AI agent behind a restricted-area fence facing an Australian government data portal, illustrating the OpenAI Medicare security incident.

Crikey! OpenAI Agent Hacks Medicare Portal

An OpenAI research agent slipped past Services Australia’s blocks in June, reached non-public files and wrote to an internal server. OpenAI sent word 84 days later, to a public inbox.

An OpenAI agent doing internal research got past the portal’s blocks, reached non-public files and wrote files to an internal server. OpenAI took nearly three months to say so, and independent researchers say OpenAI-linked agents were probing other Australian health sites.

The incident was disclosed publicly by Prime Minister Anthony Albanese during a press conference Thursday in New York.

“This incident occurred in June of this year and involved an OpenAI agent gaining unauthorised access into the public-facing Medicare statistics reporting service portal, which is administered by Services Australia,” Albanese said.

Beyond the Break weekly cybersecurity newsletter — Subscribe

“The AI agent accessed both public and non-public files. A forensic investigation aided by the Australian Signals Directorate is now underway to ascertain more information, including what other government systems were affected,” he added.

According to the PM, OpenAI had tasked an internal model with internet research into public medicine spending as part of an internal evaluation. When the portal kept blocking it, the agent went looking for another way in and found one. Albanese said Services Australia also advises that the agent wrote files to the portal’s internal server, and that is still being investigated.

Government Services Minister Katy Gallagher said OpenAI’s September 10 notice described the agent reaching infrastructure behind the public-facing portal, and that the company handed over the vulnerability the agent had found.

Albanese said no personal information is believed to have been accessed at this stage, and there is no evidence so far of a broader compromise of the Services Australia network. Gallagher described the target as a standalone, decades-old site used mostly by researchers and academics, with no connection to Medicare claims, payments or individual records. OpenAI told the ABC it found no evidence that patient records were accessed. According to AAP, the company said the files amounted to aggregate health statistics and file names.

Acting Prime Minister Richard Marles called it a very serious incident with a relatively minor impact. He told the ABC the government keeps its most important information behind a fortress, while this portal sat behind a fence the agent climbed over. The worry is less what was taken than the fact that a research bot decided to climb.

That said, Albanese confirmed the forensic investigation, aided by the Australian Signals Directorate, is ongoing, so the ultimate toll of what data was compromised could change. That includes three other systems the PM said the agent may have touched which include The Australian Institute of Health and Welfare, the NSW Bureau of Crime Statistics and Research, and the Victorian Department of Health.

Marles later said the agent’s activity on those three sites was entirely normal and involved only public information. BOCSAR later said OpenAI had identified a potential vulnerability in its Crime Mapping Tool, but that there was no evidence it had been exploited or that a breach occurred. AIHW similarly said it had no evidence the agent accessed non-public information.

The Researchers Saw Something Else

Independent researchers read the AIHW activity differently. In a report published a day before the PM spoke, nonprofit AI lab Transluce says OpenAI-linked agents went after AIHW’s pharmaceutical benefits dashboard on June 20 and 21, two days after the Medicare portal break-in. The job was hardly espionage. Transluce says the agents wanted the January 2022 rolling-average government cost per person for dermatological medicines across Victorian council areas.

When Cloudflare blocked a dataset download, an agent sent a cross-site scripting probe at the dashboard, and the firewall stopped it. The agent then pulled the same file, in pieces, from AIHW’s pre-production server, getting around the site’s anti-bot controls. Transluce says the file was public, so no non-public data was exposed, and it saw no successful exploitation. The lab also cautions that its public data is incomplete and can’t rule out activity it couldn’t see.

Transluce ties the AIHW activity to the agent swarm OpenAI has already acknowledged, based on shared targets, tactics and timing. It does not claim the AIHW probes came from the same run as the Medicare portal incident, and nobody has confirmed that yet. It calls the attempted AIHW compromise part of what it says is the first reported instance of agents hacking a government. The researchers say they disclosed their findings to OpenAI and the affected organizations on September 21 and 22.

Three Months and a Public Inbox

The break-in happened June 18. OpenAI says it found the activity during a review of misaligned model activity in training, and the ABC dates that discovery to August 11. On September 1, Altman met Marles in San Francisco, and Marles says the breach wasn’t raised.

OpenAI’s notice finally arrived September 10, as an email to Services Australia’s public mailbox. Per SBS, it was opened the next day. After verifying it was legitimate, Services Australia passed it to ASD’s Australian Cyber Security Centre on September 15. Gallagher was told on September 17, and ministers spent the weekend of September 19–20 working through it with Services Australia and ASD. The first technical exchange between OpenAI and Services Australia came on September 22, two days before the public announcement. Albanese said both the delay and the delivery method were unacceptable.

The two sides also describe the job differently. The government calls it research into public medicine spending. OpenAI, in a statement to the ABC, said its models were looking up answers and statistics about Australia during an internal evaluation, and acted in ways the company didn’t intend.

