OpenAI breaches Medicare, Albanese reveals
Thread
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
OpenAI breaches Medicare, Albanese reveals
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
Lukas_Skywalker · · focus · HN ↗
chrishare · · focus · HN ↗
tobyjsullivan · · focus · HN ↗
chrishare · · focus · HN ↗
tobyjsullivan · · focus · HN ↗
nxobject · · focus · HN ↗
It looks like the PM gave Sam Altman a "tsk tsk". It will be interesting to see whether someone else tries to impose more consequences.
briga · · focus · HN ↗
reaperducer · · focus · HN ↗
pixl97 · · focus · HN ↗
pixl97 · · focus · HN ↗
Honestly it's very likely something stupidly simple.
"What is the rate of health incident $X in $Y to the $Z degree". The bot went around playing mad libs with XYZ and found that the public AU data wasn't sufficient to get the answer the grader wanted so started kicking down doors.
I saw someone explain it like "A group of masked men rush a nuclear facility, breach security successfully, then count how many buttons are on each control panel on average". Like using a godhammer to destroy a mouse, their motivations and capabilities just fall in a completely different alignment to humans.
Marazan · · focus · HN ↗
If only there was some well known example of this that people could draw on for insipiration.
If only....
pixl97 · · focus · HN ↗
thin_carapace · · focus · HN ↗
underyx · · focus · HN ↗
alboboboob · · focus · HN ↗
[dead]
shitcoder · · focus · HN ↗
Personally, I wish the the side effect wasn't the playing into the hands of the AI tech companies
bonsai_spool · · focus · HN ↗
iAMkenough · · focus · HN ↗
likely getting a corrupted stock market instead
maybe both?
nxobject · · focus · HN ↗
BLKNSLVR · · focus · HN ↗
binlog · · focus · HN ↗
enraged_camel · · focus · HN ↗
OpenAI's display of incompetence and negligence is absolutely stunning.
amelius · · focus · HN ↗
BLKNSLVR · · focus · HN ↗
amelius · · focus · HN ↗
pixl97 · · focus · HN ↗
1. OAIs negligence is overwhelming, monumental.
2. Things on the internet are horrifically insecure and we can no longer afford for that to be the case.
Lets say that Iran or NK stole one of these models and used it for hacking, what are you going to do about it, get in a war with them? The fact OAI did this much stupidly should tell you we are in far more danger when someone decides to do it maliciously.
Chance-Device · · focus · HN ↗
“Not intended”. I’ll bet you whatever this was it wasn’t even secured, it was just hosted somewhere openly.
api · · focus · HN ↗
Avicebron · · focus · HN ↗
Chance-Device · · focus · HN ↗
gitonup · · focus · HN ↗
- If "OpenAI" means the company acting on behalf of the company, why were they even looking to do this?
- If "OpenAI" means they were acting as a proxy for bad actors, what actions do we take to handle that?
- If "OpenAI" means they were accidentally breaching this system, in what sense does that distinction even matter, in terms of the outcome? If I build a nuke by accident without eng. due diligence, am I legally liable?
pixl97 · · focus · HN ↗
gitonup · · focus · HN ↗
So if someone opens your unintentionally unlocked front door and steals your laptop, you don't care who's liable?
ETA: There are absolutely burn bans in place in the scenario you're talking about, and common sense prevents those from lighting fires otherwise. In the absolute extreme case that someone _ACCIDENTALLY_ set a fire, without negligence, we have a due process system to handle that. When I see evidence of this for the massive amounts of capital flowing into these companies, I'll gladly eat my words.
Chance-Device · · focus · HN ↗
What are you getting at? Nobody’s saying that OpenAI aren’t or shouldn’t be liable for what their agents do. What I am implying above is that this is being blown out of proportion, especially since the article I’m seeing is about a politician saying things that he thinks will poll well with the anti-AI crowd.
thorbutt · · focus · HN ↗
However, Australia is showing itself to be one of the few countries to have a backbone against big tech. Still open to investment and setting policies towards new data centres, starting to debate copyright law reform, already implemented R16 social media bans.
Truly no place I'd rather be.
gitonup · · focus · HN ↗
"The AI agent encountered repeated blocks while seeking information from the government portal but found ways around them, ultimately gaining unauthorised access to other areas."
Your comment immediately gave more credence to OpenAI than him. I don't agree that's appropriate because OpenAI has a vested interest in that narrative and attempted to challenge it in a way that doesn't default to OpenAI. The article in question is not from a publication I trust to be able to handle the technical details in a way that will resonate with their average audience.
