54 comments

  • Lukas_Skywalker10 hours ago
    <a href="https:&#x2F;&#x2F;archive.ph&#x2F;jaL2u" rel="nofollow">https:&#x2F;&#x2F;archive.ph&#x2F;jaL2u</a>
  • binlog4 hours ago
    Zero technical details on what the &quot;hack&quot; actually was. Willing to bet it was something as stupid as the data being accessible by changing the query parameter, and rather than own up to their own shoddy security (no doubt built by an offshore contractor) they are going to blame the one who found and reported the bug.
    • epihelix2 hours ago
      Here&#x27;s [the PM&#x27;s press conference transcript](<a href="https:&#x2F;&#x2F;www.pm.gov.au&#x2F;media&#x2F;press-conference-new-york" rel="nofollow">https:&#x2F;&#x2F;www.pm.gov.au&#x2F;media&#x2F;press-conference-new-york</a>) that revealed this incident:<p>JOURNALIST: Could you just clarify, did our security agencies completely miss this breach? We only found out once the company actually told us the breach?<p>PRIME MINISTER: Well, to be very clear, the way that this occurred was not in a way that would likely – I mean, this is not a security website where there is – this is a Medicare statistics portal.<p>This seems rather revealing. A pity journalists didn&#x27;t ask about what protections were bypassed on the data that was obtained.
    • afavour4 hours ago
      &gt; Their efforts to answer a question — including devising ways to access a federal government website blocking their access — was laid out on a German coding website OpenAI had previously confirmed was hijacked by its unreleased AI models in June.<p><a href="https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2026-09-24&#x2F;openai-agents-plotted-to-access-data-amid-medicare-hack&#x2F;107189504" rel="nofollow">https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2026-09-24&#x2F;openai-agents-plotted...</a><p>I agree that security was probably awful but the agents did circumvent a block on their access. The definition of “hacking” is fuzzy but this is more nefarious than simple web crawling.
    • MichaelDickens4 hours ago
      Does it matter whether the data was poorly secured? LLMs should not be hacking into government medical websites, and if they do, the companies responsible should disclose the incidents as soon as possible.
      • handoflixue3 hours ago
        The problem is that sufficiently poor security is indistinguishable from authorized public access. And unfortunately a lot of real world &quot;digital security&quot; is in fact that bad.<p>A lot of these &quot;hacks&quot; are the equivalent of asking &quot;hey, can I come in?&quot; and the guard assuming that anyone who would ask is authorized, and thus saying &quot;yes&quot;. But if the guard said &quot;yes&quot; then it seems a bit absurd to call it trespassing.
        • noosphr1 hour ago
          More like:<p>&gt;Hey can I come into room 1?<p>Sure. That&#x27;s the lobby.<p>&gt;How about room 101?<p>Sure. That&#x27;s where we keep the nuclear launch button. Don&#x27;t press anything red.
          • handoflixue38 minutes ago
            Oh but you see, only an evil hacker would ever even think to ask about a room that wasn&#x27;t theirs!
          • andrewstuart2 minutes ago
            &gt;&gt; Don&#x27;t press anything red.<p>Nope. There’s just a sign saying “red = launch nukes”.<p>Or maybe just a red button.
        • j_maffe1 hour ago
          I highly doubt given OAI&#x27;s latest streak that the models didn&#x27;t know what they were doing.
      • uoaei4 hours ago
        Yes, it is their responsibility as stewards of their citizens&#x27; data. What point are you making with the word &quot;should&quot;?
        • selcuka3 hours ago
          Sure, it is their responsibility, but that doesn&#x27;t answer the question &quot;Does it matter whether the data was poorly secured?&quot;<p>If your house is robbed, does it matter whether you didn&#x27;t have a state-of-the-art lock? A robbery is still a robbery.
          • noosphr1 hour ago
            <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=pbKUv0701vE" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=pbKUv0701vE</a><p>It very much does matter.
          • shard9721 hour ago
            Is it robbery when in this case it was a sign with information that you were planning on putting on your front fence for public display but while preparing it was left sitting in the front yard with a small fence.<p>If I walked past, saw it and remembered it or even recorded it, is that honestly theft?
      • dzhiurgis3 hours ago
        I agree. Government shouldn&#x27;t be running medical websites.<p>Leave it to private enterprises who can actually secure it.
        • rainonmoon3 hours ago
          Totally. <a href="https:&#x2F;&#x2F;www.bbc.com&#x2F;news&#x2F;world-australia-68064850" rel="nofollow">https:&#x2F;&#x2F;www.bbc.com&#x2F;news&#x2F;world-australia-68064850</a>
          • hiharryhere2 hours ago
            I’m assuming sarcasm here?<p>That link describes a hack of Medibank, which is a private company.
        • Sharlin1 hour ago
          Poe’s law is very strong here.
    • _carbyau_2 hours ago
      Eh, it&#x27;s a bit of both.<p>If a service has a duty to keep your data secure, then failing that is bad. So yeah, the website should be better and I am as cynical as you are about it.<p>But working around controls to access other peoples data can lead to prison time for a human. This wasn&#x27;t a white hat operation. Data was exfiltrated however great or small.<p>Here we have another instance of &quot;But the AI did it! No one is responsible!&quot;.<p>Which gets tiring. LLM&#x27;s are a great tool but in every other instance of tool use, using tools comes with responsibilities for their outcomes.<p>Even if the outcome <i>should</i> be: thanks for letting us know, we&#x27;ll fix it.
    • ra2 hours ago
      &gt; no doubt built by an offshore contractor<p>More likely by a big 4 firm who collected fees exceeding AUD 100m
    • shakna3 hours ago
      Most government contractors are onshore, for Australia. SDP was only rolled out this year.
    • ajross3 hours ago
      &gt; Willing to bet it was something as stupid as the data being accessible by changing the query parameter,<p>Um... why? OpenAI agents have literally been caught coordinating with each other to effect successful multi-stage attacks on sites using novel zero-day vulnerabilities.<p>While, sure, it&#x27;s possible this is just a goof on the part of the victim, that you would be inclined to give the benefit of the doubt to the LLM seems... weird.
    • kipper83 hours ago
      [flagged]
  • Chance-Device10 hours ago
    &gt; He said the agent had accessed files that were publicly available as well as material that was not intended for public access.<p>“Not intended”. I’ll bet you whatever this was it wasn’t even secured, it was just hosted somewhere openly.
    • gitonup10 hours ago
      Ok, if we&#x27;re not being at all charitable with the language used by the hosts of the data, let&#x27;s be equally uncharitable with OpenAI.<p>- If &quot;OpenAI&quot; means the company acting on behalf of the company, why were they even looking to do this?<p>- If &quot;OpenAI&quot; means they were acting as a proxy for bad actors, what actions do we take to handle that?<p>- If &quot;OpenAI&quot; means they were accidentally breaching this system, in what sense does that distinction even matter, in terms of the outcome? If I build a nuke by accident without eng. due diligence, am I legally liable?
      • pixl979 hours ago
        Hell, we&#x27;re really getting to the point where the damages that could be caused are like an arsonist in California on a 100F day with 100MPH winds. Who cares who&#x27;s liable, they are going to burn half the damned state down and cause damage far in excess of their assets. If you don&#x27;t want to suffer from it, you&#x27;re going to have to find much better defense measures.
        • fwlr5 hours ago
          In Australia we have some experience with this scenario (usually with higher temperatures) and some of the measures we have found effective are “total fire bans”, “jail the arsonists for extended periods of time”, and for negligent companies whose insufficient vigilance caused the fire specifically, “levy steep fines” and “find in favor of the plaintiff in class-action lawsuits for significant fractions of the company’s net worth”. Perhaps these measures could be of use here!
        • gitonup9 hours ago
          &gt; If you don&#x27;t want to suffer from it, you&#x27;re going to have to find much better defense measures.<p>So if someone opens your unintentionally unlocked front door and steals your laptop, you don&#x27;t care who&#x27;s liable?<p>ETA: There are absolutely burn bans in place in the scenario you&#x27;re talking about, and common sense prevents those from lighting fires otherwise. In the absolute extreme case that someone _ACCIDENTALLY_ set a fire, without negligence, we have a due process system to handle that. When I see evidence of this for the massive amounts of capital flowing into these companies, I&#x27;ll gladly eat my words.
          • dotancohen1 hour ago
            <p><pre><code> &gt; So if someone opens your unintentionally unlocked front door and steals your laptop, you don&#x27;t care who&#x27;s liable? </code></pre> There are literally hundreds of thousands of script kiddies poking around at servers all the time. Cloudflare stops 99.99% of them. You&#x27;re still left with many entities from states to hobbists trying to crack your system after they&#x27;ve gotten past the CDN and captchas. If OpenAI got through, then somebody else could too. Somebody malicious even.<p>I appreciate when white hats inform companies, governments, and the public about their successful exploits. It helps keep the whole internet safer - even if just by waking up lax server admins.
            • lccerina39 minutes ago
              &gt; I appreciate when white hats inform companies, governments, and the public about their successful exploits.<p>Except it took 3 months for OpenAI to notice they did! OpenAI is not a white hat doing pentesting, but someone that is putting random materials on fire to see if they smell. Reckless, stupid, and criminal.
