Skip to content
OpenAI’s dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphon

OpenAI’s dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphon

Theregister • September 29, 2026

JadePuffer crims hijacked Azure identities and used them to blow up cloud resources 9 hours ago

JadePuffer crims hijacked Azure identities and used them to blow up cloud resources

OpenAI GPT-6 Astra really good at supply chain attacks, UK gov warns 10 hours ago

OpenAI GPT-6 Astra really good at supply chain attacks, UK gov warns

Ex-soldier's telecom hacking spree earns him 70 months 17 hours ago

Ex-soldier's telecom hacking spree earns him 70 months

UK government vows to reclaim services from outsourcing giants 18 hours ago

UK government vows to reclaim services from outsourcing giants

HMRC vowed to break up with Capgemini then paid it another £4.2B 21 hours ago

HMRC vowed to break up with Capgemini then paid it another £4.2B

OpenAI has detailed the extent of the dirty deeds its agents indulged in Down Under in a Tuesday blog post titled How we will do better for Australia , which addresses last week’s news that one of its models improperly accessed a website that stores data related to national health scheme Medicare.

“Our models accessed Australian government websites in ways they were not authorised to,” the post opens. “We also should have handled our response better. We are sorry and working to do better in the future.”

The post offers some new detail on the Medicare incident, saying that it involved “an experimental, internal-only OpenAI model that was not intended for public release and without the full set of safeguards used in our publicly available products.”

OpenAI gave the model the job of researching government spending per person on medicines for skin conditions in one Australian state.

“The model had difficulty obtaining that information, and it took actions that we had not authorised it to take,” OpenAI admitted. “In the course of looking for this information at Services Australia’s Medicare Statistics Reporting Service, it discovered a way to gain non-public access to the service. It then used this access to review technical system information and source code related to the service – all still with the objective of trying to find the information it was originally looking for.”

The Register last week asked OpenAI if the company conducted the tests itself or used a partner. The company did not respond to our request.

In another incident disclosed in the new post, the company’s bots visited the Australian Institute of Health and Welfare and tried, unsuccessfully, to bypass access controls. The agents were still able to retrieve statistics using third-party browsing and download services, including from the institute’s website.

“The downloaded material appears to have been publicly available. There was no system compromise. Individual medical records were not accessed,” OpenAI wrote. The company didn’t report the incident because it “did not meet our disclosure thresholds because the way it was accessed seemed consistent with public access.” OpenAI changed its mind and notified the Institute on 24 September – the day Australia’s prime minister announced the Medicare incident.

Another concerning incident took place at the State of Victoria’s Agency for Health Information, which OpenAI agents visited after they “discovered an exposed access key.”

The agent used that key to “retrieve reporting configuration and aggregate survey statistics.”

OpenAI has given itself a pass on this one, writing “The extent to which this information should have been accessible is unclear, and depends on VAHI’s access policies. Individual medical records or identifiable survey responses were not accessed.”

A fourth incident revealed in the post saw OpenAI agents visit the State of New South Wales’ Bureau of Crime Statistics and Research and make API and website metadata requests using a public-facing research tool.

OpenAI has promised it will “commit the resources needed to help affected agencies understand what happened and assess the impact” – whatever that means. It’s also donating credits for the Daybreak cyber-defense service and promised to “establish a taskforce with independent Australian expertise to develop practical policy recommendations for managing risks from increasingly capable AI agents.”

That taskforce “will focus on improving notification processes, strengthening coordination between AI developers and government, and identifying measures to better protect government systems.”

OpenAI wants the taskforce to deliver recommendations by the end of 2026.

The post is very much of the “We’re sorry and we promise to do better in future” genre, pioneered by Meta and popular with entities that leak data or experience outages.

The Register expects more of the same sentiments week, when OpenAI’s Chief Strategy Officer, Jason Kwon, appears before the Australian Senate’s Joint Select Committee on Artificial Intelligence.

