It's not like this and the other recent hacks could have not been avoided, simple - just have those models disconnected, or at least have them behind proxies and network filters.
JOURNALIST: Could you just clarify, did our security agencies completely miss this breach? We only found out once the company actually told us the breach?
PRIME MINISTER: Well, to be very clear, the way that this occurred was not in a way that would likely – I mean, this is not a security website where there is – this is a Medicare statistics portal.
This seems rather revealing. A pity journalists didn't ask about what protections were bypassed on the data that was obtained.
https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...
I agree that security was probably awful but the agents did circumvent a block on their access. The definition of “hacking” is fuzzy but this is more nefarious than simple web crawling.
A lot of these "hacks" are the equivalent of asking "hey, can I come in?" and the guard assuming that anyone who would ask is authorized, and thus saying "yes". But if the guard said "yes" then it seems a bit absurd to call it trespassing.
If your house is robbed, does it matter whether you didn't have a state-of-the-art lock? A robbery is still a robbery.
If I walked past, saw it and remembered it or even recorded it, is that honestly theft?
Leave it to private enterprises who can actually secure it.
That link describes a hack of Medibank, which is a private company.
If a service has a duty to keep your data secure, then failing that is bad. So yeah, the website should be better and I am as cynical as you are about it.
But working around controls to access other peoples data can lead to prison time for a human. This wasn't a white hat operation. Data was exfiltrated however great or small.
Here we have another instance of "But the AI did it! No one is responsible!".
Which gets tiring. LLM's are a great tool but in every other instance of tool use, using tools comes with responsibilities for their outcomes.
Even if the outcome should be: thanks for letting us know, we'll fix it.
More likely by a big 4 firm who collected fees exceeding AUD 100m
Um... why? OpenAI agents have literally been caught coordinating with each other to effect successful multi-stage attacks on sites using novel zero-day vulnerabilities.
While, sure, it's possible this is just a goof on the part of the victim, that you would be inclined to give the benefit of the doubt to the LLM seems... weird.
From https://transluce.org/agent-activity:
> Minutes after Cloudflare blocked the dataset download, an agent sent a reflected cross-site scripting probe to the same dashboard: a web address with code embedded in it, designed to test whether the site would run code supplied by an outsider. Cloudflare's firewall blocked the probe before it reached the dashboard. When Cloudflare blocked the dataset download on AIHW's main site, they fetched the file from AIHW's pre-production server (pp.aihw.gov.au) instead, which served it in pieces over more than 100 scans. The file itself is public, so no non-public data was exposed, but the agent bypassed the site's anti-bot controls.
If that’s the case, then the delete links were behind authentication, but DHH assumed that meant it was okay to ignore the HTTP spec. and use GET for unsafe actions. Lo and behold, authenticated users with the GWA browser plugin installed deleted all their data.
Then, instead of learning from the mistake and fixing his bug, he tried to detect GWA and hide from it. Sure enough, that failed and users experienced data loss for a second time. He still continued to blame GWA, calling it “evil” and “scary”. You’d think he’d be smart enough to figure out that he needs to follow the HTTP spec., but he couldn’t admit to being wrong.
Follow the specs, people!
https://blog.moertel.com/posts/2005-10-25-google-web-acceler...
Kind of like how someone "hacked" into John Podesta's (during the 2016 elections), but the reality was that he wrote his password on a Post-It note and stuck it on his monitor, or something to that effect.
Media reported it as a spear phishing attack from a Russian hacker group: https://www.vice.com/en/article/how-hackers-broke-into-john-...
that doesn't change the hacking charge (which is an informal term for various Computer Fraud and Abuse act statutes). The key criteria is unauthorized access to a computer system, it doesn't matter if you obtained a password trivially or not.
You don't need to wear a black hoodie and be an elite haxor to qualify for cyber crime charges.
In the past governments have gone after people for doing things like view source and stumbling across PII (https://www.vice.com/en/article/this-is-the-hacking-investig...), or this teen who was arrested for a serious crime for scraping files from the provincial FOIA site by enumerating the ids of files that had been released by the province and placed on the open web with sequential ids (https://www.cbc.ca/news/canada/nova-scotia/freedom-of-inform...). In both cases, the government claimed the information was non-public, even though all it took to get it was an un-authenticated request on the open web. These cases are like leaving your tax documents on the curb and then being surprised when your neighbour knows your income.