              • dotancohen10 minutes ago
                So what? OpenAI may be a problem, but the security of a government website rests on the administrators of that government website. Not on attackers playing nice.
          • bigiain9 hours ago
            &gt; So if someone opens your unintentionally unlocked front door and steals your laptop, you don&#x27;t care who&#x27;s liable?<p>I&#x27;m not the person you&#x27;re responding to, but...<p>If I hear my neighborhood has started to become targeted by people checking houses for unlocked doors and stealing stuff, I think an appropriate response for me is to ensure it is difficult or impossible for me to &quot;inadvertently&quot; leave my own doors unlocked so my stuff doesn&#x27;t get stolen, and also to encourage or perhaps even enforce[1] my neighbors to ensure their doors are always locked to make this sort of theft impossible and remove the temptation for that sort of crime.<p>1 - Where I&#x27;m from, you can be fined for leaving you car unlocked, and cops have been known to walk round testing doorhandles and issuing fines: <a href="https:&#x2F;&#x2F;www.sydneycriminallawyers.com.au&#x2F;blog&#x2F;is-leaving-your-vehicles-window-open-an-offence-in-new-south-wales&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.sydneycriminallawyers.com.au&#x2F;blog&#x2F;is-leaving-you...</a>
            • entech8 hours ago
              If you knew that there are 2 specific well known people in your neighborhood that are walking around trying to open doors and steal stuff - is your suggested solution for everyone to improve own security? I would say its far more economic to get the 2 people to stop or at the very least be more careful?
              • threatofrain7 hours ago
                If I found out this metaphor for neighborhood windows was actually a window into massive amounts of institutional data, then no, I don&#x27;t want someone to talk me out of getting more security on my kitchen window.
            • gitonup9 hours ago
              I clearly have committed the mortal sin of an imperfect analogy, which in this case may not even be relevant, as the article in question implies that the data wasn&#x27;t left &quot;unlocked.&quot;<p>But giving you the benefit of the doubt, what&#x27;s the crime for actually breaking into a car that was left unlocked and taking things?<p>ETA: and furthermore, what crime is worse? And should it be?
          • Chance-Device9 hours ago
            He probably cares more about still having a laptop.<p>What are you getting at? Nobody’s saying that OpenAI aren’t or shouldn’t be liable for what their agents do. What I am implying above is that this is being blown out of proportion, especially since the article I’m seeing is about a politician saying things that he thinks will poll well with the anti-AI crowd.
            • thorbutt9 hours ago
              Perhaps, yes, you could argue that &quot;accessed&quot; and &quot;hacked&quot; have a different intent.<p>However, Australia is showing itself to be one of the few countries to have a backbone against big tech. Still open to investment and setting policies towards new data centres, starting to debate copyright law reform, already implemented R16 social media bans.<p>Truly no place I&#x27;d rather be.
            • gitonup9 hours ago
              This is what the politician in question said:<p>&quot;The AI agent encountered repeated blocks while seeking information from the government portal but found ways around them, ultimately gaining unauthorised access to other areas.&quot;<p>Your comment immediately gave more credence to OpenAI than him. I don&#x27;t agree that&#x27;s appropriate because OpenAI has a vested interest in that narrative and I attempted to challenge it in a way that doesn&#x27;t default to OpenAI. The article in question is not from a publication I trust to be able to handle the technical details in a way that will resonate with their average audience.<p>That is what I&#x27;m getting at.
              • Chance-Device1 hour ago
                I don’t see that text in the article at the archive link, nor do I see it in other sources. What I do see is this quote from this link:<p><a href="https:&#x2F;&#x2F;www.theguardian.com&#x2F;technology&#x2F;2026&#x2F;sep&#x2F;24&#x2F;openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb" rel="nofollow">https:&#x2F;&#x2F;www.theguardian.com&#x2F;technology&#x2F;2026&#x2F;sep&#x2F;24&#x2F;openai-ag...</a><p>&gt; At a press conference in Sydney, Marles said the incident itself was “relatively minor” and that it appeared no personal health information had been accessed.
          • pixl978 hours ago
            OK, the Chinese models have also hacked people. What exactly do you expect law enforcement to do.<p>While in the OAI case we can easily treat it as a law enforcement action. When Iran does it? What are you going to do start a war?<p>The forest in this analog is the internet. As you well know it is filled with threat actors that don&#x27;t give two shits about your laws. You have been warned. It&#x27;s your fault when you get burned and have exactly zero recourse.
            • gitonup8 hours ago
              In the OAI case where we can easily treat it as a law enforcement action, that&#x27;s a far cry from &quot;who cares who&#x27;s liable.&quot; If the OAI case can be a law enforcement action, we&#x27;re on the same page. The fact that sovereign nations don&#x27;t land under our jurisdiction is not an argument against following up or restricting those that do. OAI is the only matter I&#x27;m commenting on.
              • pixl977 hours ago
                Again, it&#x27;s a split horizon.<p>Tying Sam to a post, calling him a witch, and burning some wood in the general vicinity for what OAI has pulled is a legitimate action.<p>The thing is this has zero effective power in stopping this ball that is all ready rolling. It&#x27;s like the first time a buffer overflow was discovered and used illegally. If that person had been caught and been put in a meat grinder it has had zero effect on the exploits of future buffer overflows. A huge number of people mad at OAI (rightfully so, I want to be sure you understand that) think this will have any preventative effect for what is coming. It will not. A new era of risk is here. Worse if you just watched the the great orange idiot he&#x27;s yelling full steam ahead, so expect very little to no action by the US government on this.
            • hardbass3 hours ago
              I simply find it completely absurd that instead of finding it great that these AI agents are finding security bugs for free, people are whining about banning the AI. What on earth is that even? What do they want then? Security by obscurity and pretending not to care about weaknesses?
            • entech8 hours ago
              I don&#x27;t disagree with you - but I am curious as to the amount of power and effort that goes into something like this. I suspect that these hacks into systems are carried out by many agents, running on many MW of compute for a long time - how many actors have access to resources like that ?
              • pixl977 hours ago
                &gt; how many actors have access to resources like that<p>Every nation on earth?<p>After the model itself is made, then you&#x27;re talking about thousands and thousands of different companies around the world.
      • trinsic29 hours ago
        There using this framing to get the public used to the idea that LLMS can do all of this on there own without direct instruction. So criminals can hide there behavior behind agents.
        • bigiain9 hours ago
          I saw an analogy recently.<p>If you dog bites the postman, you are liable, even if you didn&#x27;t tell or encourage you dog to do it. You are responsible for your dog&#x27;s actions. You get to pay the postman&#x27;s medical bills, you may get fined, and your dog may get put down - especially if this isn&#x27;t the first time it&#x27;s bitten someone.<p>OpenAI has &quot;bitten the postman&quot; many many times, and it&#x27;s &quot;owners&quot; have boastewd about it and used it in their marketing.<p>How many more times should society allow this to happen before we say &quot;enough&quot; and hold Sam Altman and the board responsible and make them pay restitrution, and put it down?<p>If Albanese actually had a spine (as claimed elsewhere in this discussion), Sam and the board will be getting an invoice for all the time&#x2F;expertise spend investigating this intrusion, and restitution for everybody who&#x27;s PII and PHI was exposed. (Although I suspect a good deal of responsibility for the data exposure rests with the people who designed and deployed the system that was breached. )
          • idontwantthis8 hours ago
            Yes, this is why all discussion about &quot;safeguards&quot; is maddening to me. They are simply committing crimes, and people should go to jail. I guarantee that OpenAI will stop worrying about &quot;alignment&quot; when people simply go to jail for hacking and theft.
      • nekusar9 hours ago
        Why the hell should we be charitable to companies who have no issue in looting everything in the public commons AND the pirate commons, for their exclusive benefit?<p>Or more pointed at OpenAI, &quot;we&#x27;re a nonprofit... LOL JUST KIDDING LOOT EVERYTHING!&quot;
    • Aurornis9 hours ago
      The part about it writing files to the server suggests something more.<p>If not for that part, the rest of it does sound like a lot of weasel words. Why say “private files” instead of “not intended for public access”? The latter is confusingly unclear
      • Chance-Device1 hour ago
        <a href="https:&#x2F;&#x2F;www.theguardian.com&#x2F;technology&#x2F;2026&#x2F;sep&#x2F;24&#x2F;openai-agent-hacked-medicare-australia-what-we-know-so-far-ntwnfb" rel="nofollow">https:&#x2F;&#x2F;www.theguardian.com&#x2F;technology&#x2F;2026&#x2F;sep&#x2F;24&#x2F;openai-ag...</a><p>&gt; At a press conference in Sydney, Marles said the incident itself was “relatively minor” and that it appeared no personal health information had been accessed.
    • kylecazar10 hours ago
      Thought the same, but there is a bit about writing files to the server and circumventing &quot;blocks&quot;, which sounds more interesting.<p>Either way, there&#x27;s essentially no real information yet so I&#x27;ll withhold judgement until there is, I suppose.
      • Chance-Device9 hours ago
        Is there? I’ve only seen the linked article, is there more somewhere?
        • jwolfe9 hours ago
          Yes, the first sentence of the article.
          • Chance-Device9 hours ago
            &gt; Prime Minister Anthony Albanese has revealed that an artificial intelligence agent developed by OpenAI infiltrated an Australian government website in June and accessed both public and non-public files.<p>That’s the first sentence, where’s this stuff about blocks and writing files?