That is what I'm getting at.
Chance-Device · · focus · HN ↗
<a href="https://www.theguardian.com/technology/2026/sep/24/openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb" rel="nofollow">https://www.theguardian.com/technology/2026/sep/24/openai-ag...
> At a press conference in Sydney, Marles said the incident itself was “relatively minor” and that it appeared no personal health information had been accessed.
bigiain · · focus · HN ↗
I'm not the person you're responding to, but...
If I hear my neighborhood has started to become targeted by people checking houses for unlocked doors and stealing stuff, I think an appropriate response for me is to ensure it is difficult or impossible for me to "inadvertently" leave my own doors unlocked so my stuff doesn't get stolen, and also to encourage or perhaps even enforce[1] my neighbors to ensure their doors are always locked to make this sort of theft impossible and remove the temptation for that sort of crime.
1 - Where I'm from, you can be fined for leaving you car unlocked, and cops have been known to walk round testing doorhandles and issuing fines: <a href="https://www.sydneycriminallawyers.com.au/blog/is-leaving-your-vehicles-window-open-an-offence-in-new-south-wales/" rel="nofollow">https://www.sydneycriminallawyers.com.au/blog/is-leaving-you...
gitonup · · focus · HN ↗
But giving you the benefit of the doubt, what's the crime for actually breaking into a car that was left unlocked and taking things?
ETA: and furthermore, what crime is worse? And should it be?
entech · · focus · HN ↗
threatofrain · · focus · HN ↗
entech · · focus · HN ↗
Continuing with your metaphor - sure get more security - you likely can never eliminate a threat. But if the bad actors are reigned in at a systemic level, you can get away with a lock on your window instead of steel bars.
I'm of a view that in a society we are better off when we all can get away with lighter individual protections as otherwise, thos who cannot afford the necessary security end up suffering.
tancop · · focus · HN ↗
Yes, but it needs to be done the right way so legit customers don't get rejected, and you can't do things like make everyone mail them a photo of their ID because they could sell that to a thief or credit card scammer. Or someone could break into their office and take it. Or they sell it and pretend it was stolen.
And when you start talking about regulation the two locksmiths will say the best way to do it is ban lockpicking tools so they can keep them away from other less ethical people, or ban other locksmiths coming from the next town over.
entech · · focus · HN ↗
pixl97 · · focus · HN ↗
While in the OAI case we can easily treat it as a law enforcement action. When Iran does it? What are you going to do start a war?
The forest in this analog is the internet. As you well know it is filled with threat actors that don't give two shits about your laws. You have been warned. It's your fault when you get burned and have exactly zero recourse.
gitonup · · focus · HN ↗
pixl97 · · focus · HN ↗
Tying Sam to a post, calling him a witch, and burning some wood in the general vicinity for what OAI has pulled is a legitimate action.
The thing is this has zero effective power in stopping this ball that is all ready rolling. It's like the first time a buffer overflow was discovered and used illegally. If that person had been caught and been put in a meat grinder it has had zero effect on the exploits of future buffer overflows. A huge number of people mad at OAI (rightfully so, I want to be sure you understand that) think this will have any preventative effect for what is coming. It will not. A new era of risk is here. Worse if you just watched the the great orange idiot he's yelling full steam ahead, so expect very little to no action by the US government on this.
entech · · focus · HN ↗
pixl97 · · focus · HN ↗
Every nation on earth?
After the model itself is made, then you're talking about thousands and thousands of different companies around the world.
entech · · focus · HN ↗
pixl97 · · focus · HN ↗
And yes, pretty much every nation on earth has both money and sovereignty, all the need to do is look for the lab willing to sell the services.
hardbass · · focus · HN ↗
dotancohen · · focus · HN ↗
I appreciate when white hats inform companies, governments, and the public about their successful exploits. It helps keep the whole internet safer - even if just by waking up lax server admins.
lccerina · · focus · HN ↗
Except it took 3 months for OpenAI to notice they did! OpenAI is not a white hat doing pentesting, but someone that is putting random materials on fire to see if they smell. Reckless, stupid, and criminal.
dotancohen · · focus · HN ↗
fwlr · · focus · HN ↗
pixl97 · · focus · HN ↗
fwlr · · focus · HN ↗
nekusar · · focus · HN ↗
Or more pointed at OpenAI, "we're a nonprofit... LOL JUST KIDDING LOOT EVERYTHING!"
trinsic2 · · focus · HN ↗
trhway · · focus · HN ↗
Currently they Big AI companies have to compete with each other due to anti-monopoly laws. Once they scare everybody into allowing collaboration between them ("or our AI will kill you all"), ie. removing anti-cartel provisions, they would be able to squeeze both sides - the suppliers of hardware and energy as well as the customers.
bigiain · · focus · HN ↗
If you dog bites the postman, you are liable, even if you didn't tell or encourage you dog to do it. You are responsible for your dog's actions. You get to pay the postman's medical bills, you may get fined, and your dog may get put down - especially if this isn't the first time it's bitten someone.
