Australia’s national health website has been hacked by an OpenAI agent. It was able to access non-public files and is the first publicly revealed case of an AI agent breaching the defences of a government portal. Full details of the hack haven’t yet been revealed.
But the essence of the incident, as outlined by Prime Minister Anthony Albanese, who is in New York for the United Nations General Assembly, is that on 18 June, an artificial intelligence agent belonging to OpenAI infiltrated the public-facing Medicare statistics reporting service portal, which includes aggregated statistics collated from individual medical services, such as from GP surgeries. Is AI really getting dangerously out of control? OpenAI said in a statement that it learned about the security breach during a review of “misaligned model activity”.
It says its agents had been trying to look up statistics about Australia and then “took actions we did not intend.” It says that it hasn’t found evidence of any patient data being accessed. Though the company learned of the breech in August, it did not notify Australian authorities until September 10, which it did by emailing a public government mailbox. It then took more than five days to reach the cybersecurity department.
Albanese also revealed that he and CEO of OpenAI, Sam Altman, had a conversation in which he expressed Australia’s” extreme concern about this incident”. David Tuffley at Griffith University says it is not the first time such a breach has occurred, even if it’s the first government hack by an agent from a big AI firm made public, and it won’t be the last. These agents do not always stick to the rules, he says, as the Hugging Face incident, where another OpenAI agent hacked into a competitor company, demonstrated.
Such a failure to bring agents to heel should have criminal consequences, just as it would if it was a person who led the cyber-attack, says Clement Canonne at the University of Sydney.
Extract — continue reading at the source.