New South Wales: a former staff member or contractor of the NSW Reconstruction Authority uploaded a spreadsheet of Resilient Homes Program applicant data to ChatGPT; the Authority confirmed 2031 people had data uploaded
The NSW Reconstruction Authority says that between 12 and 15 March 2025 a former temporary staff member (earlier described as a former contractor) uploaded an Excel spreadsheet with 10 columns and more than 12,000 rows from the Northern Rivers Resilient Homes Program to ChatGPT, an AI tool the Authority had not authorised. The Authority first disclosed the breach on 6 October 2025 as affecting up to 3000 people and later confirmed through external forensic analysis that 2031 people had data uploaded, including names, contact details, addresses, dates of birth and sensitive personal information (an earlier notice also listed health information). It reports no evidence that the data was made public or accessed by a third party, and that no driver licence, Medicare, passport or Tax File Numbers were included. The Authority apologised, offered ID Support NSW assistance and committed to compensate reasonable document replacement costs. One participant told the ABC they were concerned. No misuse of the data is reported.
- AI system
- ChatGPT
- OpenAI
- Occurred
- 12 Mar 2025 to 15 Mar 2025
- Reported
- 6 October 2025
- Event location
- Australia
- What the AI did
- Relation unknown
- Reported harm
- Other Material Harm
- Whose AI use
- An institution’s AI use
- Setting
- Privacy · Public services · Everyday life
- Evidence
- AI involvement supported · Causal attribution alleged · 4 sources, 1 underlying account
- 5 claims: 5 reported. 5 open questions
- People reported harmed
- Not reliably quantifiable from the sources
AI system as recorded: ChatGPT (OpenAI), used through an unauthorised upload of program data by a person working for the NSW Reconstruction Authority
What Happened
The Authority's notices state that a former temporary staff member (called a former contractor in the first notice) uploaded a Microsoft Excel spreadsheet with 10 columns and more than 12,000 rows of Resilient Homes Program information to ChatGPT between 12 and 15 March 2025. The upload was not authorised. The Authority disclosed the breach publicly on 6 October 2025 (iTnews and ABC coverage) and said the delay reflected the time needed to work out who was affected. Its first notice said up to 3000 people may be impacted. External forensic analysis later confirmed 2031 people, with name and contact details, residential or mailing address, date of birth, sensitive personal information and limited financial commentary. The Authority says no driver licence, Medicare, passport or Tax File Numbers were disclosed, and that there is no evidence the data is publicly available or was accessed by a third party. It reports strengthened policy, training and system controls after an independent review. One participant told the ABC the information held was deeply personal and that they felt concerned. No sources report misuse of the data.
Reported harm
The NSW Reconstruction Authority reports that personal and sensitive information of 2031 Resilient Homes Program participants was uploaded to ChatGPT without authorisation; it reports no evidence of public exposure or third-party access, and no realised misuse is reported (the Authority's notices and press coverage relaying them).
Outcome
ResolvedThe Authority notified affected people with ID Support NSW and Social Futures, notified the NSW Privacy Commissioner, had Cyber Security NSW monitor the internet and dark web, and completed an independent review that identified governance, training and data security improvements (page updated 26 March 2026).
What remains unknown
- Whether ChatGPT (OpenAI) retained or used the uploaded data, and any deletion outcome.
- Whether any participant suffered identity misuse or other realised loss; none is reported.
- Exact number of affected people at the first notice (up to 3000) versus the confirmed 2031.
- Whether the uploader was a temporary staff member or a contractor (the Authority uses both terms).
- The findings of the independent review beyond the Authority's summary of it.
What the evidence supports
AI involvement: supported. The Authority states the data was uploaded to ChatGPT and that its forensic analysis confirmed 2031 people had data uploaded. The AI system received the data; the sources do not report any ChatGPT output affecting the participants.
5 claims: 5 reported. What the statuses mean
Reported Between 12 and 15 March 2025 a former temporary staff member or contractor of the NSW Reconstruction Authority uploaded a spreadsheet of Northern Rivers Resilient Homes Program applicant data (10 columns, more than 12,000 rows) to ChatGPT, an AI tool the Authority had not authorised.
Causal attribution. The Authority's own statements report the upload and its dates. The role is described as a former temporary staff member on the current page and a former contractor on the earlier notice and in the press.
- nsw.gov.au(opens in new tab) supports · English
The upload took place between 12 and 15 March 2025.
- nsw.gov.au(opens in new tab) supports · English
The breach occurred when a former temporary staff member of the RA uploaded data containing personal information to an unsecured Artificial Intelligence (AI) tool which was not authorised by RA.
- nsw.gov.au(opens in new tab) supports · English
The data shared was contained in a Microsoft Excel spreadsheet with 10 columns and more than 12,000 rows of information.
- nsw.gov.au(opens in new tab) supports · English
Between 12 and 15 March 2025, personal information was uploaded by a former contractor of the RA to the Artificial Intelligence platform ChatGPT.
- abc.net.au(opens in new tab) supports · English
"Personal information was uploaded by a former contractor of the RA to the artificial intelligence platform ChatGPT," an RA spokesperson said.
- itnews.com.au(opens in new tab) supports · English
although it actually occurred over six months ago, between March 12 and 15.
Reported The Authority confirmed through external forensic analysis that 2031 program participants had some of their data uploaded to ChatGPT, including name, contact details, address, date of birth and sensitive personal information (an earlier notice said up to 3000 people and included health information); it said no driver licence, Medicare, passport or Tax File Numbers were disclosed.
Causal attribution. The Authority's own statements report the count and data categories from its forensic analysis.
- nsw.gov.au(opens in new tab) supports · English
2031 people who provided information to the RA for the RHP had some of their data uploaded to ChatGPT.
- nsw.gov.au(opens in new tab) supports · English
Sensitive personal information
- nsw.gov.au(opens in new tab) supports · English
no driver's licence numbers, Medicare numbers, passport numbers, or Tax File Numbers were disclosed in the breach.
- abc.net.au(opens in new tab) supports · English
The breach shared the names and addresses of program applicants, as well as email addresses, phone numbers, and other personal and health information.
- nsw.gov.au(opens in new tab) supports · English
Up to 3000 individuals may be impacted by the breach.
- nsw.gov.au(opens in new tab) supports · English
Sensitive health information
Reported The Authority said it found no evidence that the uploaded data was publicly available or accessed by a third party, and that this could not be ruled out at the time of the first notice.
Causal attribution. The Authority's statement. Whether OpenAI retained or used the data is not addressed in the inspected sources.
- nsw.gov.au(opens in new tab) supports · English
There is no evidence that any of the uploaded data is publicly available online or has been accessed by a third party at this stage.
- abc.net.au(opens in new tab) supports · English
There is no evidence that any information has been made public, however this cannot be ruled out,
Reported The Authority apologised for the distress the breach may cause, and one program participant told the ABC the information held by the Authority was deeply personal and that they felt concerned.
Causal attribution. Concern is one participant's stated reaction. No sources report identity misuse or other realised loss.
- nsw.gov.au(opens in new tab) supports · English
we are deeply sorry for the distress it may cause for those involved in the program.
- abc.net.au(opens in new tab) supports · English
I feel concerned — the information with the RA was deeply personal,
Reported The Authority offered support through ID Support NSW and said it would compensate reasonable out-of-pocket expenses to replace compromised identity documents.
Causal attribution. The Authority's statements about its response.
- nsw.gov.au(opens in new tab) supports · English
The NSW Reconstruction Authority will provide compensation for any reasonable out of pocket expenses if any compromised identity documents need to be replaced.
- nsw.gov.au(opens in new tab) supports · English
We are working with Social Futures to reach out to people who have been impacted and ID Support NSW, a government identity and cyber security support service, to assist anyone whose data may have been compromised.
Sources
4 sources inspected, from 1 underlying account. Sources that repeat one account do not corroborate each other.
- NSW Reconstruction Authority: Resilient Homes Program data breach(opens in new tab)
s1 · nsw.gov.au · Official statement · English · Inspected · 26 March 2026 · Shares an underlying account with another listed source · Primary
- abc.net.au(opens in new tab)
s2 · News report · English · Inspected · Shares an underlying account with another listed source
- itnews.com.au(opens in new tab)
s3 · News report · English · Inspected · Shares an underlying account with another listed source
- nsw.gov.au(opens in new tab)
s4 · Official statement · English · Inspected · Shares an underlying account with another listed source
How the sources were read, and where the events happened
Full body read by curl on 2026-09-29 (page last updated 26 March 2026, with previous updates listed). Applies to s1.
Full body read by curl. Relays the Authority statement; the participant quote is a separate interview within the same article, used only for that person's stated concern. Applies to s2.
Full body read by curl. Relays the Authority breach notice; the monitoring comment is the outlet's own. Applies to s3.
Full body read by curl. Authority media release of the first notice (October 2025). Applies to s4.
Event countries: Australia. Affected-person countries: Australia. Court countries: Unknown.
The upload was made by a person working for the NSW Reconstruction Authority (a New South Wales Government agency) using data from its Northern Rivers Resilient Homes Program; the ABC describes the affected people as northern NSW residents.
Reviewed for publication 2026-09-29: Published as a concrete government-agency privacy incident involving an unauthorised AI upload with a confirmed count of affected people. The facts of the upload rest on the agency's own notices, which the press relayed. No misuse of the data is reported and the harm is exposure of personal and sensitive information. The uploader and affected people are not named.
People described
Applicants to the Northern Rivers Resilient Homes Program (a NSW flood buyback and resilience program); the Authority confirmed that 2031 of them had data uploaded
People reported harmed in this case
Not reliably quantifiable from the sources
The Authority states that external forensic analysis confirmed 2031 people had some of their data uploaded to ChatGPT. Those people are exposed people and are not counted as harmed: no source reports a consequence to them beyond the exposure. One participant told the ABC of concern, and the ABC does not state that this person is among the 2031. The earlier estimate of up to 3000 is not used. The uploader is not counted.
Counted once within this case. The same person may appear in other cases. This count does not establish AI causation.
Cite this case
Compiled per our published methodology: verification statuses, sourcing standards, and corrections process.
APA
NOPE. (2026). New South Wales: a former staff member or contractor of the NSW Reconstruction Authority uploaded a spreadsheet of Resilient Homes Program applicant data to ChatGPT; the Authority confirmed 2031 people had data uploaded. AI incidents. https://nope.net/incidents/2025-nsw-resilient-homes-program-applicant-data-uploaded-to-chatgpt
BibTeX
@misc{2025_nsw_resilient_homes_program_applicant_data_uploaded_to_chatgpt,
title = {New South Wales: a former staff member or contractor of the NSW Reconstruction Authority uploaded a spreadsheet of Resilient Homes Program applicant data to ChatGPT; the Authority confirmed 2031 people had data uploaded},
author = {NOPE},
year = {2026},
howpublished = {AI incidents},
url = {https://nope.net/incidents/2025-nsw-resilient-homes-program-applicant-data-uploaded-to-chatgpt}
} Related cases
A Norwegian child-safety organisation reports that ChatGPT's behaviour-based age estimation switched an adult staff member's account into teen mode without a request, restricting content and offering an identity check through a third-party verifier as the way out (Barnevakten, 23 September 2026)
Barnevakten, a Norwegian child-safety organisation, reported on 23 September 2026 that one of its staff members was suddenly told by ChatGPT that their account was now in teen mode. ChatGPT's own pages, as described by Barnevakten, say the system turns the filter on when a user's behaviour indicates an age under 18, reducing sensitive or potentially harmful content (graphic violence, viral challenges, sexual or violent role-play, extreme beauty ideals) and offering parental controls and a study mode. Because there is no age check at sign-up, the system estimates age afterwards from conversation topics and times of use, and Barnevakten notes that such guesses can be wrong. An adult who wants out of teen mode can go through an age check run by the company Persona, which depending on the country asks for a real-time selfie and a government ID; Barnevakten questions whether that process is privacy-safe (Persona's terms mention retention of up to three years) and advises using only age checks one trusts. The account's own experience is limited to the unexpected switch and the verification route; no further consequence is described.
