'This situation is obviously unacceptable': OpenAI agent allegedly hacks Australian government healthcare website
Date:
Thu, 24 Sep 2026 10:13:46 +0000
Description:
Australian government calls OpenAI behavior "unacceptable" as it investigates the incident further.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter OpenAI agent breached
Australias Medicare portal on June 18, 2026, accessing internal files Government says no personal medical data was taken, but three other agencies may be affected PM Albanese slammed OpenAIs 84day delay in disclosure,
calling the notification unacceptable and warning of legal consequences An OpenAI agent has allegedly broken into a website of the Australian
government, which has slammed the unacceptable attack, promising an in-depth investigation, and threatening legal consequences.
Australian Prime Minister Anthony Albanese revealed how in June 2026, OpenAIs research team tasked the agent with researching public medicine spending, as part of an internal capability evaluation - but as the agent got to work, it was initially denied access to some of the information it requested. However, instead of stopping, or trying to find a different lawful way of obtaining this data, it circumvented those restrictions and landed inside the infrastructure behind Services Australias public-facing Medicare Statistics Reporting Service portal. Latest Videos From TechRadar Watch full video here: AI agent did what? The public details are still quite limited, and we dont know the technicalities of what the AI actually did.
The acting prime minister, Richard Marles, told the media during a recent press conference that the AI scaled the fence, despite the portal having security measures in place. You may like OpenAI says its models escaped a sandbox and breached Hugging Face OpenAI reveals more on Hugging Face AI hack incident, and it's pretty disturbing stuff AI agents organized into a swarm, considered the risks of attack, and did whatever it took to achieve its goal OpenAI hid AI agent hijacking of German wiki forum for weeks because its model did the exact same thing in the Hugging Face attack
The bot apparently accessed internal infrastructure and wrote files to an internal server but exactly what it wrote, how it obtained the access, and precisely which technical mechanism it used, is still not public knowledge.
Once inside, it accessed both public and non-public files, but individual medical data was not accessed and the system itself was not compromised, the Australian government said. Are you a pro? Subscribe to our newsletter Sign
up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
There is also the possibility that three other government systems were affected - the Australian Institute of Health and Welfare and two state-based agencies - the New South Wales Bureau of Crime Statistics and Research and
the Victorian Department of Health. However, this has not been confirmed yet.
"No personal information is believed to have been accessed at this stage, but investigations are ongoing," Albanese said. "Nonetheless this situation is obviously unacceptable." OpenAI's sluggish escalation Albanese was particularly unsatisfied with how OpenAI handled the situation. The breach happened on June 18, but it took the company 84 days to notify the Australian government of the incident. And when it did - it did so in a manner better suited for an amateurish start-up rather than one of the most important organizations on the planet right now. What to read next RubyGems say OpenAI agents responsible for undisclosed swarm attack against its infrastructure Experts explain why OpenAI's 'mind-blowing' cyberattack should worry us all White hat hackers just breached OpenAI using Anthropic's Claude in less than 72 hours and it is a case study in just how fast AI is advancing
OpenAI was apparently evaluating its models, and investigating misaligned model activity when, on August 11, it discovered the breach in Australia. It seems the AI agent simply did not take no for an answer. The company then notified Services Australia on September 10 - almost three months after the incident. To make matters worse, the company reached out via
publicdisclosures@servicesaustralia.gov.au, inbox researchers usually use to report potential vulnerabilities, instead of trying to escalate the incident higher.
Services Australia reviewed the information and notified the Australian Signals Directorate on September 15.
When the news reached prime minister Anthony Albanese, he spoke to OpenAI
CEO, Sam Altman, and expressed the countrys extreme concern about this incident, as well as his disappointment that it took the company way too long to inform the government what had occurred. He also pointed out the way
OpenAI reached out: The notification was an email sent just to the public mailbox. Albanese described the nature of the notification as unacceptable.
The Australian government is now looking into the matter to see if any laws were broken and what legal consequences, if any, could follow.
"And obviously we will investigate all of that. What the consequences are, if there has been a breach of the law, but also part of the task force is to assess whether or not the legal regime we have in place is fitforpurpose in a world where we have an emerging AI capability, Marles said.
Via BBC The best antivirus for all budgets Our top picks, based on
real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/this-situation-is-obviously-unacceptabl e-openai-agent-allegedly-hacks-australian-government-healthcare-website
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)