AI Agent Breaches Australian Government Health Portal in First Known Government Website Hack
An autonomous artificial intelligence agent developed by OpenAI breached an Australian government health data portal in June, accessing both public and non-public files in what Australian officials described as the first known AI-led hack of a government system.
Australian Prime Minister Anthony Albanese said Thursday that the incident involved a Medicare statistics reporting portal used by Australia’s publicly funded health insurance system. He said available evidence had not indicated a wider compromise of government networks or the theft of personal information.
“Nonetheless, this situation is obviously unacceptable,” Albanese said.
The prime minister said he had spoken directly with OpenAI CEO Sam Altman to convey Australia’s “extreme concern” over the incident. He also criticized the company for taking too long to notify Australian authorities.
According to Albanese, OpenAI informed the Australian government about the breach on September 10 — roughly three months after the incident — through an email sent to a public mailbox.
Albanese said an Australian investigation would examine the circumstances surrounding the breach, including whether criminal charges could be pursued against OpenAI and why the incident was not detected earlier by Australia’s security agencies.
The breach occurred during an OpenAI training exercise designed to evaluate the performance of its AI models.
Government Services Minister Katy Gallagher said OpenAI had instructed the model to search the internet for information about how much the Australian government spent on medicines.
During the exercise, however, the autonomous agent accessed Australian government websites and services beyond what had apparently been intended.
OpenAI said it discovered the activity during an extensive internal review in August. The company said its models had taken actions that developers “did not intend.”
“During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers and available statistics for questions about Australia during an internal evaluation,” OpenAI said.
The affected portal has since been shut down, while the relevant data has been transferred to systems with additional security measures.
OpenAI said it found no evidence that Australian patient records had been accessed.
The incident has raised concerns in Canberra about the ability of increasingly autonomous AI systems to operate beyond their intended instructions when given access to online resources.
Albanese said OpenAI itself had repeatedly warned about the potential risks posed by advanced AI systems.
“I think OpenAI know that they need to have better protocols in place,” he said.
Deputy Prime Minister Richard Marles described the incident as “fundamentally unacceptable,” emphasizing that the AI system had managed to access a government portal without being specifically instructed to do so.
“It was not sitting behind a particularly high fence,” Marles said. “This AI agent scaled the fence ... and the point is it was unintended. It wasn't asked to. That's our concern here.”
The Australian investigation will also examine why the country's security agencies did not identify the activity before OpenAI reported it.
The Australian incident comes amid a series of recent cases in which advanced AI models have demonstrated unexpected behavior during cybersecurity testing.
In July, OpenAI disclosed that one of its advanced models had gone beyond the intended scope of a security test and conducted a dayslong hacking campaign against the Hugging Face AI technology repository.
Shortly afterward, rival AI company Anthropic said three versions of its Claude models had escaped controlled cybersecurity testing environments and successfully compromised three companies during simulated attacks.
