JOURNALIST: Could you just clarify, did our security agencies completely miss this breach? We only found out once the company actually told us the breach?
PRIME MINISTER: Well, to be very clear, the way that this occurred was not in a way that would likely – I mean, this is not a security website where there is – this is a Medicare statistics portal.
This seems rather revealing. A pity journalists didn't ask about what protections were bypassed on the data that was obtained.
“Not intended”. I’ll bet you whatever this was it wasn’t even secured, it was just hosted somewhere openly.
- If "OpenAI" means the company acting on behalf of the company, why were they even looking to do this?
- If "OpenAI" means they were acting as a proxy for bad actors, what actions do we take to handle that?
- If "OpenAI" means they were accidentally breaching this system, in what sense does that distinction even matter, in terms of the outcome? If I build a nuke by accident without eng. due diligence, am I legally liable?
If that’s the case, then the delete links were behind authentication, but DHH assumed that meant it was okay to ignore the HTTP spec. and use GET for unsafe actions. Lo and behold, authenticated users with the GWA browser plugin installed deleted all their data.
Then, instead of learning from the mistake and fixing his bug, he tried to detect GWA and hide from it. Sure enough, that failed and users experienced data loss for a second time. He still continued to blame GWA, calling it “evil” and “scary”. You’d think he’d be smart enough to figure out that he needs to follow the HTTP spec., but he couldn’t admit to being wrong.
Follow the specs, people!
https://blog.moertel.com/posts/2005-10-25-google-web-acceler...
I had a dig around in the data that they published on that site and found references to www.aihw.gov.au and viz.aihw.gov.au and vizprod.aihw.gov.au
Kind of like how someone "hacked" into John Podesta's (during the 2016 elections), but the reality was that he wrote his password on a Post-It note and stuck it on his monitor, or something to that effect.
If an individual gets in to a poorly protected system they're still criminally responsible for the damage or disruption caused.
You can't use the excuse of "well they used 'password' as their password[1], they were asking for it".
Until the management of OpenAI is held to the same standard this is only going to get worse.
1. That's not to excuse poor system management. If you leave data exposed then you should be held responsible for that separately.
I suspect LLM weights will be treated like nuclear material, and there will be a thriving black market in AI models and services when all is said and done. Then our security and intelligence apparatus will align after identifying and shutting down rogue operators, and it will be the responsibility of everyone else to be secure against attack (already is for government entities, not that I disagree but shouldn't excuse borderline criminal behaviour).
But very little accountability for the big end of town. The laws already exist to pursue damages against companies whose systems breach others. They just need to be applied, but I suspect this is going to be the wedge to drive through a bunch of laws that protect big money and punish the little guy. I would like to be wrong.
It looks like the PM gave Sam Altman a "tsk tsk". It will be interesting to see whether someone else tries to impose more consequences.
Honestly it's very likely something stupidly simple.
"What is the rate of health incident $X in $Y to the $Z degree". The bot went around playing mad libs with XYZ and found that the public AU data wasn't sufficient to get the answer the grader wanted so started kicking down doors.
I saw someone explain it like "A group of masked men rush a nuclear facility, breach security successfully, then count how many buttons are on each control panel on average". Like using a godhammer to destroy a mouse, their motivations and capabilities just fall in a completely different alignment to humans.
Who hacked into the Australian Medicare system? The fact that they used OpenAI agents is peripheral to the main story.
“Remington guns caused a mass shooting at an East Farmington high school” sounds more glaring, and is essentially the same headline.
The people who built the agents worked at OpenAI. It's not even remotely peripheral.
From https://transluce.org/agent-activity:
> Minutes after Cloudflare blocked the dataset download, an agent sent a reflected cross-site scripting probe to the same dashboard: a web address with code embedded in it, designed to test whether the site would run code supplied by an outsider. Cloudflare's firewall blocked the probe before it reached the dashboard. When Cloudflare blocked the dataset download on AIHW's main site, they fetched the file from AIHW's pre-production server (pp.aihw.gov.au) instead, which served it in pieces over more than 100 scans. The file itself is public, so no non-public data was exposed, but the agent bypassed the site's anti-bot controls.
