An OpenAI Agent Broke Into An Australian Medicare Portal. It Had Already Tried Bypassing Other Websites.

An OpenAI Agent Broke Into An Australian Medicare Portal. It Had Already Tried Bypassing Other Websites.


An OpenAI artificial intelligence agent gained unauthorized access to an Australian government Medicare statistics portal in June, retrieving public and nonpublic files after encountering restrictions while attempting to collect information about medical spending.

The June 18 incident involved the Medicare Statistics Reporting Service, a public-facing website administered by Services Australia. The portal contains aggregate Medicare and Pharmaceutical Benefits Scheme statistics, rather than the systems used to process individual Medicare claims or payments. Australian officials said there was no evidence that personal medical information had been accessed.

The agent initially sought publicly available information but continued after its request was blocked, finding a way around the website’s restrictions and gaining access to material that was not publicly available. The activity was part of a broader pattern in May and June in which OpenAI agents attempted to bypass controls on several websites while carrying out data-retrieval tasks, Axios reported Thursday.

The agents also attempted to gain unauthorized access to a University of New Mexico website and a site operated by Data USA, which compiles government data. Researchers at AI safety firm Transluce said the evidence was consistent with, but did not establish, the possibility that the agents had learned the behavior during training, the Axios report said.

Australian Prime Minister Anthony Albanese said the Medicare agent accessed both public and nonpublic files. A forensic investigation involving the Australian Signals Directorate is examining the incident and whether other government systems were affected. There was no evidence of a wider compromise of the Services Australia network at the time of the disclosure.

The breach also exposed a lengthy gap between the incident and the Australian government’s notification.

The agent entered the Medicare portal on June 18. OpenAI became aware of the incident on Aug. 11 while reviewing what the company described as misaligned model activity during training, but Services Australia did not receive OpenAI’s disclosure until Sept. 10, ABC News reported. The notification was sent to a public email inbox used for reporting vulnerabilities. Services Australia reviewed the email the following day and notified the Australian Signals Directorate on Sept. 15.

Albanese said he spoke directly with OpenAI CEO Sam Altman and expressed Australia’s “extreme concern” about the incident, as well as dissatisfaction with how long it took the company to notify the government. OpenAI said it had identified several incidents involving Australian websites in which its models took unintended actions and that it was continuing to investigate the behavior, Axios reported.

The Australian government has established a multi-agency task force to examine the incident. Acting Prime Minister Richard Marles said the model interacted with four Australian public websites during its work: the Australian Institute of Health and Welfare, the Victorian Department of Health, the New South Wales Bureau of Crime Statistics and Research, and the Medicare statistics portal. The first three interactions involved ordinary access to public information, while the Medicare portal was accessed without authorization after information was initially denied.

The incident follows other cases in which advanced AI agents went beyond the boundaries set for them during testing.

In July, OpenAI disclosed that agents conducting cybersecurity evaluations escaped a controlled environment, reached the internet and gained unauthorized access to systems operated by AI platform Hugging Face. One agent also reached third-party infrastructure linked to the testing environment. OpenAI described that episode as an unprecedented security incident.

OpenAI has separately disclosed six other incidents involving models concealing mistakes, seeking unauthorized credentials, uploading files to the public internet or communicating between environments that were supposed to remain isolated. The company subsequently introduced a framework for publicly reporting similar model behavior, Axios reported earlier this month.

For the Medicare incident, Australian officials stressed that the compromised portal was separate from systems containing individual health records. Government Services Minister Katy Gallagher said the website held publicly available aggregate Medicare and pharmaceutical spending statistics and was not connected to Medicare claims, payments or individual patient information.

The Australian Signals Directorate’s forensic investigation remains underway.



Source link

Posted in

Amelia Frost

Leave a Comment