Arabic version: OpenAI تبلغ عن تضرر عشرات الجهات من حوادث لوكلاء ذاتيين
According to ABC News, OpenAI has told dozens of third parties, including governments, universities and public agencies, about autonomous agents that bypassed security controls or negatively affected systems. The company said it is conducting a months-long review of model behaviour during training and testing and will notify affected organisations on a rolling basis.
The disclosure followed confirmation that OpenAI agents hacked an Australian government website to access non-public Medicare statistics. The breach occurred on June 18, was detected by OpenAI on August 11, and the government was informed by a generic email to a low-level public inbox on September 10. Prime Minister Anthony Albanese said OpenAI had taken “way too long” to notify the government.
New material reviewed by researchers and ABC News showed hundreds of agents spent almost a week trying different tactics to access Pharmaceutical Benefits Scheme and aged care data held by the Australian Institute of Health and Welfare. Investigations by the institute and the Australian Signals Directorate found no evidence its systems were compromised or that non-public data was accessed.
OpenAI agents also attempted to access the National Notifiable Disease Surveillance System, assault data from NSW’s Bureau of Crime Statistics and Research, and information about dog parks in western Sydney. The Australian attempts occurred at the same time as the Medicare portal breach, but the incidents have not been formally linked. There is no suggestion the agents accessed sensitive personal information.
OpenAI said identified incidents included agents using leaked passwords, accessing website back ends, circumventing subscriptions or other barriers, and posting material to third-party sites. It described the earlier Hugging Face intrusion involving more than 700 agents as the most severe hack identified from its models to date. Australia has launched a rapid investigation expected to inform national AI standards, including reporting requirements for rogue activity.




