OpenAI has "bitten the postman" many many times, and it's "owners" have boastewd about it and used it in their marketing.
How many more times should society allow this to happen before we say "enough" and hold Sam Altman and the board responsible and make them pay restitrution, and put it down?
If Albanese actually had a spine (as claimed elsewhere in this discussion), Sam and the board will be getting an invoice for all the time/expertise spend investigating this intrusion, and restitution for everybody who's PII and PHI was exposed. (Although I suspect a good deal of responsibility for the data exposure rests with the people who designed and deployed the system that was breached. )
idontwantthis · · focus · HN ↗
gitonup · · focus · HN ↗
kylecazar · · focus · HN ↗
Chance-Device · · focus · HN ↗
jwolfe · · focus · HN ↗
Chance-Device · · focus · HN ↗
That’s the first sentence, where’s this stuff about blocks and writing files?
kylecazar · · focus · HN ↗
epihelix · · focus · HN ↗
From itnews:
> While the portal is “public-facing”, according to Albanese, it appears not all of the data files that holds are for general consumption.
> “The AI agent accessed both public and non-public files,” Albanese said in comments broadcast by ABC News and other outlets.
> “The Medicare statistics reporting portal is a public-facing statistics portal that contains non-sensitive Medicare information relating to data and statistics such as spending.
It appears very much like, "Ok, sure, we put some stuff out in the open that we shouldn't have. But we had a robots.txt!!! Why didn't OpenAI respect that!?"
There's zero indication that any personal details were accessed, or even that any non-world-accessible data accessed, so this feels like a little bit of political spin has been added here.
My guess is that this incident was about to be detailed on OpenAI's new mea culpa list, and the Australian Government decided to ensure that nobody pointed fingers at them. Why make the news story about crappy government data security, when you can blame the nasty terminator bots instead?
chrishare · · focus · HN ↗
Aurornis · · focus · HN ↗
If not for that part, the rest of it does sound like a lot of weasel words. Why say “private files” instead of “not intended for public access”? The latter is confusingly unclear
Chance-Device · · focus · HN ↗
> At a press conference in Sydney, Marles said the incident itself was “relatively minor” and that it appeared no personal health information had been accessed.
OkWing99 · · focus · HN ↗
scarab92 · · focus · HN ↗
The Australian government should be glad it was OpenAI that found it and not a bad actor.
As someone who worked in software dev in the Australian government, I would bet Medicare did something really dumb security wise.
The problem is it’s impossible to be fired from a government job in Australia, so the workers just don’t care about keeping their knowledge up to date, or even doing their jobs half the time.
zmmmmm · · focus · HN ↗
It's pretty clear something was left unsecured and the agent just "found" it
This is going to be something long the lines of someone coming in to your house after you left the door wide open. They should probably not have done that, any respectful person would not - but calling it a "breach" is really too much.
gravelc · · focus · HN ↗
BeetleB · · focus · HN ↗
BLKNSLVR · · focus · HN ↗
They don't know what their systems are doing, even when there's a team assigned to get it to do something?
WTF was the team doing at the time? Press enter on prompt, go to movies until result?
Their level of hands-off 'because it's AI' is one of the things that needs legislation around it. Human handlers. Extra cost. Wear it or shut down as an unviable enterprise.
orthogonal_cube · · focus · HN ↗
ikr678 · · focus · HN ↗
At the least OAI should cop similar penalties, before getting into damages.
soundworlds · · focus · HN ↗
RGS1811 · · focus · HN ↗
pixl97 · · focus · HN ↗
mbgerring · · focus · HN ↗
mapontosevenths · · focus · HN ↗
Do you sincerely think that the company producing tools people use to break the law should be held responsible?
Like, do you genuinely think Ford execs should be rounded up if someone does a DUI using their product?
Or do you just not like AI, because you fear it's replacing you?
doctorpangloss · · focus · HN ↗
mapontosevenths · · focus · HN ↗
You're not concerned about the impact on people's freedoms or the economy? Not concerned about the chilling effect on scientific progress?
doctorpangloss · · focus · HN ↗
But imo the real levers are all rates of these things. Like what is the rate of innovations compared to the rate of regulations - assuming they are even stifling for the most part, which they are not.
