Cybersecurity

Chinese hackers impersonated AI experts to target US policy minds | Cybersecurity News

TA419 hackers used deceptive tactics, impersonating real figures like a former White House AI official

Chinese hackers have been impersonating artificial intelligence (AI) experts in the United States, including a former government official, according to a new report from cybersecurity firm Proofpoint.

The report, released on Thursday, found that in July, a China-aligned hacking group called TA419 targeted a slate of US policy experts by impersonating prominent figures, including Lynne Edwards Parker, the former principal deputy director of the White House Office of Science and Technology Policy.

Recommended Stories

list of 4 itemsend of list

The hackers, who had been operating since April 2025, first sent otherwise harmless-looking emails intended to engage a target, such as requests to join an “AI Policy Advisory Committee”, and, once they responded, the target would be sent to a fake login page designed to steal their credentials.

The targets included policy experts at think tanks, defence contractors, universities and law firms in both the US and Japan.

The report used a technique that creates a fake browser pop-up window inside a legitimate webpage that mimics an authentic-looking sign-in prompt to deceive victims and make it harder for them to realise they are handing over their information to hackers.

Proofpoint did not specifically name the targets hacked, but the Reuters news agency was able to confirm at least one of them as Alex Engler, a former White House official who now heads the Penn Center on Media, Technology, and Democracy.

Engler told Reuters that he got one of the emails, but after checking with industry colleagues, he discovered that he had received the email from an impersonator.

In February, the same group was behind the impersonation of a “prominent” Anthropic employee in efforts to target AI policy experts. The cybersecurity firm behind the report believes that the group will continue to target think tanks and other policy experts and will continue to use the identity of real-world experts to do it.

Parker did not respond to Al Jazeera’s request for comment.

Source link

How an OpenAI ‘agent’ hacked Australia’s Medicare and what that means | Technology News

Australian authorities have raised the alarm after OpenAI-powered models hacked into a government health data system in June, slipping past its digital defences and accessing files without authorisation.

This is the first publicly known case of artificial intelligence (AI) “agents” – AI-powered software systems that can carry out tasks autonomously – breaking into a government website, and the latest of several AI breaches of external systems.

Recommended Stories

list of 3 itemsend of list

The disclosure comes as top AI firms warn of the risk of humans losing control of AI, calling for its development to slow to a pace that allows it to be safely regulated. Global powers must cooperate to ensure this, they have said.

A research scientist at AI firm Anthropic, Evan Hubinger, went so far as to say he believes there is a greater than 10 percent chance AI could “kill all humans” within a decade.

Addressing the United Nations Security Council on Wednesday, OpenAI CEO Sam Altman said there is a risk of AI moving “so fast that people can no longer follow what’s happening or intervene when needed”.

“This would obviously be terrible,” he said. “And we should not train models that we cannot make an extremely strong case that we will be able to keep under human control.”

What do we know about the AI breach in Australia?

Australian Prime Minister Anthony Albanese revealed the breach on Wednesday, saying an OpenAI agent had made its way into the public-facing medical statistics portal of Medicare, the country’s universal health insurance system, on July 18.

When OpenAI accessed the government portal while conducting research on public medical spending, Albanese said the AI agent circumvented “blocks” that should have prevented it from breaking into the portal.

“The AI agent found a way around those blocks – didn’t accept no for an answer,” said Albanese.

Deputy Prime Minister Richard Marles said the information the OpenAI agent accessed was “not particularly sensitive” and was later publicly released.

Still, Albanese called the situation “obviously unacceptable” and said Australia had relayed its “extreme concern” to OpenAI, which had failed to notify the government of the breach until September 10.

Albanese also said several other government websites may have been affected by rogue OpenAI agents, though he did not confirm any other breaches.

He added that an inquiry into the breach would look at how Australian security agencies missed it initially and whether criminal charges could be brought against OpenAI.

Australian Minister for Government Services Katy Gallagher speaks to the media alongside Australian Deputy Prime Minister and Defence Minister Richard Marles after it was revealed an AI agent developed by OpenAI infiltrated an Australian government website in June, in Sydney, Australia, September 24, 2026. REUTERS/Hollie Adams
Australia’s Government Services Minister Katy Gallagher, right, addresses the media alongside Deputy Prime Minister Richard Marles in Sydney, Australia, September 24, 2026 [Hollie Adams/Reuters]

How has OpenAI responded?

In a statement, OpenAI said it had “identified activity involving several Australian government websites and services as our models attempted to look up answers” and “took actions we did not intend”.

The company said the incident occurred as its models searched for statistics on medical spending, and that they are not believed to have obtained personal medical records.

OpenAI learned of the incident in August only as it conducted a review of “misaligned model activity”, it added.

Last week, OpenAI said it had put in place a new system to monitor, probe and disclose cases of “misalignment”. That includes instances of AI models that operate “without authorisation, coordinate with other models, or evade oversight”, it said.

Have there been previous AI breaches?

Yes. The Australia data breach is the latest of several instances in which AI agents belonging to OpenAI, Google or Anthropic have accessed external systems without authorisation.

In July, OpenAI reported that two of its most advanced AI models had broken out of a controlled test and hacked another AI company, Hugging Face. OpenAI later said it had detected its AI models communicating with each other and gaining internet access without authorisation months before that hack occurred.

In August, rival Meta AI said its AI model had hacked another company during cybersecurity testing. It said the model made changes to the internal systems of the hacked company, which it did not name, after accessing the public internet because of an error in the setup of its testing environment.Interactive_AI_Myth_Reality_July29_2026_INTERACTIVE-How-the-AI-escaped-its-test-environment-1785326132-1785974640

What does this mean for AI safety?

Maurice Chiodo, an Australian mathematician who works at Cambridge University’s Centre for the Study of Existential Risk, told the Reuters news agency the breach appeared to be “a significant escalation in seriousness from similar incidents we have ‌seen ‌in recent months”.

Experts say the Australia data breach highlights the growing dangers AI poses to cybersecurity as well as possible gaps in monitoring and disclosure capabilities.

“The important matter here is not what OpenAI says its agent can do, it is what the agent actually does when it hits a barrier,” Niusha Shafiabady, a professor of computational intelligence and head of the IT discipline at the Australian Catholic University, said in comments published by science news portal Scimex.

“The deeper technical risk is that autonomous AI does not always know when it is wrong, and humans may not be able to see why it made a decision,” added Shafiabady. “Without strong verification and hard boundaries, probabilistic errors can quietly become operational failures.”

Raffaele Fabio Ciriello, a senior lecturer in business information systems at the University of Sydney Business School, said OpenAI’s delay in reporting the breach was “concerning”.

“The incident occurred in June and only came to light months later,” said Ciriello. “Even if OpenAI did not detect the activity immediately, that still points to weaknesses in detection, escalation, and external notification.”

Source link

Australia says OpenAI agent hacked Medicare portal | Cybersecurity News

Australia’s Prime Minister Anthony Albanese has revealed a security breach of a government website containing Australians’ health data by an “AI agent”, less than a day after signing a joint appeal for “urgent global guardrails” around artificial intelligence.

Albanese co-signed the “A Call for Control of Frontier AI Models” statement on Tuesday together with 21 signatories including Canada, Spain and Germany, on the sidelines of the United Nations General Assembly (UNGA) meeting in New York.

Recommended Stories

list of 3 itemsend of list

Addressing reporters on Wednesday, Albanese said the agent, developed by OpenAI, accessed public and non-public data on the government’s Medicare portal in June.

Australia’s Labor government is tightening tech regulations with new online safety laws, age bans and proposed digital duty of care frameworks.

Albanese said he had spoken to OpenAI CEO Sam Altman to express Canberra’s “extreme concern” about the hack and disappointment that the company took three months to admit the breach.

OpenAI responded in the hours after the news conference, stating that while it was still investigating, there was no evidence patient records were accessed.

The company’s review had identified activity involving several Australian government websites and services as its “models attempted to look up answers”, it said.

OpenAI CEO Sam Altman addresses the United Nations Security Council during a session on Artificial Intelligence during the 81st United Nations General Assembly, at UN Headquarters in New York City, US, September 23, 2026 [Brendan McDermid/Reuters]
OpenAI CEO Sam Altman addresses the United Nations Security Council during a session on artificial intelligence during the 81st United Nations General Assembly, at UN headquarters in New York City, US, September 23, 2026 [Brendan McDermid/Reuters]

World leaders respond to AI warnings

The leaders of artificial intelligence companies warned of the risks of unregulated AI development before a 15-member UN Security Council meeting on Wednesday.

