What's notable is:
1. AFAICT, they don't state whether the flaw has been fixed.
2. He said: "The government will establish a task force led by the Department of the Prime Minister and Cabinet to urgently examine the incident and determine whether existing processes are adequate for responding to AI-related cyber incidents."
First, I don't know how sophisticated the attack was, but it's interesting that he's positioning this as an "AI-related cyber incident". For all we know, their security was not up to snuff, and human hackers had already accessed the material.
At least OpenAI informed them of their poor security!
How do you protect against an arsonist lighting a forest on fire? The number one method is by setting up your property to be fire safe.
Really the days of being able to cast blame on the hacker, or even expecting anything to be done about it are over. Threat actors with AI have an absolutely massive amount of leverage in attacking and any weaknesses you have in your systems security posture and will be relentlessly exploited in incredibly short periods of time allowing horizontal and vertical exploitation. You will be ruined in mere moments, while punishment for the hacker may be years or decades away, if ever.
blaming the victim
The government is not the victim, the public are. The government is responsible for protecting the public from attackers. Asking the government to do their job is not blaming the victim.
Added to the fact that, if I recall correctly, according to US law it's a breach even if the data is publicly available but unintentionally.
Refer: Weev AT&T
Which is mad, really.
Absolutely.
It is, however, a glowing beacon of an example of law being designed to maintain the status quo and/or protect companies at the expense of individuals.
As someone else said, welcome to late stage capitalism.
I don't see why, and I've no idea what "late stage capitalism" is, other than people like to repeat the phrase.
Not yet, as they haven't given details out. If they were not following standard security practices, then absolutely.
And when the victim doesn't do reasonable actions to safeguard, yes, they are also partially responsible.
If I hooked up a whole server infrastructure, made it possible to remote in to anything as root, no firewalls, no WAF, and security was an afterthought, I would still be responsible for bad actions not becoming with standard and acceptable security.
Even if the hackers shouldnt be hacking, I still did it wrong. I'm still partially responsible.