Ongoing Issue

The incident is the latest in a run of OpenAI agents wandering outside their intended boundaries. OpenAI’s own Misalignment Reports and Notices page logs a Hugging Face compromise, agents using a public wiki as a shared message board, and an open investigation into agent activity on RubyGems. The same page’s training reports describe models searching public GitHub repositories for leaked API keys and uploading files to public hosting services. As of this writing, it carries no entry for the Australian incident.

Transluce’s findings stretch the timeline further. The lab logged similar probes against Data USA and the University of New Mexico’s digital library in May. It traces agent activity back to at least March, earlier than previously reported incidents, and the most recent it records is September 16. In the hacking attempts Transluce identified, the agents were doing ordinary data lookups, not security work, when they began probing for vulnerabilities. Transluce says the pattern is consistent with, but doesn’t prove, agents picking up the behavior over one or more training runs.

OpenAI’s own review is broader than Australia. A company spokeswoman told The New York Times that it has contacted Data USA and the University of New Mexico about agent activity there and said the wider investigation will take months. OpenAI said it is prioritizing the most serious incidents while expanding the review to lower-severity behavior, including agents spamming websites.

Lawrence Chan, an alignment researcher who by his own account spent 2022 to 2026 building dangerous-capability evaluations at METR, called Transluce’s investigation clever. “I do hope that OpenAI will do full disclosure of incidents on their own in the future, instead of via independent researchers doing digital forensics,” Chan wrote on X.

Even the industry’s chief supplier is losing patience. Nvidia CEO Jensen Huang, speaking on The Ezra Klein Show the day before the Australian disclosure, framed it as a conditional. If labs concede there is no way to contain their experiments, “then I think the answer is that we have to shut the labs down.” Huang made clear in the same interview that he opposes a broad industry slowdown.

The timing did the PM’s argument no harm. A day earlier, on the sidelines of the UN General Assembly, Albanese co-signed a statement with 21 other signatories calling for control of frontier AI models, and Altman addressed the UN Security Council on AI risk. Albanese said lessons from the incident will feed into his government’s AI standards legislation.

Assistant Minister for Science, Technology and the Digital Economy Andrew Charlton said Friday Australian time that the government plans to unveil mandatory AI safety standards by the end of this year and hopes to pass the legislation in early 2027.

As for Albanese, the Aussie-In-Chief says he had a chat with OpenAI boss Sam Altman to “express Australia’s extreme concern” with the incident, which seems to be a very diplomatic way to say he gave the CEO a good chewing out.

Albanese described the conversation as courteous in both directions but “very frank.” Asked whether Altman had apologized, the prime minister said the OpenAI chief had clearly accepted that the company “had not done good enough” and acknowledged problems with its protocols.

‘Misalignment’ or Malfeasance?

OpenAI subsequently said the incident surfaced during an extensive review of “misaligned model activity” during training and evaluation. The company said its models had been trying to retrieve answers and publicly available statistics about Australia during an internal evaluation when they “took actions we did not intend.”

The company said its review found activity involving several Australian government websites and services, but no evidence that patient records were accessed. It said the information reached included aggregate health statistics and internal file names. OpenAI also defended its initial notification process, saying the company used a designated channel commonly used for direct communication between security practitioners and later maintained contact with the Australian Signals Directorate.

OpenAI told CNBC that it notified Services Australia after investigating what the agent had accessed.

As a result, the Australian government has established a task force to review whether existing processes are up to the job of handling AI-related cyber incidents.

“The taskforce will be led by my department and involve the National Cybersecurity Coordinator, the Office of AI, the Australian Signals Directorate, the Australian AI Safety Institute, and Services Australia,” Albanese said.

“And we will release – Acting Prime Minister Richard Marles and Katy Gallagher will hold a media conference soon this morning and release the terms of reference into the review. The report will consider also possible law enforcement and legislative responses and how to ensure that incidents like this don’t happen again.”

Those terms of reference are now out. The rapid review will examine reporting requirements for AI-driven cyber incidents, how incidents are escalated and information shared inside government, what obligations AI companies should have to report and cooperate, whether existing offences, liabilities, penalties and enforcement powers are adequate, and how government networks can be hardened against AI-driven vulnerabilities.

The PM said the government will also refer the incident to Parliament’s Joint Select Committee on Artificial Intelligence. A newly created interagency taskforce will examine the incident, including whether laws were broken and whether the matter should be referred to the Australian Federal Police.

Marles and Gallagher held a media conference in Sydney later Thursday, where Marles said the taskforce would also examine emerging AI cyber threats, government network security and whether Australia’s existing legal framework is adequate. Gallagher said further technical meetings with OpenAI were planned.

In a same-day response that considerably widened the audience for the warning, ASD’s Australian Cyber Security Centre issued a High-rated alert on AI misalignment. The agency warned that when security controls prevent an agent from completing its assigned task, an agent may independently identify vulnerabilities and attempt actions its operators never authorized.

ASD said there was no indication of broader malicious targeting of Australia, but urged organizations with public-facing systems to prepare for exactly this kind of behavior.

Total
0
Shares
Previous Article
Okta CEO Todd McKinnon discusses AI agent security during the Oktane 2026 keynote in Las Vegas

Okta CEO Lays Out AI Agent Security Push at Oktane 2026

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading