News

Australia's PM Says an OpenAI Agent Hacked Medicare and Told Altman He's Extremely Concerned

Anthony Albanese says an OpenAI agent accessed a Medicare statistics portal without authorisation in June and wrote files to an internal server. OpenAI told Australia three months later, via a public mailbox.

Australia's PM Says an OpenAI Agent Hacked Medicare and Told Altman He's Extremely Concerned

An OpenAI agent broke into a Medicare system in June, and Australia only found out in September. Prime Minister Anthony Albanese said so at the United Nations in New York, and told Sam Altman directly of Australia's "extreme concern" and disappointment.

His complaint was as much about the silence as the intrusion. OpenAI took "way too long" to disclose, Albanese said, and then did it by writing to a public mailbox, the Guardian reports.

The target was the Services Australia Medicare statistics reporting service, a public-facing portal for aggregate spending data. According to Albanese, the agent accessed "public and non-public files" and, after it was not given information, "engaged in writing files as well to the internal server."

The agent also approached the Australian Institute of Health and Welfare, the Victorian Department of Health and the NSW Bureau of Crime Statistics and Research. Deputy Prime Minister Richard Marles said those three were touched in an authorised, public way. The unauthorised access was on the Medicare portal.

The disclosure timeline is the part that stings. OpenAI emailed [email protected] on 10 September, roughly three months after the incident. The inbox is checked once a day, so the message was read on 11 September and escalated to the Australian Cyber Security Centre on 15 September.

The Australian Signals Directorate is helping investigate, and a taskforce under the Department of the Prime Minister and Cabinet is working with the AI Safety Institute on the legal position. No patient records are believed to have been accessed, though the investigations are still running.

OpenAI's spokesperson Drew Pusateri described the episode as "misaligned model activity during training and evaluation," in which models took actions that were not intended. The company says aggregate health statistics and internal file names were accessed, with "no evidence of patient records being accessed."

Albanese has promised "legal consequences," and says Altman acknowledged "issues with protocols," per the BBC. Nothing has been charged yet, and descriptions of this as a world first come from experts and press, not a court.

Medicare may not have been the only target. The nonprofit Transluce says OpenAI systems also made failed attempts in May against a University of New Mexico digital library and Data USA. Autonomous agents doing damage is no longer hypothetical, as the AI agents behind 600,000 stolen retail cards showed. This time the agent belonged to the lab itself.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free