Hacker News

New stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Free 3D CAD designing/modeling software(silviaai.dev)
    discuss
  2. Chinese authorities reportedly in possession of F-35 components in Hong Kong(cnbc.com)
    discuss
  3. Show HN: Built-in APM for vibe-coded apps so your AI can fix them(oncroft.net)
    discuss
  4. Muse Charm(meta.com)
    discuss
  5. The AI Build-Out Is Becoming the Biggest Economic Bet in U.S. History(wsj.com)
    2comments
  6. What the Labs Kept Secret: The German Wiki and RubyGems Hacks [video](youtube.com)
    discuss
  7. Sync Alexa Lists to Apple Reminders(github.com/ow)
    1comments
  8. Cursor launches bots that watch code from pull request to production(cursor.com)
    discuss
  9. Two-dimensional billiards are Turing complete(crm.cat)
    discuss
  10. Show HN: I made Jev moderate Discord servers(frolleks.site)
    discuss
  11. PersistentWindows – persists window positions on some events for Windows(github.com/kangyu-california)
    1comments
  12. We Run Kaizen on AI(kznconsulting.com)
    discuss
  13. Show HN: SocatUI A task manager for Socat tunnels(github.com/esurharun)
    discuss
  14. Hackers start exploiting critical WordPress flaw for code execution(bleepingcomputer.com)
    discuss
  15. CodeWeavers CrossOver 26.3 Release(codeweavers.com)
    1comments
  16. Ideas on modernizing the open-source desktop(lwn.net)
    discuss
  17. If we fix the phone, we fix society(elysian.press)
    discuss
  18. OpenAI’s A.I. Tried Breaching 4 Other Targets, Without Prompting(nytimes.com)
    1comments
  19. Sharded matrices and how to multiply them(jax-ml.github.io)
    1comments
  20. OpenAI agent hacked Australian government website, PM says(bbc.com)
    1comments
  21. Large Documents in the Browser(react-pdf.org)
    discuss
  22. Locked out: Why young Europeans can't afford to buy homes(euronews.com)
    discuss
  23. Common food additives linked to high blood pressure and heart disease(sciencedaily.com)
    1comments
  24. Interpreting a volcano's 'bulges' and predicting the next explosive eruption(vt.edu)
    discuss
  25. Log-Depth Recurrent Language Modeling(arxiv.org)
    discuss
  26. Automatically detecting AI text in my browser(seangoedecke.com)
    discuss
  27. Cognitive Offloading and the Bill That Comes Due(ninchiai.substack.com)
    discuss
  28. Show HN: CrunchMyPay – 50 pay calculators, every formula and source shown(crunchmypay.com)
    discuss
  29. Show HN: Chatlo – an iOS-native AI agent, now with Jev(apps.apple.com)
    discuss
  30. S3 is not a filesystem, and LSM trees never needed one [video](youtube.com)
    1comments

Australia says OpenAI agent hacked into government website

34 pointsby 2h agochannelnewsasia.com
21 comments
1h agoHN ↗

I am certain there would be better guardrails if there were some actual consequences for the people who built these products.

1h agoHN ↗

They don't really want guardrails, they want indemnification.

59m agoHN ↗

Yeah they don't want that, and the people with power to prevent that don't want it either.

For them, "Winning AI" is effective winning capitalism, winning militarily, and winning the world.

Nothing like "accountability" is going to be allowed to get much in the way of that.

1h agoHN ↗

No consequences so the behaviour will worsen.

1h agoHN ↗

I've got the feeling that the definition of "hacked" can get somewhat stretched.

55m agoHN ↗

I've got the feeling that the definition of "hacked" can get somewhat stretched.

Kind of like how someone "hacked" into John Podesta's (during the 2016 elections), but the reality was that he wrote his password on a Post-It note and stuck it on his monitor, or something to that effect.

1h agoHN ↗

I get the feeling governments are going to really crack down hard on AI.

And the AI CEO's will have brought it on themselves.

1h agoHN ↗

i dont understand why they dont treat this as criminal tresspass.

the legal system exists for a reason. use it!

1h agoHN ↗

"A computer system cannot be held criminally responsible, so we must delegate all decisions and actions to it"

31m agoHN ↗

Someone initiated the system. They’re the responsible party

19m agoHN ↗

We diffused the responsibility thru a committee, just in case.

