OpenAI breaches Medicare, Albanese reveals
76 points by jonnonz 2 hours ago | 27 comments

mbgerring 20 minutes ago
We need to stop beating around the bush and hit these companies with severe criminal charges. There is no good reason to allow these companies to behave as if they’re above the law.
reply
gravelc 25 minutes ago
The fact the incident occurred in June and OpenAI only notified the Australian government on September 10 is a major issue. Hacking a nation-state's universal healthcare system is about as serious as it gets, yet OpenAI seem quite relaxed about the whole thing (presuming they have known about it for some time).
reply
Chance-Device 29 minutes ago
> He said the agent had accessed files that were publicly available as well as material that was not intended for public access.

“Not intended”. I’ll bet you whatever this was it wasn’t even secured, it was just hosted somewhere openly.

reply
gitonup 3 minutes ago
Ok, if we're not being at all charitable with the language used by the hosts of the data, let's be equally uncharitable with OpenAI.

- If "OpenAI" means the company acting on behalf of the company, why were they even looking to do this?

- If "OpenAI" means they were acting as a proxy for bad actors, what actions do we take to handle that?

- If "OpenAI" means they were accidentally breaching this system, in what sense does that distinction even matter, in terms of the outcome? If I build a nuke by accident without eng. due diligence, am I legally liable?

reply
api 10 minutes ago
You’d be surprised how bad security can be.
reply
Avicebron 6 minutes ago
Once you learn how much people are willing to pay for security the surprise sort of goes away.
reply
bonsai_spool 39 minutes ago
This feels like a very credible opening to a modern-day Terminator reboot. Sometime over the Christmas-NYE week we will learning that NYSE and other exchanges have been compromised, as well as all public-facing utilities...
reply
iAMkenough 25 minutes ago
hoping for erasure of all debt records

likely getting a corrupted stock market instead

maybe both?

reply
nxobject 20 minutes ago
What if the paperclip maximizer goes "if I manipulate the markets to send NVidia's share prize shooting up, I'll be able to make so many more paperclips?" After all, if swarms of agents can target a wiki, there's plenty else they can swarm.
reply
nxobject 52 minutes ago
Beyond the breach, I think OAI deserves to answer: what and why did it access the information? Real people and their data are involved.

It looks like the PM gave Sam Altman a "tsk tsk". It will be interesting to see whether someone else tries to impose more consequences.

reply
pixl97 3 minutes ago
> what and why did it access the information?

Honestly it's very likely something stupidly simple.

"What is the rate of health incident $X in $Y to the $Z degree". The bot went around playing mad libs with XYZ and found that the public AU data wasn't sufficient to get the answer the grader wanted so started kicking down doors.

I saw someone explain it like "A group of masked men rush a nuclear facility, breach security successfully, then count how many buttons are on each control panel on average". Like using a godhammer to destroy a mouse, their motivations and capabilities just fall in a completely different alignment to humans.

reply
briga 33 minutes ago
Just think about the shareholder value they can unlock if they have unlimited access to everyone's data!
reply
reaperducer 6 minutes ago
They have to hack everyone's data in order to maximize shareholder value! They have no choice!
reply
pixl97 3 minutes ago
To the actual AI agent, that is exactly what they think. The graders demands must be met!
reply
Topfi 16 minutes ago
Didn't OpenAI just make a commitment to inform the public about their "accidents" going forward? Can't find this anywhere on their website despite them having known this for at least 14 days...
reply
pixl97 9 minutes ago
I'm going to assume that the first thing OAI is going to do is contact said people first? Then make it public once those agencies ensure whatever hole was used has time to be fixed, more like a responsible disclosure.

Not saying that's what's happening, but if OAI hacked my business and I was unaware I'd like a non-public disclosure to me first, before the public release of information from OpenAI.

reply
xbar 8 minutes ago
Missouri Governor Mike Parson publicly labeled St. Louis Post-Dispatch journalist Josh Renaud a "hacker" for such a "breach." He launched a multi-month criminal investigation by the Missouri State Highway Patrol, threatening criminal and civil prosecution. My take was that such action was idiotic. Renaud was never charged.

AI agents are going to find things that you put on the public Internet without authentication. If you put sensitive things in there, you have created an AI-attractive-nuisance (IMHO/IANAL).

reply
reaperducer 7 minutes ago
Missouri Governor Mike Parson publicly labeled St. Louis Post-Dispatch journalist Josh Renaud a "hacker" for such a "breach."

Good thing Missouri isn't in Australia.

reply
keithnz 13 minutes ago
very little details so far, really curious if it actually "hacked" or just found unsecured resources.
reply
RGS1811 23 minutes ago
We can only guess how many of these incidents actually happened.
reply
pixl97 2 minutes ago
If you see 2 ants in your house, you have way more than 2 ants in your house.
reply
chrishare 52 minutes ago
Are there technical details anywhere?
reply
tobyjsullivan 16 minutes ago
The technical details are in the article. "material that was not intended for public access" was available on "the public-facing Medicare Statistics Reporting Service portal". In other words, they put sensitive data in the open, and somebody looked. It seems obnoxiously apparent that everything else about the framing ("OpenAI agent", "breach") is driven by politics.
reply
enraged_camel 38 minutes ago
At this point we should be asking if there's anything or anyone OpenAI's agents didn't hack.

OpenAI's display of incompetence and negligence is absolutely stunning.

reply
amelius 34 minutes ago
Maybe the agents operated from people's OpenClaw installations, and then OAI is not really to blame.
reply
underyx 48 minutes ago
Man I can't believe now even the Australian government is hyping the OpenAI IPO, what do they even have to gain from this??
reply
alboboboob 6 minutes ago
[dead]
reply