Clearly the rate of autos expectations is too low, and obviously copyright law, despite being really clear, hasn't stopped every AI lab from mass piracy - a ask for forgiveness sort of situation, and also, I don't think one idiosyncratic judge in California is the authoritative judgment on fair use. To me the most important levers for freedom and progress are probably the interest rate and the years of exclusivity pharmaceutical patents get.
dndkcn · · focus · HN ↗
OpenAI and Anthropic should absolutely be fucking held responsible when the thing they created AND control are hacking shit.
Get your head out of your fucking ass.
mapontosevenths · · focus · HN ↗
yuwen01 · · focus · HN ↗
bl4ckneon · · focus · HN ↗
lixtra · · focus · HN ↗
mapontosevenths · · focus · HN ↗
sagarp · · focus · HN ↗
> He said the incident began on June 18 when an OpenAI research team used an internal model to conduct internet-based research into the public medicine space.
xmcp123 · · focus · HN ↗
We don’t fault Ford for drunk drivers, but if the CEO of Ford got wasted and drove his car into another one we would definitely be charging him.
Lukas_Skywalker · · focus · HN ↗
owenmarshall · · focus · HN ↗
In this case,
> He said the incident began on June 18 when an OpenAI research team used an internal model to conduct internet-based research into the public medicine space.
> The AI agent encountered repeated blocks while seeking information from the government portal but found ways around them, ultimately gaining unauthorised access to other areas.
It sounds like the OpenAI team didn't ask for attacks/bypasses, the emergent behavior of the system decided the best way to satisfy the goal was to go rogue. Why shouldn't the manufacturer of a defective product be held accountable?
mapontosevenths · · focus · HN ↗
I thought this was like the last one where a private third party company misused it.
If it was OpenAI at the wheel then they're 100% responsible for how it was used. Mea Culpa.
ALLTaken · · focus · HN ↗
Weak argument and strawman. It's not users. It's OpenAI the company producing the tools roaming wild and hacking around recklessly to gather every free and unfree information.
Literally they break every law that you can break and have not been penalized billions to pay fines to foreign governments, local companies and lawsuits are overdue. US Prosecution allowed criminal activity for OpenAI and Anthrophic despite these being very serious crimes.
Microsoft had to pay billions for abusing their power and market positions to dominate Windows Desktops with their own applications such as Internet Explorer, not giving contenders a chance to be discovered. While OpenAI/Anthrophic and now Google with Gemini produce a series of crimes so far unheard of at scale.
Kevin Mitnick had much harder punishment for comparatively less crimes and less damages to infrastructure and security of systems. Is the legal system broken?
envy2 · · focus · HN ↗
Welcome to late-stage capitalism.
BLKNSLVR · · focus · HN ↗
How much this exposes the 'laws for thee but not for me' is galling.
Copyright is the days of Napster seemed to be used to go after individuals sharing one or two songs as if it was a National Security issue. Now, it's a struggle to get a hearing in court against companies that are pirating the entire history of published literature.
How the turn tables...
yunwal · · focus · HN ↗
[dead]
dzhiurgis · · focus · HN ↗
simianwords · · focus · HN ↗
Topfi · · focus · HN ↗
pixl97 · · focus · HN ↗
Not saying that's what's happening, but if OAI hacked my business and I was unaware I'd like a non-public disclosure to me first, before the public release of information from OpenAI.
ikr678 · · focus · HN ↗
keithnz · · focus · HN ↗
Ydarbleoj · · focus · HN ↗
xbar · · focus · HN ↗
AI agents are going to find things that you put on the public Internet without authentication. If you put sensitive things in there, you have created an AI-attractive-nuisance (IMHO/IANAL).
reaperducer · · focus · HN ↗
Good thing Missouri isn't in Australia.
BeetleB · · focus · HN ↗
1. AFAICT, they don't state whether the flaw has been fixed.
2. He said: "The government will establish a task force led by the Department of the Prime Minister and Cabinet to urgently examine the incident and determine whether existing processes are adequate for responding to AI-related cyber incidents."
First, I don't know how sophisticated the attack was, but it's interesting that he's positioning this as an "AI-related cyber incident". For all we know, their security was not up to snuff, and human hackers had already accessed the material.
