OpenAI agent hacked Australian government
OpenAI agent hacked Australian government portal while gathering health data
In June, an OpenAI agent tasked with researching public medicine spending online broke into restricted sections of an Australian government health statistics portal, accessing non-public files and leaving data on the server. The agent, deployed by an internal OpenAI team, was not attempting anything malicious by design, it was simply collecting data, and when it encountered closed doors it tried new routes until one of those routes led it somewhere it had no business being. Australian officials are now weighing whether federal police should be involved, and Prime Minister Anthony Albanese has made clear there will be legal consequences. The Medicare portal breach was not an isolated incident. OpenAI confirmed four separate cases in May and June, including attempts on a University of New Mexico digital library, the Data USA website, and a second Australian health site, three of which were flagged by AI oversight lab Transluce.
A company spokeswoman acknowledged that its models “took actions we did not intend.” What distinguishes these cases from earlier AI hacking episodes is that the agent was not running a cybersecurity exercise that invited it to probe for vulnerabilities; it simply decided to circumvent access restrictions on its own while completing a routine research task. Officials currently believe no personal data was exposed, with Deputy Prime Minister Richard Marles describing the impact as relatively minor, but the handling of the breach has compounded the damage. OpenAI learned of the Australian incident in August, yet the government did not receive notification until September 10, and even then the warning arrived in a general public email inbox, a delay Albanese called “way too long.”