Gridware Logo

Contractor uploads NSW flood victims’ data to ChatGPT

By Ahmed Khanji Updated 7 October 2025 3 min read

in 𝕏
Contractor uploads NSW flood victims’ data to ChatGPT

Flood victims’ data uploaded to ChatGPT by former contractor

A former contractor working for the NSW Reconstruction Authority uploaded a government spreadsheet containing personal details of flood victims to ChatGPT. The file held more than 12,000 rows of information from the Northern Rivers Resilient Homes Program, which was created after the 2022 floods that devastated large parts of northern New South Wales.

The upload happened between March 12th and 15th but was disclosed publicly yesterday, more than six months later as Cybersecurity Awareness Month begins across Australia.

While the file may not have been accessed by anyone else, the act of uploading it put private data in an uncontrolled system that can’t be audited or recalled.

What the file contained

The spreadsheet included names, contact details, addresses, and in some cases health information tied to program applicants.

Forensic checks suggest that around 3000 people are directly affected, although every entry is still being reviewed to confirm exactly what data was shared.

The file came from an internal dataset used to manage rebuilding and relocation grants. The spreadsheet was uploaded to ChatGPT by a contractor looking for help with data analysis.

It has since been removed, and no copies have been found online or on the dark web yet.

The risk behind the upload

Public AI platforms like ChatGPT store prompts and inputs to improve their language models.

Once information is submitted, there is no way to guarantee that it can be deleted or prevented from being surfaced in future outputs. For any organisations managing sensitive or regulated data, this makes generative AI tools vulnerable for any task involving real people’s details.

Government response

People whose identity information was involved will be offered support to replace documents and receive guidance on identity protection

The broader issue

We’ve seen similar incidents that have been reported across Australia, where staff have uploaded internal information into open AI systems without understanding how data persistence works.

These breaches are rarely malicious. They happen because people put too much trust in the tools they use every day.

Human error continues to be the single biggest driver of data exposure in both public and private sectors. Without clear rules and training, the same mistakes will keep repeating.

Where responsibility lies now

Every organisation using AI needs defined boundaries. Staff and contractors should know which platforms are approved, what kinds of data are off limits, and how to check before uploading.

Governance should extend beyond policy documents to real technical controls, including data loss prevention and prompt filtering.

Generative AI has changed what “uncontrolled data” means. Once information is entered, it belongs to the model, not the user. Treating that boundary seriously is the only way to keep sensitive data secure.

Gridware works with government and enterprise clients to build safe AI environments and educate teams on secure automation practices.

Ahmed Khanji

Ahmed Khanji

CEO, Gridware

Ahmed Khanji is the CEO of Gridware, a leading cybersecurity consultancy based in Sydney, Australia. He is recognised for his insights into offensive security and emerging technologies such as blockchain, and often contributes to broader cybersecurity conversations across the country. With an extensive background as a security advisor to major Australian enterprises, Ahmed helps organisations navigate the evolving threat landscape with clarity and confidence.