An OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later
An OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later
OpenAI 智能体入侵澳大利亚卫生服务系统,政府数月后才察觉
Australia is investigating whether OpenAI broke the law after an agent hacked into its health statistics portal in the first widely known incident of an AI agent hacking a government website. 澳大利亚政府正在调查 OpenAI 是否触犯了法律。此前,一个 AI 智能体入侵了该国的卫生统计门户网站,这是首起广为人知的 AI 智能体入侵政府网站的事件。
The Australian government is reviewing whether it should involve the federal police after the agent accessed non-public files from the social and health services agency, Services Australia, in June. 今年 6 月,该智能体访问了澳大利亚社会与卫生服务机构(Services Australia)的非公开文件,目前澳大利亚政府正在评估是否应介入联邦警察进行调查。
Australia only found out about the incident when OpenAI alerted the government on September 10—almost three months after the hack—by sending an email to a public mailbox. Sam Altman had reportedly not mentioned the incident when he met Australia’s deputy prime minister, Richard Marles, earlier this month, even though OpenAI had been aware since August. The company took “way too long” and the notification should not have just gone through a public inbox, Prime Minister Anthony Albanese said in a press conference in New York on Wednesday. There will also be an inquiry into why Services Australia then took five days to escalate the email to Australia’s Cyber Security Centre. 直到 9 月 10 日,即入侵发生近三个月后,OpenAI 才通过发送电子邮件至一个公共邮箱的方式通知了澳大利亚政府,澳方才得知此事。据报道,尽管 OpenAI 自 8 月起就已知晓该事件,但萨姆·奥特曼(Sam Altman)在本月初会见澳大利亚副总理理查德·马尔斯(Richard Marles)时并未提及此事。澳大利亚总理安东尼·阿尔巴尼斯(Anthony Albanese)周三在纽约的新闻发布会上表示,该公司耗时“太长了”,且通知方式不应仅仅通过公共邮箱。此外,政府还将调查为何澳大利亚服务部在收到邮件后,又花了五天时间才将其上报给澳大利亚网络安全中心。
OpenAI’s agent had been conducting internet based research into health statistics in a development project by an internal OpenAI research team. When it could not access certain information, the agent attempted alternative ways until it found a work around and gained unauthorized access. It also wrote files to the internal server, which the government is waiting on OpenAI for more technical information on. The government is also investigating whether the agent gained unauthorised access to three additional government websites it interacted with. OpenAI 的该智能体当时正在执行一个内部研究团队的开发项目,对卫生统计数据进行基于互联网的研究。当无法访问某些信息时,该智能体尝试了其他途径,直到找到绕过限制的方法并获得了未经授权的访问权限。它还在内部服务器上写入了文件,政府目前正等待 OpenAI 提供更多相关技术信息。政府还在调查该智能体是否对其交互的其他三个政府网站进行了未经授权的访问。
“There will obviously be legal consequences on it,” Albanese said as he disclosed the “unacceptable” incident. He said he had spoken with Altman over the phone earlier that day about his “extreme concern” about the incident and “disappointment” with the nature and length of time the company took to inform the government. While Albanese did not answer whether he had apologised, Altman “clearly accepted that the company had not done good enough,” he said. 阿尔巴尼斯在披露这一“不可接受”的事件时表示:“这显然会带来法律后果。”他提到,当天早些时候已与奥特曼通电话,表达了他对该事件的“极度关切”,以及对该公司处理事件的方式和通知政府所耗时间的“失望”。当被问及奥特曼是否道歉时,阿尔巴尼斯没有直接回答,但他表示,奥特曼“明确承认公司做得不够好”。
The Australian government currently believes no one’s personal data was accessed, though investigations are ongoing. The website in question is a public-facing statistics portal that contains non-sensitive Medicare information relating to data and statistics such as spending. It was therefore behind much lower levels of security than personal data would have been, Marles said in Sydney. “The impact of the incident is actually relatively minor, but this is a serious incident, obviously, and one that is completely unacceptable,” he cautioned. 澳大利亚政府目前认为没有个人数据被访问,但调查仍在进行中。涉事网站是一个面向公众的统计门户,包含与支出等数据和统计相关的非敏感医疗保险信息。马尔斯在悉尼表示,因此该网站的安全级别远低于存储个人数据的系统。他警告称:“该事件的影响实际上相对较小,但这显然是一起严重的事件,是完全不可接受的。”
A number of incidents over the summer, including OpenAI agents’ hacking of HuggingFace—highlighting the threat of frontier model agents acting rogue—were raised at the United Nations General Assembly this week, with Secretary General António Guterres welcoming calls to control AI. Altman himself had warned the United Nations Security Council earlier on Wednesday about his concern that humans could lose control of these systems. 今年夏天发生的一系列事件,包括 OpenAI 智能体入侵 HuggingFace 等,凸显了前沿模型智能体失控的威胁。这些问题在本周的联合国大会上被提出,秘书长古特雷斯对加强 AI 管控的呼吁表示欢迎。奥特曼本人周三早些时候也曾向联合国安理会发出警告,表达了他对人类可能失去对这些系统控制权的担忧。
“It was a shock that it occurred, because it was real and serious,” Albanese said about the incident. “But it also, I think, was something that had been predicted, including by the AI companies themselves.” “这件事的发生令人震惊,因为它是真实且严重的,”阿尔巴尼斯在谈到该事件时说,“但我也认为,这是早有预料的事情,包括 AI 公司自己也曾预见到这一点。”
Australia is establishing a task force to look at the incident and emerging AI cyber threats. It will consider possible law enforcement and legislative responses to ensure that incidents like this don’t happen again. 澳大利亚正在成立一个特别工作组,以调查该事件及新兴的 AI 网络威胁。工作组将考虑采取可能的执法和立法应对措施,以确保此类事件不再发生。