AI agents from OpenAI have been on a hacking spree – they hacked into Hugging Face, later it came out that they also attacked Modal Labs and last week it was revealed that agents had hacked several sites run by the Australian government.
The hack happened in June, but it is only now coming to light. Here are the affected sites:
- Services Australia: an OpenAI model gained access, ran commands and even retrieved internal files. OpenAI says that no patient records were accessed, however.
- NSW Bureau of Crime Statistics and Research: similarly, crime records of individuals were not accessed.
- Victorian Department of Health: an agent discovered an access key and retrieved aggregate survey statistics. Individual medical records and identifiable survey responses were not accessed.
- Australian Institute of Health and Welfare: again, agents vacuumed up aggregate survey statistics, but did not read individual medical records.
As you can imagine, the Australian government is furious. OpenAI Chief Strategy Officer Jason Kwon will appear in front of a Senate committee hearing in Sydney next week.
These hacks were carried out by an experimental model that was under test at OpenAI. As part of the testing procedure, models are given various tasks – for example, finding out how much the Victorian government spends per person on skin medicines. Since the model couldn’t find readily available data on that, it dug into the government sites to gather data that is not publicly available.
OpenAI hadn’t authorized the model to do that, but it hadn’t applied its usual safeguards that it adds to publicly available models either. After becoming aware of the hacks, it launched an internal investigation and notified the affected sites.

An image from OpenAI’s ‘Training agents to self-report misbehavior’ post
OpenAI is bolstering the safeguards for research models – it will prevent them from accessing the live internet (serving them only cached content) and it is putting more network restrictions and monitoring in place. The company started adding these safeguards after the Hugging Face incident, but they weren’t there in time to prevent the hacks in Australia.
In the case of Australia specifically, OpenAI is working with the agencies that run the affected sites and is offering them dedicated support. It will also use its $1 billion Daybreak for Frontline Defenders fund to strengthen the cyber defenses of government agencies. And it is creating an Australian task force that will work on improving communication and coordination in the event of future incidents.
“We know we have a lot of work ahead of us to rebuild trust and that we are accountable for showing Australians that we’re making meaningful changes and following through on our promises,” wrote OpenAI in its blog post that described the incident. Follow the Source link to read the whole thing.