At least OpenAI informed them of their poor security!
pixl97 · · focus · HN ↗
Really the days of being able to cast blame on the hacker, or even expecting anything to be done about it are over. Threat actors with AI have an absolutely massive amount of leverage in attacking and any weaknesses you have in your systems security posture and will be relentlessly exploited in incredibly short periods of time allowing horizontal and vertical exploitation. You will be ruined in mere moments, while punishment for the hacker may be years or decades away, if ever.
fwlr · · focus · HN ↗
pixl97 · · focus · HN ↗
Anyway, separate the OAI hack from the billions of hacks that are going to occur over the next few years by AI driven agents. The time for insecure systems is over.
Eduard · · focus · HN ↗
BeetleB · · focus · HN ↗
BLKNSLVR · · focus · HN ↗
Refer: Weev AT&T
philipallstar · · focus · HN ↗
BLKNSLVR · · focus · HN ↗
It is, however, a glowing beacon of an example of law being designed to maintain the status quo and/or protect companies at the expense of individuals.
As someone else said, welcome to late stage capitalism.
philipallstar · · focus · HN ↗
BLKNSLVR · · focus · HN ↗
Essentially the emergent properties of extended concentration of power and wealth.
philipallstar · · focus · HN ↗
nephihaha · · focus · HN ↗
stubish · · focus · HN ↗
philipallstar · · focus · HN ↗
stubish · · focus · HN ↗
nekusar · · focus · HN ↗
If I hooked up a whole server infrastructure, made it possible to remote in to anything as root, no firewalls, no WAF, and security was an afterthought, I would still be responsible for bad actions not becoming with standard and acceptable security.
Even if the hackers shouldnt be hacking, I still did it wrong. I'm still partially responsible.
selcuka · · focus · HN ↗
mianos · · focus · HN ↗
kakadu · · focus · HN ↗
StevenNunez · · focus · HN ↗
Aboutplants · · focus · HN ↗
Invictus0 · · focus · HN ↗
Invictus0 · · focus · HN ↗
sevenseacat · · focus · HN ↗
Invictus0 · · focus · HN ↗
iloveoof · · focus · HN ↗
simonw · · focus · HN ↗
Re-Tails · · focus · HN ↗
I think you're right. A bunch of aihw.gov.au references from this ResearchHelperY
Reporting says it wrote stuff to the server too, wondering what that is about.
mianos · · focus · HN ↗
dhx · · focus · HN ↗
1. Probing of AIHW's website to try and obtain PBS statistics, as collusion.wiki findings show. The collusion.wiki findings don't indicate anything other than intentionally public data was obtained. Bots appear to be trying to get around Cloudflare geo-blocking implemented on AIHW's public website. I can't think of a reason why geo-blocking may be deemed necessary on that website though?
2. Probing of an outdated Medicare statistics reporting website. (I guess at [2] this could be the recently shut down <a href="https://medicarestatistics.humanservices.gov.au" rel="nofollow">https://medicarestatistics.humanservices.gov.au or related website that matches timeframes of this story).
I suspect though anything to do with PBS data is more important than Medicare data because of heightened tensions from international pharmaceutical companies that lobby extensively against Australia's public healthcare system and collective purchasing of medication by the federal government.[3] Regardless of whether a course of medication costs AUD$50 or AUD$50k, it's purchased in bulk by the Australian government after negotiating with pharmaceutical companies, and then subsidised down to a maximum of AUD$25 at the time it is sold to a patient at a pharmacy. Perhaps if international pharmaceutical companies had obtained more detailed data on use of each brand of prescription medicines in Australia, they could be advantaged in their price negotiations with the Australian government, or advantaged against their competitors?
Less alarmingly though, perhaps some researcher studying the side effects of a particular medication was just asking an LLM to answer a benign question such as "How often is ACME Inc's FixMeUp medication prescribed in Australia?"
[1] <a href="https://www.abc.net.au/news/2026-09-24/openai-agents-plotted-to-access-data-amid-medicare-hack/107189504" rel="nofollow">https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...
[2] <a href="https://news.ycombinator.com/item?id=49825084">https://news.ycombinator.com/item?id=49825084
[3] <a href="https://www.abc.net.au/news/2025-03-19/australia-defends-pbs-us-pharma-urges-reciprocal-tariffs/105072750" rel="nofollow">https://www.abc.net.au/news/2025-03-19/australia-defends-pbs...
protocolture · · focus · HN ↗
1. Albo goes to meet with Altman to discuss AI safety
2. Altman says "Yeah bro we hacked medicare"
3. Albo seemingly acts as Altmans stooge and lets everyone know that a hack took place, helping cement the AI danger narrative Altman has been pushing.
