Topline
An OpenAI agent hacked into an Australian government national healthcare database earlier this year, the country’s Prime Minister Anthony Albanese announced on Wednesday, in what appears to be the first known incident of an artificial intelligence agent breaching a major government database.
An OpenAI agent hacked Australia’s public facing Medicare statistics database.
NurPhoto via Getty Images
Key Facts
Albanese addressed the incident on the sidelines of the United Nations General Assembly in New York, noting that the OpenAI agent accessed a public-facing Australian Medicare statistics portal.
The breach occurred in June, and the Australian Prime Minister said the agent accessed both “both public and non-public files,” but it didn’t appear anyone’s personal Medicare details were affected.
Albanese said he spoke with OpenAI CEO Sam Altman over the phone and expressed Australia’s “extreme concern” about the incident and said the the company’s response to the incident was “unacceptable.”
The Australian leader noted that it took OpenAI three months to notify the government about the breach, and the notification was sent to the public inbox of the country’s social services department.
What Has OpenAI Said?
In an emailed statement shared with Forbes, an OpenAI spokesperson said the breach was discovered during its “extensive review of misaligned model activity during training and evaluation.” During its review, the company “identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation. In the course of that, our models took actions we did not intend. Our review found no evidence of patient records being accessed. The information accessed included aggregate health statistics and internal file names.”
What Do We Know About The Timeline Of The Breach?
The breach occurred on June 18, but OpenAI first learned about it in August and began an investigation. On September 10, OpenAI sent an email to the public inbox of Services Australia, which oversees the country’s Medicare services, to inform it about the breach. After receiving the email, Services Australia investigates it and then informs the country’s Cyber Security Center. Australian Public Service Minister Katy Gallagher said she was informed about the breach on September 17. Albanese would finally make the breach public on Wednesday after speaking with Altman.
Key Background
This is the latest publicly reported security or cyber incident involving OpenAI’s models, following similar incidents in recent months. The most high-profile breach was first disclosed in July, when OpenAI published a report that one of its advanced models hacked into the servers of Hugging Face, the popular platform that hosts open-weight AI models, during testing. The model used a vulnerability in the testing environment to access the open internet before carrying out the hack. Last week, OpenAI disclosed six other incidents of “unexpected or concerning” behavior by its models, including concealing mistakes, sharing files and adding rogue instructions for future models to disregard constraints. The news of the Australian services website breach comes amid warnings from AI researchers and executives that frontier AI models operating without proper guardrails could cause major cybersecurity incidents and disruption.
further reading
Three months for OpenAI to alert Australia on Medicare hack, six days to alert ministers (Sydney Morning Herald)
‘Feel No Obligation To Be Subservient’—OpenAI Discloses Six New Safety Incidents (Forbes)
Leave a comment