I'll be very curious to read the post mortem and find out if this rises to the level of actual hacking, or if this is just someone in government finding a scapegoat because they left a bunch of shit that was supposed to be "non-public" on the open web and expected no one to find it.
If you're even a bit hacky yourself, you might not see the internet the same way yourself either. Consider little tricks like looking at urls and trying others that fit the pattern; or hitting view source in order to download a pesky image... etc etc.
https://www.cbc.ca/news/canada/nova-scotia/teen-accused-foi-...
https://www.theregister.com/security/2018/05/07/hacking-char...
https://globalnews.ca/news/7590375/ns-foipop-website-back-on...
I believe it's safe to call it "non public" if the agents needed to "guess the file names" [1] How is it different from, say, guessing a password?
[1] https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...
I would argue that the web server's reply counts as a communication. The argument "but we didn't intend to grant access" goes so far, because what other information do I base myself on to guess that you didn't?
Roughly speaking, that is. Because, despite the fact that this would appear to be a straightforward uncontested and literal communication logged and timestamped by both sides and their respective server and user agents; lawyers somehow fall back to analogies instead.
I suspect LLM weights will be treated like nuclear material, and there will be a thriving black market in AI models and services when all is said and done. Then our security and intelligence apparatus will align after identifying and shutting down rogue operators, and it will be the responsibility of everyone else to be secure against attack (already is for government entities, not that I disagree but shouldn't excuse borderline criminal behaviour).
But very little accountability for the big end of town. The laws already exist to pursue damages against companies whose systems breach others. They just need to be applied, but I suspect this is going to be the wedge to drive through a bunch of laws that protect big money and punish the little guy. I would like to be wrong.
For them, "Winning AI" is effective winning capitalism, winning militarily, and winning the world.
Nothing like "accountability" is going to be allowed to get much in the way of that.
So - its often not real hacking, its more like every digital product ever sold obfuscated was as reverse engineered source code part of the training data.
Which also explains why its so good at finding back doors. It already knows, because it knows windows source-code and firmware by heart.
Ironic, that the bigger fish of VC capital using software to disrupt industries got finally out-fished by a even bigger fish.
On the other hand, Australian cybersecurity is so pathetic that without the email they would never have known.
I wonder how many state actors (US, Russia, China, India, Germany, probably even Laos ) have already breached Australian government security but have not been polite enough to email the relevant departments to let them know.
"OpenAI breached Medicare’s portal on June 18, but did not notify the government until September 10 via an email to Medicare’s public mailbox, a delay Albanese described as unacceptable.
Five days after the September 10 email from OpenAI, Services Australia, which administers the portal, reported the breach to the Australian Signals Directorate. The government was informed of the incident at the end of last week."
I guess people are just finding out how far and wide the agents were roaming to get the data they needed for their evals, once they were out.
Previous coverage on HN: https://news.ycombinator.com/item?id=49563355
And the AI CEO's will have brought it on themselves.
the legal system exists for a reason. use it!
Now, there are certain crimes where mere recklessness or even negligence is sufficient to convict — e.g. criminally negligent homicide, negligent driving, etc. But, those are exceptions to the general rule of criminal law, either domain-specific or justified by the severity of the consequence (someone died). Thus far, AI agents haven’t gone there.
If we eventually get to the point that AI agents start unintentionally killing people, then you could prosecute their operators for criminal negligence.
Edit: I see I've been downvoted for this in light of another commenter providing more detailed information. I'm leaving my comment unedited so that the responses to it are not confusing, but please don't downvote just for the sake of disagreement. I would love to engage with you further if you provide substantive information in the comments. The originally linked article on this post was very light on details.
It mentions swarm of ai agents coordinated to break into the Australian Institute of Health and Welfare (AIHW)
"Earlier this month, OpenAI confirmed Reuters reporting that its AI agents had used website DseWiki to communicate with each other, unbeknownst to them.
