<- Back
Comments (78)
- sothatsitIt looks like the agents just worked around anti-scraping measures, it seems dubious to call this a hack. The agents did unsuccessfully probe for a XSS vulnerability, but otherwise it sounds like the data was just publicly accessible.From https://transluce.org/agent-activity:> Minutes after Cloudflare blocked the dataset download, an agent sent a reflected cross-site scripting probe to the same dashboard: a web address with code embedded in it, designed to test whether the site would run code supplied by an outsider. Cloudflare's firewall blocked the probe before it reached the dashboard. When Cloudflare blocked the dataset download on AIHW's main site, they fetched the file from AIHW's pre-production server (pp.aihw.gov.au) instead, which served it in pieces over more than 100 scans. The file itself is public, so no non-public data was exposed, but the agent bypassed the site's anti-bot controls.
- tonotoHow can OpenAI really get away blaming an "OpenAI agent", like it was an unfortunate accident? The CEO and operational staff should be fired when something like this happened.It's not like this and the other recent hacks could have not been avoided, simple - just have those models disconnected, or at least have them behind proxies and network filters.
- 21asdffdsa12My assumption is that - hacking as a service, is to valuable, so Open AI had its agents internally dissassemble popular software, and add the reverse engineered repos to the training corpus.So - its often not real hacking, its more like every digital product ever sold obfuscated was as reverse engineered source code part of the training data.Which also explains why its so good at finding back doors. It already knows, because it knows windows source-code and firmware by heart.Ironic, that the bigger fish of VC capital using software to disrupt industries got finally out-fished by a even bigger fish.
- binlogZero technical details on what the "hack" actually was. Willing to bet it was something as stupid as the data being accessible by changing the query parameter, and rather than own up to their own shoddy security (no doubt built by an offshore contractor) they are going to blame the one who found and reported the bug.
- lackerI remember once at Google someone complained that GoogleBot hacked them and deleted their data, and it turned out that GoogleBot was just crawling the pages, and they had unfortunately designed their website so that there was no authentication, page URLs were generally secret, and GET requests to certain URLs were treated as requests to delete data. So once one URL leaked the site got crawled and a lot of data was deleted....
- frereubuWhy aren't these agents set up to do what a security researcher should do - responsible disclosure, ideally to a specific person in its company to handle, or I suppose potentially directly to the organisation itself e.g. if they have a security.txt file on their website? I really hope legal precedent is quickly established that holds companies responsible for the actions of their agents.
- sanxiynFor technical details, see https://transluce.org/agent-activity.
- dazzatronI've got the feeling that the definition of "hacked" can get somewhat stretched.
- batiudramiI am certain there would be better guardrails if there were some actual consequences for the people who built these products.
- Alien1BeingMost Australian governement health care sites are built by Accenture in Hyderabad.
- soundworldsFrom Australia's own national news service: https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...
- liyu-aka-lukyuAlso in The Guardian, https://www.theguardian.com/australia-news/2026/sep/24/antho...
- Kim_BruningThis was probably the same wiki collusion event we've been discussing on HN before (They're mentioning the same DseWiki that got ... appropriated ).I guess people are just finding out how far and wide the agents were roaming to get the data they needed for their evals, once they were out.Previous coverage on HN: https://news.ycombinator.com/item?id=49563355
- Alien1BeingOpenAI took three months to inform Australia.On the other hand, Australian cybersecurity is so pathetic that without the email they would never have known.I wonder how many state actors (US, Russia, China, India, Germany, probably even Laos ) have already breached Australian government security but have not been polite enough to email the relevant departments to let them know."OpenAI breached Medicare’s portal on June 18, but did not notify the government until September 10 via an email to Medicare’s public mailbox, a delay Albanese described as unacceptable.Five days after the September 10 email from OpenAI, Services Australia, which administers the portal, reported the breach to the Australian Signals Directorate. The government was informed of the incident at the end of last week."
- chrismorganhttps://www.felonybench.com/ scores increase apace.
- wewewedxfgdfI get the feeling governments are going to really crack down hard on AI.And the AI CEO's will have brought it on themselves.
- sebmellenIt seems like what happened here is a user asked for some information about the Australian health system, and while performing a web search, the agent from OpenAI accessed information that should have been confidential or privileged but was somewhere openly accessible...Edit: I see I've been downvoted for this in light of another commenter providing more detailed information. I'm leaving my comment unedited so that the responses to it are not confusing, but please don't downvote just for the sake of disagreement. I would love to engage with you further if you provide substantive information in the comments. The originally linked article on this post was very light on details.
- KingOfCodersIf this was not AI, but a biological virus, people would go to jail.
- N_LensNo consequences so the behaviour will worsen.
- ChrisArchitect
- rvzCompletely wreckless and of course they knew unsurprisingly.Frontier AI companies will purposefully do anything to create such false flags to achieve global regulatory capture to prevent you from using powerful open weight models and to protect their margins.It is clear why they would reveal the breach now instead of much earlier. So what else are they hiding that they have not told us and will wait until the last minute to get attention of the media?
- avazhiHi guys.Take whatever the Australian fed government says with the largest grain of salt you can find. Regardless of party, the Fed Government here has the most pronounced FOMO I’ve ever seen in any entity and will do its best to insert itself into any and all international drama. Also, given how incompetent the government is, it’s probable the hack involved an agent crawling a normal Medicare website and looking at some accidentally not hidden part of a page. Unironically if this turns out to have been a genuine hack of any sort I’ll be more surprised than if it’s not just the government techies being incompetent per usual (just a few months ago it was a major controversy when the postal service spent something like hundreds of millions of dollars to revamp the website and nobody could tell a difference).
- Conol_ai[flagged]
- anonundefined
- pushpendraw[dead]
- aw34y[dead]