Summary
- OpenAI agent breached Australia’s Medicare portal, accessing public and non-public health data.
- OpenAI only detected the June breach in August and notified officials weeks later.
- Australia launches a task force to probe legal and cybercrime gaps for autonomous AI attacks.
As the global outcry is getting amplified about the dangers of AI, an OpenAI agent has made the headlines today for hacking an Australian public health service website.
Per covered by Financial Times, the incident occurred in June, but it wasn’t until August that OpenAI detected it after reviewing the agent’s behavior. This marks the first time the reports regarding an AI agent trying to access government files have gone public.
“This situation is obviously unacceptable,” says the Australian prime minister
But apparently the impact was “relatively minor”
Reportedly, an OpenAI agent breached the Medicare Statistics Reporting Service portal, which is operated by Services Australia. The website contains information about insurance billings, pharmaceutical spending, organ donations, and other similar healthcare programs.
At first, the portal failed to provide the information the agent wanted, which led the agent to find another way inside. Australian Prime Minister Anthony Albanese says the agent subsequently accessed both “public and non-public” files. Moreover, Australia’s defense minister, Richard Marles, mentioned that multiple systems that contained health and crime statistics had been accessed by OpenAI’s agent. While he labeled the incident as “very serious,” he also mentioned that the effects were “relatively minor.”
In another discussion with an ABC broadcaster, he said:
“We will look at what is the legal situation in respect of this and what it means to have gained an unauthorised access, albeit in an unintended way.”
OpenAI didn’t detect the Medicare breach until August, and waited until September 10 to let Australian officials know by emailing a general Services Australia inbox. It took another five days for the incident to reach the Australian Signals Directorate.
Prime Minister Anthony Albanese called both the breach and the delayed disclosure unacceptable. Australia has now created a task force to investigate the incident, determine whether any laws were broken, and reconsider whether existing cybercrime legislation can handle an attacker that has no human intent of its own.
Even though nothing with grave consequences occurred, this incident offers a much clearer picture of the catastrophic outcomes unsupervised AI could cause. About two weeks ago, an Anthropic researcher warned that AI could kill every human within the next ten years. Although sci-fi-grade AI uprising scenarios remain predominantly hypothetical, recent incidents show how far AI agents can infiltrate sensitive systems before anyone realizes they have crossed the line.