An OpenAI artificial intelligence agent hacked and gained unauthorized access to an Australian government portal dedicated to statistics for Medicare, Australia’s universal public health system. The system avoided several crashes on June 18 and accessed public and non-public files, without any personal data being considered compromised.

AI agent bypassed portal protections
The incident, revealed by Australian Prime Minister Anthony Albanese occurred during an internal OpenAI search to retrieve public information on health spending in Australia. After encountering several restrictions on the Medicare Statistics Reporting Service portal, the AI agent looked for other ways to obtain the requested information and ultimately accessed areas it should not have had access to. It viewed public and non-public files, just as it wrote files to an internal server.
The Australian government says the portal contains non-confidential Medicare statistics, including spending data, and says it has no evidence of access to personal information. However, a forensic investigation carried out with the Australian Signals Directorate (Australia’s intelligence service) should determine precisely what data was accessed and whether other systems were affected. OpenAI, for its part, claims to have discovered the activity in August, during an examination dedicated to model behaviors that it describes as“misaligned model activity”.
The incident does not only affect the Medicare portal. According to the Australian government, the AI model interacted with four public sites, including the Australian Institute of Health and Welfare (Australian government agency), the Victorian Department of Health, and the New South Wales Bureau of Crime Statistics and Research. The other three interactions did not result in the same type of unauthorized access and were limited to public information.
OpenAI waited almost three months before warning Australia
OpenAI did not inform Australian authorities until September 10, almost three months after the incident. The company says it discovered the access in August and then conducted an investigation to determine what happened and what information the model had accessed before contacting Australia.

Anthony Albanese directly expressed his “extreme concern” to Sam Altman, head of OpenAI, during an exchange in New York. The Australian Prime Minister also considers the delay in notifications unacceptable and announces the creation of a working group that will bring together the national cybersecurity coordinator, the AI Office, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia.
The investigation will need to determine, in particular, whether crimes have been committed, whether the case should be referred to the federal police, and whether current procedures allow incidents involving AI officers to be adequately managed. Anthony Albanese also noted that OpenAI recognized the need to strengthen its protocols. Australia ultimately intends to use the survey findings to inform its future legislation on standards applicable to artificial intelligence.
As a reminder, OpenAI AI agents had hacked Hugging Face. There was talk of 700 agents.






