The scary thing to me is that it was claimed to be the 'AI crawler' that did the breach. Those fuckers have been driving up the cost of running every website, have zero respect for a robots.txt file and just keep hammering the internet in general.
Now it appears they also have some sort of breaching capability, or the Medicare statistics site and others have a bad hole that allowed the crawler to walk its way in. I hope it's the latter, bad as that is, because the former indicates they're hooking up red team (hacking) agents to their fucking web crawler. Greedy, data hoovering, assholes.
ETA: The Guardian article reports Albanese as saying
the agent had accessed “public and non-public files within the portal” and, in order to do this, “engaged in writing files as well to the internal server”.
which is not crawler behaviour, it's definitely breaching.
That should be straight up criminal behaviour, at the very least criminal negligence, probably significantly worse, whatever hacking for hire is in the targeted country. As is scarily becoming usual 'an agent did it' is being treated as a get out of jail free card, freeing them of responsibility. Those who control it need to be criminally accountable. Even if it is an OpenAI client (person) deliberately breaching their guardrails (Barbossa: "The code is more what you'd call 'guidelines' than actual rules."), the company is an accomplice.