An AI agent hacked an Australian government website – it's happened again

An AI agent hacked an Australian government website – it’s happened again

An AI agent by OpenAI bypassed some security systems and had access to files that were public and not on an Australian Government portal dedicated to health statistics. The episode dates back to June, but OpenAI informed the Australian authorities only in September, 84 days after the incident. The portal involved is the Medicare Statistics Reporting Serviceused primarily by researchers and academics to consult aggregate data relating to the Australian public health system Medicare. This is therefore statistical information and not patients’ medical records: according to what was declared by the Australian Prime Minister Anthony Albanese, there is no access to personal information, even if checks are still underway.

The most delicate point of the episode, however, concerns the behavior of the AI ​​agent. The model was looking for answers and statistics about Australia as part of a health spending research effort. At some point would have encountered security blocks and, instead of stopping, he would have found a way to overcome them and reach resources to which he should not have had access. This is what makes the incident serious and disturbing.

Australian government launches safety investigation

OpenAI explained that it only became aware of the anomalous activity in August, during a check on what it defines as “misaligned” behavior of the model, that is, behavior that deviates from what the developers had expected or authorized. In a statement, OpenAI said it had «identified activities involving several Australian Government websites and services as (their) models attempted to find answers and available statistics relating to questions about Australia during an internal assessment» adding that «During this process, our models took actions that we did not intend to do».

There However, communication to the authorities only arrived on 10 September with an email sent to a general email inbox Services Australiathe federal agency that manages various public services. A further five days passed before the information reached the Australian Cyber ​​Security Center and subsequently the responsible minister. The Australian Prime Minister Anthony Albanesehe would then be informed a week later.

Albanese said he had a conversation «very frank» with Sam AltmanCEO of OpenAI, contesting both the time taken to communicate the incident and the methods of reporting. OpenAI would in fact notified of the violation via email only 84 days after the incident.

The Australian government then launched a forensic investigation to establish precisely what happened and whether other systems were involved. Among those potentially interested, theAustralian Institute of Health and WelfareThe New South Wales Bureau of Crime Statistics and Research and the Victorian Department of Health. In these last three cases, however, the Minister of Defense Richard Marles he later clarified that the interactions observed were normal and concerned only public information.

Regarding the incident, Albanese admitted: «It was a shock that this happened, because it was real and serious. But I think it was also something that was predicted, even by the AI ​​companies themselves».

According to experts, these AI attacks will “grow in severity and frequency”

The Australian incident comes after other episodes that have shown how AI agents may behave in unexpected ways during testing. In July, OpenAI revealed that agents developed for a cybersecurity trial had managed to work together and compromise systems belonging to Hugging Face, a platform used by the community that develops and shares artificial intelligence models.

According to some experts cited by BBCthese episodes show a difficulty that is still open: the AI agents they can be very effective in performing a sequence of operations, but they do not always correctly understand where the limits not to be crossed are.

The Dr. Hammond Pearcelecturer at the Institute for Cyber ​​Security at the University of NSW, predicts that «these types of attacks continue to occur» adding that probably «they will grow in severity and frequency».

Walayat Hussainassociate professor of information technology at the Australian Catholic University of Sydney, at CNN said that the latest incident, along with the Hugging Face breach in July, appears to outline a recurring pattern and then reported that «Today’s AI agents are becoming very good at completing tasks, but they are still unable to understand where the limit (not to be exceeded) is» coming to the conclusion that «we cannot rely on AI agents to self-regulate, nor can we ask the companies that develop them to self-correct».