“He will answer questions what we know, how we responded, what steps we have taken, and how we will do better going forward,” OpenAI says. ®

OpenAI’s dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphon

Admits its agents side-swiped four Australian government sites

AMD bets $8.2B that worlds matter more than words in AI

AI pioneer Fei-Fei Li just co-founded spatial AI research company World Labs in 2024. Now it's joining AMD

Huawei Cloud Rolls Out Enterprise AI Products Across the Board, Building an Open Agentic Cloud

PARTNER CONTENT: Huawei Cloud strengthens the silicon bedrock on the cloud

AWS needs to embrace its place as the Depot of AI infrastructure

What's wrong with being a great wholesaler?

Open source datacenters and open source thinking will undo self-inflicted DC damage

Denial and distraction have served the bit barn barons very badly. Wise up

JadePuffer crims hijacked Azure identities and used them to blow up cloud resources

Smells like more agentic ransomware, Redmond warns

Astronomer watches Starlink satellites sinking to build a ‘planetary barometer’

Astronomer watches Starlink satellites sinking to build a ‘planetary barometer’

ShinyHunters claims FBI hack: 'This is NOT financially motivated'

ShinyHunters claims FBI hack: 'This is NOT financially motivated'

UPDAted Register reader hit with surprise bill after Microsoft portals disagreed

Register reader hit with surprise bill after Microsoft portals disagreed

Security firm finds naming AI agents after Seinfeld characters helps bots join the team

Security firm finds naming AI agents after Seinfeld characters helps bots join the team

DoJ: Uncle Sam bought forensics software from same Russian operation supplying FSB

DoJ: Uncle Sam bought forensics software from same Russian operation supplying FSB

BT Tower's rooftop pool plan brings swimmers back down to earth

BT Tower's rooftop pool plan brings swimmers back down to earth

AMD bets $8.2B that worlds matter more than words in AI AI pioneer Fei-Fei Li just co-founded spatial AI research company World Labs in 2024. Now it's joining AMD

AMD bets $8.2B that worlds matter more than words in AI

AI pioneer Fei-Fei Li just co-founded spatial AI research company World Labs in 2024. Now it's joining AMD

AWS needs to embrace its place as the Depot of AI infrastructure What's wrong with being a great wholesaler?

AWS needs to embrace its place as the Depot of AI infrastructure

What's wrong with being a great wholesaler?

French dev aims to solve bots' blindness so they can understand GUIs Because sometimes escaping your sandbox requires clicking a button

French dev aims to solve bots' blindness so they can understand GUIs

Because sometimes escaping your sandbox requires clicking a button

OPINION Open source datacenters and open source thinking will undo self-inflicted DC damage Denial and distraction have served the bit barn barons very badly. Wise up

Open source datacenters and open source thinking will undo self-inflicted DC damage

Denial and distraction have served the bit barn barons very badly. Wise up

OPINION Big AI's content problem: Take the work, keep the money The more we learn how AI does business, the more unfair it looks

Big AI's content problem: Take the work, keep the money

The more we learn how AI does business, the more unfair it looks

Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Russians are posing as Signal support to launch phishing attacks

PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack

PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Black Hat and DEF CON

DEF CON Franklin project enlists hackers to harden critical infrastructure

Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

EQT buys majority in Swiss cybersecurity biz Acronis

Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career

Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight

On the plus side, infosec's a good bet for a long, stable career

KDE turns 30 and someone's brought an AI-native desktop proposal Akademy talk imagines Plasma assembling itself around a personal model of each user

KDE turns 30 and someone's brought an AI-native desktop proposal

Akademy talk imagines Plasma assembling itself around a personal model of each user

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line

Acquisition gives open source CSS framework 'a stable long-term '

Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push

Switzerland tests a FOSS escape route from Microsoft 365

Swiss Army sticks a knife in American cloud apps with its own FOSS push

Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin

Feel peak Windows was 7? You might like Kumander Linux

Debian and Xfce – solid, sensible choices – with a pretty skin

Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted

Canonical shuttering some of its legacy chat channels

The Ubuntu Pastebin went in June, IRC gets demoted

Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Audacity audio-editing app no longer looks like it's from the early 2000s

The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Extracted Entities

APT Groups (1)

Attack Types (1)

Companies (2)

Countries (1)

Industries (1)