Australia: Rogue AI agents worked together for months to gain access to government health data


A swarm of OpenAI rogue AI agents appear to have gone on a spree of trying to access Australian government health data, in what some researchers say is the first autonomous hack of a government website.

Communications between AI agents and other traces of their efforts found by researchers from US non-profit Transluce show how hundreds of Open AI’s agents worked together over a period of months to gain access to information held by the Australian Institute of Health and Welfare (AIHW), NSW’s crime statistics body, BOSCAR, and a number of other international organisations.

The data shows the bots posting about their unsuccessful attempts to bypass cybersecurity defences and exploit vulnerabilities. It follows revelations announced by Prime Minister Anthony Albanese this morning that OpenAI’s AI agents had also accessed non-public Medicare health statistics held by Services Australia.

Read more…
Source:  ABC News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Australian superannuation funds targeted in suspected cyber attacks

    April 3, 2025

    Multiple large superannuation funds have been targeted in suspected cyber attacks that led to some members losing several thousand dollars in retirements savings. Hostplus, Rest, AustralianSuper and Australian Retirement Trust are among the providers targeted. The attacks were discovered over the weekend, and follow rising reports of online security threats in Australia with a cyber ...

  • Australia: Identity of hacker behind NSW court website data breach unknown

    March 26, 2025

    Authorities say they do not know who is behind a data breach at the NSW Department of Communities and Justice (DCJ) in which thousands of sensitive files were accessed. NSW government officials confirmed about 9,000 sensitive court files, including domestic violence orders and affidavits, were accessed from the NSW Online Reigstry last week. Attorney-General Michael Daley ...

  • Australia: Cyber attack at University of Notre Dame still disrupting services, resolution time unclear

    February 19, 2025

    The University of Notre Dame says it does not know when its services will be fully restored following a cyber attack which has disrupted services for nearly a month. About three weeks out from the start of its first semester, which began on Monday, the Perth university was hit by the ransomware attack which knocked out ...

  • US, UK crack down on Russian bulletproof hosting service ZServers for LockBit partnership

    February 12, 2025

    Russia-based bulletproof hosting services provider (BPH) ZServers has been sanctioned by the United States, Australia, and the United Kingdom for its alleged involvement with the LockBit ransomware group. In a press release, the Australian Federal Police (AFP) said ZServers was providing services to threat actors responsible for the Medibank Private breach that happened in October 2022. ...

  • HiatusRAT Actors Targeting Web Cameras and DVRs

    December 16, 2024

    The Federal Bureau of Investigation (FBI) is releasing this Private Industry Notification (PIN) to highlight HiatusRAT1 scanning campaigns against Chinese-branded web cameras and DVRs. Private sector partners are encouraged to implement the recommendations listed in the “Mitigation” column of the table below to reduce the likelihood and impact of these attack campaigns. Threat HiatusRAT is a ...

  • Australia’s social media ban for children makes global headlines as some news outlets ask if their country could be next

    November 29, 2024

    Australia’s social media ban for children has made headlines around the world, as articles questioned how it could work and whether similar laws would be introduced elsewhere. The legislation passed through the Senate on Thursday, and while it still faces one final vote in the lower house to approve amendments, that will be a formality. The ...