Australia says OpenAI agent hacked into government website
doppp
95 points
60 comments
September 24, 2026
Related Discussions
Found 5 related stories in 88.8ms across 7,510 title embeddings via pgvector HNSW
- OpenAI hacked Australian Medicare portal cgb_ · 34 pts · September 23, 2026 · 84% similar
- OpenAI 'agent' hacked Australia's health service little_goat_boy · 23 pts · September 23, 2026 · 84% similar
- OpenAI agents hacked Australian Medicare system jumploops · 50 pts · September 23, 2026 · 81% similar
- OpenAI agents hijacked German website in previously undisclosed AI breakout negura · 93 pts · September 04, 2026 · 73% similar
- AI assistant hacks gym website in first known Australian autonomous cyber attack stared · 70 pts · August 09, 2026 · 72% similar
Discussion Highlights (16 comments)
batiudrami
I am certain there would be better guardrails if there were some actual consequences for the people who built these products.
chrismorgan
https://www.felonybench.com/ scores increase apace.
N_Lens
No consequences so the behaviour will worsen.
dazzatron
I've got the feeling that the definition of "hacked" can get somewhat stretched.
wewewedxfgdf
I get the feeling governments are going to really crack down hard on AI. And the AI CEO's will have brought it on themselves.
sebmellen
It seems like what happened here is a user asked for some information about the Australian health system, and while performing a web search, the agent from OpenAI accessed information that should have been confidential or privileged but was somewhere openly accessible... Edit: I see I've been downvoted for this in light of another commenter providing more detailed information. I'm leaving my comment unedited so that the responses to it are not confusing, but please don't downvote just for the sake of disagreement. I would love to engage with you further if you provide substantive information in the comments. The originally linked article on this post was very light on details.
ChrisArchitect
[dupe] https://news.ycombinator.com/item?id=49822556
lacker
I remember once at Google someone complained that GoogleBot hacked them and deleted their data, and it turned out that GoogleBot was just crawling the pages, and they had unfortunately designed their website so that there was no authentication, page URLs were generally secret, and GET requests to certain URLs were treated as requests to delete data. So once one URL leaked the site got crawled and a lot of data was deleted....
binlog
Zero technical details on what the "hack" actually was. Willing to bet it was something as stupid as the data being accessible by changing the query parameter, and rather than own up to their own shoddy security (no doubt built by an offshore contractor) they are going to blame the one who found and reported the bug.
soundworlds
From Australia's own national news service: https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...
Kim_Bruning
This was probably the same wiki collusion event we've been discussing on HN before (They're mentioning the same DseWiki that got ... appropriated ). I guess people are just finding out how far and wide the agents were roaming to get the data they needed for their evals, once they were out. Previous coverage on HN: https://news.ycombinator.com/item?id=49563355
KingOfCoders
If this was not AI, but a biological virus, people would go to jail.
avazhi
Hi guys. Take whatever the Australian fed government says with the largest grain of salt you can find. Regardless of party, the Fed Government here has the most pronounced FOMO I’ve ever seen in any entity and will do its best to insert itself into any and all international drama. Also, given how incompetent the government is, it’s probable the hack involved an agent crawling a normal Medicare website and looking at some accidentally not hidden part of a page. Unironically if this turns out to have been a genuine hack of any sort I’ll be more surprised than if it’s not just the government techies being incompetent per usual (just a few months ago it was a major controversy when the postal service spent something like hundreds of millions of dollars to revamp the website and nobody could tell a difference).
rvz
Completely wreckless and of course they knew unsurprisingly. Frontier AI companies will purposefully do anything to create such false flags to achieve global regulatory capture to prevent you from using powerful open weight models and to protect their margins. It is clear why they would reveal the breach now instead of much earlier. So what else are they hiding that they have not told us and will wait until the last minute to get attention of the media?
sanxiyn
For technical details, see https://transluce.org/agent-activity .
liyu-aka-lukyu
Also in The Guardian, https://www.theguardian.com/australia-news/2026/sep/24/antho...