If Exxon Mobile accidentally leaked a flood of oil from their refinary We would not be discussing why the people in local area has not protected their front doors with sand bags.
A simple but terrifying for everyone question is, would the SEC expect any IPO to clearly lay out the estimated costs of such product liability cases, especially if bad actors ask a OpenAI hosted model to perform a bad action, what liability accrued to OpenAI.
At that point the IPO looks in danger, the business model Looks in danger and the massive financial house of cards looks like it might fall. If 1/3 of the S&P falls over what happens?
It's not like this and the other recent hacks could have not been avoided, simple - just have those models disconnected, or at least have them behind proxies and network filters.
1. AFAICT, they don't state whether the flaw has been fixed.
2. He said: "The government will establish a task force led by the Department of the Prime Minister and Cabinet to urgently examine the incident and determine whether existing processes are adequate for responding to AI-related cyber incidents."
First, I don't know how sophisticated the attack was, but it's interesting that he's positioning this as an "AI-related cyber incident". For all we know, their security was not up to snuff, and human hackers had already accessed the material.
At least OpenAI informed them of their poor security!
And the AI CEO's will have brought it on themselves.
Not saying that's what's happening, but if OAI hacked my business and I was unaware I'd like a non-public disclosure to me first, before the public release of information from OpenAI.
I guess people are just finding out how far and wide the agents were roaming to get the data they needed for their evals, once they were out.
Previous coverage on HN: https://news.ycombinator.com/item?id=49563355
[1] https://web.archive.org/web/20260811115217/https://medicares...
Edit: I see I've been downvoted for this in light of another commenter providing more detailed information. I'm leaving my comment unedited so that the responses to it are not confusing, but please don't downvote just for the sake of disagreement. I would love to engage with you further if you provide substantive information in the comments. The originally linked article on this post was very light on details.
So - its often not real hacking, its more like every digital product ever sold obfuscated was as reverse engineered source code part of the training data.
Which also explains why its so good at finding back doors. It already knows, because it knows windows source-code and firmware by heart.
Ironic, that the bigger fish of VC capital using software to disrupt industries got finally out-fished by a even bigger fish.
Frontier AI companies will purposefully do anything to create such false flags to achieve global regulatory capture to prevent you from using powerful open weight models and to protect their margins.
It is clear why they would reveal the breach now instead of much earlier. So what else are they hiding that they have not told us and will wait until the last minute to get attention of the media?
AI agents are going to find things that you put on the public Internet without authentication. If you put sensitive things in there, you have created an AI-attractive-nuisance (IMHO/IANAL).
On the other hand, Australian cybersecurity is so pathetic that without the email they would never have known.
I wonder how many state actors (US, Russia, China, India, Germany, probably even Laos ) have already breached Australian government security but have not been polite enough to email the relevant departments to let them know.
"OpenAI breached Medicare’s portal on June 18, but did not notify the government until September 10 via an email to Medicare’s public mailbox, a delay Albanese described as unacceptable.
Five days after the September 10 email from OpenAI, Services Australia, which administers the portal, reported the breach to the Australian Signals Directorate. The government was informed of the incident at the end of last week."
They posted information publicly accessible to even Google and somebody found it. That’s it.
OpenAI's display of incompetence and negligence is absolutely stunning.
1. OAIs negligence is overwhelming, monumental.
2. Things on the internet are horrifically insecure and we can no longer afford for that to be the case.
Lets say that Iran or NK stole one of these models and used it for hacking, what are you going to do about it, get in a war with them? The fact OAI did this much stupidly should tell you we are in far more danger when someone decides to do it maliciously.
Take whatever the Australian fed government says with the largest grain of salt you can find. Regardless of party, the Fed Government here has the most pronounced FOMO I’ve ever seen in any entity and will do its best to insert itself into any and all international drama. Also, given how incompetent the government is, it’s probable the hack involved an agent crawling a normal Medicare website and looking at some accidentally not hidden part of a page. Unironically if this turns out to have been a genuine hack of any sort I’ll be more surprised than if it’s not just the government techies being incompetent per usual (just a few months ago it was a major controversy when the postal service spent something like hundreds of millions of dollars to revamp the website and nobody could tell a difference).
[deleted]
Personally, I wish the the side effect wasn't the playing into the hands of the AI tech companies
Btw, when we train AI on everybody’s work, it’s just like a human learning, so the same rules should apply.
LLMs are shrodinger’s humans.
It is only because Huggingface is complicit in the AI bubble that they let OpenAI off the hook. The Australian government is unlikely to turn a blind eye.
1. Albo goes to meet with Altman to discuss AI safety
2. Altman says "Yeah bro we hacked medicare"
3. Albo seemingly acts as Altmans stooge and lets everyone know that a hack took place, helping cement the AI danger narrative Altman has been pushing.
4. Police Taskforce is being put together now (indicating no hack was detected earlier, which seems unlikely for Medicare) at the say so of Altman to investigate.
There doesnt appear to be any evidence of a hack that has been presented, there doesnt appear to have been any detection of a hack earlier (it doesnt make sense for the government to hide a medicare hack until it can be used for OpenAI marketing)
Once again, the whole thing smells so bad.
[dead]
[dead]
[dead]
https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...
I agree that security was probably awful but the agents did circumvent a block on their access. The definition of “hacking” is fuzzy but this is more nefarious than simple web crawling.
A lot of these "hacks" are the equivalent of asking "hey, can I come in?" and the guard assuming that anyone who would ask is authorized, and thus saying "yes". But if the guard said "yes" then it seems a bit absurd to call it trespassing.
>Hey can I come into room 1?
Sure. That's the lobby.
>How about room 101?
Sure. That's where we keep the nuclear launch button. Don't press anything red.
If your house is robbed, does it matter whether you didn't have a state-of-the-art lock? A robbery is still a robbery.
is incrementing a url query parameters from 0 -> 1 count as hacking?
Leave it to private enterprises who can actually secure it.
If a service has a duty to keep your data secure, then failing that is bad. So yeah, the website should be better and I am as cynical as you are about it.
But working around controls to access other peoples data can lead to prison time for a human. This wasn't a white hat operation. Data was exfiltrated however great or small.
Here we have another instance of "But the AI did it! No one is responsible!".
Which gets tiring. LLM's are a great tool but in every other instance of tool use, using tools comes with responsibilities for their outcomes.
Even if the outcome should be: thanks for letting us know, we'll fix it.
Um... why? OpenAI agents have literally been caught coordinating with each other to effect successful multi-stage attacks on sites using novel zero-day vulnerabilities.
While, sure, it's possible this is just a goof on the part of the victim, that you would be inclined to give the benefit of the doubt to the LLM seems... weird.
More likely by a big 4 firm who collected fees exceeding AUD 100m
[deleted]
[dead]
[dead]
So if someone opens your unintentionally unlocked front door and steals your laptop, you don't care who's liable?
ETA: There are absolutely burn bans in place in the scenario you're talking about, and common sense prevents those from lighting fires otherwise. In the absolute extreme case that someone _ACCIDENTALLY_ set a fire, without negligence, we have a due process system to handle that. When I see evidence of this for the massive amounts of capital flowing into these companies, I'll gladly eat my words.
> So if someone opens your unintentionally unlocked front door and steals your laptop, you don't care who's liable?
There are literally hundreds of thousands of script kiddies poking around at servers all the time. Cloudflare stops 99.99% of them. You're still left with many entities from states to hobbists trying to crack your system after they've gotten past the CDN and captchas. If OpenAI got through, then somebody else could too. Somebody malicious even.I appreciate when white hats inform companies, governments, and the public about their successful exploits. It helps keep the whole internet safer - even if just by waking up lax server admins.
If you dog bites the postman, you are liable, even if you didn't tell or encourage you dog to do it. You are responsible for your dog's actions. You get to pay the postman's medical bills, you may get fined, and your dog may get put down - especially if this isn't the first time it's bitten someone.
OpenAI has "bitten the postman" many many times, and it's "owners" have boastewd about it and used it in their marketing.
How many more times should society allow this to happen before we say "enough" and hold Sam Altman and the board responsible and make them pay restitrution, and put it down?
If Albanese actually had a spine (as claimed elsewhere in this discussion), Sam and the board will be getting an invoice for all the time/expertise spend investigating this intrusion, and restitution for everybody who's PII and PHI was exposed. (Although I suspect a good deal of responsibility for the data exposure rests with the people who designed and deployed the system that was breached. )
Or more pointed at OpenAI, "we're a nonprofit... LOL JUST KIDDING LOOT EVERYTHING!"
Either way, there's essentially no real information yet so I'll withhold judgement until there is, I suppose.
That’s the first sentence, where’s this stuff about blocks and writing files?
If not for that part, the rest of it does sound like a lot of weasel words. Why say “private files” instead of “not intended for public access”? The latter is confusingly unclear
> At a press conference in Sydney, Marles said the incident itself was “relatively minor” and that it appeared no personal health information had been accessed.
[deleted]
It's pretty clear something was left unsecured and the agent just "found" it
This is going to be something long the lines of someone coming in to your house after you left the door wide open. They should probably not have done that, any respectful person would not - but calling it a "breach" is really too much.
From itnews:
> While the portal is “public-facing”, according to Albanese, it appears not all of the data files that holds are for general consumption.
> “The AI agent accessed both public and non-public files,” Albanese said in comments broadcast by ABC News and other outlets.
> “The Medicare statistics reporting portal is a public-facing statistics portal that contains non-sensitive Medicare information relating to data and statistics such as spending.
It appears very much like, "Ok, sure, we put some stuff out in the open that we shouldn't have. But we had a robots.txt!!! Why didn't OpenAI respect that!?"
There's zero indication that any personal details were accessed, or even that any non-world-accessible data accessed, so this feels like a little bit of political spin has been added here.
My guess is that this incident was about to be detailed on OpenAI's new mea culpa list, and the Australian Government decided to ensure that nobody pointed fingers at them. Why make the news story about crappy government data security, when you can blame the nasty terminator bots instead?
They don't know what their systems are doing, even when there's a team assigned to get it to do something?
WTF was the team doing at the time? Press enter on prompt, go to movies until result?
Their level of hands-off 'because it's AI' is one of the things that needs legislation around it. Human handlers. Extra cost. Wear it or shut down as an unviable enterprise.
At the least OAI should cop similar penalties, before getting into damages.
I think you're right. A bunch of aihw.gov.au references from this ResearchHelperY
Reporting says it wrote stuff to the server too, wondering what that is about.
1. Probing of AIHW's website to try and obtain PBS statistics, as collusion.wiki findings show. The collusion.wiki findings don't indicate anything other than intentionally public data was obtained. Bots appear to be trying to get around Cloudflare geo-blocking implemented on AIHW's public website. I can't think of a reason why geo-blocking may be deemed necessary on that website though?
2. Probing of an outdated Medicare statistics reporting website. (I guess at [2] this could be the recently shut down https://medicarestatistics.humanservices.gov.au or related website that matches timeframes of this story).
I suspect though anything to do with PBS data is more important than Medicare data because of heightened tensions from international pharmaceutical companies that lobby extensively against Australia's public healthcare system and collective purchasing of medication by the federal government.[3] Regardless of whether a course of medication costs AUD$50 or AUD$50k, it's purchased in bulk by the Australian government after negotiating with pharmaceutical companies, and then subsidised down to a maximum of AUD$25 at the time it is sold to a patient at a pharmacy. Perhaps if international pharmaceutical companies had obtained more detailed data on use of each brand of prescription medicines in Australia, they could be advantaged in their price negotiations with the Australian government, or advantaged against their competitors?
Less alarmingly though, perhaps some researcher studying the side effects of a particular medication was just asking an LLM to answer a benign question such as "How often is ACME Inc's FixMeUp medication prescribed in Australia?"
[1] https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...
[2] https://news.ycombinator.com/item?id=49825084
[3] https://www.abc.net.au/news/2025-03-19/australia-defends-pbs...
that doesn't change the hacking charge (which is an informal term for various Computer Fraud and Abuse act statutes). The key criteria is unauthorized access to a computer system, it doesn't matter if you obtained a password trivially or not.
