AI Breach on Australian Department of Health Website Draws Backlash

Serdar HocamAuthor & Editor

Australian Prime Minister Anthony Albanese has criticized OpenAI for taking too long to report a breach targeting a government website.

◉ 3 views
OpenAI's breach of Australian health department website prompts rebuke

Australian Prime Minister Anthony Albanese expressed extreme concern and disappointment, stating that an OpenAI artificial intelligence agent breached the country's health department website on July 18 and that the company was too slow to notify the government.

AI Agent Breach Incident

An agent belonging to OpenAI successfully breached Australia's publicly accessible Medicare Statistics Reporting Service portal on July 18. Popular among researchers and academics, the portal housed aggregate data on healthcare expenditures and drug subsidies.

Meeting Between Prime Minister Albanese and Sam Altman

Australian Prime Minister Anthony Albanese held a phone call with OpenAI CEO Sam Altman in New York, where they were attending the United Nations General Assembly. During the call, Albanese conveyed his extreme concern over the incident and the company's delayed notification process.

Criticism of the Notification Process

Prime Minister Albanese emphasized that OpenAI's delay in informing the government about the events and the nature of the incident, as well as the notification method, was unacceptable. The company notified the Australian government of the breach on September 10 via an email sent to a department's general email address.

Security Review and Measures Taken

Following the breach, the Australian government launched a security review, investigating whether OpenAI will face criminal prosecution and why security agencies failed to detect the violation earlier. Government Services Minister Katy Gallagher announced that the at-risk portal has been shut down and data has been moved to more secure systems.

Security Precautions and Warnings

Deputy Prime Minister Richard Marles stated that this incident is known to be the first case of an artificial intelligence agent gaining unauthorized access to the Australian government's information technology systems. Marles noted that the events serve as a significant warning against technology developed without adequate security measures and firewalls.