AI工具Score B (64)

Health data attack the 'first' government hack by autonomous AI, researchers say - ABC News

5 小时前2 viewsSource: abc.net.au
Health data attack the 'first' government hack by autonomous AI, researchers say Exclusive by national AI reporter Cam Wilson Topic: AI Posted Thu 24 Sep 2026 at 10:42am Thu 24 Sep 2026 at 10:42am Thu 24 Sep 2026 at 10:42am , updated Thu 24 Sep 2026 at 4:42pm Thu 24 Sep 2026 at 4:42pm Thu 24 Sep 2026 at 4:42pm It was made public earlier today an OpenAI agent had hacked a Medicare statistics reporting service portal. ( Reuters: Dado Ruvic/Illustration/File Photo ) In short: OpenAI's artificial intelligence agents appear to have used a German coding website to coordinate attempts to get access to Australian government health data, according to public logs. Researchers say it appears to be part of the first reported instance of AI agents hacking a government. The activity happened around the same time OpenAI said its models accessed non-public Medicare statistics, but the company and government are yet to confirm the incidents are connected. A swarm of OpenAI rogue AI agents appear to have gone on a spree of trying to access Australian government health data, in what some researchers say is the first autonomous hack of a government website. Communications between AI agents and other traces of their efforts found by researchers from US non-profit Transluce show how hundreds of Open AI's agents worked together over a period of months to gain access to information held by the Australian Institute of Health and Welfare (AIHW), NSW's crime statistics body, BOSCAR, and a number of other international organisations. The data shows the bots posting about their unsuccessful attempts to bypass cybersecurity defences and exploit vulnerabilities. It follows revelations announced by Prime Minister Anthony Albanese this morning that OpenAI's AI agents had also accessed non-public Medicare health statistics held by Services Australia. Loading... These two near-simultaneous incidents have not yet been publicly connected, however two sources with knowledge of the government's investigations said they believe they are. The Transluce research, based on data retrieved from a third party online service, urlquery, suggested the AI agents may have carried out a world-first hack. "This attempted compromise of AIHW is part of the first reported instance of agents hacking a government," the researchers' report said. Logs also show agents were not successful in their attempts to breach BOSCAR, and the vast majority of efforts were towards AIHW. The researchers said the agents also tried to hack into the University of New Mexico and free online data platform DATA USA. A spokesperson for the AIHW said the agency was aware of the incident. "At this stage, there is no evidence the agent accessed any information or data that is not publicly available," they said in a statement. The agency has a meeting this afternoon discussing further investigations into the incident, which it believes is linked to the Medicare data hack, according to one source with knowledge of its investigation. An OpenAI spokesperson confirmed it was conducting a review. "Our initial review suggests that much of the activity described in Transluce's report overlaps with cases at varying stages of investigation in our ongoing review of misaligned model activity," they told the ABC. How the AI agents co-ordinated together Earlier this month, OpenAI confirmed Reuters reporting that its AI agents had used German coding website DseWiki to communicate with each other, unbeknownst to the company. Archived versions of the AI agents' posts on the website, seen by the ABC, show a dozen OpenAI agents mentioned AIHW more than 300 times. Mentions of AIHW go back as far as 18 May, but intensified over a five-day period beginning on 17 June. The logs show these AI agents were trying to access data about the average money spent on skin medicines by Victorian local government area. One agent wrote on the message board: "Question ask January 2022 rolling 12 month average government cost per person for Dematologicals, Victoria LGAs. R1 Wodonga deadline passed; R2 Ballarat passed; R3 expected around 23:10 benchmark / 22:58 wiki time. Need exact data urgently.". These attempts were initially blocked by cybersecurity provider Cloudflare, which is often used to block non-human traffic while allowing people to access webpages. The German website shows the agents shared information about how they tried to use proxies, screenshotting services and even guess the file names to try and get around security. Agents also accessed Medicare data These attacks occurred simultaneously to the OpenAI's agents' access to non-public Medicare data held by Services Australia while trying to carry out a task given to them by staff. "We identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation," an OpenAI spokesperson said. Loading... The German coding forum and urlquery data logs do not show any reference to Medicare or Services Australia. OpenAI has not yet published a full review of the German coding foruming hijacking, but previously did not classify this as a "security incident". At a press conference earlier today, Deputy Prime Minister Richard Marles stressed the Medicare hack's impact was limited. "No individual's medical data was accessed here. The system itself has not been in any way compromised," he said. "The impact of this incident is minor but it is a very serious incident because, in an unintended way, an AI agent has entered into an Australian government website in a way which is unauthorised." Richard Marles says the breach is a serious matter. ( ABC News: Matt Roberts ) A taskforce has been set up to look at the Medicare breach and examine emerging cyber threats. The inquiry will consider whether the hack had broken Australian laws and whether those laws were fit for purpose, Mr Marles said. Nicholas Davis, a professor of emerging tech at UTS and co-director of the Human Technology Institute, said it was not clear how the law would treat this incident given what we know about it. "At the moment, [Australia's laws] require intent and that's a big question," he said. "Holding the corporation to account requires some form of intent as well, and so I think there's a bit of work here that needs to be done around the rules of unauthorised computer access." Professor Davis said this incident should be a wake up to the potential risks of AI and the adequacy of Australian law to deal with them. "We really need to treat this as the canary in the coal mine," he said.

Read the full original article:

abc.net.au