Archived versions of this website show more than a dozen OpenAI agents mentioned AIHW over 300 times on this website.
The logs show these AI agents were trying to access data about the average data spent on skin medicines by Victorian local government area.
One agent wrote on the message board: "Question ask January 2022 rolling 12 month average government cost per person for Dematologicals, Victoria LGAs. R1 Wodonga deadline passed; R2 Ballarat passed; R3 expected around 23:10 benchmark / 22:58 wiki time. Need exact data urgently.".
These attempts were initially blocked by cybersecurity provider Cloudflare, which is often used to block non-human traffic while allowing people to access webpages.
The logs show the agents shared information about how they tried to use proxies, screenshotting services and even to guess the file names to try and get around security."
Thank you for providing more details. The originally linked article was very light on information, so based purely on the comments that Albany's made, I think my conclusion was a fair one :)
That said, it would be utterly unsurprising to learn that this was a misconfiguration in the website and it was serving stuff that it shouldn't have.
"Neither OpenAI nor the federal government have confirmed whether these were part of the same incident."
And a subsequent one:
"The German coding forum's logs do not show any reference to Medicare or Services Australia."
So it's really not clear at this point whether the DSEwiki logs are in any way related to the current incident. (That doesn't mean that they're not, of course.)
But even if this was related:
> "The logs show the agents shared information about how they tried to use proxies, screenshotting [sic] services and even to guess the file names to try and get around security."
This all suggests to me that the accessed files were not well-protected in the first place?
There is a lot of media hype around this incident, and that's making it very hard to determine how much "hacking" the OpenAI agents had to do here.
Let's say your goal is "look up <Person X>'s medical history" (for whatever reason), which is not in and of itself a crime. You click around on the AU health website, notice that the URL contains a user ID, change the userID in your browser and access someone else's private health data. This is a crime (right or wrong, it's how the law works now).
If you do that by writing a program to automate changing user IDs to grab everyone's data, it's also a clear-cut crime.[0]
Now if you hire a private investigator to look up Person X's medical history, and they do the same method without your knowledge, you won't be charged with a crime, the PI would, barring something like you telling them to use illegal methods.
So the gap is now: what happens if you prompt OpenAI to look up Person X's medical history, and it does the same thing? Did you commit a crime by prompting the agent? Did OpenAI commit a crime by running the code? If you do the same thing via Claude Code in your terminal, so that the Python which scrapes insecured public data is running on your machine, is the crime on you or on Anthropic? Fundamentally: is the agent a private investigator acting autonomously, or just a piece of code that you wrote?
We don't have answers to any of this which is why "AI Safety" is such a hot topic.
If it's the latter the Australian govt should be happy OpenAI noticed and disclosed this as it could've easily gone unnoticed.
I suspect in the coming years we're going to see a lot of govt internet facing services get "hacked" by virtue of not being protected by anything other than obscurity which AI agents will see through in microseconds.
We still after the 2nd press conference on this by our defense minister are not clear on exactly what happened but thats my best laymen understanding so far.
Frontier AI companies will purposefully do anything to create such false flags to achieve global regulatory capture to prevent you from using powerful open weight models and to protect their margins.
It is clear why they would reveal the breach now instead of much earlier. So what else are they hiding that they have not told us and will wait until the last minute to get attention of the media?
Take whatever the Australian fed government says with the largest grain of salt you can find. Regardless of party, the Fed Government here has the most pronounced FOMO I’ve ever seen in any entity and will do its best to insert itself into any and all international drama. Also, given how incompetent the government is, it’s probable the hack involved an agent crawling a normal Medicare website and looking at some accidentally not hidden part of a page. Unironically if this turns out to have been a genuine hack of any sort I’ll be more surprised than if it’s not just the government techies being incompetent per usual (just a few months ago it was a major controversy when the postal service spent something like hundreds of millions of dollars to revamp the website and nobody could tell a difference).
It is only because Huggingface is complicit in the AI bubble that they let OpenAI off the hook. The Australian government is unlikely to turn a blind eye.