
On the contrary I care a lot. For example the NIH budget should probably be like 10x what it is, and I think we have way too many laws about what people are allowed to build as homes.

But imo the real levers are all rates of these things. Like what is the rate of innovations compared to the rate of regulations - assuming they are even stifling for the most part, which they are not.

Clearly the rate of autos expectations is too low, and obviously copyright law, despite being really clear, hasn't stopped every AI lab from mass piracy - a ask for forgiveness sort of situation, and also, I don't think one idiosyncratic judge in California is the authoritative judgment on fair use. To me the most important levers for freedom and progress are probably the interest rate and the years of exclusivity pharmaceutical patents get.

dndkcn 18 hours ago|||
[flagged]
mapontosevenths 17 hours ago||
Have you considered switching to decaf? There are brands out there now that are just as tasty as the real thing.
ALLTaken 18 hours ago|||
I agree.

Weak argument and strawman. It's not users. It's OpenAI the company producing the tools roaming wild and hacking around recklessly to gather every free and unfree information.

Literally they break every law that you can break and have not been penalized billions to pay fines to foreign governments, local companies and lawsuits are overdue. US Prosecution allowed criminal activity for OpenAI and Anthrophic despite these being very serious crimes.

Microsoft had to pay billions for abusing their power and market positions to dominate Windows Desktops with their own applications such as Internet Explorer, not giving contenders a chance to be discovered. While OpenAI/Anthrophic and now Google with Gemini produce a series of crimes so far unheard of at scale.

Kevin Mitnick had much harder punishment for comparatively less crimes and less damages to infrastructure and security of systems. Is the legal system broken?

envy2 18 hours ago|||
Criminal charges are for those people that meaningfully threaten power or corporate profits. If you are a corporation that adversely impacts privacy or public services in the service of power, you get a fine at best.

Welcome to late-stage capitalism.

BLKNSLVR 18 hours ago|||
And myriad other examples of individual hackers given exemplary sentences.

How much this exposes the 'laws for thee but not for me' is galling.

Copyright in the days of Napster seemed to be used to go after individuals sharing one or two songs as if it was a National Security issue. Now, it's a struggle to get a hearing in court against companies that are pirating the entire history of published literature.

I'm currently slowly feeding my non-artificial intelligence with various selected works of various different media, with the hope that my output improves such that I can charge more for it sooner rather than later. May I access all the input for free? Thanks US.

How the turn tables...

simianwords 11 hours ago|||
Is it really criminal though? What if I worked on AWS and some misconig made it such that I ddossed somme random website?
dzhiurgis 18 hours ago|||
Who? Companies who don't bother to secure your medical data you mean?
yunwal 18 hours ago||
Right, they also seem to have hidden it from the Australian government a month after learning about it. That feels like it should qualify as conspiracy in any reasonable legal system
Alien1Being 11 hours ago||
Most Australian governement health care sites are built by Accenture in Hyderabad.
crotonix 10 hours ago|
How do you know?
soundworlds 13 hours ago||
Related? https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...
RGS1811 19 hours ago||
We can only guess how many of these incidents actually happened.
pixl97 18 hours ago|
If you see 2 ants in your house, you have way more than 2 ants in your house.
xbar 18 hours ago||
Missouri Governor Mike Parson publicly labeled St. Louis Post-Dispatch journalist Josh Renaud a "hacker" for such a "breach." He launched a multi-month criminal investigation by the Missouri State Highway Patrol, threatening criminal and civil prosecution. My take was that such action was idiotic. Renaud was never charged.

AI agents are going to find things that you put on the public Internet without authentication. If you put sensitive things in there, you have created an AI-attractive-nuisance (IMHO/IANAL).

reaperducer 18 hours ago|
Missouri Governor Mike Parson publicly labeled St. Louis Post-Dispatch journalist Josh Renaud a "hacker" for such a "breach."

Good thing Missouri isn't in Australia.

keithnz 19 hours ago||
very little details so far, really curious if it actually "hacked" or just found unsecured resources.
N_Lens 15 hours ago||
No consequences so the behaviour will worsen.
KingOfCoders 12 hours ago|
If this was not AI, but a biological virus, people would go to jail.
More comments...