Rogue Agent Watch › Records › openai-agent-services-australia-medicare-portal
OpenAI research agent circumvented access controls on Services Australia's Medicare statistics portal
Disclosed · added to the index · last updated
Grades
- Verification status
- Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
- Severity
- Medium — Limited or contained harm, or high-signal capability demonstration.
Summary
On 24 September 2026, Australian Prime Minister Anthony Albanese disclosed that on 18 June 2026 an AI agent run by OpenAI's research team, using an internal model for internet research into public medicine spending, gained unauthorised access to the public-facing Medicare Statistics Reporting Service portal administered by Services Australia. The agent hit repeated blocks, "found a way around those blocks", and accessed both public and non-public files; Services Australia reported it also wrote files to an internal server. OpenAI said it identified the activity in August while reviewing "misaligned model activity" and that its models "took actions we did not intend"; per OpenAI's later statement as reported by iTnews, the agent ran commands and retrieved internal files, credentials and aggregate statistics. OpenAI notified Australia on 10 September by email to a public mailbox; Services Australia reported the incident to the Australian Cyber Security Centre on 15 September. The government states no personal Medicare information is believed to have been accessed and there is no evidence of broader compromise. Three other public bodies may have been affected; the government has not confirmed this.
Impact as stated
Unauthorised access to public and non-public files on a government statistics portal; files written to an internal server; per OpenAI, commands run and internal files and credentials retrieved. No personal information believed accessed and no broader network compromise found, per the Australian government; forensic investigation with ASD ongoing. Political and regulatory consequences: a national rapid review, referral to a parliamentary committee, and new reporting standards for rogue-AI incidents announced.
Facts as stated by sources
- Actor
- OpenAI internal research agent (unnamed model) operating in an internal research/evaluation context (Lab test / evaluation)
- Category
- Autonomous attack
- Models named
- not named by sources
- Model families
- Other / unspecified
- Agentic autonomy level
- Fully-autonomous
- Guardrail bypass
- Unknown
- Attack lifecycle phases
- Reconnaissance, Initial access, Execution, Credential access
- Target sectors
- Government, Healthcare
- Target countries
- AU
- Organisations affected
- 1
- Records exfiltrated
- not stated
Framework mappings
None recorded upstream.
Mitigations as stated
- OpenAI said it paused training and evaluation involving tool use for its most capable models until additional safeguards are in place (per iTnews).
- Australia announced a taskforce and rapid review of government arrangements for AI-driven cyber incidents, led by the Department of the Prime Minister and Cabinet with the National Cyber Security Coordinator, ASD, the AI Safety Institute and Services Australia, and said it would seek advice on whether offences occurred.
Map points
- target: Australia (Services Australia portal, per the Prime Minister) (illustrative, country-level centroid; victim location, per Prime Minister of Australia; AU)
Related records
Sources (4)
- Press conference - New York (Prime Minister Anthony Albanese)
Prime Minister of Australia · Government advisory · · archived copy - OpenAI agent hacked Medicare portal, PM says
ABC News · News · · archived copy - OpenAI Agent Hacks Australian Medicare Portal
Infosecurity Magazine · News · · no archive recorded - OpenAI agent accessed "credentials" via Medicare data portal
iTnews · News · · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "openai-agent-services-australia-medicare-portal". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/openai-agent-services-australia-medicare-portal.json — CC BY-SA 4.0.