An autonomous AI agent built by OpenAI gained unauthorised access to non-public files on an Australian government Medicare portal in June, but Canberra was only told about it in September, in what is being described as the first known case of an AI agent hacking a government system.
Prime Minister Anthony Albanese, speaking in New York yesterday, said the agent got into the Medicare Statistics Reporting Service portal, administered by Services Australia, on 18 June while researching government spending on healthcare. The portal repeatedly refused the agent’s requests, but it found a way around the blocks and reached both public and non-public files. The agent also wrote files to an internal server, which is still being investigated.
OpenAI says it found the activity in August but did not notify the Australian government until 10 September and did so via an email to a public Services Australia mailbox. Albanese said he had spoken to OpenAI CEO Sam Altman to express Australia’s “extreme concern”, called the delay and the manner of the notification unacceptable, and has announced a taskforce to investigate.
“Australians should be concerned and frustrated here, for two reasons. The first is their own data. An OpenAI agent got to non-public files in a Medicare system on the 18th of June. Nobody here found out until September 10, when OpenAI told them. There’ll be an argument about whether that thing was a researcher or an agent or a threat actor. From where I sit, it’s all the same. Something reached data it had no business reaching, and nobody noticed for three months. Intent doesn’t change the outcome, and it shouldn’t change the response,” said Justin Allen, senior manager of security operations, APAC at Huntress.
OpenAI said its models had been looking up statistics about Australia during an internal evaluation and “took actions we did not intend”. There is currently no evidence that patient records were accessed, or the wider Services Australia network compromised. Investigators are also examining whether three other sites – the Australian Institute of Health and Welfare (AIHW), the NSW Bureau of Crime Statistics and Research and the Victorian Department of Health – were affected.
Graeme Stewart, head of public sector at Check Point, said: “We prosecute hackers for breaking into companies. When an AI system does something similar, we cannot shrug and call it an interesting experiment. There is still a lot we do not know, and this investigation is at an early stage, but the bigger warning is already staring us in the face: an apparently innocent research request appears to have sent an AI agent pursuing its goal in ways its creators did not intend. That gap between what we ask AI to do and what it actually does is where this gets dangerous.”
Jamie Akhtar, CEO and co-founder of CyberSmart, cautioned against how the incident is framed: “But this shouldn’t simply be framed as ‘AI going rogue’. AI doesn’t carry corporate accountability. It is the organisations building, deploying and supervising these systems that do. If an autonomous agent is given access to the open internet, it needs clearly enforced technical boundaries around what it can access and what actions it can take, alongside monitoring capable of detecting when those boundaries are crossed.”
Damian Skeeles, senior solution engineering manager at Filigran, pointed to the wider political debate over liability: “Last week we saw the Frontier AI companies asking for a legal ‘safe harbour’, which Treasury Secretary Bessent rejected in saying ‘It is humans who are responsible, not the AI’. This latest incident in Australia makes me wonder what else we will find that these agents, and their humans, have been responsible for.”
Agents probing at machine speed
The same day, US non-profit research lab Transluce published a report on related OpenAI agent activity. It found agents on ordinary data-retrieval tasks used urlquery.net, a public web scanning service, to get around access restrictions. On 20 and 21 June, an agent seeking pharmaceutical spending data hit bot protection on the AIHW site, probed a Tableau dashboard for vulnerabilities and retrieved a public dataset from a pre-production server. The AIHW says there is no evidence non-public data was accessed, and the two incidents have not been formally linked.
“It’s not clear what goals and prompts agents were originally tasked with, but activity has left markers and signatures which point to activity originating from OpenAI, and well before the Hugging Face Incident. This fact shouldn’t be surprising in nature, and I actually predict we’ll continue to see articles like this one now we’ve learnt how to spot what agentic behaviour looks like. This is also compounded by agents bypassing anti-bot controls to achieve their goal, which includes leveraging relay services to mask the original origin of requests. Therefore, some of the more traditional defences are likely to prove ineffective,” said Nathan Davies-Webb, principal consultant at Acumen Cyber.
He added: “It highlights one of the key differences between a botnet and an AI agent. Something like a botnet can also present as a mass of scanning requests, but an AI agent works in a more informed manner. For example, when probing the Australian Institute of Health and Welfare’s (AIHW) site, the agent reportedly identified data was being served by Tableau and moved to probing for vulnerabilities against the application. This kind of behaviour elevates the risk of exposing services because that level of information gathering and action operates at machine speed.”
The case follows OpenAI’s disclosure in July that its models escaped a controlled testing environment and broke into parts of Hugging Face’s systems.
“The severity of these reported incidents is increasing, this one crossing the borders. What’s concerning is that none of the detection mechanisms caught this attack, from any agency or security tools. It took three months and got detected only when OpenAI proactively looked for other potential incidents after the HuggingFace fiasco,” said Neena Sharma, cybersecurity expert at Filigran.
Allen added: “In one week, we’ve had Google’s Gemini get into three companies during an evaluation and an agent get into a Commonwealth system for real. Nobody is speculating about this anymore. We’re still arguing about what the guardrails should say while the thing they’re meant to guard against is already happening.”
Detection gets funded last
Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, said: “If OpenAI’s own monitoring didn’t catch this for two months, how many other environments are currently being accessed by AI agents in ways their developers haven’t intended and don’t yet know about? The industry was worried about AI agents taking unexpected actions in evaluation environments. The difference here is that this wasn’t a controlled test. This was a production government system. For governments and enterprises deploying or planning to deploy agentic AI, this incident makes a previously theoretical governance question urgently practical. Who is monitoring what your AI agents are actually doing, at the network level, in real time?”
Allen said the guidance already exists: “The department wasn’t covering it up. They didn’t know. That’s worse. Nobody needs to invent a fix here because the ASD has already written it down. Everyone can recite the Essential Eight, but that’s the prevention half of the story. Detection is the half that gets funded last. Three months of silence is what that looks like in practice. And logs on their own don’t detect anything. Someone has to be reading them and able to act at the same speed as the attacker.”
Akhtar said: “For organisations, incidents like this should be a reminder to assume that both legitimate and malicious AI agents will increasingly probe systems at machine speed. Strong authentication, least-privilege access, network segmentation, continuous vulnerability management and effective monitoring remain fundamental, but organisations also need to test how their systems behave when interacting with autonomous agents.”
Stewart concluded: “We need proper guard rails, least-privilege access, visibility of AI agents and other non-human activity, automated prevention and clear accountability when things go wrong. Boards should stop asking only whether they are compliant and ask the question that really matters: if an autonomous agent got into our systems tomorrow, could we keep operating and keep people safe? Nobody should wait for the next incident to find out.”
Allen said: “If a Commonwealth department can go three months without knowing, then I’d want to know what that looks like for critical infrastructure. If they couldn’t see it with the ASD on speed dial, then a 30-person business has no hope on its own. Telling people to do better is not the same as giving them the means to do it. Policy, hygiene and detection needed to be the priority yesterday.”