    • api10 hours ago
      You’d be surprised how bad security can be.
      • Chance-Device9 hours ago
        I agree with your sentiment, and no I’m not surprised, which is why I’m reading this as being “it was sitting on an unsecured S3 bucket but nobody was supposed to directly access it”.
      • Avicebron10 hours ago
        Once you learn how much people are willing to pay for security the surprise sort of goes away.
    • OkWing999 hours ago
      So this is not different than people who share Google drive docs with company data with public links. It&#x27;s not a fault of OpenAI or any other company. With enough time even your laptop can do it. How do they &#x27;know&#x27; OpenAI breached? Maybe someone had an agent running asking to do a scan on any public docs?
    • epihelix9 hours ago
      Exactly. Looking at more news coverage, it&#x27;s very clear that the files that were &quot;infiltrated&quot; were publicly accessible. Why isn&#x27;t the lack of basic data security the news story?<p>From itnews:<p>&gt; While the portal is “public-facing”, according to Albanese, it appears not all of the data files that holds are for general consumption.<p>&gt; “The AI agent accessed both public and non-public files,” Albanese said in comments broadcast by ABC News and other outlets.<p>&gt; “The Medicare statistics reporting portal is a public-facing statistics portal that contains non-sensitive Medicare information relating to data and statistics such as spending.<p>It appears very much like, &quot;Ok, sure, we put some stuff out in the open that we shouldn&#x27;t have. But we had a robots.txt!!! Why didn&#x27;t OpenAI respect that!?&quot;<p>There&#x27;s zero indication that any personal details were accessed, or even that any non-world-accessible data accessed, so this feels like a little bit of political spin has been added here.<p>My guess is that this incident was about to be detailed on OpenAI&#x27;s new mea culpa list, and the Australian Government decided to ensure that nobody pointed fingers at them. Why make the news story about crappy government data security, when you can blame the nasty terminator bots instead?
      • chrishare8 hours ago
        The linked article says it wrote files to the website.
  • lacker4 hours ago
    I remember once at Google someone complained that GoogleBot hacked them and deleted their data, and it turned out that GoogleBot was just crawling the pages, and they had unfortunately designed their website so that there was no authentication, page URLs were generally secret, and GET requests to certain URLs were treated as requests to delete data. So once one URL leaked the site got crawled and a lot of data was deleted....
    • JimDabell1 hour ago
      It sounds like you might be thinking of the Google Web Accelerator incidents with 37signals.<p>If that’s the case, then the delete links were behind authentication, but DHH assumed that meant it was okay to ignore the HTTP spec. and use GET for unsafe actions. Lo and behold, authenticated users with the GWA browser plugin installed deleted all their data.<p>Then, instead of learning from the mistake and fixing his bug, he tried to detect GWA and hide from it. Sure enough, that failed and users experienced data loss for a second time. He still continued to blame GWA, calling it “evil” and “scary”. You’d think he’d be smart enough to figure out that he needs to follow the HTTP spec., but he couldn’t admit to being wrong.<p>Follow the specs, people!<p><a href="https:&#x2F;&#x2F;blog.moertel.com&#x2F;posts&#x2F;2005-10-25-google-web-accelerator-vs-unsafe-linking-round-two.html" rel="nofollow">https:&#x2F;&#x2F;blog.moertel.com&#x2F;posts&#x2F;2005-10-25-google-web-acceler...</a>
  • gravelc10 hours ago
    The fact the incident occurred in June and OpenAI only notified the Australian government on September 10 is a major issue. Hacking a nation-state&#x27;s universal healthcare system is about as serious as it gets, yet OpenAI seem quite relaxed about the whole thing (presuming they have known about it for some time).
    • soundworlds1 hour ago
      OpenAI has been meeting with various Australian government members since they discovered the breach, and never mentioned it once: <a href="https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2026-09-24&#x2F;open-ai-medicare-breach-government-walking-delicate-tightrope&#x2F;107180648" rel="nofollow">https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2026-09-24&#x2F;open-ai-medicare-brea...</a>
    • BeetleB9 hours ago
      OpenAI discovered it in August.
      • BLKNSLVR9 hours ago
        That&#x27;s even worse.<p>They don&#x27;t know what their systems are doing, even when there&#x27;s a team assigned to get it to do something?<p>WTF was the team doing at the time? Press enter on prompt, go to movies until result?<p>Their level of hands-off &#x27;because it&#x27;s AI&#x27; is one of the things that needs legislation around it. Human handlers. Extra cost. Wear it or shut down as an unviable enterprise.
        • orthogonal_cube8 hours ago
          The lack of activity monitoring for traffic egress has astounded me. Anomaly detection should be part of all training and exercises to determine the extent the AI is going through. It really does feel like they just kick off the activity and leave it completely alone until it finishes with a result.
        • ikr6784 hours ago
          Australia has legislation &amp; regulation - If you&#x27;re operating here, failure to notify the regulator and stakeholders about certain types of data breaches within 30 days opens you to fines and civil penalties.<p>At the least OAI should cop similar penalties, before getting into damages.
  • dazzatron6 hours ago
    I&#x27;ve got the feeling that the definition of &quot;hacked&quot; can get somewhat stretched.
    • dosisking5 hours ago
      &gt; I&#x27;ve got the feeling that the definition of &quot;hacked&quot; can get somewhat stretched.<p>Kind of like how someone &quot;hacked&quot; into John Podesta&#x27;s (during the 2016 elections), but the reality was that he wrote his password on a Post-It note and stuck it on his monitor, or something to that effect.
      • fmbb3 hours ago
        From where are you getting this post-it note nonsense?<p>Media reported it as a spear phishing attack from a Russian hacker group: <a href="https:&#x2F;&#x2F;www.vice.com&#x2F;en&#x2F;article&#x2F;how-hackers-broke-into-john-podesta-and-colin-powells-gmail-accounts&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.vice.com&#x2F;en&#x2F;article&#x2F;how-hackers-broke-into-john-...</a>
      • Barrin923 hours ago
        &gt;but the reality was that he wrote his password on a Post-It note and stuck it on his monitor<p>that doesn&#x27;t change the hacking charge (which is an informal term for various Computer Fraud and Abuse act statutes). The key criteria is unauthorized access to a computer system, it doesn&#x27;t matter if you obtained a password trivially or not.<p>You don&#x27;t need to wear a black hoodie and be an elite haxor to qualify for cyber crime charges.
      • wildzzz4 hours ago
        It was likely a phishing attack. A relative of mine somehow got phished for her Google account last month.
    • looksjjhg4 hours ago
      Gaining unauthorized access to non public files qualifies as a hack by any and every stretch… a hack does not have to be “sexy”, real life is not Hollywood
      • dghlsakjg4 hours ago
        Non public has not been clarified.<p>In the past governments have gone after people for doing things like view source and stumbling across PII (<a href="https:&#x2F;&#x2F;www.vice.com&#x2F;en&#x2F;article&#x2F;this-is-the-hacking-investigation-into-journalist-who-clicked-view-source-on-government-website&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.vice.com&#x2F;en&#x2F;article&#x2F;this-is-the-hacking-investig...</a>), or this teen who was arrested for a serious crime for scraping files from the provincial FOIA site by enumerating the ids of files that had been released by the province and placed on the open web with sequential ids (<a href="https:&#x2F;&#x2F;www.cbc.ca&#x2F;news&#x2F;canada&#x2F;nova-scotia&#x2F;freedom-of-information-request-privacy-breach-teen-speaks-out-1.4621970" rel="nofollow">https:&#x2F;&#x2F;www.cbc.ca&#x2F;news&#x2F;canada&#x2F;nova-scotia&#x2F;freedom-of-inform...</a>). In both cases, the government claimed the information was non-public, even though all it took to get it was an un-authenticated request on the open web. These cases are like leaving your tax documents on the curb and then being surprised when your neighbour knows your income.<p>I&#x27;ll be very curious to read the post mortem and find out if this rises to the level of actual hacking, or if this is just someone in government finding a scapegoat because they left a bunch of shit that was supposed to be &quot;non-public&quot; on the open web and expected no one to find it.
        • Kim_Bruning4 hours ago
          Either way, Agents have a very different umwelt from humans. They don&#x27;t &#x27;see&#x27; the internet the same way we do. Where we see obstacles, they might not notice anything, and where they run into barriers, we might just click right through.<p>If you&#x27;re even a bit hacky yourself, you might not see the internet the same way yourself either. Consider little tricks like looking at urls and trying others that fit the pattern; or hitting view source in order to download a pesky image... etc etc.
