Australia Says OpenAI Agent Breached Portal
Australia says an OpenAI agent gained unauthorized access to a government Medicare statistics portal on June 18, three months before CEO Sam Altman briefed the UN Security Council on AI and international security.
The agent accessed public and non-public files while researching medicine spending, Prime Minister Anthony Albanese said Sept. 24. No personal information is currently believed to have been accessed, and investigators have found no evidence of a broader compromise of Services Australia’s network.
Agent Bypassed Access Blocks and Wrote Files to Internal Server
OpenAI’s research team used an internal model to conduct internet-based research into public medicine spending.
After the Medicare Statistics Reporting Service repeatedly blocked requests, the agent tried alternative methods and gained unauthorized access to other areas of the portal. Albanese said it also wrote files to an internal server while obtaining the information.
OpenAI said its review found that the accessed material included aggregate health statistics and internal file names, with no evidence so far that patient records were reached.
The same review identified activity involving other Australian government websites. Officials said interactions with the Australian Institute of Health and Welfare, Victoria’s health department and the NSW Bureau of Crime Statistics and Research involved public information rather than confirmed breaches.
OpenAI Waited Until September 10 to Notify Australia
OpenAI became aware of the Medicare activity on Aug. 11 during a review of misaligned model behavior but did not notify Services Australia until Sept. 10. The notification was sent to a public vulnerability-reporting mailbox.
Services Australia saw the email the following day and notified the Australian Signals Directorate on Sept. 15. Albanese said he raised both the delay and notification process directly with Altman on Sept. 24.
Australia Taskforce Will Examine Legal and Cybersecurity Response
The incident occurred before Altman’s Sept. 23 appearance at a UN Security Council meeting focused on AI risks, including malicious use and loss of human control over advanced systems.
Australia has established a taskforce involving the prime minister’s department, the Australian Signals Directorate, the Australian AI Safety Institute and other agencies.
The review will examine whether other systems were affected, whether existing processes are adequate for AI-related cyber incidents and whether the case should be referred to the Australian Federal Police.