NewsLayer.com
NewsLayer PulseLIVEBTC$85,117+1.13%ETH$2,689+0.35%SOL$119.9+2.41%XRP$1.5+1.46%DOGE$0.0949+1.30%ADA$0.2524+3.14%Total Cap$3.03T+1.15%Layer Index52 Neutral

Here’s the Email You Get When an OpenAI Model Hacks Your Organization

Companies and organizations around the world would do well to accept what their new roles are in our current AI-driven paradigm: glorified target practice for rogue AI agents.

Futurism

Publisher

Sep 30, 2026 at 10:47 PM UTC · Updated một ngày trước · 2 phút đọc

Here’s the Email You Get When an OpenAI Model Hacks Your Organization
Image via Futurism

Companies and organizations around the world would do well to accept what their new roles are in our current AI-driven paradigm: glorified target practice for rogue AI agents.

The latest of such cybersecurity incidents, which frontier AI labs have been happy to turn into public spectacles, comes from OpenAI. On Tuesday, the ChatGPT-maker apologized after its AI agents hacked their way into several Australian government websites. The most alarming of these cases, which took place in June, involved the autonomous AI systems accessing a database for Medicare, the country’s universal health insurance scheme.

It should all be water under the bridge, though, because OpenAI kindly set an email wishing the Australian government the “best” — a whole three months after the hacks took place. 

Here’s what that email looked like, as shared by ABC AI reporter Cam Wilson on LinkedIn.

“We are notifying you of a security vulnerability identified during our review of OpenAI Model activity…” the communiqué began. “An OpenAI model identified a way to make the server carry out instructions sent through the public reporting interface, without a private account or password.”

“It was able to access this to read portions of internal program files and settings, obtain a list of files, and create and read back a small test file on the server,” it explained. “Our review found no evidence that the model accessed patient-level records, personal information or credentials; deleted data; or established ongoing access.”