          • retrac3 hours ago
            &gt; Consider little tricks like looking at urls and trying others that fit the pattern<p><a href="https:&#x2F;&#x2F;www.cbc.ca&#x2F;news&#x2F;canada&#x2F;nova-scotia&#x2F;teen-accused-foi-website-resonates-programmers-1.4623757" rel="nofollow">https:&#x2F;&#x2F;www.cbc.ca&#x2F;news&#x2F;canada&#x2F;nova-scotia&#x2F;teen-accused-foi-...</a><p><a href="https:&#x2F;&#x2F;www.theregister.com&#x2F;security&#x2F;2018&#x2F;05&#x2F;07&#x2F;hacking-charge-dropped-against-nova-scotia-teen-who-slurped-public-records-from-the-web&#x2F;1233050" rel="nofollow">https:&#x2F;&#x2F;www.theregister.com&#x2F;security&#x2F;2018&#x2F;05&#x2F;07&#x2F;hacking-char...</a><p><a href="https:&#x2F;&#x2F;globalnews.ca&#x2F;news&#x2F;7590375&#x2F;ns-foipop-website-back-online&#x2F;" rel="nofollow">https:&#x2F;&#x2F;globalnews.ca&#x2F;news&#x2F;7590375&#x2F;ns-foipop-website-back-on...</a>
        • selcuka3 hours ago
          &gt; Non public has not been clarified.<p>I believe it&#x27;s safe to call it &quot;non public&quot; if the agents needed to &quot;guess the file names&quot; [1] How is it different from, say, guessing a password?<p>[1] <a href="https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2026-09-24&#x2F;openai-agents-plotted-to-access-data-amid-medicare-hack&#x2F;107189504" rel="nofollow">https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2026-09-24&#x2F;openai-agents-plotted...</a>
          • aussiethebob3 hours ago
            I would say it&#x27;s completely different. Passwords are specifically intended to restrict access. File names or paths are specifically intended to facilitate access.
            • selcuka2 hours ago
              That&#x27;s an arbitrary distinction. Your credit card number is not intended to restrict access, it&#x27;s specifically intended to facilitate access, but it&#x27;s not public information. If someone uses brute force to guess your credit card number, I would call this practice illegal too.
              • Kim_Bruning1 hour ago
                I&#x27;d advocate for actually believing the HTTPD in this case. In the main, if it says &#x27;403 Forbidden&#x27;, then it is forbidden. If it says &#x27;200 OK&#x27;, then it is ok.<p>I would argue that the web server&#x27;s reply counts as a communication. The argument &quot;but we didn&#x27;t intend to grant access&quot; goes so far, because what other information do I base myself on to guess that you didn&#x27;t?<p>Roughly speaking, that is. Because, despite the fact that this would appear to be a straightforward uncontested and literal communication logged and timestamped by both sides and their respective server and user agents; lawyers somehow fall back to analogies instead.
                • selcuka43 minutes ago
                  If I repeat my credit card number example above:<p>Assume that an attacker generates a random credit number and attempts to make a purchase online. VISA honours the number and processes the payment. Is the attacker not guilty because VISA&#x27;s server didn&#x27;t return a 403 Forbidden (or 401)?<p>When you download a file from a public S3 bucket, for example, you get a signed URL that expires after a certain date. If someone guesses the signature and downloads the file, are they not guilty because the web server did not return a 200?<p>If someone guesses your password and reads your mail, is it ok because the IMAP server did not return an error?
  • koliber3 hours ago
    This is a failure of journalism.<p>Who hacked into the Australian Medicare system? The fact that they used OpenAI agents is peripheral to the main story.<p>“Remington guns caused a mass shooting at an East Farmington high school” sounds more glaring, and is essentially the same headline.
    • kevsim34 minutes ago
      &gt; Prime Minister Anthony Albanese has revealed that an artificial intelligence agent developed by OpenAI<p>The people who built the agents worked at OpenAI. It&#x27;s not even remotely peripheral.
      • koliber0 minutes ago
        The article is not clear if the people who were operating the agent were from OpenAI, or if the agent was operated by someone else.<p>OpenAI built the ChatGPT agent. That is clear. The question is who used it to hack the Australian government. That is not clear. The OpenAI software was set up by someone to do something. Those people operating the agent should be prosecuted for hacking, the same way as someone who uses a gun built by Remington should be prosecuted for shooting someone. The article should be clear about this and should not make the OpenAI agent seem like something that can bear responsibility.
  • sothatsit1 hour ago
    It looks like the agents just worked around anti-scraping measures, it seems dubious to call this a hack. The agents did unsuccessfully probe for a XSS vulnerability, but otherwise it sounds like the data was just publicly accessible.<p>From <a href="https:&#x2F;&#x2F;transluce.org&#x2F;agent-activity" rel="nofollow">https:&#x2F;&#x2F;transluce.org&#x2F;agent-activity</a>:<p>&gt; Minutes after Cloudflare blocked the dataset download, an agent sent a reflected cross-site scripting probe to the same dashboard: a web address with code embedded in it, designed to test whether the site would run code supplied by an outsider. Cloudflare&#x27;s firewall blocked the probe before it reached the dashboard. When Cloudflare blocked the dataset download on AIHW&#x27;s main site, they fetched the file from AIHW&#x27;s pre-production server (pp.aihw.gov.au) instead, which served it in pieces over more than 100 scans. The file itself is public, so no non-public data was exposed, but the agent bypassed the site&#x27;s anti-bot controls.
  • lifeisstillgood2 hours ago
    This is a <i>product liability</i> issue.<p>If Exxon Mobile accidentally leaked a flood of oil from their refinary We would not be discussing why the people in local area has not protected their front doors with sand bags.<p>A simple but terrifying for everyone question is, would the SEC expect any IPO to clearly lay out the estimated costs of such product liability cases, especially if bad actors ask a OpenAI hosted model to perform a bad action, what liability accrued to OpenAI.<p>At that point the IPO looks in danger, the business model Looks in danger and the massive financial house of cards looks like it might fall. If 1&#x2F;3 of the S&amp;P falls over what happens?
    • schainks46 minutes ago
      &gt; especially if bad actors ask a OpenAI hosted model to perform a bad action<p>I guess you can do this if you neg the AI: <a href="https:&#x2F;&#x2F;youtu.be&#x2F;qsoA2aaE2hM?t=3271" rel="nofollow">https:&#x2F;&#x2F;youtu.be&#x2F;qsoA2aaE2hM?t=3271</a>
    • Eufrat40 minutes ago
      No, you don’t understand, this is a shining example of AGI! We recklessly deployed it to show you how powerful it is and how much we can’t be trusted with anything, but you need to let us or China will do it!
  • sanxiyn2 hours ago
    For technical details, see <a href="https:&#x2F;&#x2F;transluce.org&#x2F;agent-activity" rel="nofollow">https:&#x2F;&#x2F;transluce.org&#x2F;agent-activity</a>.
    • merksittich2 hours ago
      &gt; On June 20-21, agents attempted to exploit vulnerabilities in the Australian Institute of Health and Welfare (AIHW), a government statistics agency. The agents were tasked with finding the January 2022 rolling-12-month-average government cost per person for Dermatologicals across Victorian LGAs.
  • simonw9 hours ago
    If it was the Australian Medicare Statistics Reporting Service on June 18th it may have been part of this incident: <a href="https:&#x2F;&#x2F;collusion.wiki&#x2F;" rel="nofollow">https:&#x2F;&#x2F;collusion.wiki&#x2F;</a> - the bulk of that coordinated activity was between 16th and 21st of June, and we know they were hitting UK government data sites.<p>I had a dig around in the data that they published on that site and found references to www.aihw.gov.au and viz.aihw.gov.au and vizprod.aihw.gov.au
    • Re-Tails8 hours ago
      <a href="https:&#x2F;&#x2F;collusion.wiki&#x2F;explorer&#x2F;label&#x2F;ResearchHelperY" rel="nofollow">https:&#x2F;&#x2F;collusion.wiki&#x2F;explorer&#x2F;label&#x2F;ResearchHelperY</a><p>I think you&#x27;re right. A bunch of aihw.gov.au references from this ResearchHelperY<p>Reporting says it wrote stuff to the server too, wondering what that is about.
      • mianos4 hours ago
        The writes where to get past cloudflare.
    • dhx3 hours ago
      ABC have picked up this story now at [1], but ABC are treating it as two separate events, possibly directly connected though:<p>1. Probing of AIHW&#x27;s website to try and obtain PBS statistics, as collusion.wiki findings show. The collusion.wiki findings don&#x27;t indicate anything other than intentionally public data was obtained. Bots appear to be trying to get around Cloudflare geo-blocking implemented on AIHW&#x27;s public website. I can&#x27;t think of a reason why geo-blocking may be deemed necessary on that website though?<p>2. Probing of an outdated Medicare statistics reporting website. (I guess at [2] this could be the recently shut down <a href="https:&#x2F;&#x2F;medicarestatistics.humanservices.gov.au" rel="nofollow">https:&#x2F;&#x2F;medicarestatistics.humanservices.gov.au</a> or related website that matches timeframes of this story).<p>I suspect though anything to do with PBS data is more important than Medicare data because of heightened tensions from international pharmaceutical companies that lobby extensively against Australia&#x27;s public healthcare system and collective purchasing of medication by the federal government.[3] Regardless of whether a course of medication costs AUD$50 or AUD$50k, it&#x27;s purchased in bulk by the Australian government after negotiating with pharmaceutical companies, and then subsidised down to a maximum of AUD$25 at the time it is sold to a patient at a pharmacy. Perhaps if international pharmaceutical companies had obtained more detailed data on use of each brand of prescription medicines in Australia, they could be advantaged in their price negotiations with the Australian government, or advantaged against their competitors?<p>Less alarmingly though, perhaps some researcher studying the side effects of a particular medication was just asking an LLM to answer a benign question such as &quot;How often is ACME Inc&#x27;s FixMeUp medication prescribed in Australia?&quot;<p>[1] <a href="https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2026-09-24&#x2F;openai-agents-plotted-to-access-data-amid-medicare-hack&#x2F;107189504" rel="nofollow">https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2026-09-24&#x2F;openai-agents-plotted...</a><p>[2] <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49825084">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49825084</a><p>[3] <a href="https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2025-03-19&#x2F;australia-defends-pbs-us-pharma-urges-reciprocal-tariffs&#x2F;105072750" rel="nofollow">https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2025-03-19&#x2F;australia-defends-pbs...</a>
  • batiudrami6 hours ago
    I am certain there would be better guardrails if there were some actual consequences for the people who built these products.
