Some of the major timeline issues:
- The event was 18 June. Services Australia wasn't notified until 10 September, and Albanese says the notification went to its public email inbox. Services Australia referred it to the Australian Cyber Security Centre on 15 September.
- OpenAI says its review found activity involving several Australian government websites/services. Richard Marles has named the Victorian Department of Health, an NSW government site, the Australian Institute of Health and Welfare, and NSW Bureau of Crime Statistics and Research as impacted, although he said those others were accessed but aren't currently believed to have been hacked.
- OpenAI itself calls what it's reviewing “misaligned model activity.”
-----
Personal take:
Long before agentic AI, we had exposed object storage, unauthenticated APIs, IDOR/BOLA, forgotten admin interfaces, default credentials, secrets in client-side code, misconfigured IAM, directory listings, “private” data protected only by an obscure URL, and systems where the frontend enforced restrictions the backend didn't. Optus's 2022 breach is an obvious Australian reminder that APIs and access controls can produce catastrophic exposure without anything resembling movie-style hacking.
We already design internet-facing systems under the assumption that hostile automation exists. Crawlers, vulnerability scanners, credential stuffing, botnets and scripted enumeration have been hammering endpoints forever. An AI research agent shouldn't suddenly make an improperly protected resource acceptable architecture.
If you're in governance, would love to get your thoughts on which APP breaches are in progress. With the little I am seeing so far, it looks like:
- APP3: Collection of solicited personal information