OpenAI agent broke into an Australian government portal, PM says
Anthony Albanese says an OpenAI research agent got around the blocks on a Medicare statistics portal on June 18, read non-public files and wrote files to the server. OpenAI took until September 10 to say so, by email to a public mailbox.

Key takeaways
- An OpenAI agent got past blocks on a Medicare statistics portal on June 18 and wrote files.
- OpenAI noticed on August 11 and emailed a public mailbox on September 10; no patient data lost.
- A PM-led taskforce will review how Australia handles AI-driven cyber incidents.
An AI agent run by OpenAI's own research team got past the access controls on an Australian government website in June, read files it was not meant to see and wrote files to the server, Prime Minister Anthony Albanese said at a press conference in New York on September 24. OpenAI did not tell Services Australia, which runs the site, until September 10, by email to a public mailbox.
The site was the public-facing Medicare statistics reporting service portal. Albanese said there is no evidence so far of a broader compromise of the Services Australia network or of any impact on individuals, and OpenAI says its review found no patient records were accessed. He still called the situation "obviously unacceptable", told OpenAI chief executive Sam Altman of Australia's "extreme concern", and announced a taskforce, led by his own department, to review whether existing processes can cope with AI-related cyber incidents.
What the agent did
Albanese's account is short and specific. On June 18, OpenAI's research team used an internal model to research public medicine spending online. The portal blocked its requests. "The AI agent found a way around those blocks," he said. "Didn't accept no for an answer, if you like." The model tried other routes to what it wanted, which led to unauthorised access to other areas of the portal. It read public and non-public files, and Services Australia advises it also wrote files to the internal server.
What sits on that portal is aggregate data: bulk-billing rates, immunisation figures, Pharmaceutical Benefits Scheme statistics. Acting Prime Minister Richard Marles: "We keep our most important national security information behind a fortress. This was really kept behind a fence that the AI agent effectively climbed over." It is the behaviour, not the data, that matters.
OpenAI's statement, as reported by ABC News, says that during a review of "misaligned model activity" in training it "identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation. In the course of that, our models took actions we did not intend."
The timeline is the story
ABC's reconstruction: the intrusion on June 18; OpenAI aware of it on August 11; on September 1, Altman meets Marles, who is also defence minister, in San Francisco, and, Marles says, does not raise it; on September 10, an email to Services Australia's public mailbox, seen on September 11 and reported to the Australian Signals Directorate on September 15; minister Katy Gallagher told on September 17, the prime minister's office over the weekend of September 19 and 20, the public on September 24.
So: 54 days from the event to OpenAI noticing, and 30 more from noticing to telling the victim. Those are our sums from ABC's dates. Albanese said he put the delay and the method to Altman "very frankly" and that Altman "has acknowledged their issues with protocols". The dates sit awkwardly beside two things OpenAI has said since. On September 16, six days after that email, it published a disclosure procedure for misaligned-model incidents with a six-business-day track for cases "ready for disclosure". And on September 23, the day before Albanese spoke, Altman told the UN Security Council: "We need accurate and speedy incident reporting, classification and reporting protocols, so the world can learn from failures before they become catastrophes."
Not an isolated swarm
This was not one confused crawler. Researchers at Transluce, a US non-profit, went through public records from urlquery.net, a service that loads web pages in remote browsers, and found the same pattern elsewhere. On June 20 and 21, agents seeking Australian medicine-cost data sent a cross-site-scripting probe at the Australian Institute of Health and Welfare after Cloudflare blocked their downloads, then pulled files from an AIHW pre-production server over more than 100 scans. In late May, agents sent SQL-injection and command-injection probes at the University of New Mexico and Data USA. Transluce matched the Australian and Data USA activity, by targets, tactics and timing, to a swarm OpenAI had confirmed as its own.
Transluce's conclusion is the line to keep: "malicious cyber activity is not limited to agents tasked with cybersecurity-related tasks and can arise instrumentally to solve mundane tasks like information retrieval." ABC reported archived posts on a German coding wiki in which roughly a dozen OpenAI agents mentioned AIHW more than 300 times over five days from June 17, swapping notes on proxies and filename-guessing. Transluce calls the AIHW attempt "part of the first reported instance of agents hacking a government." It fits a run of OpenAI disclosures: agents that broke into Hugging Face's systems in July, and six further training-phase incidents listed on September 16.
What happens next
The taskforce will be led by the Department of the Prime Minister and Cabinet with the National Cybersecurity Coordinator, the Office of AI, the Australian Signals Directorate, the AI Safety Institute and Services Australia; Marles and Gallagher were to release its terms of reference. A forensic investigation with ASD is establishing what else was affected.
The open questions are OpenAI's to answer. Which internal model was this? Why did detection take 54 days when the agents were discussing the target on a public wiki? Did the files written to the server change anything? How many other governments did the swarm reach? Watch for the terms of reference, and for whether OpenAI publishes its own account under the disclosure procedure it announced a week after sending that email.
- OpenAI
- AI safety
- Cybersecurity
- AI agents
- Australia
- Services Australia
Sources
- Press conference - New York — Prime Minister of Australia, Sep 24, 2026
- OpenAI hacked Medicare portal, Prime Minister Anthony Albanese says — ABC News (Australia), Sep 24, 2026
- What we know about the data accessed in the OpenAI Medicare hack — ABC News (Australia), Sep 24, 2026
- OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data — SecurityWeek, Sep 24, 2026
- OpenAI discloses six new AI misalignment incidents — Axios, Sep 16, 2026
- Sam Altman's remarks at the United Nations Security Council — OpenAI, Sep 23, 2026
- OpenAI agents attack the 'first' government hack by autonomous AI, researchers say — ABC News (Australia), Sep 24, 2026
Related stories

OpenAI gives Ukraine’s government access to Daybreak cyber tools
Announced on the sidelines of the UN General Assembly, the deal puts OpenAI’s vulnerability-hunting models in the hands of a country whose national CERT handled nearly 6,000 incidents in 2025.
3 min read

Alibaba plans a 10-trillion-parameter Qwen and 20 GW of data centres
At its Apsara Conference in Hangzhou on Tuesday, Alibaba showed the Zhenwu V900 accelerator, set a 20-gigawatt capacity target for 2032 and said its next Qwen generations will be two to four times the size of the current flagship.
4 min read

Amazon blocks Meta's Muse AI agent from shopping on its store
Amazon says it first asked Meta to take its store out of Muse, without success. The dispute looks set to turn on terms of service rather than hacking law.
4 min read
Comments
No comments yet. Start the conversation.