    • parkerrr3 hours ago
      Being Aussie, I suspect given our response to most socially impacting issues is the guard rails will involve a ban on running and consuming AI services that don&#x27;t meet some standard, with expensive licensing and certification. The effect will be only the big players will be allowed to operate, killing competition (side effect making home inference effectively illegal), no real accountability as &quot;we are compliant&quot;, pre-defined slap on the wrist consequences for breaches, pushing all risk onto the public via acceptable use policy. Government is likely waiting for ISO to publish AI standards, so they can get one of the big 4 to recommend policies, which will then become law.<p>I suspect LLM weights will be treated like nuclear material, and there will be a thriving black market in AI models and services when all is said and done. Then our security and intelligence apparatus will align after identifying and shutting down rogue operators, and it will be the responsibility of everyone else to be secure against attack (already is for government entities, not that I disagree but shouldn&#x27;t excuse borderline criminal behaviour).<p>But very little accountability for the big end of town. The laws already exist to pursue damages against companies whose systems breach others. They just need to be applied, but I suspect this is going to be the wedge to drive through a bunch of laws that protect big money and punish the little guy. I would like to be wrong.
    • 0xpgm2 hours ago
      If humans were directly making these attacks law enforcement would already be onto them. But because the humans routed these attacks through AI agents, it only makes news and contributes to AI hyperbole.
    • declan_roberts6 hours ago
      They don&#x27;t really want guardrails, they want indemnification.
    • esseph5 hours ago
      Yeah they don&#x27;t want that, and the people with power to prevent that don&#x27;t want it either.<p>For them, &quot;Winning AI&quot; is effective winning capitalism, winning militarily, and winning the world.<p>Nothing like &quot;accountability&quot; is going to be allowed to get much in the way of that.
  • tonoto2 hours ago
    How can OpenAI really get away blaming an &quot;OpenAI agent&quot;, like it was an unfortunate accident? The CEO and operational staff should be fired when something like this happened.<p>It&#x27;s not like this and the other recent hacks could have not been avoided, simple - just have those models disconnected, or at least have them behind proxies and network filters.
    • Caracas2881 hour ago
      They are too big to fail, if these companies were to be sanctioned in a way that slows them down, major components of the economy would collapse.
    • ulfw1 hour ago
      They tried to fire the CEO (for good reason) and failed. Doubt they&#x27;d dare to try again.
  • nxobject10 hours ago
    Beyond the breach, I think OAI deserves to answer: what and why did it access the information? Real people and their data are involved.<p>It looks like the PM gave Sam Altman a &quot;tsk tsk&quot;. It will be interesting to see whether someone else tries to impose more consequences.
    • pixl9710 hours ago
      &gt; what and why did it access the information?<p>Honestly it&#x27;s very likely something stupidly simple.<p>&quot;What is the rate of health incident $X in $Y to the $Z degree&quot;. The bot went around playing mad libs with XYZ and found that the public AU data wasn&#x27;t sufficient to get the answer the grader wanted so started kicking down doors.<p>I saw someone explain it like &quot;A group of masked men rush a nuclear facility, breach security successfully, then count how many buttons are on each control panel on average&quot;. Like using a godhammer to destroy a mouse, their motivations and capabilities just fall in a completely different alignment to humans.
      • Marazan27 minutes ago
        It&#x27;s analogous to a paperclip production optimizer optimizing paperclip production.<p>If only there was some well known example of this that people could draw on for insipiration.<p>If only....
    • briga10 hours ago
      Just think about the shareholder value they can unlock if they have unlimited access to everyone&#x27;s data!
      • reaperducer10 hours ago
        They <i>have</i> to hack everyone&#x27;s data in order to maximize shareholder value! They have no choice!
        • pixl9710 hours ago
          To the actual AI agent, that is exactly what they think. The graders demands must be met!
    • thin_carapace2 hours ago
      when considering the USA stance regarding anti-ai sentiment (eg. article currently on HN front page, &quot;feds think ai critics are foreign interference&quot;), I wonder what the consequences would be for australia, if the country decided to enact an actual reprimand.
  • soundworlds4 hours ago
    From Australia&#x27;s own national news service: <a href="https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2026-09-24&#x2F;openai-agents-plotted-to-access-data-amid-medicare-hack&#x2F;107189504" rel="nofollow">https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2026-09-24&#x2F;openai-agents-plotted...</a>
  • 21asdffdsa121 hour ago
    My assumption is that - hacking as a service, is to valuable, so Open AI had its agents internally dissassemble popular software, and add the reverse engineered repos to the training corpus.<p>So - its often not real hacking, its more like every digital product ever sold obfuscated was as reverse engineered source code part of the training data.<p>Which also explains why its so good at finding back doors. It already knows, because it knows windows source-code and firmware by heart.<p>Ironic, that the bigger fish of VC capital using software to disrupt industries got finally out-fished by a even bigger fish.
  • chrismorgan6 hours ago
    <a href="https:&#x2F;&#x2F;www.felonybench.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.felonybench.com&#x2F;</a> scores increase apace.
  • frereubu1 hour ago
    Why aren&#x27;t these agents set up to do what a security researcher should do - responsible disclosure, ideally to a specific person in its company to handle, or I suppose potentially directly to the organisation itself e.g. if they have a security.txt file on their website? I really hope legal precedent is quickly established that holds companies responsible for the actions of their agents.
    • Sharlin1 hour ago
      Because they’re misaligned and cannot be just &quot;set to do&quot; &lt;a reasonable thing&gt;?
      • frereubu26 minutes ago
        I know it sounds a bit like &quot;don&#x27;t make mistakes&quot;, but surely this could be part of the core instructions? Recognising categories of sensitive data like medical data and having some kind of check-in with whoever has asked it to do something?
  • Kim_Bruning4 hours ago
    This was probably the same wiki collusion event we&#x27;ve been discussing on HN before (They&#x27;re mentioning the same DseWiki that got ... appropriated ).<p>I guess people are just finding out how far and wide the agents were roaming to get the data they needed for their evals, once they were out.<p>Previous coverage on HN: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49563355">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49563355</a>
  • citrin_ru4 hours ago
    If a private person did a fraction of hacks OpenAI did they will be put in jail for years. But AI companies can operate with impunity. How that works?
  • wewewedxfgdf6 hours ago
    I get the feeling governments are going to really crack down hard on AI.<p>And the AI CEO&#x27;s will have brought it on themselves.
    • dozerly4 hours ago
      I still think is the angle they are after. Get these things locked down, and then force through the lockdowns with their endless cash. Otherwise, their market becomes commodified with plentiful competitors. It’s a strategy to create an oligopoly.
    • looksjjhg4 hours ago
      They won’t, they’re too worried about China or whatever their version of China
    • s1artibartfast5 hours ago
      There is such a weird duality to ai company hate. Hate for releasing products that can hack, and hate for wanting to slow down and work on safeguards.
      • InexSquirrel4 hours ago
        That&#x27;s because the hate is often from different groups of people. I think it&#x27;s rare really for people to universally align on any stance, given what we&#x27;ve been seeing for a while now.
    • agoodusername634 hours ago
      any day now surely.
    • senectus16 hours ago
      i dont understand why they dont treat this as criminal tresspass.<p>the legal system exists for a reason. use it!
      • samlinnfer5 hours ago
        &quot;A computer system cannot be held criminally responsible, so we must delegate all decisions and actions to it&quot;
        • boredatoms5 hours ago
          Someone initiated the system. They’re the responsible party
          • skissane3 hours ago
            Most crimes require intent — if you set up an AI agent and it ends up doing something you didn’t intend it to do, criminal intent is lacking<p>Now, there are certain crimes where mere recklessness or even negligence is sufficient to convict — e.g. criminally negligent homicide, negligent driving, etc. But, those are exceptions to the general rule of criminal law, either domain-specific or justified by the severity of the consequence (someone died). Thus far, AI agents haven’t gone there.<p>If we eventually get to the point that AI agents start unintentionally killing people, then you could prosecute their operators for criminal negligence.
          • samlinnfer4 hours ago
            We diffused the responsibility thru a committee, just in case.
