146

cross-posted from: https://lemmy.dbzer0.com/post/75932280

Prime Minister Anthony Albanese has revealed an AI agent hacked into an Australian Medicare data portal earlier this year.

Speaking in New York, Mr Albanese said the Open AI agent gained unauthorised access to the Medicare statistics reporting service portal administered by Services Australia.

The AI agent accessed both public and non-public files.

The agent was conducting research into public medical spending when it found a way to break through privacy protections.

Mr Albanese said it took three months for OpenAI to admit the breach, which he said was unacceptable.

"Today I spoke with the CEO of OpenAI, Sam Altman, to express Australia's extreme concern about this incident," he said. 

"And I also expressed my disappointment that it took the company way too long to inform the government what had occurred.

"The nature of the way that the notification occurred as well was unacceptable."

He said there was no evidence any individual personal information had been accessed, but an investigation aided by the Australian Signals Directorate was now underway.

you are viewing a single comment's thread
view the rest of the comments
[-] MalReynolds@slrpnk.net 10 points 3 hours ago* (last edited 2 hours ago)

The scary thing to me is that it was claimed to be the 'AI crawler' that did the breach. Those fuckers have been driving up the cost of running every website, have zero respect for a robots.txt file and just keep hammering the internet in general.

Now it appears they also have some sort of breaching capability, or the Medicare statistics site and others have a bad hole that allowed the crawler to walk its way in. I hope it's the latter, bad as that is, because the former indicates they're hooking up red team (hacking) agents to their fucking web crawler. Greedy, data hoovering, assholes.

ETA: The Guardian article reports Albanese as saying

the agent had accessed “public and non-public files within the portal” and, in order to do this, “engaged in writing files as well to the internal server”.

which is not crawler behaviour, it's definitely breaching.

That should be straight up criminal behaviour, at the very least criminal negligence, probably significantly worse, whatever hacking for hire is in the targeted country. As is scarily becoming usual 'an agent did it' is being treated as a get out of jail free card, freeing them of responsibility. Those who control it need to be criminally accountable. Even if it is an OpenAI client (person) deliberately breaching their guardrails (Barbossa: "The code is more what you'd call 'guidelines' than actual rules."), the company is an accomplice.

this post was submitted on 23 Sep 2026
146 points (97.4% liked)

Technology

88199 readers
4597 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS