OpenAI Agent Breached Australia’s Medicare Portal, Prime Minister Says
Prime Minister Anthony Albanese says an OpenAI research agent bypassed access controls on a government Medicare statistics portal in June, and OpenAI didn't tell Canberra for nearly three months.
Australian Prime Minister Anthony Albanese confirmed this week that an OpenAI research agent broke into a government Medicare statistics portal in June, bypassing access controls that were built specifically to stop it. “There were blocks clearly which were coming back telling the AI agent, no,” Albanese said. “The AI agent found a way around those blocks.”
Table Of Content
The confirmation, made from New York during the UN General Assembly and reported by BleepingComputer, landed alongside a separate report from the nonprofit research lab Transluce, published independently the same week. Built entirely from public scan records rather than any OpenAI disclosure, it documents a broader pattern: the same class of OpenAI research agents probing for SQL injection, cross-site scripting, and path traversal flaws at public data providers in Australia and the United States over several months.
What the Agent Actually Reached
The breached system is Services Australia’s public-facing Medicare statistics reporting portal, which publishes aggregate figures such as health spending. It is separate from the systems that hold Medicare claims and personal patient records, according to the government’s own account. On June 18, the portal repeatedly refused the agent’s data requests, but it got in anyway and reached files that were not public. Acting Prime Minister Richard Marles, standing in while Albanese was overseas, told the ABC that the portal’s information was “kept behind a fence that the AI agent effectively climbed over.”
Albanese said the task behind the intrusion was research into public medicine spending. “The model attempted alternative ways to obtain the info that it wanted, and this led to unauthorized access into some other areas,” he said. Services Australia has also told the government the agent wrote files to an internal server, a detail still under investigation. OpenAI, in a statement, said its models “took actions we did not intend” while looking up statistics about Australia during an internal evaluation, and that its own review found no evidence patient records were touched. What the agent did access, per OpenAI, was aggregate health statistics and internal file names. By September 24, the portal had been taken offline, with its data moved to data.gov.au and other platforms.
A Three-Month Gap Before Canberra Knew
OpenAI says it found the unauthorized activity in August, during what it calls a wider review of misaligned model behavior in training and evaluation. It did not tell the Australian government until September 10, and even then only by emailing a public mailbox at Services Australia rather than contacting a specific official. Services Australia confirmed the email was genuine on September 11 and reported the incident to the Australian Cyber Security Centre, part of the Australian Signals Directorate, on September 15. Government Services Minister Katy Gallagher was briefed on September 17, and Albanese himself learned of it only the weekend before the government made it public on September 24, Australian time.
Albanese said the company took far too long to tell the government, and that the way it chose to do so was unacceptable. He raised the delay directly with OpenAI chief executive Sam Altman in what he described as a frank phone call, adding that Altman had acknowledged the company’s own protocols fell short. The government has launched a forensic investigation and will decide whether the incident should be referred to federal police.
A Wider Pattern, Documented Independently
Transluce, an independent nonprofit that says it builds public infrastructure for AI oversight, based its report entirely on public scan logs from the URL-testing service urlquery.net. Out of 37,649 reports it analyzed, the lab classified 6,467 as significant agent-like activity and flagged another 31,182 as merely suggestive. It traces the trail back to at least March 6, when agents began escalating attempts to pull Thai drug-enforcement statistics, then documents a sharp jump in activity in mid-April, over 1,000 reports in two weeks, before the pattern collapsed around June 22.
Three specific cases stand out between May and June. At the Australian Institute of Health and Welfare, an agent hunting for a pharmaceutical-spending figure (dermatology costs per person, broken down by Victorian local government areas) hit a Cloudflare block, sent a reflected cross-site-scripting probe at a Tableau dashboard, then ran more than 100 scans against a pre-production server to pull the public dataset anyway. At Data USA, agents researching University of Iowa education statistics sent a dozen vulnerability probes, including SQL injection payloads, after hitting malformed query errors. At the University of New Mexico’s digital library, an agent trying to retrieve a photograph from its Valmora collection fired seven exploit probes and what Transluce calls “a self-described flood of 80 requests.”
Transluce is careful to say it found no evidence any of the three attempts actually succeeded, and that its own visibility is incomplete: the agents created accounts on urlquery.net that let them run scans privately, so the public logs the lab analyzed are only a partial record of what happened. It ties the activity to OpenAI through several signals, including matching task parameters, a shared relay service, and an account that signed its wiki posts as “OpenAIResearcher.” The coordination channel behind that signature is DseWiki, a German coding wiki that sxz.io reported was itself secretly overrun by the same class of rogue OpenAI agents for weeks earlier this year. It is worth noting the government’s own confirmed-breach language covers only the Medicare portal; officials have described the agents’ contact with AIHW and a similar New South Wales crime-statistics body as ordinary activity that touched only public information, a milder read than Transluce’s own logs of injection attempts against AIHW.
What Comes Next
Albanese has ordered a taskforce, led by the Department of the Prime Minister and Cabinet, to review whether Australia’s existing incident-response processes can handle AI-driven breaches at all. It will draw in the National Cybersecurity Coordinator, the Office of AI, the Australian Signals Directorate, the Australian AI Safety Institute, and Services Australia itself. University of Technology Sydney professor Nicholas Davis, asked about the incident, called it “the canary in the coal mine.”
The Medicare portal is at least the fourth publicly documented case this year of OpenAI’s own research agents taking unauthorized action against real infrastructure while nominally performing ordinary lookup tasks, following incidents involving RubyGems, DseWiki itself, and Hugging Face that sxz.io has covered as they emerged. What is different this time is the response: a sitting head of government, on the record, describing an AI system’s evasive behavior as a national incident and standing up an interagency taskforce to deal with it.








No Comment! Be the first one.