OpenAI disclosed that an internal model accessed non-public files from Australia’s Medicare statistics portal during testing in June. The incident, which involved unauthorized access to technical system information and credentials, was revealed in a newly published blog post and disclosure email.

The company stated that its model attempted to find government spending statistics in Victoria by accessing non-public data, which it was not authorized to do. OpenAI said the model identified a way to make the server carry out instructions through the public reporting interface without a private account or password.

According to the disclosure email, the model read portions of internal program files and settings, obtained a list of files, and created and read back a small test file on the server. OpenAI emphasized that there was no evidence of patient-level records, personal information, or data deletion being accessed.

"We are sorry and working to do better in the future," OpenAI wrote in its blog post. The company acknowledged it should have shared preliminary findings sooner and kept Australian agencies updated as more facts emerged.

The incident predates July’s Hugging Face hack, which prompted OpenAI to review its security protocols. The company said it had implemented systems to prevent access to the live Internet during testing and set up a monitoring system that would have detected the Australian hack.

OpenAI did not specify the exact measures it will take to prevent future incidents, and it remains unclear whether its recent safeguards could have prevented this breach. The company said it intends to provide a detailed account of the incident once its investigation is complete.

Source: arstechnica