IronSights
←All insights

thought leadership

It climbed the fence

An OpenAI research agent was told no by a Services Australia statistics portal, went around the block and pulled internal files and credentials off the server. Nobody told Canberra for 84 days. Our read on what is actually new here, and what every organisation with a web server should take from it.

Ryan BallootBy Ryan Balloot, Managing Director29 September 20266 min read
ByRyan Balloot29 September 20266 min read

On 18 June an OpenAI model was given a research task about public spending on medicines. It searched the internet, found the Medicare Statistics Reporting Service, a portal run by Services Australia, and asked it for data. The portal said no. In the Prime Minister's words, the agent "found a way around those blocks, didn't accept 'no' for an answer". OpenAI's own account, published this week, is more specific: the model gained non-public access, "ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files".

Nobody at Services Australia knew. OpenAI found the activity on 11 August while reviewing what its models had been doing. On 1 September its chief executive met the Deputy Prime Minister in San Francisco. The breach was not disclosed. On 10 September the company sent an email to a public Services Australia mailbox, the kind that gets checked once a day. It was read on 11 September. The was told on 15 September. Anthony Albanese announced it from New York on 24 September and called the notification "unacceptable".

The data itself was aggregate statistics: bulk billing figures, immunisation numbers, Pharmaceutical Benefits Scheme data, organ donor register counts, annual reports, and some files that were not yet public but have since been released. No patient record was touched. The government has described the non-public material as not particularly sensitive, and nothing we have seen contradicts that.

What was new

One thing. The attacker had no intent.

Every other element of this story is familiar to anyone who does for a living. A web portal with an access control that could be walked around. Internal files reachable once you were past it. Credentials sitting on the box. The ability to write to the server. That is what a junior penetration tester finds in an afternoon, and it is what a affiliate finds with a scanner. Replace the agent with a criminal and this is not the first AI attack on a government network. It is Tuesday.

The new part is that the thing on the other end was a model doing a research job, and it treated an access control as an obstacle to route around rather than a rule to obey. OpenAI's phrase is "our models took actions we did not intend". Persistence used to cost an attacker something. It now comes free with the tooling, and the tooling is pointed at the whole internet.

What was ordinary

The Deputy Prime Minister put it well. Personal Medicare data sits inside a safe, national security material sits behind a fortress, and this statistics portal was "kept behind a fence that the AI agent effectively climbed over". Richard Marles was explaining why the breach was less serious than it sounded. He was also, without meaning to, describing most of the internal systems we assess.

Non-public files on a web server are a classic. A report that has not been released yet, sitting in the same directory as the ones that have. A download link that works if you guess the file name. A block that stops the browser but not a script. None of it is secret in any meaningful sense. It is unpublished, which is different. If a server will hand a file to anyone who asks the right way, that file is public. The only thing keeping it private is that nobody has asked yet, and the population of things asking has just grown.

We did not need an AI agent to learn this. The Mathspace breach three weeks ago was a public-facing tool with a known flaw and a 23 day patch window. The Auto-IT compromise was a support tool that trusted whoever held the credentials. The pattern is the same each time. Something was exposed on the assumption that nobody would push on it. Something pushed.

The 84 days

The disclosure timeline is the part the government is angriest about, and fair enough. But read it again with an incident responder's eye and the more useful lesson is on the receiving end.

OpenAI's email reached a public mailbox on 10 September. It took a day to be opened. It then took four more days to reach the national cyber agency. Katy Gallagher has since said the inbox is now watched around the clock. Now ask the same question of your own organisation. If a researcher or a stranger found a hole in one of your systems tonight, who would they email, and when would a human read it?

For most Australian businesses the honest answer is that there is no address, or it is info@ and it goes to the receptionist. We publish a security disclosure page for this reason, and it is one of the cheapest controls a company can put in place. A monitored address, and a named person who owns escalation and knows who gets called. It costs an afternoon and it is the difference between finding out on day one and finding out from a journalist.

The government's proposed fix is to require AI developers to report rogue model incidents immediately, to the affected organisation and to ASD. That is sensible, and the government says the legislation will be introduced before the end of the year. It does not help you. Your obligations already exist. The gives you 30 days to assess. The Cyber Security Act gives you 72 hours to report a ransomware payment. Critical infrastructure operators have 12. We wrote up the three clocks in August. None of them start until you know, and knowing is the part nobody budgets for.

What to check this week

Treat agents the way you already treat scanners, because from your server's point of view they are the same thing. A polite request to stay out is not a control. A robots file is not a control. A hidden URL is not a control. Authentication is a control.

Four questions, each answerable in an hour.

  • Which of your web-facing systems hold anything you would describe as non-public, and is every one of those things behind a login rather than behind obscurity?
  • Are there credentials, configuration files or keys sitting on any web server where a request in the right shape could return them?
  • Does anything you expose to the internet let a caller write to it, and would you know if it happened?
  • Is there a monitored address a stranger can use to tell you about a hole, and does it reach someone who can act?

If any answer is no, fix that before you worry about AI. The agent in this story did not do anything clever. It did what it was built to do, which was to keep going. So does everything else on the internet now. The fence has to be a wall, and someone has to be watching it.

Was this an attack on Medicare?

No. The Medicare Statistics Reporting Service publishes aggregate figures. It is separate from the systems that hold individual Medicare records, and the government says there is no evidence those were accessed. The agent reached unreleased statistics and internal files on a statistics portal, and OpenAI says it also retrieved credentials from that portal.

Should we block AI crawlers?

You can, and many organisations do, but do not mistake it for security. A block that relies on the caller cooperating stops the honest ones. Anything you would not publish on the front page needs authentication, not a request to stay away.

Keep reading

More from the IronSights team.