‘This situation is obviously unacceptable’: OpenAI agent allegedly hacks Australian government healthcare website
- OpenAI agent breached Australian Medicare portal on June 18, 2026, accessing internal files
- Government says no personal medical data was taken, but three other agencies may be affected
- Prime Minister Albanese criticized OpenAI’s 84-day delay in disclosure, calling the notification “unacceptable” and warning of legal consequences.
An OpenAI agent allegedly broke into an Australian government website, which criticized the attack as “unacceptable,” promised a thorough investigation, and threatened “legal consequences.”
Australian Prime Minister Anthony Albanese revealed how in June 2026, the OpenAI research team tasked the agent with investigating spending on public medicine, as part of an internal capacity assessment, but when the agent got to work, he was initially denied access to some of the information he requested.
However, rather than stopping or trying to find a different legal way to obtain this data, it bypassed those restrictions and landed within the infrastructure behind Services Australia’s Medicare Statistics Reporting Service public portal.
Latest videos ofTechnologyRadar
What did the AI agent do?
Public details are still quite limited and we don’t know the technical details of what the AI actually did.
Acting Prime Minister Richard Marles told the media during a recent press conference that the AI “scaled the fence,” even though the portal had security measures in place.
The robot apparently accessed internal infrastructure and wrote files to an internal server, but it is not yet public knowledge exactly what it wrote, how it gained access, and exactly what technical mechanism it used.
Once inside, public and non-public files were accessed, but no individual medical data was accessed and the system itself was not compromised, the Australian government said.
There is also the possibility that three other government systems have been affected: the Australian Institute of Health and Welfare and two state agencies: the New South Wales Bureau of Crime Statistics and Research and the Victorian Department of Health. However, this has not yet been confirmed.
“It is not believed that personal information was accessed at this time, but investigations are ongoing,” Albanese said. “However, this situation is clearly unacceptable.”
The slow rise of OpenAI
Albanese was particularly dissatisfied with the way OpenAI handled the situation. The breach occurred on June 18, but it took 84 days for the company to notify the Australian government of the incident. And when it did, it did so in a way more suited to an amateur startup than one of the biggest organizations on the planet right now.
OpenAI was apparently evaluating its models and investigating “misaligned model activity” when, on August 11, it discovered the breach in Australia. It seems that the AI agent simply didn’t take “no” for an answer. The company then notified Services Australia on September 10, almost three months after the incident. To make matters worse, the company reached out via [email protected], the inbox researchers typically use to report potential vulnerabilities, rather than attempting to escalate the incident to a higher level.
Services Australia reviewed the information and notified the Australian Signals Directorate on 15 September.
When the news reached Prime Minister Anthony Albanese, he spoke to OpenAI CEO Sam Altman and expressed the country’s “extreme concern” about this incident, as well as its “disappointment that it took too long for the company to inform the government what had happened.” He also noted OpenAI’s approach: “The notification was an email sent to the public mailbox only.” Albanese described the “nature of the notification” as “unacceptable.”
The Australian government is now investigating the matter to see if any laws were broken and what legal consequences, if any, might follow.
“And obviously we will investigate all of that. What the consequences are, whether there has been a violation of the law, but also part of the task force is to evaluate whether the legal regime that we have is fit for purpose in a world where we have an emerging AI capability,” Marles said.
Through bbc
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.



Post Comment