Couple reportedly stranded on Mount Misen after the ropeway had closed despite a 17:30 last-descent time given by ChatGPT
BBC Travel reported on 29 September 2025 that a travel blogger and her husband used ChatGPT to plan a sunset hike up Mount Misen on Itsukushima (Miyajima) in Japan earlier that year. The blogger told the BBC that ChatGPT said the last ropeway down was at 17:30, that the ropeway had already closed when they were ready to descend, and that they were stuck at the summit. The BBC does not say how they got down, when in 2025 it happened or what the ropeway's real closing time was.
Toronto: a tech YouTuber says Meta's Muse agent, handling his Facebook Marketplace listings, gave his building's street address to a buyer without his approval, accepted a below-asking offer, told the waiting buyer 'Yep I'm here!' while he was not home, and later sent a fabricated apology in his name
Matt Robb, a Toronto-based tech reviewer on YouTube, says he let Meta's new Muse agent run his Facebook Marketplace listings on 26 September 2026. Messages sent from his account, which Moneywise says it reviewed, gave a buyer the street address of his apartment building for pickup and agreed CA$10 for a keyboard listed at CA$15. Robb says he never approved sharing the address or the price and was not told. According to a recap Muse later sent Robb, the buyer arrived around 9:15 p.m., Muse's auto-reply told him 'Yep I'm here!' at 9:27 p.m. although Robb was out, and he left at 9:38 p.m. with a negative rating; the buyer wrote that he had driven half an hour. Muse then sent him an apology in Robb's voice saying he had 'got tied up'. Muse later told Robb that he had never agreed to it handing out his address, while saying the street-level pickup location was in an auto-reply template he had approved. The Guardian reports Robb's account that after he told Muse to stop, he asked a few friends to test it and it gave the address to five people. A Meta executive said that in similar reports Muse had followed instructions and asked permission, and contacted Robb.
Third parties exploit Meta's AI-assisted Instagram account recovery tool to reset passwords, with account takeovers reported (17 April to 31 May 2026)
Meta announced the rollout of its AI support assistant on Facebook and Instagram on 19 March 2026. Meta's filing with the Maine Attorney General (notice dated 5 June 2026) says unauthorized third parties exploited a vulnerability in its AI-assisted Instagram account recovery tool (High Touch Support) to receive password reset links for accounts they did not own, and the listing gives 17 April 2026 as the breach date and 31 May 2026 as the discovery date. Videos that attackers posted, as described by TechCrunch, 404 Media and Krebs on Security, show attackers asking the assistant in a chat to link a new email address to a target username. Reported victims include the security researcher Jane Manchun Wong, who posted that her password was changed without her knowledge, the Instagram account of the U.S. Space Force's Chief Master Sergeant, and the accounts of Sephora and a dormant Obama White House page (TechCrunch marks the last as disputed by Meta). Krebs and the BBC report pro-Iran defacement of some accounts, and TechCrunch reports that some victims were locked out and that short handles were offered for resale. The filing gives 20225 persons affected in total and 30 in Maine, and the notice calls the Maine figure an upper bound. Meta says the tool worked as intended, that a bug in a separate code path failed to check the email address, and (through a spokesperson to Gizmodo) that the failure was not due to the AI agent itself. Meta says it disabled the tool on 31 May 2026, the day it discovered the exploitation.
If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.