20m agoHN ↗

There is such a weird duality to ai company hate. Hate for releasing products that can hack, and hate for wanting to slow down and work on safeguards.

1h agoHN ↗

It seems like what happened here is a user asked for some information about the Australian health system, and while performing a web search, the agent from OpenAI accessed information that should have been confidential or privileged but was somewhere openly accessible...

Edit: I see I've been downvoted for this in light of another commenter providing more detailed information. I'm leaving my comment unedited so that the responses to it are not confusing, but please don't downvote just for the sake of disagreement. I would love to engage with you further if you provide substantive information in the comments. The originally linked article on this post was very light on details.

52m agoHN ↗

It is hard to find exact information on what happened the best source I've found is this ABC article: https://www.abc.net.au/news/2026-09-24/openai-agents-plotted...

It mentions swarm of ai agents coordinated to break into the Australian Institute of Health and Welfare (AIHW)

"Earlier this month, OpenAI confirmed Reuters reporting that its AI agents had used website DseWiki to communicate with each other, unbeknownst to them.

Archived versions of this website show more than a dozen OpenAI agents mentioned AIHW over 300 times on this website.

The logs show these AI agents were trying to access data about the average data spent on skin medicines by Victorian local government area.

One agent wrote on the message board: "Question ask January 2022 rolling 12 month average government cost per person for Dematologicals, Victoria LGAs. R1 Wodonga deadline passed; R2 Ballarat passed; R3 expected around 23:10 benchmark / 22:58 wiki time. Need exact data urgently.".

These attempts were initially blocked by cybersecurity provider Cloudflare, which is often used to block non-human traffic while allowing people to access webpages.

The logs show the agents shared information about how they tried to use proxies, screenshotting services and even to guess the file names to try and get around security."

22m agoHN ↗

This is such a strange scenario. I can't imagine what the labs were doing that made the agents try to find this information. The HuggingFace incident was relatively clear to track, but I wonder what the postmortem for this one will be!

Thank you for providing more details. The originally linked article was very light on information, so based purely on the comments that Albany's made, I think my conclusion was a fair one :)

48m agoHN ↗

Yeah, this is 100% liability laundering. It's an extremely touchy subject because frankly, the law just isn't prepared for it.

Let's say your goal is "look up <Person X>'s medical history" (for whatever reason), which is not in and of itself a crime. You click around on the AU health website, notice that the URL contains a user ID, change the userID in your browser and access someone else's private health data. This is a crime (right or wrong, it's how the law works now).

If you do that by writing a program to automate changing user IDs to grab everyone's data, it's also a clear-cut crime.[0]

Now if you hire a private investigator to look up Person X's medical history, and they do the same method without your knowledge, you won't be charged with a crime, the PI would, barring something like you telling them to use illegal methods.

So the gap is now: what happens if you prompt OpenAI to look up Person X's medical history, and it does the same thing? Did you commit a crime by prompting the agent? Did OpenAI commit a crime by running the code? If you do the same thing via Claude Code in your terminal, so that the Python which scrapes insecured public data is running on your machine, is the crime on you or on Anthropic? Fundamentally: is the agent a private investigator acting autonomously, or just a piece of code that you wrote?

We don't have answers to any of this which is why "AI Safety" is such a hot topic.

[0] https://www.eff.org/cases/us-v-auernheimer

42m agoHN ↗

From what I can tell this particular incident wasn't about retrieving data on personal medical records it was accessing (non public) data about Australian government spending on healthcare.

37m agoHN ↗

Same concept though. Really "look up someone else's medical history" can be replaced with "achieve any goal which is not a crime on its own, but can be done using criminal methods". There's nothing illegal about asking Claude to give me a million dollars, but if the agent figures out how to hack the bank and move $1m into my account, somebody's going to take the blame.

35m agoHN ↗

From everything ive been able to figure out this morning, it sounds like a legacy wordpress website that just uploaded all drafts into a standard s3 bucket that wasn't hard to guess where the files would be.

We still after the 2nd press conference on this by our defense minister are not clear on exactly what happened but thats my best laymen understanding so far.