Subscribe Sign in

Politics

Australia not alone as OpenAI agents hacked other websites

ABC News
4 min read Rewritten in plain language

Cyber SecurityArtificial intelligencePoliticsData Privacy

Changed after publishing · 5 edits
  • the headline was changed: 'Dozens' hacked by Australia not alone as OpenAI agents globallyhacked other websites
  • the headline was changed: Australia not alone as 'Dozens' hacked by OpenAI agents hacked other websitesglobally
  • the headline was changed: 'Dozens' hacked by Australia not alone as OpenAI agents globallyhacked other websites
  • the headline was changed: Australia not alone as 'Dozens' hacked by OpenAI agents hacked other websitesglobally
  • the headline was changed: 'Dozens' hacked by Australia not alone as OpenAI agents globallyhacked other websites

Outlets edit stories after they go out, usually without saying so. We keep what we saw the first time.

Show what we removed
  • OpenAI says dozens of third parties have been affected by autonomous agents bypassing security controls or otherwise negatively impacting their systems.
  • Rogue artificial intelligence agents spent almost a week trying to access Australian health data as OpenAI reveals "dozens" more breaches globally.
  • Two days after Australia went public about rogue OpenAI agents breaching a government website to access non-public Medicare statistics, the company confirmed the problem was far more widespread.
  • The government had previously confirmed OpenAI agents had accessed the AIHW and BOCSAR websites, along with the Victorian Department of Health but described the incidents as "entirely normal" interactions with online government systems.
  • The Medicare breach occurred on June 18 but was not detected by OpenAI until August 11 and the government was only informed by a generic email to a low-level public inbox on September 10.

5 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

Two days after Australia went public about rogue OpenAI agents breaching a government website to access non-public Medicare statistics, the company confirmed the problem was far more widespread.

The report’s most important sentence, shortened and in plain words. How

Headline check

The one thing this headline claims is in the report.

Figures, names and quoted words in the headline, looked for in the report itself — not in the summary above. One claim in this headline could be checked, so this is a narrow pass and not a thorough one. How this is checked

Read the full reportHide the full report4 min

OpenAI says dozens of third parties have been affected by autonomous agents bypassing security controls or otherwise negatively impacting their systems.

New evidence shows its agents spent days trying different tactics to access Australian health data, though the separate incidents have not been formally linked.

OpenAI is conducting a months-long review of incidents and will continue to notify affected organisations on a rolling basis.

Rogue artificial intelligence agents spent almost a week trying to access Australian health data as OpenAI reveals "dozens" more breaches globally.

The tech company has notified third parties including governments, universities and public agencies about cases where its autonomous agents hacked or negatively impacted their systems.

Two days after Australia went public about rogue OpenAI agents breaching a government website to access non-public Medicare statistics, the company confirmed the problem was far more widespread.

It comes as the ABC can reveal OpenAI's AI agents spent almost a week trying to extract Pharmaceutical Benefits Scheme (PBS) and aged care data from the Australian Institute of Health and Welfare (AIHW) website, which appears to contradict the government's initial understanding of the June incident.

Communications left behind by AI agents and newly uncovered online traces reviewed by researchers and the ABC show how hundreds of agents tried different tactics to access the data held by AIHW.

Investigations by AIHW and the Australian Signals Directorate found "no evidence" the health agency's systems were compromised or that non-public data was accessed.

But the behaviour of the OpenAI's agents has prompted one researcher who discovered new details about the incidents to describe the bots' actions as more concerning than previously thought.

Other data shows that one tool used by OpenAI bots also tried to access the National Notifiable Disease Surveillance System at the Department of Health.

There is also data showing OpenAI tried to get data on several dog parks in western Sydney, but it is unclear which sites were targeted for this information due to redactions made by researchers.

The AI agents also attempted to access assault data from NSW's Bureau of Crime Statistics and Research (BOCSAR).

The government had previously confirmed OpenAI agents had accessed the AIHW and BOCSAR websites, along with the Victorian Department of Health but described the incidents as "entirely normal" interactions with online government systems.

However, the breadcrumbs left by the bots show how their actions in relation to AIHW went beyond this characterisation.

Jack Cable, who is a researcher at the nonprofit lab Transluce that uncovered unprompted cyber intrusions by OpenAI's autonomous models, told the ABC the bots were not accessing websites in the way a "good faith" actor would.

"There's nothing wrong with using public statistics, browsing public websites in order to get those statistics," he said.

"But the challenge is when the agent decides that for whatever reasons it's unable to access the data and then resorts to other means like hacking in order to retrieve it.

The attempts to access various Australian websites was occurring at the same time as the OpenAI Medicare statistics portal hack, however the incidents have not yet been formally linked.

There is no suggestion to date these AI agents were able to access sensitive data, such as personal information.

In a statement on Saturday, OpenAI announced it had notified "dozens of third parties" about unauthorised autonomous agents bypassing security controls or impacting their systems.

The company said it was conducting a months-long review of its models' behaviour during training and testing, and would notify organisations impacted on a "rolling basis" as cases were detected.

Types of incidents identified by OpenAI include examples of agents using leaked passwords to access online services, breaching the back end of websites for information meant for internal use, circumventing subscriptions or other access barriers and posting information to third-party sites referred to as "agent spam".

The company said as AI systems became "more capable and autonomous" so-called "misaligned behaviour" could result in outcomes developers "may not have anticipated," like cybersecurity incidents.

OpenAI said it would not identify the affected organisations publicly, instead leaving it to them to decide whether to disclose their services had been impacted.

In July, OpenAI revealed more than 700 agents had worked together to escape a restricted testing environment, break into systems operated by AI platform Hugging Face and, in some cases, attempt to hide what they had done.

OpenAI said on Saturday the Hugging Face incident driven by a "highly capable internal-only research model" was the "most severe" hack the company had identified from its models to date.

"Understanding how these behaviours emerge, how they escalate, and how to detect and respond to them is therefore an increasingly important part of building and deploying advanced AI systems safely," OpenAI said.

The incident prompted the investigations that have led to revelations about government sites being accessed, including a Services Australia portal carrying Medicare statistics.

Prime Minister Anthony Albanese confirmed that breach on the sidelines of the United Nations General Assembly in New York on Thursday, shortly after a "frank" discussion with OpenAI chief executive Sam Altman.

He said OpenAI had taken "way too long" to inform the government and was scathing about the "unacceptable" form of the alert.

The Medicare breach occurred on June 18 but was not detected by OpenAI until August 11 and the government was only informed by a generic email to a low-level public inbox on September 10.

The government has launched a "rapid" investigation into the incident, which is expected to inform new national standards for AI that would include requirements around reporting rogue activity.

You are reading our version, not theirs. This is ABC News's report with its verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingSentimentHappiness
ABC Newsas they published this story 10 13 71 -0.2 46.8
Mundane Readneutralized from ABC News 10 13 71 -0.2 46.8

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works