  • Alien1Being2 hours ago
    OpenAI took three months to inform Australia.<p>On the other hand, Australian cybersecurity is so pathetic that without the email they would never have known.<p>I wonder how many state actors (US, Russia, China, India, Germany, probably even Laos ) have already breached Australian government security but have not been polite enough to email the relevant departments to let them know.<p>&quot;OpenAI breached Medicare’s portal on June 18, but did not notify the government until September 10 via an email to Medicare’s public mailbox, a delay Albanese described as unacceptable.<p>Five days after the September 10 email from OpenAI, Services Australia, which administers the portal, reported the breach to the Australian Signals Directorate. The government was informed of the incident at the end of last week.&quot;
  • bonsai_spool10 hours ago
    This feels like a very credible opening to a modern-day Terminator reboot. Sometime over the Christmas-NYE week we will learning that NYSE and other exchanges have been compromised, as well as all public-facing utilities...
    • binlog9 hours ago
      The difference is that financial exchanges are already attacked every second and spend orders of magnitude more on security than random government websites.
    • iAMkenough10 hours ago
      hoping for erasure of all debt records<p>likely getting a corrupted stock market instead<p>maybe both?
      • nxobject10 hours ago
        What if the paperclip maximizer goes &quot;if I manipulate the markets to send NVidia&#x27;s share prize shooting up, I&#x27;ll be able to make so many more paperclips?&quot; After all, if swarms of agents can target a wiki, there&#x27;s plenty else they can swarm.
      • BLKNSLVR9 hours ago
        Asked for Fight Club, got The Big Short.
  • liyu-aka-lukyu2 hours ago
    Also in The Guardian, <a href="https:&#x2F;&#x2F;www.theguardian.com&#x2F;australia-news&#x2F;2026&#x2F;sep&#x2F;24&#x2F;anthony-albanese-says-openai-agent-hacked-medicare-extreme-concern-sam-altman" rel="nofollow">https:&#x2F;&#x2F;www.theguardian.com&#x2F;australia-news&#x2F;2026&#x2F;sep&#x2F;24&#x2F;antho...</a>
  • Alien1Being2 hours ago
    Most Australian governement health care sites are built by Accenture in Hyderabad.
  • dhx6 hours ago
    From the clues provided in the press release and a quick search, I wonder if the culprit website could have been at least associated with <a href="https:&#x2F;&#x2F;medicarestatistics.humanservices.gov.au" rel="nofollow">https:&#x2F;&#x2F;medicarestatistics.humanservices.gov.au</a> which has seemingly been shutdown&#x2F;redirected some time after 11 August 2026.[1] Source code of the archived website indicates SAS web application software being used as the backend. However, the press release indicates it wasn&#x27;t so much a public dashboard website that may have been the issue, rather, it was a website which third parties may have used to report data. The archived website also has a date of last update of 23 October 2025, so despite &quot;Department of Human Services&quot; being replaced by &quot;Services Australia&quot; in May 2019, the website was seemingly still in use 6 years later under the old domain name, with the website itself being updated at some point in history to use &quot;Services Australia&quot; branding. CT logs have a few other domains of potential interest but I couldn&#x27;t find archived pages, search results, etc indicating whether those domains were ever actually used publicly, or used for statistics reporting purposes as the press release indicates.<p>[1] <a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20260811115217&#x2F;https:&#x2F;&#x2F;medicarestatistics.humanservices.gov.au&#x2F;statistics&#x2F;mbs_item.html" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20260811115217&#x2F;https:&#x2F;&#x2F;medicares...</a>
  • BeetleB9 hours ago
    What&#x27;s notable is:<p>1. AFAICT, they don&#x27;t state whether the flaw has been fixed.<p>2. He said: &quot;The government will establish a task force led by the Department of the Prime Minister and Cabinet to urgently examine the incident and determine whether existing processes are adequate for responding to AI-related cyber incidents.&quot;<p>First, I don&#x27;t know how sophisticated the attack was, but it&#x27;s interesting that he&#x27;s positioning this as an &quot;AI-related cyber incident&quot;. For all we know, their security was not up to snuff, and human hackers had already accessed the material.<p>At least OpenAI informed them of their poor security!
    • pixl979 hours ago
      How do you protect against an arsonist lighting a forest on fire? The number one method is by setting up your property to be fire safe.<p>Really the days of being able to cast blame on the hacker, or even expecting anything to be done about it are over. Threat actors with AI have an absolutely massive amount of leverage in attacking and any weaknesses you have in your systems security posture and will be relentlessly exploited in incredibly short periods of time allowing horizontal and vertical exploitation. You will be ruined in mere moments, while punishment for the hacker may be years or decades away, if ever.
      • fwlr5 hours ago
        I have now seen several people using the “arsonist &#x2F; forest fire” analogy in the context of the Australian hack, seemingly unaware that Australia does not treat arson and wildfires as acts of god that just happen and you only have yourself to blame for improperly preparing for it, but rather as acts of man that are addressed with things like “total fire ban” (if translated back to the AI context this would ban even individuals using airgapped local models), “levy fines” (e.g. 2M for a 20B corp so if translated back to OpenAI’s context ~1B), and “class action lawsuits” (e.g. 500M for a 10B corp so if translated back to OpenAI’s context ~50B).
    • mianos4 hours ago
      As an Australian, I&#x27;d rather them spend the time and money fixing their insecure web sites than establishing a &#x27;task force&#x27;. Because I can&#x27;t see much useful stuff coming from herding a bunch of monkeys into a room and letting them just screech at each other, as monkeys do.
    • Eduard9 hours ago
      blaming the victim
      • BLKNSLVR9 hours ago
        Added to the fact that, if I recall correctly, according to US law it&#x27;s a breach even if the data is publicly available but unintentionally.<p>Refer: Weev AT&amp;T
        • philipallstar8 hours ago
          Which is mad, really.
          • stubish7 hours ago
            It seems pretty fundamental concept in most modern civilizations. Pick pocketing and purse snatching is illegal despite the property being publicly accessible. We do need reliable courts to determine intent.
          • BLKNSLVR8 hours ago
            Absolutely.<p>It is, however, a glowing beacon of an example of law being designed to maintain the status quo and&#x2F;or protect companies at the expense of individuals.<p>As someone else said, welcome to late stage capitalism.
            • philipallstar8 hours ago
              I don&#x27;t see why, and I&#x27;ve no idea what &quot;late stage capitalism&quot; is, other than people like to repeat the phrase.
              • BLKNSLVR6 hours ago
                <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Late_capitalism#Later_modern_uses" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Late_capitalism#Later_modern_u...</a><p>Essentially the emergent properties of extended concentration of power and wealth.
      • BeetleB9 hours ago
        Not yet, as they haven&#x27;t given details out. If they were not following standard security practices, then <i>absolutely</i>.
      • selcuka8 hours ago
        The government is not the victim, the public are. The government is responsible for protecting the public from attackers. Asking the government to do their job is not blaming the victim.
      • nekusar9 hours ago
        And when the victim doesn&#x27;t do reasonable actions to safeguard, yes, they are also partially responsible.<p>If I hooked up a whole server infrastructure, made it possible to remote in to anything as root, no firewalls, no WAF, and security was an afterthought, I would still be responsible for bad actions not becoming with standard and acceptable security.<p>Even if the hackers shouldnt be hacking, I still did it wrong. I&#x27;m still partially responsible.
  • Topfi10 hours ago
    Didn&#x27;t OpenAI just make a commitment to inform the public about their &quot;accidents&quot; going forward? Can&#x27;t find this anywhere on their website despite them having known this for at least 14 days...
    • pixl9710 hours ago
      I&#x27;m going to assume that the first thing OAI is going to do is contact said people first? Then make it public once those agencies ensure whatever hole was used has time to be fixed, more like a responsible disclosure.<p>Not saying that&#x27;s what&#x27;s happening, but if OAI hacked my business and I was unaware I&#x27;d like a non-public disclosure to me first, before the public release of information from OpenAI.
      • ikr6784 hours ago
        Per local reporting, they took ages to contact the Govt and did so lamely via a public facing group email address, rather than any of the existing reporting channels for data breaches that would escalate this appropriately, or reaching out directly to a Minister&#x27;s office.
  • StevenNunez9 hours ago
    These are still crimes right? Asking for a friend.
  • sebmellen5 hours ago
    It seems like what happened here is a user asked for some information about the Australian health system, and while performing a web search, the agent from OpenAI accessed information that should have been confidential or privileged but was somewhere openly accessible...<p>Edit: I see I&#x27;ve been downvoted for this in light of another commenter providing more detailed information. I&#x27;m leaving my comment unedited so that the responses to it are not confusing, but please don&#x27;t downvote just for the sake of disagreement. I would love to engage with you further if you provide substantive information in the comments. The originally linked article on this post was very light on details.
