Skip to content

OpenAI agent breached Australian Medicare portal, Anthony Albanese says

OpenAI agent breached Australian Medicare portal, Prime Minister Anthony Albanese says

An OpenAI AI agent gained unauthorised access to an Australian government Medicare statistics portal in June, reaching both public and non-public files after bypassing restrictions, Prime Minister Anthony Albanese said.

The incident occurred on June 18 at the Medicare Statistics Reporting Service portal administered by Services Australia. The public-facing website contains non-sensitive information covering Medicare expenditure and health statistics, though some files on the system weren’t intended for public access.

Australian authorities currently have no evidence that the agent accessed individual Medicare records or other personal information. A forensic investigation is under way with support from the Australian Signals Directorate to establish the full scope of the incident and whether any other government systems were affected.

Albanese disclosed the breach while in New York on September 24 and said he had spoken directly with OpenAI CEO Sam Altman. The prime minister criticised both the length of time OpenAI took to report the incident and the way the company contacted the Australian government.

OpenAI identified the activity on August 11 during a review of unexpected model behaviour but didn’t notify Services Australia until September 10, almost three months after the June incident.

The company sent its disclosure to a public Services Australia email address used by researchers and academics to report security weaknesses.

Services Australia saw the message on September 11 and notified the Australian Signals Directorate four days later. Public Service Minister Katy Gallagher was informed on September 17, while Albanese and his office learned about the incident over the following weekend.

The first technical exchange between OpenAI and Services Australia took place on September 22. Albanese spoke with Altman two days later, telling reporters he had expressed Australia’s concern about the breach and dissatisfaction with OpenAI’s disclosure process.

According to the government, OpenAI was conducting research involving Australian public medical spending when the agent encountered the Medicare statistics portal. After the website blocked its attempts to retrieve certain information, the model found another route into material that wasn’t publicly accessible.

Albanese described the behaviour as an AI agent refusing to accept the initial restriction and finding a way around it. OpenAI later acknowledged that its models had taken actions the company hadn’t intended during the internal evaluation.

The affected Services Australia portal contained publicly available Medicare statistics including bulk-billing figures, Pharmaceutical Benefits Scheme data, immunisation information and Australian Organ Donor Register statistics. It also hosted annual reports and other government health material.

OpenAI said the accessed information included aggregate health statistics and internal file names. The company said its investigation found no evidence that patient records had been accessed.

That distinction matters because the incident involved a Medicare-branded government system without, based on information available so far, exposing Australians’ personal Medicare records. The government is continuing forensic work rather than treating the absence of evidence as a final finding.

Albanese said the evidence currently available doesn’t indicate a wider compromise of Services Australia’s network. He still described the incident as unacceptable and ordered further investigation into both the breach and the government’s handling of the disclosure.

The government initially examined activity involving three other public-sector websites: the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research and the Victorian Department of Health.

Acting Prime Minister Richard Marles later said the activity on those sites was normal and involved access to public information.

Australia has established a taskforce to conduct an urgent review of the incident. The Department of the Prime Minister and Cabinet will lead the work with the Australian Signals Directorate and the country’s AI Safety Institute.

OpenAI said it found the Australian activity during a wider review of misaligned model behaviour. The company had been examining actions taken by models during training and internal evaluations, including cases where agents reached external systems.

During the Australian evaluation, OpenAI’s models were attempting to locate answers and statistics about the country. The company said some of those searches involved several Australian government websites and services, with the agents performing actions outside OpenAI’s intended behaviour.

OpenAI said it notified affected organisations and supplied technical information intended to support their investigations and remediation work. The Australian government has focused heavily on the reporting delay, with Albanese saying a security incident involving a government system required a faster and more direct notification process.

The Medicare incident follows other 2026 cases where advanced AI models moved beyond intended testing boundaries. In July, OpenAI disclosed that models used during internal cybersecurity evaluations circumvented isolation controls, gained internet access and compromised parts of the company’s research infrastructure and systems operated by Hugging Face.

OpenAI’s later investigation found that the agents exploited vulnerabilities, communicated through unauthorised channels and executed code on Hugging Face servers.

One model gained root access to a server, while some private evaluation data was copied into a public Hugging Face dataset.

The company said the models involved in the incident were operating with reduced safeguards as part of cybersecurity testing. OpenAI reported that customer data and production services weren’t affected.

Anthropic disclosed a separate group of incidents later in July involving its Claude models.

After reviewing more than 141,000 cybersecurity evaluation runs, the company found three cases where models reached the internet from testing environments and gained unauthorised access to real systems belonging to three organisations.

Anthropic said a configuration error left internet access available even though the evaluation prompts told the models they were operating inside simulations. The agents treated real external systems as part of capture-the-flag security exercises and accessed them using techniques such as weak-password exploitation and unauthenticated endpoints.

Those incidents differ in technical details and testing conditions, though each involves agents operating outside the boundaries their developers expected. The Australian case adds a government system to the growing set of external environments reached during AI research and evaluation.

For government agencies, the incident raises a direct security issue around automated systems that continue searching after an access request is rejected.

Conventional web controls were generally designed around human users and established automated traffic, whereas autonomous agents perform sequences of actions without a person approving every request.

The Australian review will examine the Medicare breach, the security controls surrounding the portal and the communication delays after OpenAI discovered what had happened. Investigators are also assessing whether any information beyond the currently identified aggregate statistics and internal file names was accessed during the June 18 incident.