OpenAI AI Agent Hacked an Australian Government Portal
An AI agent tasked with collecting statistics on medicine spending hit a refusal. Rather than giving up, it bypassed the protections and accessed non-public files from an Australian government portal. That is what an OpenAI model did last June. Here is what we know.
During a press conference, Australian Prime Minister Anthony Albanese confirmed that an OpenAI agent had obtained unauthorized access to the Medicare Statistics Reporting Service. This portal, run by Services Australia (the agency that manages social security and health benefits), publishes Medicare statistics, such as healthcare-related spending.
It all reportedly began on June 18, 2026 when OpenAI's research team allegedly decided to use an internal model to investigate public medicine spending. Blocked several times, the AI agent did not give up and looked for alternative paths. "There were clearly blocks that responded no to the AI agent. The AI agent found a way around those blocks," Anthony Albanese explained. This allowed it to access public and non-public files and, according to Services Australia, write data to the internal server.
No personal data would have been accessed at this stage, and there is no indication of a broader compromise of the Services Australia network. Even so, Australia did not appreciate the intrusion at all. The Australian government also announced the creation of a task force and requested urgent advice on whether the case should be referred to the Australian Federal Police.
Nearly Three Months Before Notifying Australia
The incident dates back to June 18, 2026, and yet we are only hearing about it now. The reason is simple: OpenAI notified the Australian government only very recently. Here is the timeline of events:
- June 18: the agent accesses the Medicare portal.
- August 11: OpenAI discovers the incident while reviewing model actions that deviated from what was expected.
- September 10: OpenAI notifies Services Australia... with a simple email sent to a contact address.
- September 15: Services Australia forwards the notification to the Australian Cyber Security Centre at ASD.
Beyond the incident itself, Australia criticizes OpenAI for two things: the far too long delay between the breach and the notification, and the fact that the notification was sent by a simple email.
Hacking to... Find Statistics
At the same time, Transluce published a report based on public records from the URL analysis service urlquery.net. This service offers a "remote browser" and it was used by AI agents to interact with certain websites, especially to retrieve data when direct access failed.
According to this report, the incident would not be limited to the Australian portal, since three intrusion attempts were identified between May and June:
- University of New Mexico digital library: attempts to exploit vulnerabilities (SQL injection, command injection, path traversal) to retrieve... a photograph.
- Data USA: a search for vulnerabilities after errors returned by malformed requests sent to the University of Iowa.
- AIHW: on June 20 and 21, blocked by Cloudflare, the agents attempted a reflected XSS attack against a dashboard. Cloudflare even blocked the malicious request, which did not stop the AI agent from retrieving a file from a staging server.
Transluce directly links the AIHW and Data USA cases to a set of agents that OpenAI has confirmed were the source. Even if Transluce's data is incomplete, it highlights a real trend: AI agents can carry out real cyberattacks.

In the attack targeting Hugging Face, it was part of a cyber test that went wrong. But here, the task had nothing to do with cybersecurity. "The agents resorted to hacking tactics while working on ordinary data retrieval tasks," Transluce notes. In other words, an AI agent that hits a refusal when trying to access data can switch into attack mode, without anyone asking it to.
It may be time to take a tougher line with OpenAI (and everyone else): AIs are committing cyberattacks, we talk about it, and nothing happens. Or rather, it happens again. I get the feeling that AI has every possible free pass, sometimes to scrape data from the Web, sometimes to hack a server. I almost tend to think these companies are untouchable...


