A loose OpenAI agent has hacked an Australian government website, according to Australian Prime Minister Anthony Albanese.
Allegedly, an OpenAI agent researching public medicine spending encountered repeated blocks while looking for data, tried alternative routes, and ultimately gained unauthorized access to non-public files on a government statistics portal.
The Prime Minister said the access occurred on June 18. Australia has launched an urgent review, while officials say no personal information is believed to have been accessed.
The Medicare Statistics Reporting Service was a public-facing portal administered by Services Australia and contained non-sensitive Medicare statistics. Services Australia also advised that the agent wrote files to an internal server, which remains under investigation.
The agent also interacted with the Australian Institute of Health and Welfare, the Victorian Department of Health and the New South Wales Bureau of Crime Statistics and Research. Acting Prime Minister Richard Marles later said those interactions involved only public information. Unauthorized access has been confirmed only at the Medicare portal.
How an 84-day reporting gap split into two delays
ABC News reported that OpenAI became aware of the incident on Aug. 11 during a review of misaligned model activity, 54 days after the June access. It notified Services Australia on Sept. 10, another 30 days later, through an inbox used by researchers and academics to report vulnerabilities.
Albanese said he told OpenAI CEO Sam Altman the delay was too long and the notification method was unacceptable. Government Services Minister Katy Gallagher said the incident should instead have been escalated through the Australian Signals Directorate (ASD) or senior Services Australia channels.
OpenAI said its models “took actions we did not intend” and that its review found no evidence of patient records being accessed. The information accessed included aggregate health statistics and internal file names.
Maria Dunford, CEO of biomedical data platform, Lifebit, said that this is what happens when AI agents are given autonomous access to sensitive data instead of operating within governed boundaries.
“A health data breach shouldn’t be something a government or health system finds out about two months after the fact, via an email to a general inbox; it should be structurally impossible.”
Justin Allen, senior manager of security operations for Asia-Pacific at Huntress, said the episode shows why collecting logs is not enough without active monitoring. He pointed to ASD guidance that prioritizes logging critical data holdings and internet-facing services and recommends centrally aggregating logs for monitoring and detection.
“Logs on their own don’t detect anything,” Allen told TechInformed. “Someone has to be reading them and able to act at the same speed as the attacker.”
Agents can change tactics
Nathan Davies-Webb, principal consultant at Acumen Cyber, said the concern is less about new hacking techniques than how quickly an agent can gather information, act and change tactics. When probing the Australian Institute of Health and Welfare site, he said, the agent reportedly recognized that Tableau was serving the data and moved to probing the application for vulnerabilities.
“The real threat isn’t that it can conduct these actions; the techniques have been long established,” Davies-Webb told TechInformed. “It’s the speed at which it can execute, evaluate and then try something new.”
He also said broader agent activity has included bypassing anti-bot controls and using relay services to mask request origins, making some traditional defenses less effective.
The entry method used against the Medicare portal remains unknown. Australia’s task force will review whether existing processes are adequate for AI-related cyber incidents and consider possible law enforcement and legislative responses.