Get all your news in one place.
100's of premium titles.
One app.
Start reading
The Guardian - AU
The Guardian - AU
Technology
Josh Taylor and Josh Butler

Revealed: the five-paragraph email OpenAI used to inform Australia about agent attack

Prime minister Anthony Albanese (left) and OpenAI CEO Sam Altman.
Prime minister Anthony Albanese (left) previously said he had expressed ‘Australia’s extreme concern about the incident’ to OpenAI CEO Sam Altman. Photograph: Getty Images

OpenAI has apologised to Australians for its agent attack on Medicare, and will front parliament next week as the tech company revealed more details about its June hack of Australian government websites.

Ministers on Tuesday evening released a brief, five paragraph email which OpenAI used to inform the Australian government about the attack. The email was sent to a public inbox monitored by Services Australia on 10 September – nearly three months after the AI agent accessed the website on 18 June – and was signed off with the closing “best”.

The Labor government has publicly voiced its fury at the manner in which OpenAI disclosed the incident. The email itself, obtained by Guardian Australia, advised Services Australia that “an OpenAI model identified a way to make the server carry out instructions sent through the public reporting interface, without a private account or password”.

It comes as OpenAI’s Medicare breach prompted a government-wide assessment of cyber systems to bolster Australia’s public sector against further AI threats – deliberate or not.

Home affairs directed all government departments and agencies to undertake a “rapid” stocktake of legacy systems, to formulate risk management for legacy technology and to report their compliance back to the department.

The directive prioritises systems of government significance – the government’s critical systems – with a review due by the end of the year, while other systems will be assessed by March.

The acting home affairs minister, Richard Marles, said AI is “changing the environment in which we operate at extraordinary speed.”

“We can’t wait for an old system to fail before replacing it. We need to identify vulnerabilities and deal with them before they can be exploited.”

In a blog post released on Tuesday morning (AEST), OpenAI said it should have handled its response to the hack better.

“We also should have handled our response better. We are sorry and working to do better in the future.”

The company also provided more detail on the incident revealed by the Australian prime minister, Anthony Albanese, last week.

OpenAI said it became aware of agent activity on Australian government websites in mid-August after the company reviewed earlier training incidents after the Hugging Face attack in July.

The agents gained non-public access to a Services Australia portal for Medicare statistics, and OpenAI said the agent was able to run commands, retrieve internal files, credentials, and write files, but no patient or client records were accessed.

OpenAI’s email to Services Australia pointed the government to the “affected URL”, a Medicare statistics page on the human services website, as well as specifying an “affected report” – a CSV file, commonly used for spreadsheets.

“We recommend that the team responsible for the service investigate the vulnerability and assess the changes needed to prevent it. We would be glad to brief your security team and provide supporting evidence as available,” OpenAI wrote.

“Best, OpenAl Security Team”.

OpenAI was contacted for comment.

The NSW Bureau of Crime Statistics and Research’s public crime mapping tool was also accessed, with application configuration, operational jobs and logs and website metadata provided to the agency.

The agent discovered an exposed access key to query the Victorian agency for health information’s reporting system to access aggregate survey statistics.

For the Australian Institute of Health and Welfare, OpenAI agents retrieved aggregate statistics, but separate attempts to bypass access controls were unsuccessful and the information obtained was publicly available.

Services Australia and the Victorian health department were informed on 10 September, while the NSW bureau of crime statistics was informed on 18 September.

The Australian Institute of Health and Welfare was not informed until 24 September, as OpenAI deemed it did not meet disclosure thresholds.

“Since then we’ve worked closely with Australian government agencies to share what we’ve learned to date,” OpenAI said. “If we identify any additional affected agencies, we will notify them promptly and directly with the information available and provide updates as further facts emerge.”

The incident occurred after one model was tasked to research government spending per person on medicines for skin conditions in Victoria. The model had difficulty obtaining that information, and OpenAI said “it took actions that we had not authorised it to take” including accessing Services Australia’s Medicare statistics reporting service.

OpenAI said it would commit resources and expertise to affected agencies, and provide Australian government agencies with support to build cyberdefences on critical infrastructure.

Australian government agencies and industries will also be given credits out of OpenAI’s US$1bn (AU$1.4bn) Daybreak fund, which lets those organisations use frontier AI for cyberdefence, and to harden their systems by reviewing code and system configurations for potential vulnerabilities that can then be patched.

The company said it would also establish a taskforce with Australian expertise to develop practical policy recommendations on managing risk with AI agents.

OpenAI’s chief strategy officer, Jason Kwon, will appear at the joint select committee on AI on Tuesday 6 October. Guardian Australia reported on Monday that Anthropic would also appear at this hearing, but not at a Senate inquiry into AI and datacentres this week.

Albanese, who was in the United States last week when he announced the hack, said at the time he had spoken with OpenAI’s chief executive, Sam Altman, “to express Australia’s extreme concern about this incident”.

On Tuesday, Albanese said OpenAI had been “very constructive and open in engaging” since the incident, as had Anthropic. He said AI can improve economic growth and productivity but it also carries risks.

“And we’ve seen those risks exposed – not just in what occurred in Australia, but the revelation that has occurred in the United States and other countries as well.”

The federal government has flagged it could introduce mandatory reporting rules for AI-related data breaches, after the revelation OpenAI used a public-facing email address three months after the hack to report the incident to Services Australia.

The company said on Tuesday it had “a lot of work ahead” to rebuild trust with Australians but said it was making “meaningful changes”.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.