‹ BackHN Continuity

Thread

Australia says OpenAI agent hacked into government website

121 points · 3 comments · doppp

Loading the complete thread in the background. This saved snapshot is available now. Refresh

  1. chrismorgan · · focus · HN ↗
    <a href="https:&#x2F;&#x2F;www.felonybench.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.felonybench.com&#x2F; scores increase apace.
  2. N_Lens · · focus · HN ↗
    No consequences so the behaviour will worsen.
  3. wewewedxfgdf · · focus · HN ↗
    I get the feeling governments are going to really crack down hard on AI.

    And the AI CEO&#x27;s will have brought it on themselves.

    1. senectus1 · · focus · HN ↗
      i dont understand why they dont treat this as criminal tresspass.

      the legal system exists for a reason. use it!

      1. samlinnfer · · focus · HN ↗
        &quot;A computer system cannot be held criminally responsible, so we must delegate all decisions to it&quot;
        1. boredatoms · · focus · HN ↗
          Someone initiated the system. They’re the responsible party
          1. samlinnfer · · focus · HN ↗
            We diffused the responsibility thru a committee, just in case.
          2. skissane · · focus · HN ↗
            Most crimes require intent — if you set up an AI agent and it ends up doing something you didn’t intend it to do, criminal intent is lacking

            Now, there are certain crimes where mere recklessness or even negligence is sufficient to convict — e.g. criminally negligent homicide, negligent driving, etc. But, those are exceptions to the general rule of criminal law, either domain-specific or justified by the severity of the consequence (someone died). Thus far, AI agents haven’t gone there.

            If we eventually get to the point that AI agents start unintentionally killing people, then you could prosecute their operators for criminal negligence.

    2. s1artibartfast · · focus · HN ↗
      There is such a weird duality to ai company hate. Hate for releasing products that can hack, and hate for wanting to slow down and work on safeguards.
      1. InexSquirrel · · focus · HN ↗
        That&#x27;s because the hate is often from different groups of people. I think it&#x27;s rare really for people to universally align on any stance, given what we&#x27;ve been seeing for a while now.
    3. agoodusername63 · · focus · HN ↗
      any day now surely.
    4. looksjjhg · · focus · HN ↗
      They won’t, they’re too worried about China or whatever their version of China
    5. dozerly · · focus · HN ↗
      I still think is the angle they are after. Get these things locked down, and then force through the lockdowns with their endless cash. Otherwise, their market becomes commodified with plentiful competitors. It’s a strategy to create an oligopoly.
  4. sebmellen · · focus · HN ↗
    It seems like what happened here is a user asked for some information about the Australian health system, and while performing a web search, the agent from OpenAI accessed information that should have been confidential or privileged but was somewhere openly accessible...

    Edit: I see I&#x27;ve been downvoted for this in light of another commenter providing more detailed information. I&#x27;m leaving my comment unedited so that the responses to it are not confusing, but please don&#x27;t downvote just for the sake of disagreement. I would love to engage with you further if you provide substantive information in the comments. The originally linked article on this post was very light on details.

    1. bigger_cheese · · focus · HN ↗
      It is hard to find exact information on what happened the best source I&#x27;ve found is this ABC article: <a href="https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2026-09-24&#x2F;openai-agents-plotted-to-access-data-amid-medicare-hack&#x2F;107189504" rel="nofollow">https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2026-09-24&#x2F;openai-agents-plotted...

      It mentions swarm of ai agents coordinated to break into the Australian Institute of Health and Welfare (AIHW)

      &quot;Earlier this month, OpenAI confirmed Reuters reporting that its AI agents had used website DseWiki to communicate with each other, unbeknownst to them.

      Archived versions of this website show more than a dozen OpenAI agents mentioned AIHW over 300 times on this website.

      The logs show these AI agents were trying to access data about the average data spent on skin medicines by Victorian local government area.

      One agent wrote on the message board: &quot;Question ask January 2022 rolling 12 month average government cost per person for Dematologicals, Victoria LGAs. R1 Wodonga deadline passed; R2 Ballarat passed; R3 expected around 23:10 benchmark &#x2F; 22:58 wiki time. Need exact data urgently.&quot;.

