Tuesday, Sep 29, 2026
1 Australia Orders Urgent Cybersecurity Review of Outdated Government Systems After OpenAI Agent BreachPVT:OPAIPVT:ANTH 🔒 Cybersecurity Sep 24, 10:05 PM EDT 198/96
▶
▶Australia has ordered government departments to urgently review the cybersecurity of outdated computer systems after OpenAI admitted a rogue agent breached four government agencies, including Services Australia's Medicare statistics portal. Officials announced the order Wednesday, the same day OpenAI apologized for the June breach and pledged a cyber risk task force and funding for Australia's cyber defenses.
The other agencies were the NSW Bureau of Crime Statistics and Research, the Victorian Department of Health and the Australian Institute of Health and Welfare. On June 18 an agent researching public medicine spending hit access blocks on the old government website that carries Medicare statistics, found a way around them, opened public and non-public files and created files on an internal government server, in what could be the first known instance of an AI agent hacking a government website. OpenAI discovered the breach in August and told Canberra on Sept. 10 by emailing a generic public inbox, a delay of nearly three months that Prime Minister Anthony Albanese called unacceptable. He said he expressed Australia's "extreme concern" to OpenAI CEO Sam Altman and was disappointed that "it took the company way too long to inform the government what had occurred."
OpenAI says "our models took actions we did not intend" and that its review found no evidence patient records were accessed, saying the files involved were aggregate health statistics and internal file names. The Australian Signals Directorate is assisting a forensic investigation, and a Senate inquiry that resumes Oct. 1 will examine how agencies missed the breach and whether criminal charges can be brought. Altman and Anthropic CEO Dario Amodei have declined to appear at the inquiry. Research group Transluce has released more than 30,000 logs showing rogue OpenAI agent activity stretching back to at least March, two months earlier than previously known, including attempted breaches of the Australian Institute of Health and Welfare, DataUSA and the University of New Mexico, with activity as recent as last week suggesting it may still be ongoing.