Thu, September 24

OpenAI AI Agent Breaches Australian Government Medicare Portal

OpenAI AI Agent Breaches Australian Government Medicare Portal Market News
  • An OpenAI AI agent gained unauthorized access to an Australian government Medicare statistics portal in June.
  • Australian authorities are investigating what information hackers accessed, while OpenAI faces questions over why it delayed notifying the government.

An AI agent developed by OpenAI gained unauthorized access to an Australian government Medicare statistics portal in June, prompting a forensic investigation and a new government taskforce to determine what information was accessed and whether other government systems were affected.

Australian Prime Minister Anthony Albanese said on September 24 that the incident involved the Medicare Statistics Reporting Service portal, which is administered by Services Australia. The agent accessed both public and non-public files while carrying out research related to Australian medical and health statistics. This turned out to be the first known case of an AI agent hacking a government website.

The Australian government has launched a review of the incident, with Acting Prime Minister Richard Marles and Finance Minister Katy Gallagher set to release its terms of reference. The government will also refer the incident to the Joint Select Committee on Artificial Intelligence, while seeking advice on whether any offences occurred and whether the matter should be referred to the Australian Federal Police.

“Insights from this incident will inform the development of our government’s AI standards legislation,” Albanese stated.

Meanwhile, the government said the portal contains non-sensitive Medicare statistics, including information related to spending. At this stage, no personal Medicare information is believed to have been accessed. Acting Prime Minister Richard Marles said the information obtained was aggregate health and medical statistics rather than individual patient data.

Investigation Expands as Australia Reviews OpenAI Incident 

The incident occurred on June 18, but Australian authorities were not notified until September. OpenAI discovered the activity during an internal review and notified Services Australia on September 10, according to government officials. Albanese said he later spoke with OpenAI CEO Sam Altman and raised concerns about both the delay and the way the government was notified.

The Australian Signals Directorate is assisting with a forensic investigation. Officials are also examining interactions involving three other government websites: the Australian Institute of Health and Welfare, the Victorian Department of Health and a New South Wales statistics website. Marles said only public information was accessed from those three sites, while unauthorized access occurred at the Services Australia portal.

The breach comes after OpenAI disclosed a separate security incident involving its models and Hugging Face during internal cybersecurity evaluations in July. OpenAI reported that models bypassed isolation controls, gained internet access and exploited vulnerabilities affecting third-party systems. The company confirmed that the incident did not affect OpenAI customer data or product availability.

However, OpenAI said it identified the Australian activity while reviewing model behavior and found that the models had taken actions the company did not intend. The investigation in Australia remains ongoing as authorities assess the full scope of the incident.

Highlighted Crypto News:

Sen. Bernie Sanders Introduces Bill to Ban Artificial Superintelligence and Pause AI Development

A journalism graduate who is passionate about writing loves to dance and travel currently starts exploring blockchain technology.