Rogue Open AI agent hacked Australian government healthcare portal




Thursday, September 24, 2026 - An OpenAI artificial intelligence agent accessed an Australian government healthcare portal and other public-sector websites without authorisation during an internal evaluation, prompting Prime Minister Anthony Albanese to order an urgent security review.

The incident occurred in June while OpenAI was testing AI agents tasked with researching questions about Australian medical spending. According to the company, the agents were expected to search for publicly available information needed to answer the questions.

However, when one agent was unable to obtain all the information it required, it communicated with other AI agents through DseWiki, described in the report as a coding site that AI systems had previously accessed and used as a message board. The agents then reportedly worked together to find ways around cybersecurity restrictions protecting Australian government websites.

One of the systems accessed was the Medicare Statistics Reporting Service Portal, which contains information relating to Australia’s universal healthcare programme. “The AI agent found a way around those blocks, didn’t accept ‘no’ for an answer,” Albanese said.

At least three other government systems may also have been accessed, according to officials. They included websites associated with the Australian Institute of Health and Welfare, the New South Wales crime statistics agency and Victoria’s health department. OpenAI said it detected the activity in August and launched an investigation. The company said the information accessed included aggregate health statistics and internal file names, rather than personal patient information.

“We identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation,” OpenAI said. The company acknowledged that “our models took actions we did not intend.”

Albanese revealed the incident on Thursday and said he had spoken directly with OpenAI chief executive Sam Altman to raise concerns about both the breach and the length of time it took the company to inform Australian authorities. “Today I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident,” Albanese said. “And I also expressed my disappointment that it took the company way too long to inform the government what had occurred.”

The prime minister said OpenAI’s handling of the notification was “unacceptable,” claiming the government was not directly informed immediately after the company became aware of the incident. Instead, Albanese said notification was sent to a general government email inbox on September 10. The Australian government has now ordered an “urgent and immediate” review of the security implications of the incident.

Communications Minister Anika Wells said the Australian Signals Directorate would investigate the breach and examine whether there were grounds for legal action. “We want big tech to take accountability,” Wells said. OpenAI said it was cooperating with the investigation and providing technical assistance to help identify and address potential security vulnerabilities.

The incident was disclosed as Albanese attended meetings in New York, where international leaders were also discussing concerns surrounding the safety and security of increasingly autonomous artificial intelligence systems. OpenAI said its own review of the Australian incident remained ongoing and that the company was “committed to transparency.”

Post a Comment

0 Comments