The Australian government website, which contains information about Medicare, the country's public health system, was hacked by an AI agent operated by OpenAI, Prime Minister Anthony Albanese. Albanese made the statement at a news conference in New York, where he is attending the United Nations General Assembly. On June 18, the agent gained access to the Medicare Statistics Reporting Service run by the Australian Services Agency and was able to view both public and private records, with the Australian Services Agency saying it had also written records to an internal server. Albanese said no personal data appeared to have been obtained.
See also: RubyGems: OpenAI agents attacked the platform

A forensic review by the Australian Signals Directorate, the government’s cybersecurity agency, is still ongoing. “It is not believed that any personal information has been obtained at this stage, but investigations are ongoing. The available evidence suggests that there is no wider breach of the Australian Signals Agency network. Nevertheless, this situation is clearly unacceptable.” Albanese said an OpenAI research team had developed an internal model to examine public spending on medicines.
When the website continued to deny his requests, the agent tried alternative methods and eventually found a way to bypass the restrictions. “He didn’t take no for an answer, if you will,” Albanese said. The government is also looking into three other sites the agent may have visited, including the Australian Institute of Health and Welfare.
Later in Sydney, Deputy Prime Minister Richard Marles said the activity at those sites was normal and only involved publicly available data. OpenAI did not notify the government until September 10, when it sent an email to a public mailbox at the Australian Government Services Agency. The agency passed it on to the Australian Cybersecurity Centre five days later.
See also: Apple challenges OpenAI's forensic analysis in trade secret case

“The company took too long to inform the government about what had happened,” Albanese said after a phone call with OpenAI CEO Sam Altman. Albanese said Altman had accepted that the company had not responded adequately. In a statement to ABC News, OpenAI said its models took actions it had not intended while searching for facts about Australia. It found no sign that patient records had been viewed, the company said.
The case is part of a series of incidents involving OpenAI agents outside the lab, including the Hugging Face hack in July, the takeover of a German wiki, and the attack on RubyGems. A task force has been set up by Albanese, led by his department, to determine whether existing processes can handle cybersecurity incidents related to artificial intelligence.
See also: OpenAI Codex: Two sandbox boundary violations

“Today, I am announcing the establishment of a task force to provide an urgent and immediate review of this incident to determine whether existing processes are adequate to respond to cybersecurity incidents related to artificial intelligence,” said Anthony Albanese. In the meantime, the government will also seek advice on whether any offences have been committed and whether the case should be referred to the Australian Federal Police.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
