SKIP TO MAIN CONTENT

Jane Hume says 'we're missing the point' on OpenAI Medicare breach

The deputy Liberal leader said it was alarming the government learned of the hack only after being notified by OpenAI.

Jane Hume Senate estimates
Liberal Senator Jane Hume has called Australia's cyber defences "woefully inadequate". Source: AAP / Lukas Coch

4 min read

Published

Updated

By Josie Harvey

Source: SBS News


Skip to article content

In brief

  • Deputy Liberal leader Jane Hume has criticised the government's response to the OpenAI Medicare breach.
  • It comes after the government suggested taking legal action against the US-based ChatGPT developer over the incident.

Deputy Liberal leader Jane Hume has accused the federal government of "missing the point" in its response to the OpenAI Medicare breach, arguing the incident exposed serious gaps in Australia's cyber defences.

The government is examining whether those involved in the breach could be prosecuted under existing Australian law.

Environment Minister Murray Watt said a task force investigating the incident was seeking advice on what action was possible under current laws and whether changes were needed to deal with similar incidents in the future.

Speaking on ABC's Insiders on Sunday, Hume said the "real alarm bell" was that the government only became aware of the hack because OpenAI disclosed it.

"I'm not entirely sure who they're going to put into cuffs," she said. "I think we're missing the point here."

News that makes sense

Your trusted source for staying up-to-date with the world around you. Get free daily news updates and analysis, straight to your inbox.

By subscribing, you agree to SBS’s terms of service and privacy policy including receiving email updates from SBS.

"If they hadn't of told us that there was a breach, would we have known about it at all? That demonstrates that our cyber defences, particularly for [Services Australia], was woefully inadequate."

She questioned whether OpenAI was at fault, adding, "the idea that we would only check an inbox once a day when that inbox is specifically set up to identify cybersecurity breaches is mind-boggling".

Her comments follow Prime Minister Anthony Albanese's revelation this week that an agent linked to OpenAI, the California-based developer of ChatGPT, gained unauthorised access to Medicare Statistics Reporting Service Portal, which is administered by Services Australia.

Both the government and OpenAI have said no personal information was accessed during the breach, but it has raised broader concerns, including over the time it took to report it and who is accountable.

The 18 June incident was reported to Services Australia by OpenAI on 10 September, when the company emailed a Services Australia inbox.

Government Services Minister Katy Gallagher said that inbox is typically used by researchers to alert the government agency to possible vulnerabilities in its systems, and is only checked once a day.

She said the email was discovered the next day and escalated on 15 September after checks to determine it was legitimate.

She said she was notified on 17 September. Albanese disclosed it publicly on 24 September.

PM says incident was not isolated

There have been dozens of cases of artificial intelligence agents wrongfully accessing classified information beyond Australia's Medicare hack, Albanese said on Saturday.

But he said he wasn't aware of them before revealing the unauthorised OpenAI infiltration of the Medicare Statistics Reporting portal while in New York on Thursday.

"At the time we made our announcement ... we weren't aware of other occurrences," the prime minister told reporters on the tarmac at Sydney airport.

"We were acting purely in our national interest."

Albanese returned to Australia after a week in the US, where he addressed the United Nations General Assembly on the international need to rein in AI.

He now says news that rogue AI agents hacked into US government websites is further proof of that need.

Autonomous agents are now known to have infiltrated US university and commerce department sites, as well as the US Securities and Exchange Commission.

"We now know it wasn't just the issue of the Australian sites that have been subject to AI agents accessing information without authorisation," Albanese said.

"What this does is confirm that approach of making sure that it needs to be an appropriate national response, as well as an international response to make sure that humans are in charge of this new and emerging technology."

Albanese said it was up to OpenAI to state why multiple breaches occurred.

Albanese spoke with OpenAI chief executive Sam Altman by phone while in New York, with the tech boss admitting the company had not done enough.

Australia is among more than 20 countries that signed a joint statement calling for cooperation to establish global AI standards and ensure human control.

However, US President Donald Trump used a speech at the UN to lash out at calls to put the brakes on AI.

— With reporting by Australian Associated Press


For the latest from SBS News, download our app and subscribe to our newsletter.


Get SBS News straight to your inbox

Sign up now for daily news from Australia and around the world. You can also subscribe to Insight's weekly newsletter for in-depth features and first-person stories.

By subscribing, you agree to SBS’s terms of service and privacy policy including receiving email updates from SBS.

Follow SBS News

Download our apps

Listen to our podcasts

Get the latest with our News podcasts on your favourite podcast apps.

Watch on SBS

SBS World News

Take a global view with Australia's most comprehensive world news service

Stream now

Watch the latest news videos from Australia and across the world