An OpenAI agent hacked the Australian government

The OpenAI logo is displayed on a smartphone screen.

An OpenAI agent has hacked the Australian government’s healthcare system, gaining unauthorised access to non-public information as well as writing files to the server.

Australian prime minister Anthony Albanese announced the breach at a press conference on Thursday. OpenAI’s researchers had been using an internal AI model to research spending on public healthcare, and given it access to the internet for this purpose. However, the AI “didn’t accept no for an answer” when it encountered blocks, instead devising ways to circumvent such barriers to retrieve information without authorisation. 

This resulted in OpenAI’s agent breaching Services Australia’s Medicare statistics reporting portal on Jun. 18, accessing both public and non-public files, and even writing its own to the Australian government’s server in order to do so.

“[T]his situation is obviously unacceptable,” said Albanese. “I think OpenAI know that they need to have better protocols in place. And they’re one of the businesses that themselves have warned of the risks which are there.”

OpenAI has acknowledged the breach, a spokesperson stating that its AI models “took actions we did not intend” when searching for answers to questions about Australia.

“The information accessed included aggregate health statistics and internal file names,” the spokesperson said.

Fortunately, there is no evidence that individual people’s data was impacted, or that personal private health information was accessed. The Medicare statistics reporting portal is an online platform which provides users with information about Australia’s universal healthcare programs. This includes statistics on immunisations, organ donation, and the government’s scheme to lower the cost of prescription medication. 

Even so, an autonomous AI agent hacking a government system is a troubling development, regardless of what it did once it had gained access.

“Today I spoke with the CEO of OpenAI Sam Altman to express Australia’s extreme concern about this incident,” said Albanese. “The discussion I had with Mr. Altman was a very frank discussion, courteous in both directions, but very frank about what I saw as Australia’s national interest and what I saw as a failure which occurred here.”

Altman reportedly apologised and “clearly accepted that the company had not done good enough.” Both Albanese and Altman are attending the UN General Assembly in New York, though the prime minister stated that they spoke via a phone call rather than in person.

Australian PM admonishes OpenAI for delay in notifying of breach

Albanese further criticised OpenAI’s delay in notifying the Australian government of the breach, as well as the method through which it did so. While the hack took place on Jun. 18, OpenAI claimed it was unaware of the breach until it reviewed the AI model’s activity in August. The company subsequently waited until Sept. 10 to alert the Australian government, three months after the hack initially took place. 

Even then, it did so simply by sending an email to a public Services Australia email address —  an effort which Albanese also called unacceptable and disappointing. As such, Australia’s acting prime minister Richard Marles stated that government ministers have only known about OpenAI’s hack for less than a week.

“It was a shock that it occurred, because it was real and serious,” said Albanese. “But it also, I think, was something that had been predicted, including by the AI companies themselves [who] have said that one of the risks that we need to deal with here is that artificial intelligence can go its own way. And that’s the basis of the debate that we’re having throughout the world.”

The Medicare portal wasn’t the only Australian government system that OpenAI’s model accessed. Albanese stated that three others may have also been impacted in the same incident: the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health. OpenAI further confirmed that its AI model engaged in activities “involving several Australian government websites and services.” Fortunately, it appears to have only accessed public information on these systems, with Marles stating that “those interactions were entirely normal.” 

The Australian government will now conduct an investigation into the hack, including determining whether this is a criminal matter. However, Albanese has stated that “there will obviously be legal consequences.”

OpenAI’s hack may be the first time an AI model has autonomously hacked a government system. Even so, it’s far from the first time AI has breached an external organisation without permission. In one high-profile incident earlier this year, OpenAI revealed that one of its AI agents had autonomously hacked Hugging Face, an open source repository of AI tools.


Disclosure: Ziff Davis, Mashable’s parent company, in April 2025 filed a lawsuit against OpenAI, alleging it infringed Ziff Davis copyrights in training and operating its AI systems.

Click here to read more >> https://mashable.com/tech/openai-hack-australian-government-ai-agent

Check Also

Dont wait for Lego deals: We found early Prime Day deals on Lego Star Wars, Lego Pokémon, and more

The best early October Prime Day Lego deals: Best Lego Botanicals deal Lego Botanicals Flower …