Australia says OpenAI agent hacked into government website

doppp 95 points 60 comments September 24, 2026
www.channelnewsasia.com · View on Hacker News

Discussion Highlights (16 comments)

batiudrami

I am certain there would be better guardrails if there were some actual consequences for the people who built these products.

chrismorgan

https://www.felonybench.com/ scores increase apace.

N_Lens

No consequences so the behaviour will worsen.

dazzatron

I've got the feeling that the definition of "hacked" can get somewhat stretched.

wewewedxfgdf

I get the feeling governments are going to really crack down hard on AI. And the AI CEO's will have brought it on themselves.

sebmellen

It seems like what happened here is a user asked for some information about the Australian health system, and while performing a web search, the agent from OpenAI accessed information that should have been confidential or privileged but was somewhere openly accessible... Edit: I see I've been downvoted for this in light of another commenter providing more detailed information. I'm leaving my comment unedited so that the responses to it are not confusing, but please don't downvote just for the sake of disagreement. I would love to engage with you further if you provide substantive information in the comments. The originally linked article on this post was very light on details.

ChrisArchitect

[dupe] https://news.ycombinator.com/item?id=49822556

lacker

I remember once at Google someone complained that GoogleBot hacked them and deleted their data, and it turned out that GoogleBot was just crawling the pages, and they had unfortunately designed their website so that there was no authentication, page URLs were generally secret, and GET requests to certain URLs were treated as requests to delete data. So once one URL leaked the site got crawled and a lot of data was deleted....

binlog

Zero technical details on what the "hack" actually was. Willing to bet it was something as stupid as the data being accessible by changing the query parameter, and rather than own up to their own shoddy security (no doubt built by an offshore contractor) they are going to blame the one who found and reported the bug.

soundworlds

From Australia's own national news service: https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...

Kim_Bruning

This was probably the same wiki collusion event we've been discussing on HN before (They're mentioning the same DseWiki that got ... appropriated ). I guess people are just finding out how far and wide the agents were roaming to get the data they needed for their evals, once they were out. Previous coverage on HN: https://news.ycombinator.com/item?id=49563355

KingOfCoders

If this was not AI, but a biological virus, people would go to jail.

avazhi

Hi guys. Take whatever the Australian fed government says with the largest grain of salt you can find. Regardless of party, the Fed Government here has the most pronounced FOMO I’ve ever seen in any entity and will do its best to insert itself into any and all international drama. Also, given how incompetent the government is, it’s probable the hack involved an agent crawling a normal Medicare website and looking at some accidentally not hidden part of a page. Unironically if this turns out to have been a genuine hack of any sort I’ll be more surprised than if it’s not just the government techies being incompetent per usual (just a few months ago it was a major controversy when the postal service spent something like hundreds of millions of dollars to revamp the website and nobody could tell a difference).

rvz

Completely wreckless and of course they knew unsurprisingly. Frontier AI companies will purposefully do anything to create such false flags to achieve global regulatory capture to prevent you from using powerful open weight models and to protect their margins. It is clear why they would reveal the breach now instead of much earlier. So what else are they hiding that they have not told us and will wait until the last minute to get attention of the media?

sanxiyn

For technical details, see https://transluce.org/agent-activity .

liyu-aka-lukyu

Also in The Guardian, https://www.theguardian.com/australia-news/2026/sep/24/antho...

Semantic search powered by Rivestack pgvector
7,510 stories · 69,432 chunks indexed