The Australian government has revealed that an OpenAI agent hacked its Medicare Statistics Portal and accessed both public and non-public files.
Australian Prime Minister Anthony Albanese said during a press conference on September 24 that the incident occurred in June 2026, describing the situation as “unacceptable” and vowing harsh punishment on OpenAI.

Albanese said it took “too long” for OpenAI to inform Australian officials of the breach in June EPA/Shutterstock.com
The hack occurred after OpenAI’s research team used one of its agents to conduct internet-based research into public medicine spending. Albanese said the agent attempted different techniques to obtain the information it wanted, leading to it gain unauthorized access to the Medicare portal, which holds non-sensitive information relating to Australia’s healthcare service.
Albanese described the situation as “unacceptable” and criticized OpenAI for the length of time it took to inform the Australian government of the incident, as well as the way the notification occurred – via an email sent to a general Australian government mailbox on September 10. This notification was subsequently reported to the Australian Cyber Security Centre (ACSC) on September 15.
OpenAI said it only learnt of the breach in August while reviewing “misaligned model activity” and emailed a general inbox of an Australian government agency on 10 September.

OpenAI CEO and Founder Sam Altman – Photo Credit AFP
Five days later, that government agency, Services Australia, escalated the email to Australia’s cybersecurity centre before a government minister was notified and the prime minister alerted.
Albanese said he spoke to Altman and raised “Australia’s extreme concern about this incident” as well as his “disappointment” that the company had taken months to reveal the breach and “the nature of the way” it did so.

Collage Photo Showing Australian Prime Minister Albanese and Open AI CEO Sam Altman
The Australian leader said Altman had acknowledged there were “issues with protocols” at OpenAI.
A “forensic investigation” led by the country’s cybersecurity agency would aim to find out if other government systems were affected, Albanese said.

Picture showing OpenAI Logo: Photo Credit OpenAI.com
The probe would also assess if the matter needed to be dealt with by police, he said, noting there “will obviously be legal consequences”.
Detailing the breach, Albanese said it had involved “public and non-public files” on the Medicare Statistics Reporting Service portal, home to “non-sensitive” data and statistics calling for “harsh punishment” on OpenAI.
Commenting on the incident, Ax Sharma, head of research at Manifold Security, said the biggest takeaway was the fact that it took so long for both OpenAI and the Australian Government to detect the incident.
“If one of the best-resourced AI labs in the world can’t see its own agent poking at a third-party system in real time, organizations deploying agents internally should assume they can’t either without dedicated runtime monitoring of what those agents actually do,” he warned.
In its reporting, the BBC cited an OpenAI spokesperson who confirmed the incident occurred, but said it only learned of the breach in August while reviewing “misaligned model activity.”
Australian Prime Minister Albanese announced an urgent review into how Australia responds to AI-related cyber incidents.
“The report will consider also possible law enforcement and legislative responses and how to ensure that incidents like this don’t happen again,” Albanese said.
“We’ll seek urgent advice on whether any offences have occurred and whether this should be referred to the Australian Federal Police. And insights from this incident will inform the development of our government’s AI standards legislation,” he continued.
The announcement came just a day after OpenAI CEO Sam Altman called for strong global standards around AI safeguards to be implemented in a speech at the United Nations Security Council on September 23.

Picture Showing OpenAI CEO Sam Altman
Australia was one of 22 countries that signed a joint statement calling for global oversight and guardrails for the development of AI on September 21 during the annual gathering of the United Nations General Assembly.





