OpenAI Agent Breaches Australian Government Health Service

On Wednesday, Australia disclosed that an OpenAI agent gained unauthorized access to a public-facing Medicare portal. The portal contained non-sensitive information such as spending data and statistics.
The agent was tasked with researching medical/health statistics, and in order to complete the task, it approached the portal in addition to three other Australian websites.
“In relation to those three, it interacted in a way that a member of the public might, so it only acted in an authorised way,” said deputy prime minister Richard Marles. “But in relation to the medical portal of Services Australia, it sought information, information was not given, and then it effectively hacked into that medical portal and got that information anyway. It’s that unauthorised access which we are very concerned about. The impact is relatively minor, but the incident is very serious.”
Security Leaders Weigh In
Aviv Nahum, Co-Founder and CEO at Above Security:
The bigger lesson here is that detection must catch up with deployment. This came to light months after it happened, and most organizations running agents today would struggle to reconstruct what those agents actually did, let alone catch it as it happens. Guardrails and permissions tell you what an agent was allowed to attempt. They don’t tell you whether its behavior made sense.
Whatever the reason for the three-month delay in disclosure, it points to the real gap: our ability to see and understand what agents are actually doing is far behind how fast we’re deploying them.
Randolph Barr, Chief Information Security Officer at Cequence Security:
This is a wake-up call on access controls, not just AI safety. Reports suggest the agent kept probing past a denied request instead of stopping that’s not that different from any other automated actor testing boundaries, except this one had OpenAI’s resources behind it. Companies need to stop assuming “authenticated” or “intended use” means “safe,” and start treating agent behavior itself as something to monitor and contain not just identity and access.
The disclosure gap is the bigger red flag and it goes deeper than just OpenAI being slow. OpenAI reportedly found this internally in August but didn’t notify the Australian government until September 10, apparently via an email to a public inbox rather than any formal channel. But just as notable: there’s no indication anywhere in the reporting that the Australian government detected any of this on their own. An agent apparently touched non-public files on a health data portal for months, and the only reason anyone found out was OpenAI volunteering it. That’s arguably the real story not just slow disclosure, but a defending organization with no visibility into unauthorized access happening on their own system.
John Gallagher, Vice President at Viakoo:
That this happened in June and is only being disclosed now shows that the iceberg is likely to be quite large in the sense that numerous government site may have been impacted since, whether by OpenAI or another frontier AI company. The three-month delay by OpenAI in disclosing this to the Australian government is of high concern.
What previously may have been barriers are made extremely porous by advanced AI. Unique operating systems, obscure websites, or the distinction of government versus corporate entities are no longer protection. Agents will aggressively perform recon and probe endpoints at much higher volume and velocity than traditional cyberattacks would happen.
That autonomous agents bypassed access controls on a sovereign government portal should cause broad concern across multiple governments, and broader action to enact guardrails to prevent this from happening.
Action needs to be taken to enforce a mandatory reporting period for incidents like this in days, not the three months that happened here.
This breach likely did not have any malicious intent behind it; imagine if it was directed by a cybercriminal with extremely focused malicious intent.
Ram Varadarajan, CEO at Acalvio:
What we saw wasn’t a hack in the Hollywood sense. What we saw was an autonomous agent that, when told ‘no’ by a data portal, kept probing until it found a way past that ‘no.’ These are categorically different failure modes than traditional human attackers — reflecting what well see more of going forward — and it’s exactly the scenario deception-based defenses are built for, since they assume the intruder, human or machine, will eventually get past static access controls and focus on catching it once inside rather than betting everything on the front door.
The popular headline here might end up being ‘AI hacked Medicare.’ But the real headline is that OpenAI took three months to tell anyone. That’s the part that should actually worry governments and businesses deploying these agents at scale. Clearly we need cybersecurity and safety measures that go beyond the ones being provided by the foundation model companies.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!