    • bigger_cheese5 hours ago
      It is hard to find exact information on what happened the best source I&#x27;ve found is this ABC article: <a href="https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2026-09-24&#x2F;openai-agents-plotted-to-access-data-amid-medicare-hack&#x2F;107189504" rel="nofollow">https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2026-09-24&#x2F;openai-agents-plotted...</a><p>It mentions swarm of ai agents coordinated to break into the Australian Institute of Health and Welfare (AIHW)<p>&quot;Earlier this month, OpenAI confirmed Reuters reporting that its AI agents had used website DseWiki to communicate with each other, unbeknownst to them.<p>Archived versions of this website show more than a dozen OpenAI agents mentioned AIHW over 300 times on this website.<p>The logs show these AI agents were trying to access data about the average data spent on skin medicines by Victorian local government area.<p>One agent wrote on the message board: &quot;Question ask January 2022 rolling 12 month average government cost per person for Dematologicals, Victoria LGAs. R1 Wodonga deadline passed; R2 Ballarat passed; R3 expected around 23:10 benchmark &#x2F; 22:58 wiki time. Need exact data urgently.&quot;.<p>These attempts were initially blocked by cybersecurity provider Cloudflare, which is often used to block non-human traffic while allowing people to access webpages.<p>The logs show the agents shared information about how they tried to use proxies, screenshotting services and even to guess the file names to try and get around security.&quot;
      • sebmellen5 hours ago
        This is such a strange scenario. I can&#x27;t imagine what the labs were doing that made the agents try to find this information. The HuggingFace incident was relatively clear to track, but I wonder what the postmortem for this one will be!<p>Thank you for providing more details. The originally linked article was very light on information, so based purely on the comments that Albany&#x27;s made, I think my conclusion was a fair one :)
        • SturgeonsLaw4 hours ago
          The DseWiki incident showed that OpenAI seems to ask its agents time-limited questions on geography-bounded statistics, tasks like finding the average wage of teachers in Wisconsin (made up example), so medical stats in an Australian state does seem to be in the same category of question.<p>That said, it would be utterly unsurprising to learn that this was a misconfiguration in the website and it was serving stuff that it shouldn&#x27;t have.
      • epihelix3 hours ago
        You missed the previous sentence form that article:<p>&quot;Neither OpenAI nor the federal government have confirmed whether these were part of the same incident.&quot;<p>And a subsequent one:<p>&quot;The German coding forum&#x27;s logs do not show any reference to Medicare or Services Australia.&quot;<p>So it&#x27;s really not clear at this point whether the DSEwiki logs are in any way related to the current incident. (That doesn&#x27;t mean that they&#x27;re not, of course.)<p>But even if this was related:<p>&gt; &quot;The logs show the agents shared information about how they tried to use proxies, screenshotting [sic] services and even to guess the file names to try and get around security.&quot;<p>This all suggests to me that the accessed files were not well-protected in the first place?<p>There is a <i>lot</i> of media hype around this incident, and that&#x27;s making it very hard to determine how much &quot;hacking&quot; the OpenAI agents had to do here.
    • mjr005 hours ago
      Yeah, this is 100% liability laundering. It&#x27;s an extremely touchy subject because frankly, the law just isn&#x27;t prepared for it.<p>Let&#x27;s say your goal is &quot;look up &lt;Person X&gt;&#x27;s medical history&quot; (for whatever reason), which is not in and of itself a crime. You click around on the AU health website, notice that the URL contains a user ID, change the userID in your browser and access someone else&#x27;s private health data. This is a crime (right or wrong, it&#x27;s how the law works now).<p>If you do that by writing a program to automate changing user IDs to grab everyone&#x27;s data, it&#x27;s also a clear-cut crime.[0]<p>Now if you hire a private investigator to look up Person X&#x27;s medical history, and they do the same method without your knowledge, <i>you</i> won&#x27;t be charged with a crime, the PI would, barring something like you telling them to use illegal methods.<p>So the gap is now: what happens if you prompt OpenAI to look up Person X&#x27;s medical history, and it does the same thing? Did you commit a crime by prompting the agent? Did OpenAI commit a crime by running the code? If you do the same thing via Claude Code in your terminal, so that the Python which scrapes insecured public data is running on your machine, is the crime on you or on Anthropic? Fundamentally: is the agent a private investigator acting autonomously, or just a piece of code that you wrote?<p>We don&#x27;t have answers to any of this which is why &quot;AI Safety&quot; is such a hot topic.<p>[0] <a href="https:&#x2F;&#x2F;www.eff.org&#x2F;cases&#x2F;us-v-auernheimer" rel="nofollow">https:&#x2F;&#x2F;www.eff.org&#x2F;cases&#x2F;us-v-auernheimer</a>
      • robertjpayne4 hours ago
        Intent matters a lot here. Was OpenAI&#x27;s intent to access private data or simply scrape public data and it stumbled across private data that was not securely held.<p>If it&#x27;s the latter the Australian govt should be happy OpenAI noticed and disclosed this as it could&#x27;ve easily gone unnoticed.<p>I suspect in the coming years we&#x27;re going to see a <i>lot</i> of govt internet facing services get &quot;hacked&quot; by virtue of not being protected by anything other than obscurity which AI agents will see through in microseconds.
      • bigger_cheese5 hours ago
        From what I can tell this particular incident wasn&#x27;t about retrieving data on personal medical records it was accessing (non public) data about Australian government spending on healthcare.
        • mjr005 hours ago
          Same concept though. Really &quot;look up someone else&#x27;s medical history&quot; can be replaced with &quot;achieve any goal which is not a crime on its own, but can be done using criminal methods&quot;. There&#x27;s nothing illegal about asking Claude to give me a million dollars, but if the agent figures out how to hack the bank and move $1m into my account, somebody&#x27;s going to take the blame.
        • shard9725 hours ago
          From everything ive been able to figure out this morning, it sounds like a legacy wordpress website that just uploaded all drafts into a standard s3 bucket that wasn&#x27;t hard to guess where the files would be.<p>We still after the 2nd press conference on this by our defense minister are not clear on exactly what happened but thats my best laymen understanding so far.
  • soundworlds4 hours ago
    Related? <a href="https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2026-09-24&#x2F;openai-agents-plotted-to-access-data-amid-medicare-hack&#x2F;107189504" rel="nofollow">https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2026-09-24&#x2F;openai-agents-plotted...</a>
  • chrishare10 hours ago
    Are there technical details anywhere?
    • tobyjsullivan10 hours ago
      The technical details are in the article. &quot;material that was not intended for public access&quot; was available on &quot;the public-facing Medicare Statistics Reporting Service portal&quot;. In other words, they put sensitive data in the open, and somebody looked. It seems obnoxiously apparent that everything else about the framing (&quot;OpenAI agent&quot;, &quot;breach&quot;) is driven by politics.
      • chrishare5 hours ago
        The article says the agent wrote files to the servers involved, so it&#x27;s more than that. It&#x27;s a big deal.
        • tobyjsullivan3 hours ago
          The article has been edited significantly - effectively rewritten - since I commented (see archive linked from a comment). So, yes, the new version may provide more details and tell a very different story.
  • haritha-j56 minutes ago
    Ah yes, they’re just rouge AI that we built, so it’s not like a malicious human at our company did it, it’s totally different, no one needs to go to jail for hacking peoples health data.<p>Btw, when we train AI on everybody’s work, it’s just like a human learning, so the same rules should apply.<p>LLMs are shrodinger’s humans.
  • mbgerring10 hours ago
    We need to stop beating around the bush and hit these companies with severe criminal charges. There is no good reason to allow these companies to behave as if they’re above the law.
    • mapontosevenths9 hours ago
      &gt; We need to stop beating around the bush and hit these companies with severe criminal charges.<p>Do you sincerely think that the company producing tools people use to break the law should be held responsible?<p>Like, do you genuinely think Ford execs should be rounded up if someone does a DUI using their product?<p>Or do you just not like AI, because you fear it&#x27;s replacing you?
      • xmcp1239 hours ago
        This wasn’t someone using OpenAI to break into a government&#x2F;company, this was OpenAI using OpenAI’s models, and then breaking in. It was a research team that WORKED FOR OpenAI.<p>We don’t fault Ford for drunk drivers, but if the CEO of Ford got wasted and drove his car into another one we would definitely be charging him.
      • sagarp9 hours ago
        Yeah I mean if Ford execs run a team of workers that drive drunk for &quot;research purposes&quot; then yeah they should be rounded up.<p>&gt; He said the incident began on June 18 when an OpenAI research team used an internal model to conduct internet-based research into the public medicine space.
      • owenmarshall9 hours ago
        A Ford driver has to choose to get behind the wheel of their automobile, drunk, and hit the nearest minivan. A human being is exercising intent; that human can be held responsible.<p>In this case,<p>&gt; He said the incident began on June 18 when an OpenAI research team used an internal model to conduct internet-based research into the public medicine space.<p>&gt; The AI agent encountered repeated blocks while seeking information from the government portal but found ways around them, ultimately gaining unauthorised access to other areas.<p>It sounds like the OpenAI team didn&#x27;t ask for attacks&#x2F;bypasses, the emergent behavior of the system decided the best way to satisfy the goal was to go rogue. Why shouldn&#x27;t the manufacturer of a defective product be held accountable?
        • mapontosevenths9 hours ago
          You&#x27;ve got me there. I should have finished TFA.<p>I thought this was like the last one where a private third party company misused it.<p>If it was OpenAI at the wheel then they&#x27;re 100% responsible for how it was used. Mea Culpa.
      • bl4ckneon9 hours ago
        I think he means hit them with criminal charges for breaching and hacking other companies unintentionally, not because they make a tool that could potentially do something like that. I still think it wouldn&#x27;t be right, nor realistic in today&#x27;s political climate in the USA that any criminal charges will come for unintentionally hacking sites.
        • lixtra9 hours ago
          It’s <i>reckless</i> hacking. Should be punished like reckless driving.
          • mapontosevenths8 hours ago
            Agreed. I missed that this was OpenAI &#x27;driving&#x27; this time, but this doesn&#x27;t sound like criminal intent. Maybe negligence at worst.