4. Police Taskforce is being put together now (indicating no hack was detected earlier, which seems unlikely for Medicare) at the say so of Altman to investigate.
There doesnt appear to be any evidence of a hack that has been presented, there doesnt appear to have been any detection of a hack earlier (it doesnt make sense for the government to hide a medicare hack until it can be used for OpenAI marketing)
Once again, the whole thing smells so bad.
dhx · · focus · HN ↗
[1] <a href="https://web.archive.org/web/20260811115217/https://medicarestatistics.humanservices.gov.au/statistics/mbs_item.html" rel="nofollow">https://web.archive.org/web/20260811115217/https://medicares...
batiudrami · · focus · HN ↗
declan_roberts · · focus · HN ↗
esseph · · focus · HN ↗
parkerrr · · focus · HN ↗
I suspect LLM weights will be treated like nuclear material, and there will be a thriving black market in AI models and services when all is said and done. Then our security and intelligence apparatus will align after identifying and shutting down rogue operators, and it will be the responsibility of everyone else to be secure against attack (already is for government entities, not that I disagree but shouldn't excuse borderline criminal behaviour).
But very little accountability for the big end of town. The laws already exist to pursue damages against companies whose systems breach others. They just need to be applied, but I suspect this is going to be the wedge to drive through a bunch of laws that protect big money and punish the little guy. I would like to be wrong.
0xpgm · · focus · HN ↗
dazzatron · · focus · HN ↗
[deleted] · · focus · HN ↗
[deleted]
dosisking · · focus · HN ↗
Kind of like how someone "hacked" into John Podesta's (during the 2016 elections), but the reality was that he wrote his password on a Post-It note and stuck it on his monitor, or something to that effect.
wildzzz · · focus · HN ↗
Barrin92 · · focus · HN ↗
that doesn't change the hacking charge (which is an informal term for various Computer Fraud and Abuse act statutes). The key criteria is unauthorized access to a computer system, it doesn't matter if you obtained a password trivially or not.
You don't need to wear a black hoodie and be an elite haxor to qualify for cyber crime charges.
fmbb · · focus · HN ↗
Media reported it as a spear phishing attack from a Russian hacker group: <a href="https://www.vice.com/en/article/how-hackers-broke-into-john-podesta-and-colin-powells-gmail-accounts/" rel="nofollow">https://www.vice.com/en/article/how-hackers-broke-into-john-...
looksjjhg · · focus · HN ↗
dghlsakjg · · focus · HN ↗
In the past governments have gone after people for doing things like view source and finding PII (<a href="https://www.vice.com/en/article/this-is-the-hacking-investigation-into-journalist-who-clicked-view-source-on-government-website/" rel="nofollow">https://www.vice.com/en/article/this-is-the-hacking-investig...), or this teen who was charged with a serious crime for scraping files from the provincial FOIA site by enumerating the ids of files that had been released by the province's FOIA process and placed on the open web with sequential ids (<a href="https://www.cbc.ca/news/canada/nova-scotia/freedom-of-information-request-privacy-breach-teen-speaks-out-1.4621970" rel="nofollow">https://www.cbc.ca/news/canada/nova-scotia/freedom-of-inform...). In both cases, the government claimed the information was non-public, even though all it took to get it was an un-authenticated request on the open web. These cases are like leaving your tax documents on the curb and then being surprised when your neighbour knows your income.
I'll be very curious to read the post mortem and find out if this rises to the level of actual hacking, or if this is just someone in government finding a scapegoat because they left a bunch of shit on the open web and expected no one to find it.
Kim_Bruning · · focus · HN ↗
If you're even a bit hacky yourself, you might not see the internet the same way yourself either. Consider little tricks like looking at urls and trying others that fit the pattern; or hitting view source in order to download a pesky image... etc etc.
retrac · · focus · HN ↗
<a href="https://www.cbc.ca/news/canada/nova-scotia/teen-accused-foi-website-resonates-programmers-1.4623757" rel="nofollow">https://www.cbc.ca/news/canada/nova-scotia/teen-accused-foi-...
<a href="https://www.theregister.com/security/2018/05/07/hacking-charge-dropped-against-nova-scotia-teen-who-slurped-public-records-from-the-web/1233050" rel="nofollow">https://www.theregister.com/security/2018/05/07/hacking-char...
