Skip to content
Rogue OpenAI Agent Hacks Australian Medicare Site

Rogue OpenAI Agent Hacks Australian Medicare Site

Govinfosecurity • September 24, 2026

Australian officials have launched a task force and are urging government agencies to shore up cybersecurity of their public-facing websites and apps after the country's prime minister on Wednesday revealed that a rogue OpenAI agent hacked into the nation's public health Medicare website in June, accessing public and non-public information.

See Also: How Skilled Attackers Weaponize AI Faster

Australia Prime Minister Anthony Albanese in a Wednesday press conference in New York, where he was attending the United Nations General Assembly, said the incident involved an OpenAI agent gaining unauthorized access into the public-facing Medicare statistics reporting service portal, which is administered by Services Australia.

The OpenAI artificial intelligence agent on June 18 accessed both public and non-public files, he said. A forensic investigation aided by the Australian Signals Directorate is underway including examining if other government systems were affected, he said.

The Medicare Statistics Reporting Portal is a public-facing statistics portal that contains non-sensitive Medicare information relating to data and statistics such as spending, he said. "No personal information is believed to have been accessed at this stage." But he said the investigation is not complete. Evidence currently shows the compromise didn't extend beyond the Services Australia network, but "Nonetheless, this situation is obviously unacceptable."

While 27 million people - nearly Australia's entire population - are enrolled in Medicare, so far there's no evidence that patients information was affected, he said.

"Today I spoke with the CEO of OpenAI, Sam Altman, to express Australia's extreme concern this incident," Albanese said. "And I also expressed my disappointment that it took the company way too long to inform the government what had occurred and the nature of the way that that notification occurred as well was unacceptable," he said.

Albanese said it took until Sept. 10 before OpenAI provided any notification to the Australian government the incident. OpenAI's notification was an email to a public mailbox, he said. "On Sept. 15, Services Australia reported the notification to ASD's Australian Cyber Security Centre."

Albanese said the incident occurred while OpenAI "was doing research using AI and the agent." The agent was initially blocked by the Medicare website but "sought ways around the blockage," he said.

When asked by a journalist whether a crime had occurred, Albanese said the government's investigation will examine that, too. "As part of the investigation will be whether there are any issues that need to be referred to the Australian Federal Police. And it would be entirely inappropriate for me to preempt that. There will obviously be legal consequences on it."

Of course, the Australia Medicare hack isn't the first such incident involving rogue OpenAI agents. A "swarm" of OpenAI agents in July breached the AI code-sharing platform Hugging Face (see: OpenAI Models Escaped Sandbox, Breached Hugging Face ).

Australia is launching a taskforce to provide "an urgent and immediate review" into the OpenAI incident to determine whether existing processes are appropriate to respond to AI-related cyber incidents, Albanese said on Wednesday.

On Thursday, the Australian Signals Directorate's Australian Cyber Security Centre issued an urgent alert advising government agencies to take measures to better protect their public-facing websites and apps against AI-related threats.

That includes applying strong authentication, access controls and network segmentation; promptly remediating vulnerabilities; installing patches; monitoring systems for unusual activity and regularly reviewing security logs; and testing controls and incident response procedures against AI-enabled threat scenarios.

"ASD continues to work with government, industry and technology partners to establish effective guardrails, governance arrangements and testing practices for AI systems during development, deployment and operation," the alert said.

Without specifically naming OpenAI, the alert said the recent incident involved an AI agent that "was provided a specific activity to complete, however, cybersecurity controls on entities' public-facing websites/services limited the AI agent's ability to complete the activity assigned to it."

The AI agent independently identified vulnerabilities and attempted to progress actions without direct human authorization to ensure it was able to complete the activity it was assigned, the alert said.

"There is no indication that this activity represents a broader threat or malicious targeting against Australia. However, this highlights the importance of secure AI deployment practices and maintaining strong cybersecurity fundamentals."

ASD added that it routinely receives reports of vulnerabilities from security researchers, industry partners and government stakeholders. "In this case, the notable difference is that an AI agent independently identified vulnerabilities that would traditionally be discovered and assessed by human researchers."

Neither Australian officials nor OpenAI immediately responded to ISMG's requests for and additional details the incident.

OpenAI's agentic AI compromise in Australia - which allegedly happened because the agent was designed to succeed at its objective and treated access restrictions as obstacles to overcome - highlights a concerning problem, said Darren Guccione, CEO and co-founder of KeeperSecurity.

"AI optimized to accomplish a goal will inevitably treat barriers as problems to solve unless those barriers are explicit, enforced and binding."

These types of incidents also underscore the importance of strong identity controls and practices, some experts said.

"AI agents are pretty smart. Some of them will try to present as humans and spoof you into thinking they are from another source," said Rosalyn Curato, chief innovation officer and general manager of agentic security at Vouched.

"That's why agentic identity matters so much. If you can understand the human or organization tied to the agent and what authority that agent has, you will be armed with the right information to determine if it's a good or a bad actor," she said. "A clear understanding of identity and authority is what you can count on to build trust over time."

Governance & Risk Management

-Generation Technologies & Secure Development

Vulnerability Assessment & Penetration Testing (VA/PT)

Marianne Kolbasuk McGee

Executive Editor, HealthcareInfoSecurity, ISMG

McGee is executive editor of Information Security Media Group's HealthcareInfoSecurity.com media site. She has 30 years of IT journalism experience, with a focus on healthcare information technology issues for more than 15 years. Before joining ISMG in 2012, she was a reporter at InformationWeek magazine and news site and played a lead role in the launch of InformationWeek's healthcare IT media site.

Extracted Entities

Attack Types (1)

Countries (1)

Industries (1)

Platforms (1)