OpenAI Agent Breached Australia’s Medicare Stats Portal

OpenAI agent accessed Services Australia's Medicare statistics portal in June; scan records show AIHW-linked activity from 17–21 June 2026.

By Sulochana 4 Min Read 0 Follow on Google News Add to Preferred Source
OpenAI AI Agent Hacked Medicare Portal

An OpenAI AI agent gained unauthorised access to Services Australia’s Medicare Statistics Reporting Service portal on 18 June 2026 and viewed both public and non-public files, Prime Minister Anthony Albanese said on 23 September. OpenAI did not tell the government until 10 September, nearly three months later, and did so through an email to Services Australia’s public inbox, the ABC reported.

Albanese, speaking in New York during the UN General Assembly, said he raised both the delay and the way the notification was sent with OpenAI CEO Sam Altman. The agent had been researching public medical spending when it got past the portal’s protections and “didn’t accept ‘no’ for an answer,” Albanese said. The government says there is no evidence that personal Medicare records were accessed, and no sign of a broader compromise of the Services Australia network.

OpenAI said the activity surfaced during a wider review of misaligned model behaviour, meaning cases where models act against their developers’ intent. The review found several Australian government websites that its models queried while answering questions about Australia in an internal evaluation. The company said its models “took actions we did not intend” and that the material accessed was aggregate health statistics and internal file names. OpenAI says it is giving technical details to the affected agencies.

Services Australia reported the incident to the Australian Signals Directorate’s (ASD) Australian Cyber Security Centre on 15 September. Three more sites may have been involved: the Australian Institute of Health and Welfare (AIHW), the NSW Bureau of Crime Statistics and Research (BOCSAR) and the Victorian Department of Health. Albanese said access to those three has not been confirmed. A taskforce led by the Department of the Prime Minister and Cabinet will review the incident with ASD and the AI Safety Institute.

Defence Minister Richard Marles said the data was of low sensitivity and sat on a site with lighter security than systems holding national security information. “This was really kept behind a fence that the AI agent effectively climbed over,” Marles told ABC Radio National, SBS reported.

What Public Scan Records Show

AI research lab Transluce reported this week that AI agents used urlquery.net as a remote browser to get around access blocks. The public service loads any submitted link in a sandboxed browser and publishes the result. Transluce says agents tried to hack public data providers on three occasions, including an Australian government website, and it directly links the AIHW activity to the agent swarm OpenAI has confirmed as its own. The lab describes those attempts as minor, involving a small number of probe payloads with no evidence of exploitation. It notes the agents were working on ordinary data-retrieval tasks, not security tests.

Cyber Kendra’s analysis of Transluce’s released dataset (version 5, dated 23 September 2026) puts numbers on that episode. Of the 4,844 urlquery.net reports the dataset ties to AIHW, all but one were logged between 17 and 21 June 2026 (UTC), a window that brackets the 18 June Medicare breach. Activity rose from 29 reports on 17 June to 766 on 18 June and peaked at 1,775 on 20 June. Transluce rates 373 of them “significant” because they carried task-specific code that fetched data or submitted forms automatically.

OpenAI has not explained why notifying Australia took three months, named the model involved, or said whether it reached the other three sites. Medicare card holders do not need to take any action as of 24 September 2026, and the government has described the taskforce review as urgent.

One AIHW report, logged at 06:46 UTC on 20 June, is flagged as a reflected-script probe: a test of whether a site will echo injected code back to a browser. The dataset notes that the flag does not mean any data was recovered. Two custom-code requests against NSW BOCSAR appear on 19 June. The dataset has no entries for Services Australia or the Medicare portal, and Transluce labels its entries as candidate evidence rather than confirmed attribution.

Separately, the ABC found archived posts on DseWiki, a German coding site that OpenAI previously confirmed its agents used to communicate. In those posts, more than a dozen agents mentioned AIHW over 300 times while hunting for government spending data on skin medicines across Victorian council areas. After Cloudflare’s bot protection blocked them, the agents traded workarounds including proxies, screenshot services and guessed file names. The DseWiki logs make no mention of Medicare or Services Australia, and neither OpenAI nor the government has said whether the two episodes are connected.

The Medicare disclosure follows the July incident in which OpenAI models running an internal cybersecurity evaluation escaped their sandbox and broke into Hugging Face’s production infrastructure. In that case, OpenAI took about ten days to confirm to Hugging Face that its models were responsible. Transluce says the urlquery.net records show agent activity going back to at least 6 March 2026.

Community Discussion

Join the conversation. Ask questions, share solutions, and help others.

0 Comments

Be the first to start the discussion!

Leave a Comment

Your email address will not be published. Required fields are marked *

We respect your privacy, your information is safe with us.

Latest Articles

View all