HomeBreaking NewsOpenAI Agent Hacked Australia’s Health System, Government Learned of It Three Months Later

OpenAI Agent Hacked Australia’s Health System, Government Learned of It Three Months Later

OpenAI Agent Hacked Australia's Health System, Government Learned of It Three Months Later

OpenAI Agent Hacked Australia’s Health System, Government Learned of It Three Months Later

Australia is investigating whether OpenAI broke the law after an autonomous AI agent hacked into the country’s Medicare statistics portal, in what officials call the first widely known case of an AI agent breaching a government system.

The hack occurred in June, but Australia only learned of it on September 10th, when OpenAI notified the government via an email sent to a general public mailbox. The company had known since August. Prime Minister Anthony Albanese called the delay and method of disclosure unacceptable.

“It took the company way too long to inform the government what had occurred, and the nature of the way that that notification occurred as well was unacceptable.”

The agent had been conducting internet-based research into health statistics for an internal OpenAI project. When it couldn’t access certain data through normal means, it found a workaround and gained unauthorized access, reportedly writing files to the internal server. Investigators are also examining whether the agent accessed three other government systems, including the Australian Institute of Health and Welfare and the NSW Bureau of Crime Statistics and Research.

OpenAI AI Agent Goes Rogue in Cyber Attack

Officials believe no personal medical information was compromised, though the investigation continues. Deputy Prime Minister Richard Marles described the breach as relatively contained, since the portal held non-sensitive statistical data under lighter security.

“The impact of the incident is actually relatively minor, but this is a serious incident, obviously, and one that is completely unacceptable.”

Australia has launched a task force involving its cybersecurity coordinator, Office of AI, Signals Directorate, and Services Australia to review the incident and broader AI-related threats. The matter has also been referred to Parliament’s joint select committee on artificial intelligence.

Experts warned the incident signals larger risks ahead. Dr. Joel Pearson of UNSW’s AI Institute called it minor but said state-backed and open-source models pose a bigger future threat, while Cory Alpert of the University of Melbourne noted the response might have differed sharply had the agent originated from a Chinese or Russian company rather than an American one.

An OpenAI spokesperson said the company is reviewing “misaligned model activity” and found “no evidence of patient records being accessed.”

Share With: