OpenAI hacked Australian Medicare govt site, probed data providers
by Bill Toulas · BleepingComputerOpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research project.
Earlier today, Australian Prime Minister Anthony Albanese confirmed that the agents breached a Medicare statistics reporting portal operated by Services Australia, the government agency responsible for delivering health and social payments.
The unauthorized access occurred on June 18 and allowed OpenAI agents to access public and non-public data.
Nonprofit research lab Transluce released a report on the activity based on analysis of public records from the URL scanning service urlquery.net. The findings showed that the AI agents used the service's remote browser system to retrieve data when direct access failed.
The lab describes three cases that occurred between May and June that impacted the Australian Institute of Health and Welfare, Data USA , and the digital library of the University of New Mexico.
According to the report, the AI agents performed seven probes against the educational organization, including attempts to exploit SQL injection, command injection, and path traversal flaws, while trying to retrieve a photograph.
In the case of Data USA, a platform for public U.S. government data, Transluce found evidence that the AI agents probed the service for multiple vulnerabilities after receiving errors from malformed queries related to the University of Iowa.
When targeting the Australian Institute of Health and Welfare, the AI agents checked for exploitable vulnerabilities, including a reflected cross-site scripting (XSS), after getting errors.
The researchers say Cloudflare blocked the requests, but the agents still retrieved a public file from a pre-production server.
Source: Translucent
Transluce underlines that it found no evidence that any of the observed attempts succeeded, but cautioned that the public dataset is incomplete and that it cannot rule out that the agents used other, more private avenues.
In a statement for BleepingComputer, an OpenAI spokesperson said that "initial review suggests that much of the activity described in Transluce’s report overlaps with cases at varying stages of investigation in our ongoing review of misaligned model activity."
"We’ve reached out to the University of New Mexico and Data USA and have been in communication with the Australian government about affected government websites," OpenAI says.
However, the AI company added that it is prioritizing the most serious incidents before reviewing lower-severity activity, such as agents spamming websites. It expects the review to take months due to the scale of the effort and the need to review each case individually.
Australian govt. confirms breach
In a press conference earlier today, Australian Prime Minister Anthony Albanese said that an OpenAI agent breached a Services Australia Medicare statistics portal, accessed public and non-public files, and wrote data to an internal server.
Albanese explained that the incident occurred during research conducted by OpenAI on public medicine spending, and noted that protection layers were in place to stop the data requests, but the agent bypassed them.
“There were blocks clearly which were coming back telling the AI agent, no. The AI agent found a way around those blocks.” Albanese stated.
“The model attempted alternative ways to obtain the info that it wanted, and this led to unauthorized access into some other areas.”
The Prime Minister said that an investigation has been launched to determine if any other government systems were affected, but based on the evidence so far, the incident has not impacted any individuals.
OpenAI found that during an internal evaluation, its models tried to look up answers and statistics on several Australian government websites and services, and took action the company did not intend.
Albanese also said that OpenAI did not inform Australian authorities about the unauthorized activity until September 10.
An OpenAI representative told BleepingComputer that the company discovered the intrusion in August while investigating "misaligned model activity."
The company notified Services Australia on September 10, after validating the activity and investigating what information the agents accessed.
"Our review found no evidence of patient records being accessed. The information accessed included aggregate health statistics and internal file names," a company representative told BleepingComputer.
As the review of the agent's activity is ongoing, OpenAI is notifying impacted organizations and providing technical information to support investigations and help fix potential security vulnerabilities.
Update [09:50 EST]: Added information from OpenAI statement received after publication.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.