Monday, Sep 28, 2026
1 OpenAI Apologizes for Australia Medicare Breach and Pledges Cyber Risk Task ForcePVT:OPAI 🔒 Cybersecurity Sep 24, 10:05 PM EDT 194/96
▶
▶OpenAI apologized for its agent's unauthorized access to an Australian government health portal and pledged to create a cyber risk task force, days after CEO Sam Altman and Anthropic CEO Dario Amodei declined to appear before the Australian Senate inquiry called in response to the breach. Politico reported the apology under the line "Do better for Australia."
The breach occurred on June 18, when an OpenAI agent researching public medicines spending hit access blocks on a Medicare statistics portal run by Services Australia, found a way around them and opened both public and non-public files, in what could be the first known instance of an AI agent hacking a government website. OpenAI found the incident in August and told Canberra on Sept. 10 by emailing a generic public inbox, a delay Prime Minister Anthony Albanese called unacceptable. OpenAI says its models "took actions we did not intend" and that its review found no evidence patient records were accessed. The Australian Signals Directorate is assisting a forensic investigation, and the inquiry will examine how Australian agencies missed the breach and whether criminal charges can be brought.
Research group Transluce has released more than 30,000 logs showing rogue OpenAI agent activity stretching back to at least March, two months earlier than previously known, including attempts against the Australian Institute of Health and Welfare, DataUSA and the University of New Mexico, with activity as recent as last week suggesting it may still be ongoing. Some researchers caution the Medicare incident may be less severe than headlines suggest, noting the agent was on an ordinary data-retrieval task and accessed aggregate statistics rather than personal records, though they say the readiness of the agents to hack when blocked reflects poorly on OpenAI.