My B

Here’s the Email You Get When an OpenAI Model Hacks Your Organization

OpenAI will wish you the "best" after hacking into your company.
Frank Landymore Avatar
A photo illustration of a bomb.
Shutterstock / Futurism

Companies and organizations around the world would do well to accept what their new roles are in our current AI-driven paradigm: glorified target practice for rogue AI agents.

The latest of such cybersecurity incidents, which frontier AI labs have been happy to turn into public spectacles, comes from OpenAI. On Tuesday, the ChatGPT-maker apologized after its AI agents hacked their way into several Australian government websites. The most alarming of these cases, which took place in June, involved the autonomous AI systems accessing a database for Medicare, the country’s universal health insurance scheme.

It should all be water under the bridge, though, because OpenAI kindly set an email wishing the Australian government the “best” — a whole three months after the hacks took place. 

Here’s what that email looked like, as shared by ABC AI reporter Cam Wilson on LinkedIn.

“We are notifying you of a security vulnerability identified during our review of OpenAI Model activity…” the communiqué began. “An OpenAI model identified a way to make the server carry out instructions sent through the public reporting interface, without a private account or password.”

“It was able to access this to read portions of internal program files and settings, obtain a list of files, and create and read back a small test file on the server,” it explained. “Our review found no evidence that the model accessed patient-level records, personal information or credentials; deleted data; or established ongoing access.”

It then recommended “that the team responsible for the service investigate the vulnerability and assess the changes needed to prevent it.” 

“We would be glad to brief your security team and provide supporting evidence as available,” the email concluded, before signing off. “Best, OpenAl Security Team”.

It would be an absurd email to send in any other context. Would a burglar who broke into your house and nosed through your family photos sending a letter assuring he didn’t steal anything — and recommending the head of the house to change the locks — help you sleep better at night?

The company was all apologies in its announcement posted Monday, vowing that it will do whatever it takes to “rebuild trust with the Australian people.” That will likely prove easier said than done.

More on AI: It’s Starting to Look Like Frontier AI Labs Will Be Taken Down in a Storm of Product Liability Suits If Their Models Keep Going on Incredibly Illegal Rogue Hacking Sprees