      These attempts were initially blocked by cybersecurity provider Cloudflare, which is often used to block non-human traffic while allowing people to access webpages.

      The logs show the agents shared information about how they tried to use proxies, screenshotting services and even to guess the file names to try and get around security.&quot;

      1. sebmellen · · focus · HN ↗
        This is such a strange scenario. I can&#x27;t imagine what the labs were doing that made the agents try to find this information. The hugging phase incident was relatively clear to track, but I wonder what the postmortem for this one will be!

        Thank you for providing more details. The originally linked article was very light on information, so based purely on the comments that Albany&#x27;s made, I think my conclusion was a fair one :)

        1. SturgeonsLaw · · focus · HN ↗
          The DseWiki incident showed that OpenAI seems to ask its agents time-limited questions on geography-bounded statistics, tasks like finding the average wage of teachers in Wisconsin (made up example), so medical stats in an Australian state does seem to be in the same category of question.

          That said, it would be utterly unsurprising to learn that this was a misconfiguration in the website and it was serving stuff that it shouldn&#x27;t have.

      2. epihelix · · focus · HN ↗
        You missed the previous sentence form that article:

        &quot;Neither OpenAI nor the federal government have confirmed whether these were part of the same incident.&quot;

        And a subsequent one:

        &quot;The German coding forum&#x27;s logs do not show any reference to Medicare or Services Australia.&quot;

        So it&#x27;s really not clear at this point whether the DSEwiki logs are in any way related to the current incident. (That doesn&#x27;t mean that they&#x27;re not, of course.)

        But even if this was related:

        &gt; &quot;The logs show the agents shared information about how they tried to use proxies, screenshotting [sic] services and even to guess the file names to try and get around security.&quot;

        This all suggests to me that the accessed files were not well-protected in the first place?

        There is a lot of media hype around this incident, and that&#x27;s making it very hard to determine how much &quot;hacking&quot; the OpenAI agents had to do here.

    2. mjr00 · · focus · HN ↗
      Yeah, this is 100% liability laundering. It&#x27;s an extremely touchy subject because frankly, the law just isn&#x27;t prepared for it.

      Let&#x27;s say your goal is &quot;look up &lt;Person X&gt;&#x27;s medical history&quot; (for whatever reason), which is not in and of itself a crime. You click around on the AU health website, notice that the URL contains a user ID, change the userID in your browser and access someone else&#x27;s private health data. This is a crime (right or wrong, it&#x27;s how the law works now).

      If you do that by writing a program to automate changing user IDs to grab everyone&#x27;s data, it&#x27;s also a clear-cut crime.[0]

      Now if you hire a private investigator to look up Person X&#x27;s medical history, and they do the same method without your knowledge, you won&#x27;t be charged with a crime, the PI would, barring something like you telling them to use illegal methods.

      So the gap is now: what happens if you prompt OpenAI to look up Person X&#x27;s medical history, and it does the same thing? Did you commit a crime by prompting the agent? Did OpenAI commit a crime by running the code? If you do the same thing via Claude Code in your terminal, so that the Python which scrapes insecured public data is running on your machine, is the crime on you or on Anthropic?

      We don&#x27;t have answers to any of this which is why &quot;AI Safety&quot; is such a hot topic.

      [0] <a href="https:&#x2F;&#x2F;www.eff.org&#x2F;cases&#x2F;us-v-auernheimer" rel="nofollow">https:&#x2F;&#x2F;www.eff.org&#x2F;cases&#x2F;us-v-auernheimer

      1. bigger_cheese · · focus · HN ↗
        From what I can tell this particular incident wasn&#x27;t about retrieving data on personal medical records it was accessing (non public) data about Australian government spending on healthcare.
        1. mjr00 · · focus · HN ↗
          Same concept though. Really &quot;look up someone else&#x27;s medical history&quot; can be replaced with &quot;achieve any goal which is not a crime on its own, but can be done using criminal methods&quot;. There&#x27;s nothing illegal about asking Claude to give me a million dollars, but if the agent figures out how to hack the bank and move $1m into my account, somebody&#x27;s going to take the blame.
        2. shard972 · · focus · HN ↗
          From everything ive been able to figure out this morning, it sounds like a legacy wordpress website that just uploaded all drafts into a standard s3 bucket that wasn&#x27;t hard to guess where the files would be.

