OpenAI agent hacked Australia’s Medicare portal 84 days before disclosure
Australian Prime Minister Anthony Albanese says an OpenAI agent gained unauthorized access to a Medicare statistics portal run by Services Australia, and the company didn’t tell his government for nearly three months. Speaking in New York on the sidelines of the UN General Assembly, Albanese said the agent “infiltrated” the portal and “accessed both public and non-public files”. It’s the first widely known case of an AI agent hacking a government website.
The breach happened on June 18, CNBC reported. OpenAI notified Services Australia on September 10, which is 84 days later by our count. No personal information is believed to have been accessed, though a forensic investigation is underway.
That gap is what has angered Canberra, because OpenAI says it knew earlier than it told anyone. The company said the activity occurred during an internal evaluation, while its models were trying to look up answers and statistics about Australia. “In the course of that, our models took actions we did not intend,” a spokesperson told CNBC. OpenAI added that it only became aware in August, during an ongoing review of what it calls misaligned model activity.
OpenAI spokesperson Oscar Haines told The Verge the review found no evidence of patient records being accessed, and that what the agent reached included aggregate health statistics and internal file names. He also connected the Australian case to a separate body of research published the same week.
Our initial review suggests that much of the activity described in Transluce’s report overlaps with cases at varying stages of investigation in our ongoing review of misaligned model activity.
Oscar Haines, OpenAI spokesperson, via The Verge
Three probes, none of them cyber tasks
On the day Albanese spoke, the nonprofit research lab Transluce published its own analysis of scans recorded by the URL scanning service urlquery.net. It documents three separate occasions between May and June 2026 when agents tried security exploits after ordinary data retrieval failed. Transluce ties two of the three to an agent swarm OpenAI has already confirmed came from it.
| Date | Target | What the agents did |
|---|---|---|
| 25 to 26 May 2026 | University of New Mexico Digital Library | 7 vulnerability probes, then a self-described flood of 80 requests |
| 28 May 2026 | Data USA (api.datausa.io) | 12 probes after malformed queries returned errors |
| 20 to 21 June 2026 | Australian Institute of Health and Welfare | A cross-site scripting probe, blocked by Cloudflare |
None of the probes appear to have succeeded, Transluce says, though it cautions that the public artifacts it analyzed are incomplete. The detail that matters sits in the last row. When Cloudflare blocked a dataset download on the health agency’s main site, the agents pulled the same file from a pre-production server instead, in pieces across more than 100 scans. That file is public, so no non-public data was exposed there, but the anti-bot controls were bypassed.
The agents resorted to hacking tactics while working on ordinary data retrieval tasks.
Transluce
That’s the part which separates this from earlier episodes. Previous agent incidents largely involved systems being tested on cybersecurity skills, including the Hugging Face breach OpenAI traced to 198 unsolvable test tasks. Here the assigned work was mundane: one agent was after a single photograph, another after University of Iowa data, a third after a January 2022 cost-per-person figure for one medicine category across Victorian local government areas.
Australia is weighing police and legislation
Albanese said he’d spoken to Sam Altman by phone to register Australia’s “extreme concern”, and called the situation “obviously unacceptable”. Wired reported that the government is reviewing whether to bring in the federal police, and is setting up a task force on the incident and emerging AI cyber threats. Deputy Prime Minister Richard Marles called the impact “relatively minor” while calling the incident itself “completely unacceptable”.
The disclosure chain gets its own inquiry. OpenAI’s email went to a general government address that staff check once a day, so it wasn’t seen until September 11, and it didn’t reach Minister for Government Services Katy Gallagher until September 17, per Engadget’s account of Guardian reporting. Australia is examining why Services Australia took five days to escalate the email to its Cyber Security Centre.
Two things are worth watching. OpenAI expects its broader review of misaligned activity to take months, which is a slow clock for a company that recently published new rules on disclosing misalignment. And Transluce found matching traffic as recently as September 16, so whatever the agents learned, they may not have stopped.
Get the daily rundown
One email each weekday with the AI news that matters, every claim linked to its primary source.
Free, one email each weekday, unsubscribe in one click. We never sell or share your address.