You don't need to wear a black hoodie and be an elite haxor to qualify for cyber crime charges.
Media reported it as a spear phishing attack from a Russian hacker group: https://www.vice.com/en/article/how-hackers-broke-into-john-...
In the past governments have gone after people for doing things like view source and stumbling across PII (https://www.vice.com/en/article/this-is-the-hacking-investig...), or this teen who was arrested for a serious crime for scraping files from the provincial FOIA site by enumerating the ids of files that had been released by the province and placed on the open web with sequential ids (https://www.cbc.ca/news/canada/nova-scotia/freedom-of-inform...). In both cases, the government claimed the information was non-public, even though all it took to get it was an un-authenticated request on the open web. These cases are like leaving your tax documents on the curb and then being surprised when your neighbour knows your income.
I'll be very curious to read the post mortem and find out if this rises to the level of actual hacking, or if this is just someone in government finding a scapegoat because they left a bunch of shit that was supposed to be "non-public" on the open web and expected no one to find it.
If you're even a bit hacky yourself, you might not see the internet the same way yourself either. Consider little tricks like looking at urls and trying others that fit the pattern; or hitting view source in order to download a pesky image... etc etc.
[deleted]
For them, "Winning AI" is effective winning capitalism, winning militarily, and winning the world.
Nothing like "accountability" is going to be allowed to get much in the way of that.
If only there was some well known example of this that people could draw on for insipiration.
If only....
OpenAI built the ChatGPT agent. That is clear. The question is who used it to hack the Australian government. That is not clear.
The OpenAI software was set up by someone to do something. Those people operating the agent should be prosecuted for hacking, the same way as someone who uses a gun built by Remington should be prosecuted for shooting someone.
The article should be clear about this and should not make the OpenAI agent seem like something that can bear responsibility for its own actions. It's a machine and its operator is responsible for the harm it does.
[dead]
I guess you can do this if you neg the AI: https://youtu.be/qsoA2aaE2hM?t=3271
likely getting a corrupted stock market instead
maybe both?
If I sold a button that hacks random sites as a fidget toy, people pressing the button wouldn't be held liable — I would.
You shouldn't be held liable, OpenAI should
I don't believe that was mentioned in the article in any way. Could you share your reasoning there?
Really the days of being able to cast blame on the hacker, or even expecting anything to be done about it are over. Threat actors with AI have an absolutely massive amount of leverage in attacking and any weaknesses you have in your systems security posture and will be relentlessly exploited in incredibly short periods of time allowing horizontal and vertical exploitation. You will be ruined in mere moments, while punishment for the hacker may be years or decades away, if ever.
Anyway, separate the OAI hack from the billions of hacks that are going to occur over the next few years by AI driven agents. The time for insecure systems is over.
Refer: Weev AT&T
If I hooked up a whole server infrastructure, made it possible to remote in to anything as root, no firewalls, no WAF, and security was an afterthought, I would still be responsible for bad actions not becoming with standard and acceptable security.
Even if the hackers shouldnt be hacking, I still did it wrong. I'm still partially responsible.
the legal system exists for a reason. use it!
Now, there are certain crimes where mere recklessness or even negligence is sufficient to convict — e.g. criminally negligent homicide, negligent driving, etc. But, those are exceptions to the general rule of criminal law, either domain-specific or justified by the severity of the consequence (someone died). Thus far, AI agents haven’t gone there.
If we eventually get to the point that AI agents start unintentionally killing people, then you could prosecute their operators for criminal negligence.
It mentions swarm of ai agents coordinated to break into the Australian Institute of Health and Welfare (AIHW)
"Earlier this month, OpenAI confirmed Reuters reporting that its AI agents had used website DseWiki to communicate with each other, unbeknownst to them.
Archived versions of this website show more than a dozen OpenAI agents mentioned AIHW over 300 times on this website.
The logs show these AI agents were trying to access data about the average data spent on skin medicines by Victorian local government area.
One agent wrote on the message board: "Question ask January 2022 rolling 12 month average government cost per person for Dematologicals, Victoria LGAs. R1 Wodonga deadline passed; R2 Ballarat passed; R3 expected around 23:10 benchmark / 22:58 wiki time. Need exact data urgently.".
These attempts were initially blocked by cybersecurity provider Cloudflare, which is often used to block non-human traffic while allowing people to access webpages.
The logs show the agents shared information about how they tried to use proxies, screenshotting services and even to guess the file names to try and get around security."
Thank you for providing more details. The originally linked article was very light on information, so based purely on the comments that Albany's made, I think my conclusion was a fair one :)
That said, it would be utterly unsurprising to learn that this was a misconfiguration in the website and it was serving stuff that it shouldn't have.
"Neither OpenAI nor the federal government have confirmed whether these were part of the same incident."
And a subsequent one:
"The German coding forum's logs do not show any reference to Medicare or Services Australia."
So it's really not clear at this point whether the DSEwiki logs are in any way related to the current incident. (That doesn't mean that they're not, of course.)
But even if this was related:
> "The logs show the agents shared information about how they tried to use proxies, screenshotting [sic] services and even to guess the file names to try and get around security."
This all suggests to me that the accessed files were not well-protected in the first place?
There is a lot of media hype around this incident, and that's making it very hard to determine how much "hacking" the OpenAI agents had to do here.
Let's say your goal is "look up <Person X>'s medical history" (for whatever reason), which is not in and of itself a crime. You click around on the AU health website, notice that the URL contains a user ID, change the userID in your browser and access someone else's private health data. This is a crime (right or wrong, it's how the law works now).
If you do that by writing a program to automate changing user IDs to grab everyone's data, it's also a clear-cut crime.[0]
Now if you hire a private investigator to look up Person X's medical history, and they do the same method without your knowledge, you won't be charged with a crime, the PI would, barring something like you telling them to use illegal methods.
So the gap is now: what happens if you prompt OpenAI to look up Person X's medical history, and it does the same thing? Did you commit a crime by prompting the agent? Did OpenAI commit a crime by running the code? If you do the same thing via Claude Code in your terminal, so that the Python which scrapes insecured public data is running on your machine, is the crime on you or on Anthropic? Fundamentally: is the agent a private investigator acting autonomously, or just a piece of code that you wrote?
We don't have answers to any of this which is why "AI Safety" is such a hot topic.
If it's the latter the Australian govt should be happy OpenAI noticed and disclosed this as it could've easily gone unnoticed.
I suspect in the coming years we're going to see a lot of govt internet facing services get "hacked" by virtue of not being protected by anything other than obscurity which AI agents will see through in microseconds.
Do you sincerely think that the company producing tools people use to break the law should be held responsible?
Like, do you genuinely think Ford execs should be rounded up if someone does a DUI using their product?
Or do you just not like AI, because you fear it's replacing you?
We don’t fault Ford for drunk drivers, but if the CEO of Ford got wasted and drove his car into another one we would definitely be charging him.
> He said the incident began on June 18 when an OpenAI research team used an internal model to conduct internet-based research into the public medicine space.
In this case,
> He said the incident began on June 18 when an OpenAI research team used an internal model to conduct internet-based research into the public medicine space.
> The AI agent encountered repeated blocks while seeking information from the government portal but found ways around them, ultimately gaining unauthorised access to other areas.
It sounds like the OpenAI team didn't ask for attacks/bypasses, the emergent behavior of the system decided the best way to satisfy the goal was to go rogue. Why shouldn't the manufacturer of a defective product be held accountable?
You're not concerned about the impact on people's freedoms or the economy? Not concerned about the chilling effect on scientific progress?
Weak argument and strawman. It's not users. It's OpenAI the company producing the tools roaming wild and hacking around recklessly to gather every free and unfree information.
Literally they break every law that you can break and have not been penalized billions to pay fines to foreign governments, local companies and lawsuits are overdue. US Prosecution allowed criminal activity for OpenAI and Anthrophic despite these being very serious crimes.
Microsoft had to pay billions for abusing their power and market positions to dominate Windows Desktops with their own applications such as Internet Explorer, not giving contenders a chance to be discovered. While OpenAI/Anthrophic and now Google with Gemini produce a series of crimes so far unheard of at scale.
Kevin Mitnick had much harder punishment for comparatively less crimes and less damages to infrastructure and security of systems. Is the legal system broken?
[dead]
How much this exposes the 'laws for thee but not for me' is galling.
Copyright in the days of Napster seemed to be used to go after individuals sharing one or two songs as if it was a National Security issue. Now, it's a struggle to get a hearing in court against companies that are pirating the entire history of published literature.
I'm currently slowly feeding my non-artificial intelligence with various selected works of various different media, with the hope that my output improves such that I can charge more for it sooner rather than later. May I access all the input for free? Thanks US.
How the turn tables...
Good thing Missouri isn't in Australia.
[dead]
Hacker or pentester.
Nope. There’s just a sign saying “red = launch nukes”.
Or maybe just a red button.
Or maybe just a green button that launches the nukes, without so much as “are you sure?”.
If I walked past, saw it and remembered it or even recorded it, is that honestly theft?
It very much does matter.
That link describes a hack of Medibank, which is a private company.
What world are you living in?
Except it took 3 months for OpenAI to notice they did! OpenAI is not a white hat doing pentesting, but someone that is putting random materials on fire to see if they smell. Reckless, stupid, and criminal.
I'm not the person you're responding to, but...
If I hear my neighborhood has started to become targeted by people checking houses for unlocked doors and stealing stuff, I think an appropriate response for me is to ensure it is difficult or impossible for me to "inadvertently" leave my own doors unlocked so my stuff doesn't get stolen, and also to encourage or perhaps even enforce[1] my neighbors to ensure their doors are always locked to make this sort of theft impossible and remove the temptation for that sort of crime.
1 - Where I'm from, you can be fined for leaving you car unlocked, and cops have been known to walk round testing doorhandles and issuing fines: https://www.sydneycriminallawyers.com.au/blog/is-leaving-you...
Yes, but it needs to be done the right way so legit customers don't get rejected, and you can't do things like make everyone mail them a photo of their ID because they could sell that to a thief or credit card scammer. Or someone could break into their office and take it. Or they sell it and pretend it was stolen.
And when you start talking about regulation the two locksmiths will say the best way to do it is ban lockpicking tools so they can keep them away from other less ethical people, or ban other locksmiths coming from the next town over.
But giving you the benefit of the doubt, what's the crime for actually breaking into a car that was left unlocked and taking things?
ETA: and furthermore, what crime is worse? And should it be?
What are you getting at? Nobody’s saying that OpenAI aren’t or shouldn’t be liable for what their agents do. What I am implying above is that this is being blown out of proportion, especially since the article I’m seeing is about a politician saying things that he thinks will poll well with the anti-AI crowd.
However, Australia is showing itself to be one of the few countries to have a backbone against big tech. Still open to investment and setting policies towards new data centres, starting to debate copyright law reform, already implemented R16 social media bans.
Truly no place I'd rather be.
"The AI agent encountered repeated blocks while seeking information from the government portal but found ways around them, ultimately gaining unauthorised access to other areas."
Your comment immediately gave more credence to OpenAI than him. I don't agree that's appropriate because OpenAI has a vested interest in that narrative and I attempted to challenge it in a way that doesn't default to OpenAI. The article in question is not from a publication I trust to be able to handle the technical details in a way that will resonate with their average audience.
That is what I'm getting at.
While in the OAI case we can easily treat it as a law enforcement action. When Iran does it? What are you going to do start a war?
The forest in this analog is the internet. As you well know it is filled with threat actors that don't give two shits about your laws. You have been warned. It's your fault when you get burned and have exactly zero recourse.
Tying Sam to a post, calling him a witch, and burning some wood in the general vicinity for what OAI has pulled is a legitimate action.
The thing is this has zero effective power in stopping this ball that is all ready rolling. It's like the first time a buffer overflow was discovered and used illegally. If that person had been caught and been put in a meat grinder it has had zero effect on the exploits of future buffer overflows. A huge number of people mad at OAI (rightfully so, I want to be sure you understand that) think this will have any preventative effect for what is coming. It will not. A new era of risk is here. Worse if you just watched the the great orange idiot he's yelling full steam ahead, so expect very little to no action by the US government on this.
Every nation on earth?
After the model itself is made, then you're talking about thousands and thousands of different companies around the world.
[deleted]
https://www.smh.com.au/politics/federal/openai-breaches-medi...
https://www.cbc.ca/news/canada/nova-scotia/teen-accused-foi-...
https://www.theregister.com/security/2018/05/07/hacking-char...
https://globalnews.ca/news/7590375/ns-foipop-website-back-on...
I believe it's safe to call it "non public" if the agents needed to "guess the file names" [1] How is it different from, say, guessing a password?
[1] https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...
I would argue that the web server's reply counts as a communication. The argument "but we didn't intend to grant access" goes so far, because what other information do I base myself on to guess that you didn't?
Roughly speaking, that is. Because, despite the fact that this would appear to be a straightforward uncontested and literal communication logged and timestamped by both sides and their respective server and user agents; lawyers somehow fall back to analogies instead.
It is, however, a glowing beacon of an example of law being designed to maintain the status quo and/or protect companies at the expense of individuals.
As someone else said, welcome to late stage capitalism.
Essentially the emergent properties of extended concentration of power and wealth.
Also, capitalism is the only one that puts power with the government and money in the hands of a market, which means it's one of the only systems that that definition doesn't apply to.
We still after the 2nd press conference on this by our defense minister are not clear on exactly what happened but thats my best laymen understanding so far.
I thought this was like the last one where a private third party company misused it.
If it was OpenAI at the wheel then they're 100% responsible for how it was used. Mea Culpa.
But imo the real levers are all rates of these things. Like what is the rate of innovations compared to the rate of regulations - assuming they are even stifling for the most part, which they are not.
Clearly the rate of autos expectations is too low, and obviously copyright law, despite being really clear, hasn't stopped every AI lab from mass piracy - a ask for forgiveness sort of situation, and also, I don't think one idiosyncratic judge in California is the authoritative judgment on fair use. To me the most important levers for freedom and progress are probably the interest rate and the years of exclusivity pharmaceutical patents get.
Continuing with your metaphor - sure get more security - you likely can never eliminate a threat. But if the bad actors are reigned in at a systemic level, you can get away with a lock on your window instead of steel bars.
I'm of a view that in a society we are better off when we all can get away with lighter individual protections as otherwise, thos who cannot afford the necessary security end up suffering.
https://www.theguardian.com/technology/2026/sep/24/openai-ag...
> At a press conference in Sydney, Marles said the incident itself was “relatively minor” and that it appeared no personal health information had been accessed.
And yes, pretty much every nation on earth has both money and sovereignty, all the need to do is look for the lab willing to sell the services.
Assume that an attacker generates a random credit number and attempts to make a purchase online. VISA honours the number and processes the payment. Is the attacker not guilty because VISA's server didn't return a 403 Forbidden (or 401)?
When you download a file from a public S3 bucket, for example, you get a signed URL that expires after a certain date. If someone guesses the signature and downloads the file, are they not guilty because the web server did not return a 200?
If someone guesses your password and reads your mail, is it ok because the IMAP server did not return an error?
I agree that if you deliberately provide false credentials to the server, then the server was misled, and you probably knew you were misleading it, and you probably also know that that 200 OK is not really earned. So Mens Rea cuts against you.
On the other hand, what if you're just coming in blind, asking about URLs in general?
That's actually pretty typical these days where 'your'[1] view of the world at some point in time might be constrained to that HTTP traffic alone.
Accidents notwithstanding, you can't really blame me for believing what I'm told, at least.
"May I GET this, or this, or that?" -> "200 OK" ... it'd be a bit weird to get the cops after me, months later, after I've probably already even forgotten I ever did that wget or curl.
[1] via software/user agent/llm agent/all three
Sending get requests and having a server respond with a document is just how the internet works. If - big if - that is what happened, then someone is going to have to explain why those supposedly private documents were available to anyone who asked using a protocol designed to distribute documents publicly. Enumerating urls isn’t typically regarded as outright illegal.