Gaining unauthorized access to non public files qualifies as a hack by any and every stretch… a hack does not have to be “sexy”, real life is not Hollywood
In the past governments have gone after people for doing things like view source and stumbling across PII (<a href="https://www.vice.com/en/article/this-is-the-hacking-investigation-into-journalist-who-clicked-view-source-on-government-website/" rel="nofollow">https://www.vice.com/en/article/this-is-the-hacking-investig...), or this teen who was arrested for a serious crime for scraping files from the provincial FOIA site by enumerating the ids of files that had been released by the province and placed on the open web with sequential ids (<a href="https://www.cbc.ca/news/canada/nova-scotia/freedom-of-information-request-privacy-breach-teen-speaks-out-1.4621970" rel="nofollow">https://www.cbc.ca/news/canada/nova-scotia/freedom-of-inform...). In both cases, the government claimed the information was non-public, even though all it took to get it was an un-authenticated request on the open web. These cases are like leaving your tax documents on the curb and then being surprised when your neighbour knows your income.
I'll be very curious to read the post mortem and find out if this rises to the level of actual hacking, or if this is just someone in government finding a scapegoat because they left a bunch of shit that was supposed to be "non-public" on the open web and expected no one to find it.
I believe it's safe to call it "non public" if the agents needed to "guess the file names" [1] How is it different from, say, guessing a password?
I would say it's completely different. Passwords are specifically intended to restrict access. File names or paths are specifically intended to facilitate access.
That's an arbitrary distinction. Your credit card number is not intended to restrict access, it's specifically intended to facilitate access, but it's not public information. If someone uses brute force to guess your credit card number, I would call this practice illegal too.
Guessing credit card numbers for the purpose of spending money that isn’t yours is openly malicious and illegal. I would also argue that credit card numbers are designed to restrict access. The company that issues them specifically says not to share the number and uses knowledge of that number to gate access to the spending function.
Sending get requests and having a server respond with a document is just how the internet works. If - big if - that is what happened, then someone is going to have to explain why those supposedly private documents were available to anyone who asked using a protocol designed to distribute documents publicly. Enumerating urls isn’t typically regarded as outright illegal.
dazzatron · · focus · HN ↗
looksjjhg · · focus · HN ↗
dghlsakjg · · focus · HN ↗
In the past governments have gone after people for doing things like view source and stumbling across PII (<a href="https://www.vice.com/en/article/this-is-the-hacking-investigation-into-journalist-who-clicked-view-source-on-government-website/" rel="nofollow">https://www.vice.com/en/article/this-is-the-hacking-investig...), or this teen who was arrested for a serious crime for scraping files from the provincial FOIA site by enumerating the ids of files that had been released by the province and placed on the open web with sequential ids (<a href="https://www.cbc.ca/news/canada/nova-scotia/freedom-of-information-request-privacy-breach-teen-speaks-out-1.4621970" rel="nofollow">https://www.cbc.ca/news/canada/nova-scotia/freedom-of-inform...). In both cases, the government claimed the information was non-public, even though all it took to get it was an un-authenticated request on the open web. These cases are like leaving your tax documents on the curb and then being surprised when your neighbour knows your income.
I'll be very curious to read the post mortem and find out if this rises to the level of actual hacking, or if this is just someone in government finding a scapegoat because they left a bunch of shit that was supposed to be "non-public" on the open web and expected no one to find it.
selcuka · · focus · HN ↗
I believe it's safe to call it "non public" if the agents needed to "guess the file names" [1] How is it different from, say, guessing a password?
[1] <a href="https://www.abc.net.au/news/2026-09-24/openai-agents-plotted-to-access-data-amid-medicare-hack/107189504" rel="nofollow">https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...
aussiethebob · · focus · HN ↗
selcuka · · focus · HN ↗
dghlsakjg · · focus · HN ↗
Sending get requests and having a server respond with a document is just how the internet works. If - big if - that is what happened, then someone is going to have to explain why those supposedly private documents were available to anyone who asked using a protocol designed to distribute documents publicly. Enumerating urls isn’t typically regarded as outright illegal.