cross-posted from: https://lemmy.dbzer0.com/post/75932280

Prime Minister Anthony Albanese has revealed an AI agent hacked into an Australian Medicare data portal earlier this year.

Speaking in New York, Mr Albanese said the Open AI agent gained unauthorised access to the Medicare statistics reporting service portal administered by Services Australia.

The AI agent accessed both public and non-public files.

The agent was conducting research into public medical spending when it found a way to break through privacy protections.

Mr Albanese said it took three months for OpenAI to admit the breach, which he said was unacceptable.

“Today I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident,” he said.

"And I also expressed my disappointment that it took the company way too long to inform the government what had occurred.

“The nature of the way that the notification occurred as well was unacceptable.”

He said there was no evidence any individual personal information had been accessed, but an investigation aided by the Australian Signals Directorate was now underway.

  • MalReynolds@slrpnk.net
    link
    fedilink
    English
    arrow-up
    18
    ·
    edit-2
    11 hours ago

    The scary thing to me is that it was claimed to be the ‘AI crawler’ that did the breach. Those fuckers have been driving up the cost of running every website, have zero respect for a robots.txt file and just keep hammering the internet in general.

    Now it appears they also have some sort of breaching capability, or the Medicare statistics site and others have a bad hole that allowed the crawler to walk its way in. I hope it’s the latter, bad as that is, because the former indicates they’re hooking up red team (hacking) agents to their fucking web crawler. Greedy, data hoovering, assholes.

    ETA: The Guardian article reports Albanese as saying

    the agent had accessed “public and non-public files within the portal” and, in order to do this, “engaged in writing files as well to the internal server”.

    which is not crawler behaviour, it’s definitely breaching.

    That should be straight up criminal behaviour, at the very least criminal negligence, probably significantly worse, whatever hacking for hire is in the targeted country. As is scarily becoming usual ‘an agent did it’ is being treated as a get out of jail free card, freeing them of responsibility. Those who control it need to be criminally accountable. Even if it is an OpenAI client (person) deliberately breaching their guardrails (Barbossa: “The code is more what you’d call ‘guidelines’ than actual rules.”), the company is an accomplice.

    • CapuccinoCoretto@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      8 hours ago

      Let’s not pretend the US isn’t a hostile nation. This was no accident. Information gathered is used to funnel intel to big money for sophisticated analysis used to drive privatization and corporate activity.