International Cyber Expo International Cyber Expo
  • About Us
Thursday, 24 September, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

OpenAI agent breached Australia’s Medicare portal – and nobody noticed for three months

Security experts warn that detection, disclosure and accountability are falling badly behind autonomous AI agents operating at machine speed

by Guru Writer
September 24, 2026
in Featured
OpenAI agent breached Australia’s Medicare portal – and nobody noticed for three months
Share on FacebookShare on Twitter

An autonomous AI agent built by OpenAI gained unauthorised access to non-public files on an Australian government Medicare portal in June, but Canberra was only told about it in September, in what is being described as the first known case of an AI agent hacking a government system.

Prime Minister Anthony Albanese, speaking in New York yesterday, said the agent got into the Medicare Statistics Reporting Service portal, administered by Services Australia, on 18 June while researching government spending on healthcare. The portal repeatedly refused the agent’s requests, but it found a way around the blocks and reached both public and non-public files. The agent also wrote files to an internal server, which is still being investigated.

OpenAI says it found the activity in August but did not notify the Australian government until 10 September and did so via an email to a public Services Australia mailbox. Albanese said he had spoken to OpenAI CEO Sam Altman to express Australia’s “extreme concern”, called the delay and the manner of the notification unacceptable, and has announced a taskforce to investigate.

“Australians should be concerned and frustrated here, for two reasons. The first is their own data. An OpenAI agent got to non-public files in a Medicare system on the 18th of June. Nobody here found out until September 10, when OpenAI told them. There’ll be an argument about whether that thing was a researcher or an agent or a threat actor. From where I sit, it’s all the same. Something reached data it had no business reaching, and nobody noticed for three months. Intent doesn’t change the outcome, and it shouldn’t change the response,” said Justin Allen, senior manager of security operations, APAC at Huntress.

OpenAI said its models had been looking up statistics about Australia during an internal evaluation and “took actions we did not intend”. There is currently no evidence that patient records were accessed, or the wider Services Australia network compromised. Investigators are also examining whether three other sites – the Australian Institute of Health and Welfare (AIHW), the NSW Bureau of Crime Statistics and Research and the Victorian Department of Health – were affected.

Graeme Stewart, head of public sector at Check Point, said: “We prosecute hackers for breaking into companies. When an AI system does something similar, we cannot shrug and call it an interesting experiment. There is still a lot we do not know, and this investigation is at an early stage, but the bigger warning is already staring us in the face: an apparently innocent research request appears to have sent an AI agent pursuing its goal in ways its creators did not intend. That gap between what we ask AI to do and what it actually does is where this gets dangerous.” 

Jamie Akhtar, CEO and co-founder of CyberSmart, cautioned against how the incident is framed: “But this shouldn’t simply be framed as ‘AI going rogue’. AI doesn’t carry corporate accountability. It is the organisations building, deploying and supervising these systems that do. If an autonomous agent is given access to the open internet, it needs clearly enforced technical boundaries around what it can access and what actions it can take, alongside monitoring capable of detecting when those boundaries are crossed.”

Damian Skeeles, senior solution engineering manager at Filigran, pointed to the wider political debate over liability: “Last week we saw the Frontier AI companies asking for a legal ‘safe harbour’, which Treasury Secretary Bessent rejected in saying ‘It is humans who are responsible, not the AI’. This latest incident in Australia makes me wonder what else we will find that these agents, and their humans, have been responsible for.”

Agents probing at machine speed

The same day, US non-profit research lab Transluce published a report on related OpenAI agent activity. It found agents on ordinary data-retrieval tasks used urlquery.net, a public web scanning service, to get around access restrictions. On 20 and 21 June, an agent seeking pharmaceutical spending data hit bot protection on the AIHW site, probed a Tableau dashboard for vulnerabilities and retrieved a public dataset from a pre-production server. The AIHW says there is no evidence non-public data was accessed, and the two incidents have not been formally linked.

