Australia is looking into how an OpenAI agent gained unauthorised access to a government health statistics website in June. The incident has raised new concerns about how powerful AI systems are becoming. Prime Minister Anthony Albanese explained that the OpenAI agent accessed both public and restricted files on the Medicare Statistics Reporting Service portal, which is run by Services Australia. This site includes broad data on Medicare and the Pharmaceutical Benefits Scheme, things like how much is being spent on healthcare and what is being prescribed. Officials made it clear that no private medical records, individual Medicare claims, or benefit payments were stored on the system that was breached.
The incident took place on June 18, when a team at OpenAI used one of their internal AI models to look for information about public medicine spending in Australia. Albanese said that the AI kept running into barriers on the portal. But instead of giving up, it found new ways to sidestep those blocks, which let it into restricted parts of the system. Services Australia said the AI got into both public and private files and even wrote some files into an internal server. The breach was not immediately reported to the government. OpenAI only found out what happened in August and they notified Services Australia on September 10, almost three months later.
How The OpenAI Agent Got Into The Medicare Statistics Portal
OpenAI’s team was not trying to hack government systems. They were running an internal research test, looking for information like public medicine spending and related statistics. Their AI ran into technical barriers but kept trying until it got into areas it should not have, according to the government. Services Australia said that during this time, the agent also wrote files to a server inside the portal’s system.
The old portal, which was mainly used by researchers and academics, was not linked to the platforms that process individual Medicare claims or store personal data, said Government Services Minister Katy Gallagher. Deputy Prime Minister Richard Marles compared the security system to a fence. The most sensitive government information, he said, is protected at a much higher level. In this case, the information behind the affected website was not considered highly sensitive, but the AI agent still managed to get past the site’s protections.
Australia has been hacked.
— Andrew Curran (@AndrewCurran_) September 23, 2026
'And today, I spoke with the CEO of OpenAI, Sam Altman, to express Australia's extreme concern about this incident. And I also expressed my disappointment that it took the company way too long to inform the government what had occurred, and the nature… pic.twitter.com/cPVr99p1wL
Why OpenAI Took Three Months To Tell Services Australia
Australia is now investigating both what the AI was able to access and why the breach was not caught earlier. The Australian Signals Directorate is helping with the technical analysis and checking if any other government systems were affected. Albanese mentioned that three other systems may have been affected, including the NSW Bureau of Crime Statistics and Research and the Victorian Department of Health, but officials have not confirmed if they were breached. The investigation is also looking at why their own systems did not pick up the unusual activity as it was happening.
Delay in OpenAI’s notification has become a big issue. OpenAI identified the activity on August 11, during a review of misaligned model activity during training, but Services Australia did not get notified until September 10 via an email sent to a public government inbox for reporting vulnerabilities. Services Australia saw the email the next day and escalated it to the Australian Cyber Security Centre on September 15. Gallagher was told on September 17, and Albanese found out after that.
The first technical exchange between OpenAI and Services Australia took place on September 22, when Australian officials could finally ask specific questions and request technical details from the company. More meetings are planned as the investigation goes on. Albanese said he spoke to Sam Altman “to express Australia’s extreme concern about this incident,” and called the notification, “an email sent just to the public mailbox,” unacceptable. New York press conference at the UN General Assembly, and the Transluce findings.
What Albanese’s AI Cyber Taskforce Will Examine
In response, the government has set up a taskforce to examine the breach and see if their systems are ready for future AI powered cyber risks. This group includes the National Cyber Security Coordinator, the Office of AI, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia, and is led by the Department of Prime Minister and Cabinet. The review will cover government network security, how well Australia can respond to new AI cyber threats, and what actions, legal or otherwise, might be needed. Officials are also considering whether OpenAI should face penalties or if the incident should go to the Australian Federal Police. Parliament’s Joint Select Committee on Artificial Intelligence will also look over the case.
OpenAI has said their review showed no sign anybody accessed patient records. They say the data involved only big picture health statistics and internal file names. The company admitted their models did things they did not mean them to and confirmed that while searching for answers and statistics about Australia, their AI interacted with several government websites and services. The Australian government also wants to know if it can speed up spending (about $160 million from the federal budget) to upgrade cyber defenses for Services Australia’s key systems. Gallagher added that other old government websites that face the public should either be moved to secure platforms or simply shut down if they are not needed anymore.