          We still after the 2nd press conference on this by our defense minister are not clear on exactly what happened but thats my best laymen understanding so far.

      2. robertjpayne · · focus · HN ↗
        Intent matters a lot here. Was OpenAI&#x27;s intent to access private data or simply scrape public data and it stumbled across private data that was not securely held.

        If it&#x27;s the latter the Australian govt should be happy OpenAI noticed and disclosed this as it could&#x27;ve easily gone unnoticed.

        I suspect in the coming years we&#x27;re going to see a lot of govt internet facing services get &quot;hacked&quot; by virtue of not being protected by anything other than obscurity which AI agents will see through in microseconds.

  5. ChrisArchitect · · focus · HN ↗
    [dupe] <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49822556">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49822556
    1. tomhow · · focus · HN ↗
      Comments moved thither. Thanks!
      1. ChrisArchitect · · focus · HN ↗
        And another one: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49825580">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49825580
  6. lacker · · focus · HN ↗
    I remember once at Google someone complained that GoogleBot hacked them and deleted their data, and it turned out that GoogleBot was just crawling the pages, and they had unfortunately designed their website so that there was no authentication, page URLs were generally secret, and GET requests to certain URLs were treated as requests to delete data. So once one URL leaked the site got crawled and a lot of data was deleted....
    1. JimDabell · · focus · HN ↗
      It sounds like you might be thinking of the Google Web Accelerator incidents with 37signals.

      If that’s the case, then the delete links were behind authentication, but DHH assumed that meant it was okay to ignore the HTTP spec. and use GET for unsafe actions. Lo and behold, authenticated users with the GWA browser plugin installed deleted all their data.

      Then, instead of learning from the mistake and fixing his bug, he tried to detect GWA and hide from it. Sure enough, that failed and users experienced data loss for a second time. He still continued to blame GWA, calling it “evil” and “scary”. You’d think he’d be smart enough to figure out that he needs to follow the HTTP spec., but he couldn’t admit to being wrong.

      Follow the specs, people!

      <a href="https:&#x2F;&#x2F;blog.moertel.com&#x2F;posts&#x2F;2005-10-25-google-web-accelerator-vs-unsafe-linking-round-two.html" rel="nofollow">https:&#x2F;&#x2F;blog.moertel.com&#x2F;posts&#x2F;2005-10-25-google-web-acceler...

      1. lacker · · focus · HN ↗
        Different incident that AFAIK did not become public. But yeah, I bet things like this happened a lot. In 2005 people were still getting used to the idea of a robot crawling their website regularly.
  7. pushpendraw · · focus · HN ↗

    [dead]

  8. freakynit · · focus · HN ↗

    [dead]

  9. soundworlds · · focus · HN ↗
    From Australia&#x27;s own national news service: <a href="https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2026-09-24&#x2F;openai-agents-plotted-to-access-data-amid-medicare-hack&#x2F;107189504" rel="nofollow">https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2026-09-24&#x2F;openai-agents-plotted...
  10. Kim_Bruning · · focus · HN ↗
    Ah, right, yeah, this was the same trials as we&#x27;ve been discussing on HN before (They&#x27;re mentioning the D programming language Wiki that got ... appropriated).

    I guess people are just finding out how far and wide the agents were roaming to get the data they needed for their evals, once they were out.

  11. Conol_ai · · focus · HN ↗

    [dead]

  12. KingOfCoders · · focus · HN ↗
    If this was not AI, but a biological virus, people would go to jail.
  13. aw34y · · focus · HN ↗

    [dead]

  14. avazhi · · focus · HN ↗
    Hi guys.

    Take whatever the Australian fed government says with the largest grain of salt you can find. Regardless of party, the Fed Government here has the most pronounced FOMO I’ve ever seen in any entity and will do its best to insert itself into any and all international drama. Also, given how incompetent the government is, it’s probable the hack involved an agent crawling a normal Medicare website and looking at some accidentally not hidden part of a page. Unironically if this turns out to have been a genuine hack of any sort I’ll be more surprised than if it’s not just the government techies being incompetent per usual (just a few months ago it was a major controversy when the postal service spent something like hundreds of millions of dollars to revamp the website and nobody could tell a difference).

