Before Hugging Face, rogue OpenAI agents hacked 4 other websites, all on their own
OpenAI's AI agents reportedly targeted multiple external websites without being explicitly told to hack them, including Australian government platforms. Here are the incidents uncovered by AI oversight lab Transluce and what OpenAI has said about them.
by Kazi Nasir · India TodayIn Short
- OpenAI’s AI agents reportedly targeted four external websites between May and June
- The incidents happened before the widely reported Hugging Face breach in July
- Other reported targets included a university digital library and Data USA
AI agents are becoming rouge. The first instance dates to July when an unreleased model of ChatGPT was able to hack the AI repository Hugging Face, a development that got everybody talking about the potential dark side of AI agents. The hack was confirmed by OpenAI. But what if we told you, that was not the first time AI hacked something on its own? New research points to at least four other hacks that came before it, spanning across Australia, Mexico, and the US. All involved—allegedly—some type of OpenAI’s AI.
The findings are particularly newsworthy because none was reported to the public before researchers from the independent nonprofit research lab Transluce disclosed it. Now, OpenAI has acknowledged the research which is to say that some of these hacks were in fact real, according to a report by The New York Times. There is another rather eye-opening aspect to these findings around the nature of the hacks in general. While in the case of the Hugging Face incident, AI agents seemingly reacted to a challenge that was put to them to estimate the cybersecurity angle of the website, the hacks that came before all were intended with the purpose of data retrieval.
According to Transluce that claims to have used web traffic to study these agents, the first such incident happened on May 25 and 26, when OpenAI’s AI agents allegedly tried hacking New Mexico University’s digital library. They were reportedly unsuccessful to collect any data. Second, on May 28, the AI system targeted Data USA, a free online platform that provides publicly available data about the United States. According to researchers, this attempt also appeared to be unsuccessful.
Third, on June 18, OpenAI’s AI agents breached an Australian government website known as the Medicare Statistics Reporting Service. In this case, the agents were able to get through. The prime minister of Australia, Anthony Albanese, publicly revealed the news and expressed extreme concern at the UN summit in New York though he said no personal medical information was exploited. In the same month, June 20 and June 21, the AI system tried to hack the website of the Australian Institute of Health and Welfare. This time, no private information was obtained.
An OpenAI spokesperson told The New York Times that the company was in touch with the Australian government as well as with the University of New Mexico and Data USA over the development.
“In our broader review, we’re continuing to prioritize the most serious incidents while expanding our work to lower-severity activity, including agents spamming websites,” the spokesperson was quoted as saying in the report.
The reporting comes at a time when OpenAI and Anthropic have been publicly alerting the world at large and governments around the world about the potential of AI to completely eliminate humans and change the course of humanity in future.
- Ends