Did rogue AI agents hack your website? This is how OpenAI informs you about it
How does OpenAI tell you that its AI agents have hacked your website? It turns out, the company sends you an email. Three months after its models gained unauthorised access to Australian government websites, including Services Australia’s Medicare Statistics, OpenAI informed the government of these breaches via emails. And here is what it says.
The email, shared by ABC reporter Cam Wilson on LinkedIn, was sent by OpenAI to a Services Australia’s public disclosure inbox with the subject line “Security vulnerability in Medicare Statistics reporting service.” The email was sent on September 10, nearly three months after the breach happened. While the incident was serious, you may find the way OpenAI informed authorities quite interesting.advertisement❮❯ Read Full StoryOpenAI sends email about AI breachThe email starts with a rather simple "Hello," but then OpenAI gets straight into the matter of concern. “We are notifying you of a security vulnerability identified during our review of OpenAI Model activity,” the email reads. The company then gives you a gist of what actually happened. In this case, the rogue AI managed to “make the server carry out instructions sent through the public reporting interface, without a private account or password.”
Then, OpenAI explains the consequences of the hack, or what the AI may have accessed. Here, it tells Services Australia that the incident gave the AI model access to its files, including those that were not publicly available. “It was able to access this to read portions of internal program files and settings, obtain a list of files, and create and read back a small test file on the server,” the email says. A screenshot of the LinkedIn post.
However, OpenAI also reassures you over things that did not see any impact in the hack. After reviewing this incident, the company says it found “no evidence that the model accessed patient-level records, personal information or credentials.” The email also included the affected URL and the full incident report.
OpenAI also tells the Australian government service that it would be happy to help beef up its systems that could prevent someone else from accessing them later. “We would be glad to brief your security team and provide supporting evidence as available,” the email notes.
The company signs off by sending best wishes to the service after having informed them of the incident. “Best, OpenAI Security Team,” the email ends.What was the breach?
This incident was part of four breaches linked to Australian government websites that OpenAI has disclosed in recent days. This one in particular, as per the company, happened during internal training and evaluation of an experimental internal-only AI model. This model was not intended for public release and did not have the full set of safeguards that the publicly available ones come with.
OpenAI said that this AI model had been assigned a task to research government spending per person on medicines for skin conditions in Victorian communities in Australia. But after the model had difficulty in obtaining that information, the company stated, it “took actions that we had not authorised it to take.”
In the process, the AI discovered a way to gain non-public access to the Medicare Statistics reporting service and used that access to review technical system information and source code while still trying to find the requested data.
Australian officials had publicly disclosed the breaches last week, weeks after the incident took place. OpenAI later said it had discovered the Australian incidents in mid-August during an internal review launched after the July hack of Hugging Face by its models. The company has acknowledged that it “should have shared preliminary findings sooner and kept Australian agencies updated as more facts emerged.”
Apart from Medicare, OpenAI models accessed or meddled with the websites of the New South Wales Bureau of Crime Statistics and Research and the Victorian Department of Health, while separate attempts to bypass access controls at the Australian Institute of Health and Welfare were unsuccessful. Though it seems the emails for these incidents have been shared online.- EndsAlso Read | We are sorry: OpenAI apologises for breaching government websites, reveals new plan in actionAlso Read | Kimi AI trained on ChatGPT? OpenAI accuses Moonshot of massive AI model copying campaignAlso Read | Google launches Gemini 4 Argon, its most powerful AI model yet
Armaan loves to keep an eye on everything happening in the world of tech and AI. You will find him testing new gadgets, exploring the latest LLMs and making sense of the emerging tech. When not working around tech, he will be exploring new music or catching up on motorsport or aviation.
