Flood victims’ data uploaded to ChatGPT by former contractor
A former contractor working for the NSW Reconstruction Authority uploaded a government spreadsheet containing personal details of flood victims to ChatGPT. The file held more than 12,000 rows of information from the Northern Rivers Resilient Homes Program, which was created after the 2022 floods that devastated large parts of northern New South Wales.
The upload happened between March 12th and 15th but was disclosed publicly yesterday, more than six months later as Cybersecurity Awareness Month begins across Australia.
While the file may not have been accessed by anyone else, the act of uploading it put private data in an uncontrolled system that can’t be audited or recalled.
What the file contained
The spreadsheet included names, contact details, addresses, and in some cases health information tied to program applicants.
Forensic checks suggest that around 3000 people are directly affected, although every entry is still being reviewed to confirm exactly what data was shared.
The file came from an internal dataset used to manage rebuilding and relocation grants. The spreadsheet was uploaded to ChatGPT by a contractor looking for help with data analysis.
It has since been removed, and no copies have been found online or on the dark web yet.
The risk behind the upload
Public AI platforms like ChatGPT store prompts and inputs to improve their language models.
Once information is submitted, there is no way to guarantee that it can be deleted or prevented from being surfaced in future outputs. For any organisations managing sensitive or regulated data, this makes generative AI tools vulnerable for any task involving real people’s details.
Government response
People whose identity information was involved will be offered support to replace documents and receive guidance on identity protection
The broader issue
We’ve seen similar incidents that have been reported across Australia, where staff have uploaded internal information into open AI systems without understanding how data persistence works.
These breaches are rarely malicious. They happen because people put too much trust in the tools they use every day.
Human error continues to be the single biggest driver of data exposure in both public and private sectors. Without clear rules and training, the same mistakes will keep repeating.
Where responsibility lies now
Every organisation using AI needs defined boundaries. Staff and contractors should know which platforms are approved, what kinds of data are off limits, and how to check before uploading.
Governance should extend beyond policy documents to real technical controls, including data loss prevention and prompt filtering.
Generative AI has changed what “uncontrolled data” means. Once information is entered, it belongs to the model, not the user. Treating that boundary seriously is the only way to keep sensitive data secure.
Gridware works with government and enterprise clients to build safe AI environments and educate teams on secure automation practices.