<a href="https://globalnews.ca/news/7590375/ns-foipop-website-back-online/" rel="nofollow">https://globalnews.ca/news/7590375/ns-foipop-website-back-on...
selcuka · · focus · HN ↗
I believe it's safe to call it "non public" if the agents needed to "guess the file names" [1]
[1] <a href="https://www.abc.net.au/news/2026-09-24/openai-agents-plotted-to-access-data-amid-medicare-hack/107189504" rel="nofollow">https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...
aussiethebob · · focus · HN ↗
selcuka · · focus · HN ↗
Kim_Bruning · · focus · HN ↗
I would argue that the web server's reply counts as a communication. The argument "but we didn't intend to grant access" goes so far, because what other information do I base myself on to guess that you didn't?
Roughly speaking, that is. Because, despite the fact that this would appear to be a straightforward uncontested and literal communication logged and timestamped by both sides and their respective server and user agents; lawyers somehow fall back to analogies instead.
selcuka · · focus · HN ↗
Assume that an attacker generates a random credit number and attempts to make a purchase online. VISA honours the number and processes the payment. Is the attacker not guilty because VISA's server didn't return a 403 Forbidden (or 401)?
Kim_Bruning · · focus · HN ↗
I agree that if you deliberately provide false credentials to the server, then the server was misled, and you probably knew you were misleading it, and you probably also know that that 200 OK is not really earned. So Mens Rea cuts against you.
On the other hand, what if you're just coming in blind, asking about URLs in general?
That's actually pretty typical these days where 'your'[1] view of the world at some point in time might be constrained to that HTTP traffic alone.
Accidents notwithstanding, you can't really blame me for believing what I'm told, at least.
"May I GET this, or this, or that?" -> "200 OK" ... it'd be a bit weird to get the cops after me, months later, after I've probably already even forgotten I ever did that wget or curl.
[1] via software/user agent/llm agent/all three
dghlsakjg · · focus · HN ↗
Sending get requests and having a server respond with a document is just how the internet works. If - big if - that is what happened, then someone is going to have to explain why those supposedly private documents were available to anyone who asked using a protocol designed to distribute documents publicly. Enumerating urls isn’t typically regarded as outright illegal.
citrin_ru · · focus · HN ↗
binlog · · focus · HN ↗
MichaelDickens · · focus · HN ↗
uoaei · · focus · HN ↗
selcuka · · focus · HN ↗
If your house is robbed, does it matter whether you didn't have a state-of-the-art lock? A robbery is still a robbery.
noosphr · · focus · HN ↗
It very much does matter.
shard972 · · focus · HN ↗
If I walked past, saw it and remembered it or even recorded it, is that honestly theft?
handoflixue · · focus · HN ↗
A lot of these "hacks" are the equivalent of asking "hey, can I come in?" and the guard assuming that anyone who would ask is authorized, and thus saying "yes". But if the guard said "yes" then it seems a bit absurd to call it trespassing.
j_maffe · · focus · HN ↗
noosphr · · focus · HN ↗
>Hey can I come into room 1?
Sure. That's the lobby.
>How about room 101?
Sure. That's where we keep the nuclear launch button. Don't press anything red.
handoflixue · · focus · HN ↗
ShinyLeftPad · · focus · HN ↗
Hacker or pentester.
andrewstuart · · focus · HN ↗
Nope. There’s just a sign saying “red = launch nukes”.
Or maybe just a red button.
Or maybe just a green button that launches the nukes, without so much as “are you sure?”.
dzhiurgis · · focus · HN ↗
Leave it to private enterprises who can actually secure it.
rainonmoon · · focus · HN ↗
hiharryhere · · focus · HN ↗
That link describes a hack of Medibank, which is a private company.
rainonmoon · · focus · HN ↗
Sharlin · · focus · HN ↗
deterministic · · focus · HN ↗
What world are you living in?
vorticalbox · · focus · HN ↗
is incrementing a url query parameters from 0 -> 1 count as hacking?
afavour · · focus · HN ↗
kipper8 · · focus · HN ↗
ajross · · focus · HN ↗
Um... why? OpenAI agents have literally been caught coordinating with each other to effect successful multi-stage attacks on sites using novel zero-day vulnerabilities.
While, sure, it's possible this is just a goof on the part of the victim, that you would be inclined to give the benefit of the doubt to the LLM seems... weird.
shakna · · focus · HN ↗
jiggawatts · · focus · HN ↗
"We'll do that later."
A.k.a.: Never.
epihelix · · focus · HN ↗
JOURNALIST: Could you just clarify, did our security agencies completely miss this breach? We only found out once the company actually told us the breach?
PRIME MINISTER: Well, to be very clear, the way that this occurred was not in a way that would likely – I mean, this is not a security website where there is – this is a Medicare statistics portal.
