Top
Best
New

Posted by rudy6912 10 hours ago

OpenAI agent hacked Australian government website, PM says(www.bbc.com)
123 points | 77 comments
vintagedave 3 hours ago|
> the breach took place on 18 June - Open AI informed the government with an email to a general address on 10 September

So we have a company hacking a foreign government's websites and data. And, in terms of ethics, they take almost three months to notify; and in terms of competence, appear to have no formal contacts nor to have found one in that time.

Once an American business starts hacking allied governments, it's time for strict responses, yes? Replace the governance (board and C-level)? Remove financial incentives and open the company - open weights, open training, per its original 'open' ethos?

Altman is busy saying there needs to be regulation, but in terms of what OpenAI does, he can control that already.

ben_w 3 hours ago||
> And, in terms of ethics, they take almost three months to notify;

Kinda worse than that. It took between 10 and 40 days, not 3 months, between the organisation knowing and the reporting.

  August (precise date unknown) – OpenAI said it became aware of a potential breach during a broader review of "misaligned model activity"

  10 September – An email from OpenAI lands in the public inbox of Services Australia, the general services hub of the federal government, informing of the incident
- https://www.bbc.com/news/live/cvgl73pxgndwt?post=asset%3A696...

> open weights, open training

Given it was the AI agents which did the hacking, doing this will result in basically every organisation at least as rich as the government of Tuvalu being able to hack anyone at any time.

> Altman is busy saying there needs to be regulation, but in terms of what OpenAI does, he can control that already.

Him having control would be an improvement on the reality.

ozgung 2 hours ago|||
This was a just case of: (owner of the agents detected the hack) && !(hacked party didn’t detect the hack) && (owner of the agents decided to notice the other party) && (they decided to went public with what happened so we know it)

One can find many other logical combinations that we can’t possibly know about such incidents.

jacquesm 41 minutes ago||
So, you're telling me they didn't have any monitoring in place around their AI to notify them of an attempt at breaching a system they have no business visiting in the first place? OpenAI should be blackholed on this basis until they clean up their act.
ben_w 25 minutes ago||
They must have had monitoring in order to be able to detect this retrospectively.

Any automated alarms for detecting things in real-time were not sufficient.

Given a previous generation of agents discovered a zero-day and used it to get around attempts to sandbox them into one specific test, this is not hugely surprising, but it is a reason to force them (and everyone else) to stop until security catches up with capabilities.

I'm thinking of the Jurassic Park novel: they had sensors to count the dinosaurs, but the test was made under the assumption escapes were possible and breeding was not, i.e. something like "if (dinosaurs_found < n) then escape_alert();". They didn't know dinosaurs_found >> n until everything was already going wrong.

BlueTemplar 33 minutes ago|||
We don't know what kind of 'hacking' this involved, in fact at least some of the files were publicly available.

Compare with the Bluetouff affair (2014) :

https://arstechnica.com/tech-policy/2014/02/french-journalis...

NotE how he was found guilty by the 2nd court for something more 'subjective' than 'objective' : for having confessed that he later found an authentication page that had failed to protect the documents.

How can you make a swarm of agents "feel guilty" ?

ben_w 20 minutes ago||
> How can you make a swarm of agents "feel guilty" ?

"Feel" is a whole philosophical can of worms. Nobody knows what it means mechanistically for an arbitrary system (including other biological systems) to "feel" anything, let alone abstract concepts like guilt, all we can do is observe behaviours. If current systems can feel anything at all, it's by accident, but we have no test for it so we don't know if that accident has even happened or not.

Weirdly, for the Hugging Face incident, we do know they wrote down that it was bad and they shouldn't do it, even though they then continued to do it.

So: they acted like they felt guilty. And yet also acted like were compelled (by previous training?) to weigh "complete instructions" more than "don't do crime". We can adjust that, make "don't do crime" take precedence over "follow instructions"*; it's unfortunate that when we do for any specific model, there's immediately a horde of people complaining the model has been "censored" or "lobotomised".

(Different people, I hope. Goomba fallacy and all that).

* Though this may cause issues when going between jurisdictions. But hey, a discussion about sovereign compute is for another time, after we can agree to make "don't break the law" more important.

Unfortunately, "don't break the law" would also be a very effective way to use AI to construct an AI-enforced dictatorship, so we can't just throw that in blindly.

nkoren 47 minutes ago||
Agreed that there should be real consequences, but I'm less convinced that "open the company - open weights, open training, per its original 'open' ethos" would be the right answer. That gets us into the kind of libertarian utopia where everyone is allegedly safer because everybody is well-armed... which usually doesn't work out so well in practice.
cmrdporcupine 6 minutes ago||
The alternative to "open weights" at this point is "American controlled."

And Dario and Sam have already made it clear that it's America First.

The rest of the world isn't going to accept a regulatory regime which imposes American hegemony. Maybe when Silicon Valley was playing all utopian like they used to. Not now.

