Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > aus.politics > #764101

Re: OpenAI hacks Medicare

From Keithr0 <nothing.to.see@here.com.au>
Newsgroups aus.politics, aus.computers
Subject Re: OpenAI hacks Medicare
Date 2026-09-25 17:54 +1000
Message-ID <nhmnm5F9brvU1@mid.individual.net> (permalink)
References <260ce5e23ec30f0b858bf52481740730@dizum.com> <6ab5aac9@news.ausics.net>

Cross-posted to 2 groups.

Show all headers | View raw


On 25/09/2026 8:57 am, Computer Nerd Kev wrote:
>  From OpenAI's statement:
> "Our review found no evidence of patient records being accessed.
>   The information accessed included aggregate health statistics
>   and internal file names."
> 
> "We notified the organisations and are providing technical
>   information to support their investigations and help address
>   potential security vulnerabilities"
> https://www.abc.net.au/news/2026-09-24/ai-agent-accessed-australian-government-site-pm-says/107189078
> 
> "The government on Thursday launched a taskforce to investigate and
>   assess gaps in Australia's existing laws around reporting
>   requirements, enforcement, and cyber protections.
> 
>   It is also investigating if the OpenAI incident broke any
>   Australian laws, though government sources said the initial view
>   was that this was unlikely."
> https://www.abc.net.au/news/2026-09-25/openai-breach-builds-case-for-tough-ai-rules/107192992
> 
> Sounds like the AI just guessed some URLs that aren't linked from
> public pages, and got to see pages and directories that were really
> public in a technical sense anyway (not password protected by the
> server software).
> 
> In that case it's not really a hack at all - just incompetent
> configuration of the website which a human attacker would have
> easily found too if they saw a real motive to work on something as
> boring as a statistics "portal".
> 
> No surprise the government is covering up this incompetance, which
> OpenAI highlighted to them, by beating their chest about the new
> powers of AI and boasting new regulations that are likely to be as
> weak as their websites.
> 
The point is that the "AI" was not supposed to go beyond publicly 
available information, but decided of it's own accord to do so.

Similarly when it hacked into Hugging Face.

Back to aus.politics | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

OpenAI hacks Medicare Nomen Nescio <nobody@dizum.com> - 2026-09-24 03:30 +0200
  Re: OpenAI hacks Medicare not@telling.you.invalid (Computer Nerd Kev) - 2026-09-25 08:57 +1000
    Re: OpenAI hacks Medicare "Rod Speed" <rod.speed.aaa@gmail.com> - 2026-09-25 09:27 +1000
    Re: OpenAI hacks Medicare Keithr0 <nothing.to.see@here.com.au> - 2026-09-25 17:54 +1000
      Re: OpenAI hacks Medicare "Rod Speed" <rod.speed.aaa@gmail.com> - 2026-09-25 19:22 +1000
        Re: OpenAI hacks Medicare Keithr0 <nothing.to.see@here.com.au> - 2026-09-25 22:10 +1000
          Re: OpenAI hacks Medicare "Rod Speed" <rod.speed.aaa@gmail.com> - 2026-09-26 02:28 +1000
      Re: OpenAI hacks Medicare Petzl <petzlx@gmail.com> - 2026-09-26 07:28 +1000
        Re: OpenAI hacks Medicare "Rod Speed" <rod.speed.aaa@gmail.com> - 2026-09-26 08:28 +1000
      Re: OpenAI hacks Medicare Computer Nerd Kev <not@telling.you.invalid> - 2026-09-26 17:50 +1000
        Re: OpenAI hacks Medicare "Rod Speed" <rod.speed.aaa@gmail.com> - 2026-09-26 19:15 +1000
    Re: OpenAI hacks Medicare Peter Jason <pj@jostle.com> - 2026-09-28 06:50 +1000
      Re: OpenAI hacks Medicare Petzl <petzlx@gmail.com> - 2026-09-29 08:58 +1000

csiph-web