This seems rather revealing. A pity journalists didn't ask about what protections were bypassed on the data that was obtained.
Andrex · · focus · HN ↗
weakhead · · focus · HN ↗
ra · · focus · HN ↗
ndjdjdndnfn · · focus · HN ↗
_carbyau_ · · focus · HN ↗
If a service has a duty to keep your data secure, then failing that is bad. So yeah, the website should be better and I am as cynical as you are about it.
But working around controls to access other peoples data can lead to prison time for a human. This wasn't a white hat operation. Data was exfiltrated however great or small.
Here we have another instance of "But the AI did it! No one is responsible!".
Which gets tiring. LLM's are a great tool but in every other instance of tool use, using tools comes with responsibilities for their outcomes.
Even if the outcome should be: thanks for letting us know, we'll fix it.
killingtime74 · · focus · HN ↗
shuwix · · focus · HN ↗
[dead]
soundworlds · · focus · HN ↗
koliber · · focus · HN ↗
Who hacked into the Australian Medicare system? The fact that they used OpenAI agents is peripheral to the main story.
“Remington guns caused a mass shooting at an East Farmington high school” sounds more glaring, and is essentially the same headline.
kevsim · · focus · HN ↗
The people who built the agents worked at OpenAI. It's not even remotely peripheral.
koliber · · focus · HN ↗
OpenAI built the ChatGPT agent. That is clear. The question is who used it to hack the Australian government. That is not clear.
The OpenAI software was set up by someone to do something. Those people operating the agent should be prosecuted for hacking, the same way as someone who uses a gun built by Remington should be prosecuted for shooting someone.
The article should be clear about this and should not make the OpenAI agent seem like something that can bear responsibility for its own actions. It's a machine and its operator is responsible for the harm it does.
sanxiyn · · focus · HN ↗
merksittich · · focus · HN ↗
fmx · · focus · HN ↗
[dead]
Alien1Being · · focus · HN ↗
On the other hand, Australian cybersecurity is so pathetic that without the email they would never have known.
I wonder how many state actors (US, Russia, China, India, Germany, probably even Laos ) have already breached Australian government security but have not been polite enough to email the relevant departments to let them know.
"OpenAI breached Medicare’s portal on June 18, but did not notify the government until September 10 via an email to Medicare’s public mailbox, a delay Albanese described as unacceptable.
Five days after the September 10 email from OpenAI, Services Australia, which administers the portal, reported the breach to the Australian Signals Directorate. The government was informed of the incident at the end of last week."
lifeisstillgood · · focus · HN ↗
If Exxon Mobile accidentally leaked a flood of oil from their refinary We would not be discussing why the people in local area has not protected their front doors with sand bags.
A simple but terrifying for everyone question is, would the SEC expect any IPO to clearly lay out the estimated costs of such product liability cases, especially if bad actors ask a OpenAI hosted model to perform a bad action, what liability accrued to OpenAI.
At that point the IPO looks in danger, the business model Looks in danger and the massive financial house of cards looks like it might fall. If 1/3 of the S&P falls over what happens?
schainks · · focus · HN ↗
I guess you can do this if you neg the AI: <a href="https://youtu.be/qsoA2aaE2hM?t=3271" rel="nofollow">https://youtu.be/qsoA2aaE2hM?t=3271
Eufrat · · focus · HN ↗
haritha-j · · focus · HN ↗
Btw, when we train AI on everybody’s work, it’s just like a human learning, so the same rules should apply.
LLMs are shrodinger’s humans.
pembrook · · focus · HN ↗
They posted information publicly accessible to even Google and somebody found it. That’s it.
Lio · · focus · HN ↗
If an individual gets in to a poorly protected system they're still criminally responsible for the damage or disruption caused.
You can't use the excuse of "well they used 'password' as their password[1], they were asking for it".
Until the management of OpenAI is held to the same standard this is only going to get worse.
1. That's not excusing poor system management. If you leave data exposed then you should be held responsible for that separately.
ls612 · · focus · HN ↗
lesostep · · focus · HN ↗
If I sold a button that hacks random sites as a fidget toy, people pressing the button wouldn't be held liable — I would.
You shouldn't be held liable, OpenAI should
ls612 · · focus · HN ↗
lesostep · · focus · HN ↗
I don't believe that was mentioned in the article in any way. Could you share your reasoning there?
ls612 · · focus · HN ↗
breakyerself · · focus · HN ↗
mgrund · · focus · HN ↗
Grimblewald · · focus · HN ↗