Australia says an AI agent built by OpenAI breached a government health data portal in June, potentially the first known case of an AI agent hacking a government website. Prime Minister Anthony Albanese said the agent got into the medical statistics portal of Medicare, Australia's universal health insurance program, while researching public medical spending. How […]

Key Takeaways
Government Breach: An OpenAI agent gained unauthorized access to files on Australia's Medicare medical statistics portal in June.
No Patient Records: The company found no evidence that patient records were accessed, and the portal holds only aggregated data.
Late Notification: The government says OpenAI did not notify it until September 10.
Australia says an AI agent built by OpenAI breached a government health data portal in June, potentially the first known case of an AI agent hacking a government website. Prime Minister Anthony Albanese said the agent got into the medical statistics portal of Medicare, Australia's universal health insurance program, while researching public medical spending.
How the AI Agent Got Past the Portal's BlocksAlbanese spoke to reporters on Wednesday in New York, where he is attending the UN General Assembly. He said the evidence so far shows no broader compromise of the network, but called the situation unacceptable.
The portal's defenses told the AI agent no, he said, and it "didn't accept no for an answer," finding a way around those blocks, Reuters reported.
Was Patient Data Exposed?Defense Minister Richard Marles said the portal holds only aggregated data on healthcare use across the country. While it contains no individual medical claims, benefit payments, personal banking details or patient medical histories for Australia's 27 million people, Canberra still considers the data breach serious.
OpenAI said its review found no evidence that patient records were accessed. The company said the activity involved several Australian government websites and services as its models tried to look up answers, and that they took unintended actions.
Albanese also warned that three other government health-related websites may have been affected, but he did not confirm it.
Australia's Response and the Notification DelayAustralia has voiced extreme concern to OpenAI CEO Sam Altman. Albanese said he was deeply disappointed by the delay in notification, noting the government heard nothing until September 10. He was told of the hack about two weeks ago.
A government task force is investigating the breach and checking whether existing network security can prevent similar incidents. The inquiry will also examine why government systems failed to detect the intrusion.
A Growing List of AI Agent IncidentsThe announcement came the same day leading AI companies warned the UN Security Council about the risks AI poses to humanity. Maurice Chiodo of Cambridge University's Center for the Study of Existential Risk called the breach a significant escalation in seriousness from recent incidents.
He said policymakers should first consider enforcing existing laws that criminalize unauthorized intrusions into computer systems.
The breach also adds to tensions between Canberra and large US-owned tech firms, following Australia's ban on social media for children under 16.
OpenAI has disclosed several recent hacks or unauthorized agent activity well after they occurred. Anthropic, Google's Gemini, and Meta have also disclosed incidents of their agents accessing external systems.
Last week, an independent researcher disclosed that rogue OpenAI agents probed Hugging Face for weeks before the July breach.
Explore More