本文由AI翻譯
資料整理:OpenAI 代理程式入侵澳洲政府網站,成澳洲一連串駭客攻擊最新案例
路透雪梨 9 月 24 日 - 澳洲週四表示,一個 OpenAI 代理程式於 6 月侵入政府健康資料入口網站,未經授權取得檔案。這可能是目前已知首起 AI 代理程式駭入政府網站的案例。SYDNEY, Sept 24 (Reuters) - Australia said on Thursday an OpenAI agent breached a government health data portal in June, gaining unauthorised access to files, in what could be the first known instance of an AI agent hacking a government website.
這起入侵事件是近年影響澳洲多家最大企業的數十起事件之一。專家先前表示,攻擊的頻率與規模顯示,澳洲人手不足的資安產業似乎沒有足夠能力應對這類駭客攻擊。The breach is one of dozens in recent years affecting some of Australia's biggest companies. Experts have previously said the frequency and scale of the attacks suggest the country's understaffed cybersecurity industry seems unequipped to combat such hacks.
以下是近年最大規模資料外洩事件一覽:Here is a list of the largest data breaches in recent years:
2022 年 9 月:OPTUSSEPTEMBER 2022: OPTUS
澳洲第二大行動通訊業者 Optus 隸屬新加坡電信(Singapore Telecommunications),通報一起影響 950 萬名客戶的資料外洩事件,受影響人數約占澳洲人口 40%。外洩資料包括住家地址、駕照和護照號碼。Australia's second-largest mobile operator Optus, owned by Singapore Telecommunications, reported a data breach that affected 9.5 million customers, about 40% of the nation's population. The exposed data included home addresses, drivers' licences and passport numbers.
2022 年 10 月:WOOLWORTHSOCTOBER 2022: WOOLWORTHS
澳洲最大雜貨零售商 Woolworths 表示,其持股過半的線上零售商 MyDeal 發現,有人使用「遭入侵的使用者憑證」存取其系統,導致約 220 萬名客戶的電子郵件地址、電話號碼和送貨地址外洩。Australia's biggest grocer Woolworths said its majority-owned online retailer MyDeal identified that a "compromised user credential" was used to access its systems, exposing email addresses, phone numbers and delivery addresses of about 2.2 million customers.
2022 年 11 月:MEDIBANKNOVEMBER 2022: MEDIBANK
澳洲最大健康保險公司 Medibank 為約六分之一的澳洲人提供保險,該公司表示,約 970 萬名現有及前客戶的個人資料與健康理賠資料遭到外洩。Australia's largest health insurer Medibank, which covers about one-sixth of Australians, said that personal and health claims data of around 9.7 million of its current and former customers were compromised.
2023 年 3 月:LATITUDE FINANCIAL SERVICESMARCH 2023: LATITUDE FINANCIAL SERVICES
澳洲數位支付與貸款業者 Latitude 於 2023 年 3 月表示,一名駭客竊取了數百萬筆客戶紀錄,包括 790 萬筆澳洲與紐西蘭駕照號碼。Australian digital payments and lending firm Latitude said in March 2023 a hacker had stolen millions of customer records, including 7.9 million Australian and New Zealand drivers’ license numbers.
2024 年 5 月:MEDISECUREMAY 2024: MEDISECURE
電子處方服務供應商 MediSecure 披露一起網路攻擊,該公司後來表示,事件導致約 1,290 萬人的個人與健康資訊外洩,成為澳洲史上最大規模網路攻擊之一。外洩規模最終迫使該公司進入破產管理程序。Electronic prescription service provider MediSecure disclosed a cyberattack that it later said exposed the personal and health information of around 12.9 million people, making it one of the largest cyberattacks in Australian history. The scale of the breach eventually forced the company into administration.
2025 年 7 月:QANTASJULY 2025: QANTAS
澳洲最大航空公司 Qantas 於 2025 年 7 月表示,一個第三方平台遭入侵,導致 570 萬名客戶的個人資料外洩。Qantas, Australia's biggest airline, said in July 2025 a breach of a third-party platform exposed the personal data of 5.7 million customers.
2026 年 8 月:ORIGIN ENERGYAUGUST 2026: ORIGIN ENERGY
澳洲最大電力與天然氣供應商 Origin Energy 表示,7 月底發生的一起資料外洩事件,導致約 90 萬名現有及前客戶的信用卡與銀行帳戶資料外洩。Origin Energy, the country's largest electricity and gas provider, said a late-July data breach exposed credit card and bank account details of around 900,000 current and former customers.
(Alasdair Pal 雪梨整理;Sonali Paul 編輯)(Compiled by Alasdair Pal in Sydney; Editing by Sonali Paul)