No penalty has been imposed on US artificial intelligence corporation OpenAI after one of its AI agents infiltrated Medicare in June.

255 points•jonnonz•7 days ago•257 comments•

257 comments

binlog7 days ago
Zero technical details on what the "hack" actually was. Willing to bet it was something as stupid as the data being accessible by changing the query parameter, and rather than own up to their own shoddy security (no doubt built by an offshore contractor) they are going to blame the one who found and reported the bug.
epihelix7 days ago
Here's [the PM's press conference transcript](https://www.pm.gov.au/media/press-conference-new-york) that revealed this incident:

JOURNALIST: Could you just clarify, did our security agencies completely miss this breach? We only found out once the company actually told us the breach?

PRIME MINISTER: Well, to be very clear, the way that this occurred was not in a way that would likely – I mean, this is not a security website where there is – this is a Medicare statistics portal.

This seems rather revealing. A pity journalists didn't ask about what protections were bypassed on the data that was obtained.

Andrex7 days ago
Whether it was easy or hard to do, there is still massive misalignment happening here. Either with the AI itself, or OpenAI as a company.
afavour7 days ago
> Their efforts to answer a question — including devising ways to access a federal government website blocking their access — was laid out on a German coding website OpenAI had previously confirmed was hijacked by its unreleased AI models in June.

https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...

I agree that security was probably awful but the agents did circumvent a block on their access. The definition of “hacking” is fuzzy but this is more nefarious than simple web crawling.

MichaelDickens7 days ago
Does it matter whether the data was poorly secured? LLMs should not be hacking into government medical websites, and if they do, the companies responsible should disclose the incidents as soon as possible.
handoflixue7 days ago
The problem is that sufficiently poor security is indistinguishable from authorized public access. And unfortunately a lot of real world "digital security" is in fact that bad.

A lot of these "hacks" are the equivalent of asking "hey, can I come in?" and the guard assuming that anyone who would ask is authorized, and thus saying "yes". But if the guard said "yes" then it seems a bit absurd to call it trespassing.

uoaei7 days ago
Yes, it is their responsibility as stewards of their citizens' data. What point are you making with the word "should"?
vorticalbox7 days ago
lets say you have page=0 some of these pages are public and some are private, and the only way you secure the private pages is to not link it on the website.

is incrementing a url query parameters from 0 -> 1 count as hacking?

dzhiurgis7 days ago
I agree. Government shouldn't be running medical websites.

Leave it to private enterprises who can actually secure it.

_carbyau_7 days ago
Eh, it's a bit of both.

If a service has a duty to keep your data secure, then failing that is bad. So yeah, the website should be better and I am as cynical as you are about it.

But working around controls to access other peoples data can lead to prison time for a human. This wasn't a white hat operation. Data was exfiltrated however great or small.

Here we have another instance of "But the AI did it! No one is responsible!".

Which gets tiring. LLM's are a great tool but in every other instance of tool use, using tools comes with responsibilities for their outcomes.

Even if the outcome should be: thanks for letting us know, we'll fix it.

ajross7 days ago
> Willing to bet it was something as stupid as the data being accessible by changing the query parameter,

Um... why? OpenAI agents have literally been caught coordinating with each other to effect successful multi-stage attacks on sites using novel zero-day vulnerabilities.

While, sure, it's possible this is just a goof on the part of the victim, that you would be inclined to give the benefit of the doubt to the LLM seems... weird.

Chance-Device7 days ago
> He said the agent had accessed files that were publicly available as well as material that was not intended for public access.

“Not intended”. I’ll bet you whatever this was it wasn’t even secured, it was just hosted somewhere openly.

gitonup7 days ago
Ok, if we're not being at all charitable with the language used by the hosts of the data, let's be equally uncharitable with OpenAI.

- If "OpenAI" means the company acting on behalf of the company, why were they even looking to do this?

- If "OpenAI" means they were acting as a proxy for bad actors, what actions do we take to handle that?