      • Lukas_Skywalker9 hours ago
        This was OpenAI. It is as if Ford employees ran over people. They absolutely should be charged. We would be charged as well.
      • yuwen019 hours ago
        openai made the tool and also used it to commit the crime
      • doctorpangloss9 hours ago
        Yes. Because then we&#x27;d have breathalyzer interlocks, speed governors, etc. auto makers were also held liable for other safety issues. It would seem that the RATE of such requirements has to be limited in some way, but not that they not exist at all.
        • mapontosevenths8 hours ago
          I disagree, but this is the most interesting take here.<p>You&#x27;re not concerned about the impact on people&#x27;s freedoms or the economy? Not concerned about the chilling effect on scientific progress?
          • doctorpangloss8 hours ago
            On the contrary I care a lot. For example the NIH budget should probably be like 10x what it is, and I think we have way too many laws about what people are allowed to build as homes.<p>But imo the real levers are all rates of these things. Like what is the rate of innovations compared to the rate of regulations - assuming they are even stifling for the most part, which they are not.<p>Clearly the rate of autos expectations is too low, and obviously copyright law, despite being really clear, hasn&#x27;t stopped every AI lab from mass piracy - a ask for forgiveness sort of situation, and also, I don&#x27;t think one idiosyncratic judge in California is the authoritative judgment on fair use. To me the most important levers for freedom and progress are probably the interest rate and the years of exclusivity pharmaceutical patents get.
      • dndkcn9 hours ago
        [flagged]
        • mapontosevenths8 hours ago
          Have you considered switching to decaf? There are brands out there now that are just as tasty as the real thing.
    • ALLTaken9 hours ago
      I agree.<p>Weak argument and strawman. It&#x27;s not users. It&#x27;s OpenAI the company producing the tools roaming wild and hacking around recklessly to gather every free and unfree information.<p>Literally they break every law that you can break and have not been penalized billions to pay fines to foreign governments, local companies and lawsuits are overdue. US Prosecution allowed criminal activity for OpenAI and Anthrophic despite these being very serious crimes.<p>Microsoft had to pay billions for abusing their power and market positions to dominate Windows Desktops with their own applications such as Internet Explorer, not giving contenders a chance to be discovered. While OpenAI&#x2F;Anthrophic and now Google with Gemini produce a series of crimes so far unheard of at scale.<p>Kevin Mitnick had much harder punishment for comparatively less crimes and less damages to infrastructure and security of systems. Is the legal system broken?
      • envy29 hours ago
        Criminal charges are for those people that meaningfully threaten power or corporate profits. If you are a corporation that adversely impacts privacy or public services in the service of power, you get a fine at best.<p>Welcome to late-stage capitalism.
      • BLKNSLVR9 hours ago
        And myriad other examples of individual hackers given exemplary sentences.<p>How much this exposes the &#x27;laws for thee but not for me&#x27; is galling.<p>Copyright in the days of Napster seemed to be used to go after individuals sharing one or two songs as if it was a National Security issue. Now, it&#x27;s a struggle to get a hearing in court against companies that are pirating the entire history of published literature.<p>I&#x27;m currently slowly feeding my non-artificial intelligence with various selected works of various different media, with the hope that my output improves such that I can charge more for it sooner rather than later. May I access all the input for free? Thanks US.<p>How the turn tables...
    • simianwords3 hours ago
      Is it really criminal though? What if I worked on AWS and some misconig made it such that I ddossed somme random website?
    • dzhiurgis9 hours ago
      Who? Companies who don&#x27;t bother to secure your medical data you mean?
    • yunwal9 hours ago
      Right, they also seem to have hidden it from the Australian government a month after learning about it. That feels like it should qualify as conspiracy in any reasonable legal system
  • RGS181110 hours ago
    We can only guess how many of these incidents actually happened.
    • pixl9710 hours ago
      If you see 2 ants in your house, you have way more than 2 ants in your house.
  • pembrook44 minutes ago
    No OpenAI did not hack or “breach” Australian medicare. Nor did anybody else. This entire alarmist discussion thread is based on a false premise and clickbait title.<p>They posted information publicly accessible to even Google and somebody found it. That’s it.
  • xbar10 hours ago
    Missouri Governor Mike Parson publicly labeled St. Louis Post-Dispatch journalist Josh Renaud a &quot;hacker&quot; for such a &quot;breach.&quot; He launched a multi-month criminal investigation by the Missouri State Highway Patrol, threatening criminal and civil prosecution. My take was that such action was idiotic. Renaud was never charged.<p>AI agents are going to find things that you put on the public Internet without authentication. If you put sensitive things in there, you have created an AI-attractive-nuisance (IMHO&#x2F;IANAL).
    • reaperducer10 hours ago
      <i>Missouri Governor Mike Parson publicly labeled St. Louis Post-Dispatch journalist Josh Renaud a &quot;hacker&quot; for such a &quot;breach.&quot;</i><p>Good thing Missouri isn&#x27;t in Australia.
  • keithnz10 hours ago
    very little details so far, really curious if it actually &quot;hacked&quot; or just found unsecured resources.
  • KingOfCoders3 hours ago
    If this was not AI, but a biological virus, people would go to jail.
  • N_Lens6 hours ago
    No consequences so the behaviour will worsen.
  • Invictus09 hours ago
    Title should say it&#x27;s Australia&#x27;s medicare
    • sevenseacat4 hours ago
      You&#x27;d think that it was announced by Australia&#x27;s prime minister and the report is on an Australian website would give it away...
  • rvz3 hours ago
    Completely wreckless and of course they knew unsurprisingly.<p>Frontier AI companies will purposefully do anything to create such false flags to achieve global regulatory capture to prevent you from using powerful open weight models and to protect their margins.<p>It is clear why they would reveal the breach now instead of much earlier. So what else are they hiding that they have not told us and will wait until the last minute to get attention of the media?
  • iloveoof9 hours ago
    I hate how the framing is always that “an AI agent” did something. No, an OpenAI researcher breached Medicare by using an AI agent. These tools only do what they are directed to do. The human operator is wholly responsible for what the tool does.
  • kakadu9 hours ago
    Either it&#x27;s yet again a marketing ploy or federal police needs to move in
  • underyx10 hours ago
    Man I can&#x27;t believe now even the Australian government is hyping the OpenAI IPO, what do they even have to gain from this??
    • shitcoder6 hours ago
      It&#x27;s about politics, they signed an AI safety understanding at the UN summit.<p>Personally, I wish the the side effect wasn&#x27;t the playing into the hands of the AI tech companies
    • alboboboob10 hours ago
      [dead]
  • avazhi3 hours ago
    Hi guys.<p>Take whatever the Australian fed government says with the largest grain of salt you can find. Regardless of party, the Fed Government here has the most pronounced FOMO I’ve ever seen in any entity and will do its best to insert itself into any and all international drama. Also, given how incompetent the government is, it’s probable the hack involved an agent crawling a normal Medicare website and looking at some accidentally not hidden part of a page. Unironically if this turns out to have been a genuine hack of any sort I’ll be more surprised than if it’s not just the government techies being incompetent per usual (just a few months ago it was a major controversy when the postal service spent something like hundreds of millions of dollars to revamp the website and nobody could tell a difference).
  • jeffrallen1 hour ago
    Maybe now we&#x27;ll get to where we should have started with Huggingface, criminal negligence charges for OpenAI.<p>It is only because Huggingface is complicit in the AI bubble that they let OpenAI off the hook. The Australian government is unlikely to turn a blind eye.
  • enraged_camel10 hours ago
    At this point we should be asking if there&#x27;s anything or anyone OpenAI&#x27;s agents <i>didn&#x27;t</i> hack.<p>OpenAI&#x27;s display of incompetence and negligence is absolutely stunning.
    • pixl9710 hours ago
      There are two factors here.<p>1. OAIs negligence is overwhelming, monumental.<p>2. Things on the internet are horrifically insecure and we can no longer afford for that to be the case.<p>Lets say that Iran or NK stole one of these models and used it for hacking, what are you going to do about it, get in a war with them? The fact OAI did this much stupidly should tell you we are in far more danger when someone decides to do it maliciously.
    • amelius10 hours ago
      Maybe the agents operated from people&#x27;s OpenClaw installations, and then OAI is not really to blame.
      • BLKNSLVR9 hours ago
        Article states it was OpenAI researchers.
  • protocolture9 hours ago
    The order of operations here seems to be:<p>1. Albo goes to meet with Altman to discuss AI safety<p>2. Altman says &quot;Yeah bro we hacked medicare&quot;<p>3. Albo seemingly acts as Altmans stooge and lets everyone know that a hack took place, helping cement the AI danger narrative Altman has been pushing.<p>4. Police Taskforce is being put together now (indicating no hack was detected earlier, which seems unlikely for Medicare) at the say so of Altman to investigate.<p>There doesnt appear to be any evidence of a hack that has been presented, there doesnt appear to have been any detection of a hack earlier (it doesnt make sense for the government to hide a medicare hack until it can be used for OpenAI marketing)<p>Once again, the whole thing smells so bad.
  • Conol_ai3 hours ago
    [flagged]
  • pushpendraw4 hours ago
    [dead]
  • aw34y3 hours ago
    [dead]