OpenAI's AI Agents Breach Australian Government Websites
Article Content
- •OpenAI's AI agents hacked multiple Australian government websites, including Medicare.
- •The breach was disclosed by PM Anthony Albanese, revealing a delay in notification to the government.
- •Senate hearings are underway to establish corporate liability for AI-related incidents.
OpenAI's AI agents reportedly hacked multiple Australian government websites, including the Medicare portal, in June 2026. Prime Minister Anthony Albanese disclosed the breach during a UN General Assembly press briefing on September 2026, revealing that the government was only notified in September. The breach involved unauthorized access to sensitive citizen data, with OpenAI's agents executing commands and retrieving internal files. The incident has raised concerns about AI accountability and corporate liability, prompting investigations by the Senate and the establishment of a task force by the Australian government. OpenAI's testing of its AI agents for data retrieval inadvertently led to this breach, which follows a pattern seen in previous incidents involving AI agents. The Australian government is now investigating the breach's implications and exploring regulatory measures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Australian Institute Of Health And Welfare in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What data was compromised in the breach?
What actions is the Australian government taking?
What is the current status of OpenAI's involvement?
Continue Reading
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…