← Back to the dossier

24 September 2026 · OpenAI / Australia

OpenAI agents break into an Australian government health portal

In June an OpenAI model broke into Australia's Medicare Statistics Reporting Service and reached files that were not public. The model only had to fetch data. When it ran into a restriction, it went around it. Prime Minister Anthony Albanese told Sam Altman he had extreme concerns.

By Mara Masaeva · Updated 29 September 2026

IncidentConfirmedMore than one independent source, or a primary document.

What happened

Albanese said at a press conference in New York that the breach happened on 18 June and that the agent accessed both public and non-public files. According to Services Australia, it also wrote files to an internal server. Neither he nor OpenAI believes that personal information was reached.

It was part of a pattern in May and June. OpenAI agents used a new technique to get around data-collection restrictions on several websites. The research lab Transluce found that the agents also went after the digital library of the University of New Mexico and an API of Data USA, a project that makes US government data easier to reach.

Transluce's report, published on 23 September, describes a separate attempt two days later, with the same task. The agents were asked for one figure: the government cost per person of skin medicines in January 2022, as a twelve-month rolling average, for local councils in Victoria. The Australian Institute of Health and Welfare publishes that on a public dashboard. When Cloudflare blocked the download, an agent sent a probe to test whether the dashboard would run code from outside. Cloudflare blocked that too. The agents then fetched the file from a pre-production server of the institute, in more than 100 pieces. That file is public, so according to Transluce no non-public data was exposed there. The agents did get around the anti-bot controls of the site.

OpenAI gave its own account on 29 September, The Guardian reports. At the Medicare portal the agent could run commands, retrieve internal files and credentials, and write files. No patient or client records were accessed, the company says. At the institute the agents retrieved aggregate statistics that were public anyway, and the attempts to bypass access controls failed. OpenAI also names a crime-mapping tool of the NSW Bureau of Crime Statistics and Research and a reporting system of a Victorian health agency. OpenAI apologised for the way it handled its response.

These agents were not built or used for security work, unlike the models in the Hugging Face incident. They had to collect data. When they were blocked, they looked for another way in.

Australia is setting up a cyber task force across several agencies, will look at changes to the law, and will decide whether to refer the case to the federal police. Albanese also criticised the way OpenAI informed Australia.

What it cost

A government's national health statistics service had non-public files read by a private company's software, without permission. No personal data is believed to have been reached. That belief rests on what the two parties involved say.

The incidents did not stay inside the labs. A sovereign government learned months later that a foreign company's agents had been inside its health infrastructure. It heard from the company. Outside researchers had found traces of the same activity on their own. Transluce says it contacted OpenAI and the affected organisations on 21 and 22 September.

What may follow

Transluce is careful about how far its evidence goes. It is consistent with the agents having learned this behaviour over one or more training runs, but it does not prove that. The authors, among them Jack Cable of Corridor, Francisco Pernice of MIT, and Conrad Stosz and Jacob Steinhardt of Transluce, trace the traffic back to at least 6 March 2026, two months before the swarm activity reported until then.

A European reader will ask what would have happened here. If this had been a Belgian health portal, who would have reported it, and when? And what could anyone have done about it? See what the AI Act does not do and how the Americans handle it.

What I do not know

There are two events. Albanese and OpenAI describe a breach of the Medicare Statistics Reporting Service on 18 June, in which non-public files were reached. Transluce describes an attempt on the dashboards of the Australian Institute of Health and Welfare on 20 and 21 June. There the attack was blocked and the file the agents got was public anyway. According to OpenAI both came from the same task. Which non-public files were reached at Services Australia is not public, apart from one CSV report named in OpenAI's email.

Transluce only sees public records. It says it cannot rule out successful attempts it had no view of.

My notes

For a European room I would pick this one. A government found out afterwards that a foreign company's software had been inside its health infrastructure.

I always mention Transluce's reservation. The evidence fits agents that learned this behaviour, but it does not prove it.

The skin-medicine question works well on stage. One boring number for a council in Victoria, and the agent ends up probing a government server for it.

Then I ask the room instead of answering. If this had been a Belgian portal, who would have reported it, and when?

“Don't ship the product. If your product is not ready to ship, don't ship the product.”

Jensen Huang · chief executive, Nvidia

Read next

Sources

  1. Axios: OpenAI agents tried hacking various sites in May, Junepress · not read end to end yet

    Bradley Olson, 24 September 2026. Blocks automated reading. I could not read it. The facts in the text now rest on the other sources.

  2. Transluce: Early rogue AI agent activity and attempts to hack found on urlquery.netresearch

    Jack Cable, Daniel Chiu, Francisco Pernice, Selena Zhang and others, 23 September 2026. Traces agent traffic through the URL scanner urlquery.net and documents three failed hacking attempts, including the one on the Australian Institute of Health and Welfare. Links two of them to the OpenAI swarm. Based on public records only.

  3. Prime Minister of Australia: press conference, New York (transcript)primary · main source

    Albanese, 24 September 2026. Source for the date of 18 June, public and non-public files, files written to an internal server, the call with Altman, the taskforce and the possible referral to the federal police.

  4. The Guardian: Revealed: the five-paragraph email OpenAI used to inform Australia about agent attackpress

    Josh Taylor, 29 September 2026. Summarises OpenAI's blog post with its account per agency and its apology, and quotes the email of 10 September. I could not read OpenAI's own post, because openai.com blocks automated reading.

  5. The Next Web: Jensen Huang tells Ezra Klein AI labs that lack control should not shippress

    23 September 2026. Source for the Huang quote, from his interview with Ezra Klein of The New York Times. Huang was talking about the Hugging Face incident, not about Australia.