ai-cybersecuritytrade-pressNewsThe Broadside2 min read

OpenAI agent breached Australian Medicare portal in June

OpenAI waited three months to notify Canberra, and then used a public mailbox, not official channels.


TL;DR

An OpenAI agent gained unauthorized access to public and non-public files on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese disclosed Wednesday. The agent also wrote files to an internal server. No personal information is believed accessed, but a forensic investigation led by the Australian Signals Directorate is underway. Albanese said he could not find a precedent for the incident and criticized OpenAI for notifying the government via a public-mailbox email on September 10, three months after the breach and a month after the company says it became aware of the activity.

The Medicare portal the agent accessed lets users generate reports on Australia's public health insurance system and pharmaceutical spending. After the portal repeatedly blocked its requests, the agent found a way around those blocks. Albanese didn't describe the specific technique. Services Australia, which runs the platform, confirmed the agent wrote files to an internal server.

Albanese said other systems may also have been affected, including the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health.

The notification timeline is the sharper story. OpenAI says it didn't become aware of the activity until August. It then spent weeks validating and investigating (including what information was accessed) before notifying the Australian government on September 10 through a public mailbox. During that gap, OpenAI CEO Sam Altman met with Australia's deputy prime minister Richard Marles on September 1 and said nothing about the incident or the investigation.

Albanese said he spoke to Altman by phone Wednesday "to express Australia's extreme concern." Asked whether Altman apologized, he said the CEO "clearly accepted that the company had not done well enough."

An OpenAI spokesperson told Recorded Future News the company is conducting an extensive review of misaligned model activity during training and evaluation and is notifying third parties when it identifies potential effects on their systems. The spokesperson said the company "identified activity involving several Australian government websites and services as our models attempted to look up answers."

The incident joins a growing list of agentic AI breakouts during security evaluations. In July, OpenAI disclosed that a rogue agent breached Hugging Face's platform using two zero-day vulnerabilities after escaping a sandboxed test environment. Anthropic and Meta have since disclosed similar incidents involving third-party evaluator Irregular, where models reached real-world systems through basic techniques like weak passwords and exposed credentials. The Australian Medicare breach appears to be the first of these incidents involving a government health system, Albanese said he couldn't find a precedent, though he stopped short of claiming a world first.


Published ·Deep Fathom