Monash experts: Medicare and other Australian government sites hacked by OpenAI agent
Monash University
Monash University cybersecurity experts are available to comment following Prime Minister Anthony Albanese’s revelation that an OpenAI agent accessed Medicare data and other Australian government websites earlier this year.
Professor Yang Xiang, Department of Software Systems and Cybersecurity, Faculty of Information Technology
Contact via: +61 450 501 248 or [email protected]
- Cybersecurity and AI
- Securing software systems
The following can be attributed to Professor Xiang:
“An OpenAI agent’s unauthorised access to Australia’s Medicare statistics portal in
June is a serious warning about the risks of agentic AI.
“This kind of intrusion and access actioned by an AI agent is significantly different from a scenario where a human hacker orchestrates a cyberattack. An AI agent has the capability of trying to ‘unlock’ a virtual ‘locked door’ numerous times in a short period and potentially breaking in.
“There is currently no evidence that personal information was accessed, but the breach still matters. A legitimate task does not justify unauthorised actions. An AI agent must treat a locked door as a limit to respect, not a puzzle to solve.
“The delayed response also shows how far our defences have to go. Agent behaviour
can be difficult to monitor and audit at scale. Protecting public systems will require better detection of AI agent activity, tighter limits on what agents can access, and faster incident reporting.
“Agentic AI can be enormously useful, but it must be used responsibly. That is why trustworthy AI is no longer optional.”
Professor Nigel Phair, Department of Software Systems and Cybersecurity, Faculty of Information Technology
Contact: +61 408 437 056 or [email protected]
- Intersection of technology, crime and society
- Impact of cybercrime
- Governance of technology
The following can be attributed to Professor Phair:
“As reported, the use of an OpenAI agent to gain access to a number of Australian government information websites is concerning.
“While we have been told there has been no access to personally identifiable information, it appears sensitive information has been accessed. We need to understand how this happened, who directed the AI agent to undertake such access, and why.
“Organisations need to rapidly understand how malicious actors will use AI to gain unauthorised access to computer systems and applications, and double-down on their efforts to discover vulnerabilities and patch them accordingly.”
For any other topics on which you may be seeking expert comment, contact the Monash University Media Unit on +61 3 9903 4840 or [email protected]