T.A.M · The Air Media
← Back to live feed
Weightage 75 2 outlets citing Technology AU

Government faces criticism over response to Medicare portal data exposure

Tech experts are criticizing the government's response to a Medicare statistics portal issue, arguing that the system was designed to provide data to any requester rather than being 'hacked.' Critics suggest the government is overreaching in its characterization of the event.

First reported 1 hour ago · latest update 1 hour ago
✦ T.A.M verified this synthesis across 2 independent outlets. The headline and summary are written neutrally from all citations below.
Sydney Morning Herald Authority 90

Cybersecurity experts and tech investors have accused the Albanese government of blowing the Medicare statistics breach out of proportion, arguing that the website’s code was set up to send data to anyone with the skills to request it.

Archived versions of the website show that its code directed savvy users to a digital address where they could download the statistical information it stored despite that data not being publicly available to people via its front end.

Seek co-founder Paul Bassat, one of the country’s most prominent technology investors, echoed questions from prominent industry colleagues about Prime Minister Anthony Albanese’s claim last week that “an AI agent has infiltrated an Australian government website”.

“The government clearly wanted to get onto the front foot to seize the initiative in relation to how AI is regulated,” he said, “but as the facts have emerged over the last few days, it looks like there has been a bit of overreach – there’s no question about that.”

Billionaire Atlassian co-founder Scott Farquhar, who chairs the Australian Tech Council, circulated an article arguing that the site had made the data accessible, while Canva investor Niki Scevak, reposted a meme declaring that OpenAI “accessed unindexed but publicly available files”.

Their views dovetailed with those of senior members of the federal opposition who claimed on Sunday that Albanese had overstated the severity of the issue.

Opposition defence spokesman James Paterson said Albanese’s motivations were “pretty transparent” in timing the announcement on the same day as OpenAI chief executive Sam Altman’s speech to the United Nations.

“Firstly, Medicare wasn’t hacked,” Paterson said on News24, formerly Sky News. “It was a Services Australia statistics portal, and the data that was obtained is prepared solely for the purpose of it being publicly released.

“And secondly, I’m not even sure you can really call it a ‘hack’. If it is a hack, it’s the least sophisticated from a technical point of view. But that doesn’t mean that we shouldn’t be treating this as basically a free warning, because the next time this happens it could be much more serious.”

Bassat agreed, noting that OpenAI could have explained the breach publicly and avoided any politicking. “It’s quite possible that there are no heroes in this story,” he said.

OpenAI said in a statement at the weekend that it would pause training its models until “we are confident that we have additional safeguards” in place after it disclosed the Australian incident was only one of dozens around the world in which its bots had gone beyond their intended tasks.

It is the second time in three months that OpenAI has halted development of its models. The first was in July after disclosure of a cyberattack targeting AI start-up Hugging Face, a notorious incident that raised fears the industry was losing control.

Deputy Prime Minister Richard Marles rejected the claim that Albanese had exaggerated the threat.

“The seriousness doesn’t lie in the information that was obtained. It was the fact that we’ve got an unintended action of an AI agent gaining unauthorised access into an Australian government website. So both of those things are true,” Marles said on News24’s Sunday Agenda.

Vaughan Shanks, chief executive of Melbourne cybersecurity company Cydarm, said the OpenAI tool’s decision to download files that were not listed on the website’s visual front end was “mildly naughty”.

“That’s called obscurity, not security,” he said. “If they wanted to make it secure, they wouldn’t put it in a public directory.”

Archived versions of the Medicare Statistics Reporting Service portal verified by technology publication Recorded Future News show that until 2025, accessing the address to download data did not require a login. From March that year, the portal did demand a “guest” login, which granted access without any password or username.

It is not clear if the site was intentionally set up in that manner to let researchers access public data or if it was an oversight that allowed the bot to gain access.

The government has assembled a taskforce including the Cybersecurity Co-ordinator, Office of AI, Australian Signals Directorate and Services Australia to investigate the breach. A Greens-led Senate inquiry has also asked Sam Altman to give evidence this week.

Shanks said the bot’s behaviour was akin to a passerby looking over a fence. “Nothing was stolen,” he said.

But Toby Walsh, a University of NSW professor of artificial intelligence, said the point was not that the incident was harmful, but that it showed big tech bosses’ warnings that they could lose control of AI systems had come true.

“Their AI has run rogue for weeks at a time,” Walsh said. “They really have no idea of what it is doing.”

He said the world was lucky that the tools had not yet proved capable of causing real harm.

“We really should be holding companies (and officers of these companies) accountable,” Walsh said. “Then they might pay a bit more attention to preventing these needless hacks.”

A Services Australia spokesman said it was investigating the incident and its response to OpenAI’s email.

“As the investigation remains ongoing, we cannot provide further information at this stage,” the spokesman said.

The Business Briefing newsletter delivers major stories, exclusive coverage and expert opinion. Sign up to get it every weekday morning.

You have reached your maximum number of saved items.

Remove items from your saved list to add more.

↗ Read the original at Sydney Morning Herald

Citations · 2 reports from 2 outlets

Tap a citation to read it above, right here on T.A.M.

90 Sydney Morning Herald ★ most authoritative citation

‘Obscurity not security’: Government accused of overreach in Medicare ‘hack’ response

Tech experts argue that the Medicare statistics portal’s code was set up to send data to anyone who requested files, including data that wasn’t promoted.

1 hour ago · Nick Bonyhady, Paul Sakkal
89 The Age (Australia)

‘Obscurity not security’: Government accused of overreach in Medicare ‘hack’ response

Tech experts argue that the Medicare statistics portal’s code was set up to send data to anyone who requested files, including data that wasn’t promoted.

1 hour ago · Nick Bonyhady, Paul Sakkal

Discussion

Read it on the T.A.M app Weighted news · citations · ad-free
Get the app