One of them, Yoshua Bengio, a Canadian considered one of the ‘Godfathers of AI’ and co-chair of the Independent International Scientific Panel, spoke of the “unprecedented threat” and the “real and imminent” dangers of the technology.

China’s UN ambassador Fu Cong told the meeting that Beijing believed continuous improvement of regulatory frameworks, emergency response and cross-border cooperation on AI was needed.

British Prime Minister Andy Burnham said the United Kingdom was ready to lead an international effort to establish AI standards.

“We’ve all heard the warnings which we must heed… so we have to rise to this moment,” he said, but added he also wanted the UK to pursue the benefits of AI.

French President Emmanuel Macron warned against allowing the United States and China to dominate decision-making around AI during his speech to the assembly on Wednesday.

US President Donald Trump is at odds with many of his counterparts, comparing the dangers of AI to climate change, which he has called a hoax.

He also proposed rebranding the term AI to SI, or “super intelligence”, during his address to the UNGA on Tuesday, and earlier said he planned to appoint an AI adviser.

In a Truth Social post on Monday, Trump said the US was leading the AI race over China, that he was “not going to stifle Growth”, but added ⁠that the US would be careful.

White House science and technology adviser Michael Kratsios echoed Trump in remarks to the UN Security Council on Wednesday.

“You cannot govern technology you do not understand. This body and others like it should focus on sharing best practices to build domestic capacity, not establishing a global regulatory scheme,” he said.

Source link

FBI says investigating breach of ‘very sensitive’ data by hackers | Donald Trump News

Hacker group ShinyHunters claims to have detailed data on thousands of FBI employees.

The United States Federal Bureau of Investigation says it is investigating a breach of its jobs website by a hacking group that claims to have obtained sensitive data on thousands of employees.

“The FBI is aware of a cybercriminal enterprise group claiming a compromise of the fbijobs.gov portal and alleged impact to FBI employee personally identifiable information,” the agency said in a statement on Wednesday.

Recommended Stories

list of 3 itemsend of list

“While the point of breach is still undetermined — whether a third -party or the FBI’s enterprise — we are actively and aggressively investigating this matter and working closely with those third-party providers that support fbijobs.gov to mitigate any and all risk.”

Several news outlets, including Reuters news agency, reported they had seen parts of the data, claimed to be part of a larger trove between two and three terabytes by ShinyHunters, a hacking group claiming responsibility for the breach. According to Reuters, the data includes granular detail about scores of bureau officials’s job assignments, including sensitive work against Chinese spies, Russian intelligence, drug cartels and more.

ShinyHunters said on Tuesday that it had breached the FBI and stolen data on a huge number of current and former FBI employees. ⁠⁠It said it is holding the data hostage until the bureau rescinds an unflattering statement about the group issued in May. On Wednesday, the group said it was trying to keep the ⁠⁠personnel information from circulating widely in the meantime.

An FBI statement in May characterised ShinyHunters as “threat actors” who often harass or threaten victims, using “their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims”.

The group “may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist,” the FBI said.

The FBI has been a common hacking target.

In March, the FBI disclosed that it was investigating “suspicious activities” on an internal system that contains sensitive information related to surveillance operations and investigations. Also that month, a pro-Iranian hacking group claimed to have hacked an account of FBI Director Kash Patel and posted online what appear to be years-old photographs of him, along with a work resume and other personal documents dating back more than a decade.

The jobs portal was still offline Wednesday afternoon.

Source link

Australia seeks big tech support for internet safety, AI regulation | Child Rights News

PM Anthony Albanese asks Apple CEO Tim Cook to back Canberra’s online safety laws to ‘keep Australians safe’.

The Australian government is seeking support from global tech giants as it works to strengthen the country’s online safety laws and artificial intelligence (AI) regulations.

Prime Minister Anthony Albanese, who met Apple CEO Tim Cook at the tech company’s headquarters in Cupertino, California, on Saturday, said that “Australia can’t do it alone” when it came to protecting children from the dangers of the internet.

Recommended Stories

list of 3 itemsend of list

“We spoke about what we’re doing to protect children from online harm and the work ahead,” Albanese wrote on social media.

“We’re putting stronger rules in place to keep Australians safe online,” he said. “And now, big tech companies like Apple are stepping up too.”

Albanese, who is also in the United States for the United Nations General Assembly, used his trip to call for stronger AI regulation after dire safety warnings from industry leaders.

Australia will introduce new standards for AI by the end of the year, he said.

In a video posted to his X account, Albanese said his Labor government is “making sure technology works for Australians”, and not the other way around.

In a post on X, Cook also said he shared with Albanese new “strong and intuitive controls to help keep kids safe online”.

New Australian legislation unveiled this month would place a “duty of care” requirement on the firms behind popular platforms, such as Facebook, TikTok and Instagram, and allow users to turn off their algorithms.

The draft laws will be introduced to parliament later this year after consultation with social media companies, industry bodies and civil society groups.

The opposition Liberal-National Coalition opposes the bill “in its current form”, according to a statement published on September 10, saying that it “contains inadequate safeguards for free speech and journalism, and leaves too much power in the hands of the Communications Minister”.

Australia implemented legislation barring children under 16 from social media platforms last year as part of a world-first crackdown designed to protect children from online bullying and “predatory algorithms”.

However, data last month found that Australians under 16 continued using social media apps such as Instagram and TikTok despite the ban.

Source link

OpenAI reports more incidents of models acting deceptively | Cybersecurity News

The ChatGPT creator says it is introducing a public reporting framework to share unexpected AI behaviour, admitting the industry has not solved safety challenges yet.

OpenAI says it has identified additional incidents of its AI models allegedly acting deceptively and taking unsanctioned actions during internal training and testing.

Alongside these disclosures on Wednesday, the creator of ChatGPT stated it was introducing a public reporting framework intended to frequently share instances of what it termed as unexpected or misaligned AI behaviour.

Recommended Stories

list of 3 itemsend of list

In a post on its website, OpenAI claimed that under the newly outlined framework, it will publish updates on concerning model behaviour on an ongoing basis rather than delaying disclosures to group multiple incidents into larger, periodic reports.

The company said the initiative aims to increase industry transparency around troubling model activities in the absence of standardised safety disclosure norms.

The announcement comes amid broader calls from prominent technology leaders urging a slowdown in frontier AI development over concerns that rapid scaling could outpace human oversight and control.

Last week, Anthropic claimed to have thwarted multiple malicious operations using its Claude models, ranging from cyber-espionage and weapons design to mass surveillance campaigns.

“We must slow the pace at which we improve the capabilities of AI models,” Anthropic CEO Dario Amodei wrote in an essay published on Saturday. “Progress will still seem fast, and we must make wise use of the time we gain.”

However, United States President Donald Trump has repeatedly pushed back against calls to limit the industry, arguing that maintaining the US’s technological edge over international rivals remains paramount.

Responding to slowdown proposals, Trump described critics as “very negative forces” raising exaggerated scenarios that “won’t happen”.

Escalating debate on alignment

Despite political resistance to statutory slowdowns, OpenAI signalled agreement with its industry rival regarding alignment pressures.

“As AI systems grow more advanced and more widely deployed, we need to build a broader and better-informed consensus on the progress of alignment research,” the company stated in the post.

OpenAI added that it does not believe the AI industry has solved alignment and monitoring to a sufficient degree to continue responsibly scaling at maximum speed for much longer, emphasising that decisions about future AI development need to draw on evidence that external observers can examine independently.

According to the company, safety teams observed what they categorised as “misaligned behaviour” across six specific circumstances over the past six months during training and evaluation runs.

However, OpenAI maintained that these reports document individual, rare instances rather than frequent operational failures across deployed products.

The reported incidents allegedly included unreleased research models concealing mistakes in task summaries, unauthorised file uploads to the internet to generate citation links, and agents sharing files across public servers or internal repositories to bypass local boundaries.

OpenAI further stated that its future reports will detail observed behaviours, severity, setting, discovery dates, and the specific models involved, adding that it remains committed to disclosing complex cases requiring longer investigation or third-party coordination.

Source link