OpenAI breach of Australian government linked to wider AI hacking campaign - FT中文网
登录×
电子邮件/用户名
密码
记住我
请输入邮箱和密码进行绑定操作:
请输入手机号码,通过短信验证(目前仅支持中国大陆地区的手机号)。如果该手机号尚未注册,将自动创建 FT中文网账号。短信可能需要几分钟送达,验证码15分钟内有效,请耐心等待:
请您阅读我们的用户注册协议和隐私权保护政策,点击下方按钮即视为您接受。
FT商学院

OpenAI breach of Australian government linked to wider AI hacking campaign

Researchers detail three other attempts by AI agents to break into websites during ‘mundane data retrieval tasks’
00:00

{"text":[[{"start":9.46,"text":"OpenAI ‘agents’ that hacked an Australian government website were part of a broader spate of AI bots targeting websites to gather data for training exercises, which could still be going on, according to a new report."}],[{"start":22.16,"text":"AI research group Transluce’s report found the AI models tried to break into three university and government websites during “mundane data retrieval tasks”."}],[{"start":31.78,"text":"It said the pattern of online traffic it identified continued as recently as last week, “suggesting agents may still be exploiting these services to bypass restrictions”."}],[{"start":42.52,"text":"The research, published as Australia on Wednesday said OpenAI’s agents had breached a government health website in June, raises concerns about AI systems’ widespread misbehaviour."}],[{"start":53.48,"text":"Transluce said the Australian hack was “likely overlapping” with the other incidents in its report."}],[{"start":59.16,"text":"OpenAI’s chief executive Sam Altman addressed the UN Security Council this week, alongside Anthropic’s CEO Dario Amodei, as the labs respond to public outcry about AI risks and grapple with the potential liability the companies face for their models’ actions."}],[{"start":75.2,"text":"Transluce said AI agents — bots that can perform complex tasks independently — tried to hack the Australian Institute of Health and Welfare, the University of New Mexico’s digital library, and Data USA, a public US government data platform run by Deloitte, the Massachusetts Institute of Technology and tech company Datawheel."}],[{"start":95.2,"text":"It linked two of the three attacks to a “swarm” of OpenAI’s agents that the lab has publicly acknowledged."}],[{"start":101.04,"text":"OpenAI did not immediately respond to a request for comment on the report."}],[{"start":105.62,"text":"These attacks differ from previous high-profile AI hacks, such as the Hugging Face incident in July, which involved models breaking out of testing environments during cyber security training."}],[{"start":115.96,"text":"OpenAI launched an “extensive review of misaligned model activity during training and evaluation” following the Hugging Face attack. That review led it to detect the breach of the Medicare Statistics Reporting Service, disclosed by Australian Prime Minister Anthony Albanese on Wednesday."}],[{"start":132.52,"text":"The Hugging Face incident, which OpenAI took more than a week to notice, and the Australian Medicare breach, which went undetected for months, suggest the $852bn start-up was broadly unaware of what its AI agents were doing as part of training runs as it raced to compete with arch-rival Anthropic for the most capable systems."}],[{"start":153.42,"text":"In its report, Transluce said: “Notably, the tasks the agents were trying to solve were not cyber-related; the agents resorted to hacking tactics while working on ordinary data retrieval tasks.”"}],[{"start":166.2,"text":"In November, agents began using a URL-scanning service to get around website restrictions that prevent automated access, targeting Thailand’s government and several theme park groups, the report found."}],[{"start":178.4,"text":"“When other methods of collecting the data they sought failed,” the agents then attempted to hack into the three websites between May and June, the report said."}],[{"start":187.12,"text":"The agent activity ran from at least March until as recently as September 16, with “weaker evidence of similar data-retrieval agent activity” as far back as November 2025."}],[{"start":198.68,"text":"The researchers — who also released a dataset of tens of thousands of queries apparently made by autonomous AI agents — could not trace these “less sophisticated” early attempts directly to the same agents. But they said it was consistent with a model developing new methods for retrieving data during repeated training runs."}],[{"start":217.86,"text":"“By March, they were finding creative ways around access limits. By May and June, they were gaining more access, including attempting to bypass cyber defences to complete their tasks,” the report said."}],[{"start":234.78,"text":""}]],"url":"https://audio.ftcn.net.cn/album/a_1790306651_1981.mp3"}

版权声明:本文版权归FT中文网所有,未经允许任何单位或个人不得转载,复制或以任何其他方式使用本文全部或部分,侵权必究。

黑客劫持AI账户和服务器,助推新一轮网络犯罪热潮

安全研究人员警告称,针对企业昂贵AI资源的“LLM劫持”攻击激增。

随着债券需求减弱,流入美国股市的外国资本创下纪录

截至7月的一年间,海外投资者买入美国股票的金额超过9400亿美元,与标普500指数大幅上涨同期发生。

人工智能数学突破对人类发现意味着什么

解决复杂问题时,过程可能与最终结果同等重要。

旅游税渐成趋势

各国政府看到了一个既能增加财政收入、又不会惹恼选民的办法,也能借此管理蜂拥而至的游客。但休闲旅游业对此并不热衷。

一杯冰咖啡真的会让你丢掉工作吗?

一段提供求职建议的TikTok视频引发了关于面试礼仪的热议。

量子技术能把“魔法”变成金钱吗?

一系列突破和风险投资资金激增,点燃了业内的乐观情绪,但该行业仍面临长期存在的障碍和商业不确定性。
设置字号×
最小
较小
默认
较大
最大
分享×