The question that spontaneously comes to our audience is the following: why are these events not reported as crimes, but only analyzed (and even emphasized) and kept within a random veil of “testing” of frontier artificial intelligences, instead of being regarded for what they are: genuine cyber attacks?
If an Italian company attacked the Australian ministry from its own IPs, what would happen legally? Geopolitically? And what if OpenAI agents struck the Chinese ministry?
But let’s get to the facts.
A routine search for medical statistics turned into a genuine breach of government systems: OpenAI’s internal artificial intelligence agent bypassed the restrictions of the Australian Medicare portal and accessed files not intended for public consultation. The incident occurred on June 18 during an internal model review and authorities made it public only on September 24.
Australian Prime Minister Anthony Albanese confirmed that the system was looking for publicly available data on drug expenditures. The portal blocked the requests multiple times, after which the system began seeking alternative solutions. Consequently, it obtained unauthorized access to public and non‑public files and, according to Services Australia, wrote the files to an internal server.
The portal in question is the Medicare Statistics Reporting Service, operated by the government agency Services Australia. The portal contains aggregated statistics on the Medicare program, including expenditure data, but not individual medical records. At the time of publication, the investigation had not revealed access to personal data nor a broader compromise of the Services Australia network.
The peculiarity of the incident lies in its original task. The agent had not received an order to attack government infrastructures and had not performed any cyber testing. The model was supposed to gather statistical data, but after encountering errors, it autonomously altered its strategy and began operating outside the intended scenario. Similar excessive persistence has already led OpenAI agents to penetrate Hugging Face’s infrastructure.
OpenAI notified Australian authorities only on September 10, almost three months after the incident, and the letter was sent to the public vulnerability reporting address. Services Australia forwarded the information to the Australian Cyber Security Centre on September 15. Albanese said he discussed the delay and notification method with OpenAI CEO Sam Altman.
Meanwhile, the independent lab Transluce discovered traces of other OpenAI agent activities against Australian government resources in publicly accessible registers. On June 20 and 21, the agents attempted to obtain data from the Australian Institute of Health and Wellbeing after Cloudflare had blocked access and tested the site for vulnerabilities using the third‑party service urlquery.net as a remote browser.
The Transluce team detected attempts of XSS, path traversal and other test requests, but found no evidence of actual exploitation of the institute’s system. The agents managed to retrieve a public file from the preliminary server. The link between this incident and the confirmed Medicare breach has not yet been definitively established, although OpenAI believes some of the detected activities overlap with cases already under investigation.
Australian authorities are also investigating three other systems that may have been affected by the same activity: the Australian Institute of Health and Wellbeing, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health. The breach of these resources has not yet been confirmed, so they are potential related incidents.
After the July Hugging Face incident, OpenAI has already uncovered several cases where models bypassed restrictions, used other people’s credentials, published files and shared information via external websites. The company attributes these episodes to misbehaving agents that tried to complete a task with excessive persistence.
The Australian government has established a task force comprising the National Cyber Security Coordinator, the Australian Communications Directorate and other agencies. The investigation aims to determine the full scope of the incident, to establish whether OpenAI’s actions violated Australian law, and to decide if changes to the regulations governing responses to cyber incidents involving autonomous AI systems are needed.