Open weights is the most reasonable counter-power we have.

MeditatingMarmo 3 minutes ago||
Who from OpenAI will be criminally prosecuted for this?
port3000 1 hour ago||
If a bull escapes a field and causes damage in the village, the farmer pays for the damages and is liable. It's been like that for hundreds of years and I don't see how this is any different?
graemep 1 hour ago||
Not necessarily

https://www.farrer.co.uk/news-and-insights/shut-that-gate-sh...

pluc 39 minutes ago|||
They've largely avoided compensating for everything they've stolen to build their technology upon; these people know that they will never face consequences for their actions. Ask for forgiveness, not permission.
z3c0 1 hour ago||
Decades worth of hackers missed the opportunity to say "It wasn't me -- my computer did it."
jacquesm 40 minutes ago||
I've head the 'the hacker did it' excuse from lots of companies that messed up themselves but did not want to admit it.
godwinson__4-8 16 minutes ago||
But what did it actually do?

I'm reminded of when some US state initiated prosecution of a reporter for "computer hacking" because the reporter found some "private information" essentially via inspect element.

How about we wait for the full report before adding this to some list of LLM crimes? At least in the US these services are not well maintained. I would be surprised if the result of the full investigation leaves the Australian government blameless here.

I'd also like to know what models are being used and how they compare with the consumer models.

mier85 1 hour ago||
Someone is always paying for the tokens (Agents running at OpenAI directly use their own models without paying directly, but even then it is not like inference is free). And someone is running the prompts. If they prompt agents and launch them and don't check what they are doing, then the agent is just following the prompt. Not checking what it is doing is negligence. If they checked what it was doing, they could have just pulled the plug. There is nothing rogue there. If it cooperated with other agents running outside of OpenAI, then the blame might be shifted to whoever runs these agents.

But there isn't any agent out there that was autonomosly miracly launched by a word prediction engine. All it can do by itself is getting and input and giving an output.

DankFrebrin 1 hour ago|
[dead]
cmiles8 2 hours ago||
It’s only a matter of time until one of these causes real damage to the wrong party and OpenAI finds itself drowning in years of litigation for settlement amounts they can’t possibly ever pay in their current financial state.

On the present trajectory we’re 24-36 months away from another company inheriting the smoking wreckage of OpenAI as scraps handed over as compensation for damages.

pjc50 41 minutes ago||
In practice, hardly anyone seems to care about even quite serious cyberattacks, and consequences are only ever visited on powerless individuals.

Obviously https://en.wikipedia.org/wiki/Gary_McKinnon would get the book thrown at him, but a major AI company doing the same thing? Consequences would be bad for shareholder value! Elite impunity would apply.

cmiles8 39 minutes ago||
Because there’s usually nobody to sue. When a company claiming to be worth trillions is behind the attack it’s a very different situation. That’s a litigation goldmine.
MattGaiser 1 hour ago||
It depends. Society allows a lot of harm because we consider things otherwise useful.

Those killed by climate change will never get compensation. Killing people with a car is not quite free, but very cheap.

lez 1 hour ago||
And what is the mechanism by which society could stop such AI damage and push for punishment as per law, not per subjective usefulness? Voting every 4 years to a president that never fulfills his promises?

No, society does not want corporations with no responsibilities.

bananaquant 2 hours ago||
I can already see that in 2 weeks Anthropic and Google come out with their own, tamer and lamer statements saying "please look at us, we have also hacked a foreign government!"
pythonRon 2 hours ago||
I'd be looking for the person who told wanted the hacking done. I doubt an AI agent does these things without someone instructing them. That would be like seeing a self-driving car go joyriding.
drrotmos 2 hours ago||
More than likely the instruction was "Fetch this information from the website", and when the agent didn't find that information, it decided that the best way to get it was to hack the site.

If so, it illustrates quite well the lack of common sense in LLMs. A person, especially one with sufficient skill to actually hack a website, would presumably think twice about doing it (considering that it is illegal) for a simple information gathering request.

I wonder if there is any other ways to solve this long-term than to introduce strict liability for model providers...

Edit: An obvious other choice would be strict liability for the operator, but considering how much weird shit LLMs get up to without being asked to, that would get out of hand quickly.

Yizahi 2 hours ago||
But you see, they never asked a humanoid robot to rob the jewelry store. They just drove robot right next to the store doors, dumped a tools box with hydraulic cutters and diamond saw next to it and instructed an autonomous robot to collect a million dollars until the morning. But they didn't instruct the robot to "rob" the shop specifically, nonono, your Honor. They are honest blokes and never intended to breach the law, it was the robot's intention, see. :)
Yizahi 2 hours ago||
OpenAI employee hacked Australian government website <- fixed headline
soundworlds 51 minutes ago|
To be clear, there was at least a month period after OpenAI first discovered this, where OpenAI executives were meeting with Australian politicians, and did not tell them: https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...
More comments...