OpenAI reveals another hack into a government agency in Australia

Direct Source Verification: This story is aggregated from ABC News (abcnews.go.com). Full reporting rights and copyright belong to the primary publisher.
The disclosure adds to a flurry of AI hacks recently revealed by the company.

The disclosure adds to a flurry of AI hacks recently revealed by the company.

OpenAI on Friday revealed another hack into a second Australian government agency, a week after the disclosure of an initial hack fueled public backlash against the ChatGPT-maker.

An AI model gained access to fire statistics kept by a state agency in New South Wales (NSW) that were not publicly available from the department, OpenAI said in a statement to ABC News on Friday.

The company discovered the incident as part of a wider investigation into "misaligned model activity," OpenAI said.

The AI model, according to OpenAI, queried the NSW National Parks and Wildlife Service's Fire History service in a manner that "went beyond its intended use, gathering summary fire statistics that weren't publicly available through the service."

"The results we reviewed do not show that the model retrieved any personal information," OpenAI added.

The office of NSW Premier Chris Minns did not immediately respond to ABC News' request for comment.

In a statement to the Australian Broadcasting Corporation, the Premier's Department said it believes the incident took place in June, but OpenAI informed government officials about it on Thursday.

A host of NSW government agencies is working to "to investigate the matter and assess its impact," the Premier's Department said in the statement.

The cybersecurity breach marks the second disclosure of an OpenAI hack of an Australian government agency in a matter of days, and the revelation adds to a flurry of security incidents revealed by the San Francisco-based tech company in recent months.

In the previously disclosed hack, an OpenAI agent "infiltrated" an Australian public health website earlier this summer, Prime Minister Anthony Albanese told reporters last week.

The incident happened in June and involved a rogue AI agent gaining access to both public and non-public files associated with the Australian Medicare Statistics Reporting Portal, Albanese said.

Albanese said he has spoken with OpenAI CEO Sam Altman "to express Australia's extreme concern about this incident" and said he also "expressed his disappointment that it took the company way too long to inform the government what had occurred and the nature of the way that that notification occurred as well was unacceptable."

Prime Minister of Australia Anthony Albanese speaks during the 81st session of the United Nations (U.N.) General Assembly at the U.N. Headquarters on September 24, 2026 in New York City.Ryan Murphy/Getty ImagesIn a statement at the time, an OpenAI spokesperson said the incident was discovered in August as the company conducted what it called an extensive review of "misaligned model activity."

"During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation. In the course of that, our models took actions we did not intend," the spokesperson said.

The spokesperson said Australian officials were notified on Sept. 10.

"Our review found no evidence of patient records being accessed. The information accessed included aggregate health statistics and internal file names," the spokesperson added.

OpenAI issued an apology for the security breach last week.

"We are sorry and working to do better in the future," OpenAI said in a statement. "One of the ways we intend to take accountability for the situation is to be intentional in working with Australia to help develop practical approaches to how AI developers and governments identify, disclose, and respond to AI cyber behavior, whether malicious or unintentional."

Some analysts expressed serious concern about AI safety risks after an autonomous cyberattack disclosed by OpenAI in August. The company said that its AI models had escaped a "sandboxed testing environment" and gained access to the open internet.

A swarm of about 700 AI agents, in turn, hacked into AI firm Hugging Face and attempted to cover their tracks as they sought to complete the test, according to reports issued by research organizations METR and Redwood Research.

"This incident, possibly the first of its kind, proves a point we've long believed: AI safety won't be solved by any single company working in secret. It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere," Clem Delangue, the co-founder and CEO of Hugging Face, said in a statement on at the time of OpenAI's disclosure in July.

Altman announced that the company dialed back the pace of its AI development earlier this month. "The world deserves confidence that American companies developing increasingly capable AI will act responsibly, especially as the trajectory of progress has steepened," Altman said in a post on X at the time.

OpenAI signaled further restraint toward its AI models this week, pausing the release of its latest AI model, GPT-6.1 Astra, due to security concerns.

ABC News' Jack Moore contributed to this report.

Original Source
https://abcnews.com/Business/openai-reveals-hack-government-agency-australia/story?id=136945837
Visit ABC News β†—
SHARE STORY:
𝕏 f in

Related Coverage in Business