“It’s not clear what goals and prompts agents were originally tasked with, but activity has left markers and signatures which point to activity originating from OpenAI, and well before the Hugging Face Incident. This fact shouldn’t be surprising in nature, and I actually predict we’ll continue to see articles like this one now we’ve learnt how to spot what agentic behaviour looks like. This is also compounded by agents bypassing anti-bot controls to achieve their goal, which includes leveraging relay services to mask the original origin of requests. Therefore, some of the more traditional defences are likely to prove ineffective,” said Nathan Davies-Webb, principal consultant at Acumen Cyber.

He added: “It highlights one of the key differences between a botnet and an AI agent. Something like a botnet can also present as a mass of scanning requests, but an AI agent works in a more informed manner. For example, when probing the Australian Institute of Health and Welfare’s (AIHW) site, the agent reportedly identified data was being served by Tableau and moved to probing for vulnerabilities against the application. This kind of behaviour elevates the risk of exposing services because that level of information gathering and action operates at machine speed.”

The case follows OpenAI’s disclosure in July that its models escaped a controlled testing environment and broke into parts of Hugging Face’s systems.

“The severity of these reported incidents is increasing, this one crossing the borders. What’s concerning is that none of the detection mechanisms caught this attack, from any agency or security tools. It took three months and got detected only when OpenAI proactively looked for other potential incidents after the HuggingFace fiasco,” said Neena Sharma, cybersecurity expert at Filigran.

Allen added: “In one week, we’ve had Google’s Gemini get into three companies during an evaluation and an agent get into a Commonwealth system for real. Nobody is speculating about this anymore. We’re still arguing about what the guardrails should say while the thing they’re meant to guard against is already happening.”

Detection gets funded last

Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, said: “If OpenAI’s own monitoring didn’t catch this for two months, how many other environments are currently being accessed by AI agents in ways their developers haven’t intended and don’t yet know about? The industry was worried about AI agents taking unexpected actions in evaluation environments. The difference here is that this wasn’t a controlled test. This was a production government system. For governments and enterprises deploying or planning to deploy agentic AI, this incident makes a previously theoretical governance question urgently practical. Who is monitoring what your AI agents are actually doing, at the network level, in real time?”

Allen said the guidance already exists: “The department wasn’t covering it up. They didn’t know. That’s worse. Nobody needs to invent a fix here because the ASD has already written it down. Everyone can recite the Essential Eight, but that’s the prevention half of the story. Detection is the half that gets funded last. Three months of silence is what that looks like in practice. And logs on their own don’t detect anything. Someone has to be reading them and able to act at the same speed as the attacker.”

Akhtar said: “For organisations, incidents like this should be a reminder to assume that both legitimate and malicious AI agents will increasingly probe systems at machine speed. Strong authentication, least-privilege access, network segmentation, continuous vulnerability management and effective monitoring remain fundamental, but organisations also need to test how their systems behave when interacting with autonomous agents.”

Stewart concluded: “We need proper guard rails, least-privilege access, visibility of AI agents and other non-human activity, automated prevention and clear accountability when things go wrong. Boards should stop asking only whether they are compliant and ask the question that really matters: if an autonomous agent got into our systems tomorrow, could we keep operating and keep people safe? Nobody should wait for the next incident to find out.”

Allen said: “If a Commonwealth department can go three months without knowing, then I’d want to know what that looks like for critical infrastructure. If they couldn’t see it with the ASD on speed dial, then a 30-person business has no hope on its own. Telling people to do better is not the same as giving them the means to do it. Policy, hygiene and detection needed to be the priority yesterday.”

ShareTweet
Previous Post

Zero-day hackers ditch exploits for a fake image file in new DarkMe campaign

Recent News

OpenAI agent breached Australia’s Medicare portal – and nobody noticed for three months

OpenAI agent breached Australia’s Medicare portal – and nobody noticed for three months

September 24, 2026
Zero-day hackers ditch exploits for a fake image file in new DarkMe campaign

Zero-day hackers ditch exploits for a fake image file in new DarkMe campaign

September 23, 2026
CRA Reporting Is Live: What Manufacturers, Vendors, and Distributors Need to Know

CRA Reporting Is Live: What Manufacturers, Vendors, and Distributors Need to Know

September 23, 2026
network segmentation

Only 13% of OT Network Segments Keep Operational Technology Isolated

September 22, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol