Update: The NSW Government published the update yesterday, 6 October 2025, confirming that in March 2025, a former contractor uploaded an Excel spreadsheet containing more than 12,000 rows of applicant data from the Resilient Homes Program to ChatGPT without approval. The file included names, addresses, phone numbers, email addresses and some personal and health information.
The NSWRA said it took immediate action to contain the breach, engaging forensic analysts and working with Cyber Security NSW to determine the scope and risks. The NSW Privacy Commissioner has been notified, and an independent review has been initiated to understand how the breach occurred and why notification took time.
Authorities said there is currently no evidence that any of the uploaded data has been accessed or made public, although monitoring of the internet and dark web is ongoing. Impacted individuals will be contacted this week with confirmation of what data was shared and will be offered personalised support.
In its statement, the NSWRA apologised for the incident, saying,
“We understand this news is concerning and we are deeply sorry for the distress it may cause for those who have engaged with the program.” It also added, “We know people will want to know exactly what has been shared and we are doing all we can to get that information to them as soon as possible.”
Why It Matters:
This breach is one of Australia’s first known government incidents involving the use of an unauthorised public AI platform. The fact that sensitive personal and health information was uploaded to ChatGPT without approval highlights the growing risk of shadow AI, where employees or contractors use unvetted tools to handle confidential data.
The six-month delay between the breach and its public disclosure raises questions about transparency and the effectiveness of government incident response processes. It also underscores the urgent need for clear AI-use policies, comprehensive staff training and stronger data-handling safeguards across public sector programs that manage personal information.