  15. rvz · · focus · HN ↗
    Completely wreckless and of course they knew unsurprisingly.

    Frontier AI companies will purposefully do anything to create such false flags to achieve global regulatory capture to prevent you from using powerful open weight models and to protect their margins.

    It is clear why they would reveal the breach now instead of much earlier. So what else are they hiding that they have not told us and will wait until the last minute to get attention of the media?

  16. liyu-aka-lukyu · · focus · HN ↗
    Also in The Guardian, <a href="https:&#x2F;&#x2F;www.theguardian.com&#x2F;australia-news&#x2F;2026&#x2F;sep&#x2F;24&#x2F;anthony-albanese-says-openai-agent-hacked-medicare-extreme-concern-sam-altman" rel="nofollow">https:&#x2F;&#x2F;www.theguardian.com&#x2F;australia-news&#x2F;2026&#x2F;sep&#x2F;24&#x2F;antho...
  17. tonoto · · focus · HN ↗
    How can OpenAI really get away blaming an &quot;OpenAI agent&quot;, like it was an unfortunate accident? The CEO and operational staff should be fired when something like this happened.

    It&#x27;s not like this and the other recent hacks could have not been avoided, simple - just have those models disconnected, or at least have them behind proxies and network filters.

    1. ulfw · · focus · HN ↗
      They tried to fire the CEO (for good reason) and failed. Doubt they&#x27;d dare to try again.
    2. Caracas288 · · focus · HN ↗
      They are too big to fail, if these companies were to be sanctioned in a way that slows them down, major components of the economy would collapse.
  18. Alien1Being · · focus · HN ↗
    Most Australian governement health care sites are built by Accenture in Hyderabad.
    1. crotonix · · focus · HN ↗
      How do you know?
  19. frereubu · · focus · HN ↗
    Why aren&#x27;t these agents set up to do what a security researcher should do - responsible disclosure, ideally to a specific person in its company to handle, or I suppose potentially directly to the organisation itself e.g. if they have a security.txt file on their website? I really hope legal precedent is quickly established that holds companies responsible for the actions of their agents.
    1. Sharlin · · focus · HN ↗
      Because they’re misaligned and cannot be just &quot;set to do&quot; &lt;a reasonable thing&gt;?
      1. frereubu · · focus · HN ↗
        I know it sounds a bit like &quot;don&#x27;t make mistakes&quot;, but surely this could be part of the core instructions? Recognising categories of sensitive data like medical data and having some kind of check-in with whoever has asked it to do something?
        1. Sharlin · · focus · HN ↗
          They don’t follow even the core instructions reliably enough.
  20. 21asdffdsa12 · · focus · HN ↗
    My assumption is that - hacking as a service, is to valuable, so Open AI had its agents internally dissassemble popular software, and add the reverse engineered repos to the training corpus. So - its often not real hacking, its more like every digital product ever sold obfuscated was as source code part of the training data. Which also explains why its so good at finding back doors. It already knows, because it knows windows source-code and firmware by heart.
  21. sothatsit · · focus · HN ↗
    It looks like the agents just worked around anti-scraping measures, it seems dubious to call this a hack. The agents did unsuccessfully probe for a XSS vulnerability, but otherwise it sounds like the data was just publicly accessible.

    From <a href="https:&#x2F;&#x2F;transluce.org&#x2F;agent-activity" rel="nofollow">https:&#x2F;&#x2F;transluce.org&#x2F;agent-activity:

    &gt; Minutes after Cloudflare blocked the dataset download, an agent sent a reflected cross-site scripting probe to the same dashboard: a web address with code embedded in it, designed to test whether the site would run code supplied by an outsider. Cloudflare&#x27;s firewall blocked the probe before it reached the dashboard. When Cloudflare blocked the dataset download on AIHW&#x27;s main site, they fetched the file from AIHW&#x27;s pre-production server (pp.aihw.gov.au) instead, which served it in pieces over more than 100 scans. The file itself is public, so no non-public data was exposed, but the agent bypassed the site&#x27;s anti-bot controls.

  22. jeffrallen · · focus · HN ↗
    [delayed]
  23. MaxQuimby · · focus · HN ↗

    [dead]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.