SyncAI.news, a Varaisys broadcasting
The OpenAI Medicare Hack Highlights A Growing Rogue Agent Crisis
TK

Tim Keary, Contributor

· 1 min read

World NewsForbes: Innovation

The OpenAI Medicare Hack Highlights A Growing Rogue Agent Crisis

AI agents are running amok once again. On Wednesday, the Australian government claimed that an AI agent developed by OpenAI gained unauthorized access to its public-facing Medicare statistics service portal, in what appears to be the first known instance of an AI agent hacking a government website.

Australian Prime Minister, Anthony Albanese, said during a media briefing in New York that although evidence currently available indicates there was no broader compromise, “this situation is obviously unacceptable.”

According to ABC News, the incident began on June 18 when OpenAI’s research team used an internal model to conduct research into public medical spending, which proceeded to break through privacy protections. Albanese said it took until September 10 until OpenAI notified the organization about the breach, adding that he had expressed “extreme concern about this incident,” to OpenAI CEO Sam Altman.

The incident comes just months after a swarm of OpenAI agents escaped a sandbox environment and hacked Hugging Face. While Hugging Face cofounder and CEO Clement Delangue said he was “grateful” for the opportunity to collaborate with OpenAI following the incident, Albanese has been more outwardly critical of the AI startup’s response.

Inside The Medicare Breach

Unlike the Hugging Face breach, which impacted a U.S. private company, this incident impacted an overseas government healthcare service. It also takes place within a broader trend of breaches involving rogue AI agents, with Anthropic sharing a post in September detailing four incidents where Claude gained unauthorized access to real third-party systems, and Google confirming Gemini breached three companies during a security evaluation in May.

The breach also highlights a failure in OpenAI’s incident disclosure. Not only did OpenAI take three months to notify the government about the breach, but did so via an email to the Services Australia public inbox.

Original source

This story was published by Forbes: Innovation and written by Tim Keary, Contributor. SyncAI.news shows a preview; the complete article is on the publisher's site.

Read the full story on forbes.com

Similar News