No penalty has been imposed on US artificial intelligence corporation OpenAI after one of its AI agents infiltrated Medicare in June.
257 comments
JOURNALIST: Could you just clarify, did our security agencies completely miss this breach? We only found out once the company actually told us the breach?
PRIME MINISTER: Well, to be very clear, the way that this occurred was not in a way that would likely – I mean, this is not a security website where there is – this is a Medicare statistics portal.
This seems rather revealing. A pity journalists didn't ask about what protections were bypassed on the data that was obtained.
https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...
I agree that security was probably awful but the agents did circumvent a block on their access. The definition of “hacking” is fuzzy but this is more nefarious than simple web crawling.
A lot of these "hacks" are the equivalent of asking "hey, can I come in?" and the guard assuming that anyone who would ask is authorized, and thus saying "yes". But if the guard said "yes" then it seems a bit absurd to call it trespassing.
is incrementing a url query parameters from 0 -> 1 count as hacking?
Leave it to private enterprises who can actually secure it.
If a service has a duty to keep your data secure, then failing that is bad. So yeah, the website should be better and I am as cynical as you are about it.
But working around controls to access other peoples data can lead to prison time for a human. This wasn't a white hat operation. Data was exfiltrated however great or small.
Here we have another instance of "But the AI did it! No one is responsible!".
Which gets tiring. LLM's are a great tool but in every other instance of tool use, using tools comes with responsibilities for their outcomes.
Even if the outcome should be: thanks for letting us know, we'll fix it.
Um... why? OpenAI agents have literally been caught coordinating with each other to effect successful multi-stage attacks on sites using novel zero-day vulnerabilities.
While, sure, it's possible this is just a goof on the part of the victim, that you would be inclined to give the benefit of the doubt to the LLM seems... weird.
“Not intended”. I’ll bet you whatever this was it wasn’t even secured, it was just hosted somewhere openly.
- If "OpenAI" means the company acting on behalf of the company, why were they even looking to do this?
- If "OpenAI" means they were acting as a proxy for bad actors, what actions do we take to handle that?
- If "OpenAI" means they were accidentally breaching this system, in what sense does that distinction even matter, in terms of the outcome? If I build a nuke by accident without eng. due diligence, am I legally liable?
Or more pointed at OpenAI, "we're a nonprofit... LOL JUST KIDDING LOOT EVERYTHING!"
Either way, there's essentially no real information yet so I'll withhold judgement until there is, I suppose.
If not for that part, the rest of it does sound like a lot of weasel words. Why say “private files” instead of “not intended for public access”? The latter is confusingly unclear
> At a press conference in Sydney, Marles said the incident itself was “relatively minor” and that it appeared no personal health information had been accessed.
They don't know what their systems are doing, even when there's a team assigned to get it to do something?
WTF was the team doing at the time? Press enter on prompt, go to movies until result?
Their level of hands-off 'because it's AI' is one of the things that needs legislation around it. Human handlers. Extra cost. Wear it or shut down as an unviable enterprise.
If that’s the case, then the delete links were behind authentication, but DHH assumed that meant it was okay to ignore the HTTP spec. and use GET for unsafe actions. Lo and behold, authenticated users with the GWA browser plugin installed deleted all their data.
Then, instead of learning from the mistake and fixing his bug, he tried to detect GWA and hide from it. Sure enough, that failed and users experienced data loss for a second time. He still continued to blame GWA, calling it “evil” and “scary”. You’d think he’d be smart enough to figure out that he needs to follow the HTTP spec., but he couldn’t admit to being wrong.
Follow the specs, people!
https://blog.moertel.com/posts/2005-10-25-google-web-acceler...
Read the full thread on Hacker News →
Related stories
- Hacker News · 55 points · 4 days ago
- The Verge · 0 points · 1 day ago
- OpenAI says planned GPT-6.1 is too insecure to releasearstechnica.comArs Technica · 0 points · 1 day ago
- Hacker News · 1 points · 7 days ago
- The Verge · 0 points · 8 days ago
- Hacker News · 4 points · 2 days ago