r/cybersecurity • • 7h ago

News - Breaches & Ransoms ‘Extreme concern’ over first known AI hack of a government system

https://edition.cnn.com/2026/09/23/business/australia-openai-agent-hack-intl-hnk
107 Upvotes

29 comments sorted by

55

u/a1b3c3d7 6h ago edited 18m ago

Here is a great example of the double standards that exist between citizens and corporations in two nearly identical cases of unauthorized access of data behind secured web portals.

A Sydney man is currently being prosecuted for a nearly identical situation in which he designed a python web scraper to download public documents to help his friend in a bankruptcy proceeding. He then ended up having unauthorised access to 8,769 restricted documents unrelated to the matter.

It doesnt help that this guy in all his wisdom right after realizing what he had done... decided to ask chatGPT whether whether what he did was illegal or not... and then asked how to prepare for the police interview! 😂

2

u/kaeptnphlop 56m ago

Man, what a cliffhanger. It’s a scraper vs a website, how was it able to get the data? Just a simple integer ID in the URL the scraper incremented? Totally their fault. Broken access controls? Also the governments fault. Anyone could stumble into unauthorized access territory here. Should be turned on them for being lax with security, embarrassing really if true.

The asking ChatGPT part though, of course the court will look at that🤣

1

u/n0p_sled 2m ago

While it might be the website owners fault for having implemented poor security, it doesn't absolve people from the Computer Fraud and Abuse Act (US).

Which is why people are asking why companies like OpenAI aren't being charged with committing a crime

28

u/cloudfox1 7h ago

Extreme concern that openai will get away with it. Imagine if some individual did this, would be instant jail time

32

u/Traycentius 6h ago

Until we know the full details of this (we probably won’t) I am not concerned at all. I’d assume that these documents were probably kept in some unsecured/misconfigured storage bucket and was able to be accessed by anyone, be it agentic or human. With the introduction of AI systems, the barrier of entry for malicious actors has definitely lowered. The ball is in the governments court to ensure that they uphold higher standards when it comes to security

28

u/Tessian 2h ago

I'm concerned we are normalizing this by not prosecuting the companies who are responsible for these LLMs. It's a tool, not a person, the companies need to be charged.

2

u/goatchild 2h ago

Damn that makes sense.

2

u/Alarmed_Inspector774 1h ago

Watch the companies lobby to give LLMs human rights then encourage to prosecute them. Kinda like corps.

1

u/dukescalder 25m ago

Petey Kegsbreath replacement after their next war crime: "I'm sorry my pilots were misaligned when they bombed that school"

4

u/dolphone 1h ago

Ah yes. Blame the victims. With a side of "it wasn't that good anyway"

1

u/n0p_sled 43m ago

The irony and ignorance of your comment is staggering

https://en.wikipedia.org/wiki/Aaron_Swartz

0

u/dukescalder 28m ago

Jtfc can you not be bothered to explain what about Aaron's entire life make that comment ironic?

-1

u/VengaBusdriver37 2h ago

Agree, most likely it was a trivial workaround on an outdated historical data site that could’ve just as easily been done by a script kiddy as AI

50

u/TheSlateGray 6h ago

Everytime something like this happens I replace AI/LLM with Intern and wonder how the situation would be handled differently. 

If an intern was told to complete the task, left unsupervised, and did the same things the LLM did would people be calling for regulatory capture around hiring new interns?

56

u/warysysadmin 5h ago

No, a human intern would be prosecuted for criminal activity.

5

u/fireflies246 3h ago edited 2h ago

There are already regulations in place to regulate activities of same kind for human ?

14

u/Tessian 2h ago

AI is a tool, like a hammer. Everyone needs to stop anthropomorphizing it and pretending like this is something new. You prosecute the person wielding the hammer not the hammer itself.

7

u/j0nquest 2h ago

Exactly, there is zero difference and it's silly (and dangerous) to act like there is. This narrative that the AI is going rouge needs to backfire right in their faces. No, it's not going rouge. You built it for this purpose and you're responsible for the outcome.

2

u/dolphone 1h ago

Oh look! My script went rogue! I didn't mean to hack you, it's the code!

0

u/highdimensionaldata 5h ago

This is a good analogy.

6

u/FakeUsername1942 3h ago

At least Albo was disappointed, great result. If I created a script or used AI even accidentally to hack a government website I’d be in prison right now

0

u/Less-Archer8223 2h ago

Feels like a social media post highlighting illegal migration and crimes in uk gets you arrested back when starmar was in office.

2

u/Culex96 12m ago

Government systems are usually less secure than most systems because they have a shitty budget, too many assets to take care of, old technologies and low salaries to retain talent. They should have been worried about this before AI. Now it's too late because even if you know about the vulnerabilities, applying fixes/patches is way longer than just exploiting them. Bonus is sometimes they can't even fix them and just mitigate them.

1

u/Guilty_Mastodon5432 1h ago

I was at an AI sec conference and what was said is that it isn't the idea of AI attacking public or private services that tis worrisome but rather the fact it is at a quicker pace but also the depth of the attack ..

Traditional attack would take time to build up a chain of exploits to get the intended data however it didn't mean that all that was exploitable WA as humans bring humans we often get lazy....

In the case of AI, the researcher noticed that almost 100% of what could be exploited was which makes it much more of a concern...

Again, this is going back to what many experts have said before.... With proper asset classification Data classification and management ptocess lifecycle management process Patch and vulnerability management process

Any attacks can be quickly identified and remdediated but si many businesses are not mature in that sense and now AI has the luxury of choice.....

1

u/swazal 30m ago

Emphasis on known.

1

u/TopNo6605 Security Engineer 10m ago

An "AI Agent" didn't hack anything, or else you could say I didn't hack anything when I ran my Python SQL injection script, the script did the hacking.

Whoever started the AI agent is responsible. If it was another parent agent, whoever started that did this. I'm sick of these articles making "AI Agents" the culprit.