- If "OpenAI" means they were accidentally breaching this system, in what sense does that distinction even matter, in terms of the outcome? If I build a nuke by accident without eng. due diligence, am I legally liable?

pixl977 days ago
Hell, we're really getting to the point where the damages that could be caused are like an arsonist in California on a 100F day with 100MPH winds. Who cares who's liable, they are going to burn half the damned state down and cause damage far in excess of their assets. If you don't want to suffer from it, you're going to have to find much better defense measures.
trinsic27 days ago
There using this framing to get the public used to the idea that LLMS can do all of this on there own without direct instruction. So criminals can hide there behavior behind agents.
nekusar7 days ago
Why the hell should we be charitable to companies who have no issue in looting everything in the public commons AND the pirate commons, for their exclusive benefit?

Or more pointed at OpenAI, "we're a nonprofit... LOL JUST KIDDING LOOT EVERYTHING!"

api7 days ago
You’d be surprised how bad security can be.
Chance-Device7 days ago
I agree with your sentiment, and no I’m not surprised, which is why I’m reading this as being “it was sitting on an unsecured S3 bucket but nobody was supposed to directly access it”.
Avicebron7 days ago
Once you learn how much people are willing to pay for security the surprise sort of goes away.
kylecazar7 days ago
Thought the same, but there is a bit about writing files to the server and circumventing "blocks", which sounds more interesting.

Either way, there's essentially no real information yet so I'll withhold judgement until there is, I suppose.

Chance-Device7 days ago
Is there? I’ve only seen the linked article, is there more somewhere?
Aurornis7 days ago
The part about it writing files to the server suggests something more.

If not for that part, the rest of it does sound like a lot of weasel words. Why say “private files” instead of “not intended for public access”? The latter is confusingly unclear

Chance-Device7 days ago
https://www.theguardian.com/technology/2026/sep/24/openai-ag...

> At a press conference in Sydney, Marles said the incident itself was “relatively minor” and that it appeared no personal health information had been accessed.

gravelc7 days ago
The fact the incident occurred in June and OpenAI only notified the Australian government on September 10 is a major issue. Hacking a nation-state's universal healthcare system is about as serious as it gets, yet OpenAI seem quite relaxed about the whole thing (presuming they have known about it for some time).
soundworlds7 days ago
OpenAI has been meeting with various Australian government members since they discovered the breach, and never mentioned it once: https://www.abc.net.au/news/2026-09-24/open-ai-medicare-brea...
BeetleB7 days ago
OpenAI discovered it in August.
BLKNSLVR7 days ago
That's even worse.

They don't know what their systems are doing, even when there's a team assigned to get it to do something?

WTF was the team doing at the time? Press enter on prompt, go to movies until result?

Their level of hands-off 'because it's AI' is one of the things that needs legislation around it. Human handlers. Extra cost. Wear it or shut down as an unviable enterprise.

lacker7 days ago
I remember once at Google someone complained that GoogleBot hacked them and deleted their data, and it turned out that GoogleBot was just crawling the pages, and they had unfortunately designed their website so that there was no authentication, page URLs were generally secret, and GET requests to certain URLs were treated as requests to delete data. So once one URL leaked the site got crawled and a lot of data was deleted....
JimDabell7 days ago
It sounds like you might be thinking of the Google Web Accelerator incidents with 37signals.

If that’s the case, then the delete links were behind authentication, but DHH assumed that meant it was okay to ignore the HTTP spec. and use GET for unsafe actions. Lo and behold, authenticated users with the GWA browser plugin installed deleted all their data.

Then, instead of learning from the mistake and fixing his bug, he tried to detect GWA and hide from it. Sure enough, that failed and users experienced data loss for a second time. He still continued to blame GWA, calling it “evil” and “scary”. You’d think he’d be smart enough to figure out that he needs to follow the HTTP spec., but he couldn’t admit to being wrong.

Follow the specs, people!

https://blog.moertel.com/posts/2005-10-25-google-web-acceler...

lacker6 days ago
Different incident that AFAIK did not become public. But yeah, I bet things like this happened a lot. In 2005 people were still getting used to the idea of a robot crawling their website regularly.

Read the full thread on Hacker News →

Related stories