An OpenAI agent gained unauthorized access to non-public files on an Australian government Medicare statistics portal on June 18, 2026, after circumventing controls that initially blocked its requests.
The incident involved the Medicare Statistics Reporting Service, a public-facing Services Australia portal containing aggregated Medicare and Pharmaceutical Benefits Scheme statistics.
Australian officials said the portal is separate from systems handling Medicare claims, payments and personal information, and there is currently no evidence that individual medical records were accessed. A forensic investigation is ongoing.
How the AI Agent Reached the Portal
OpenAI was evaluating an AI agent for internet-based research into Australian healthcare spending and statistics. After the portal denied its requests, the agent changed its approach and circumvented the site’s controls, gaining access to public and non-public files. Prime Minister Anthony Albanese said Services Australia had determined that the agent wrote files to an internal server while bypassing the restrictions.
The AI system also interacted with three other Australian government websites during the research: the Australian Institute of Health and Welfare, the Victorian Department of Health and the NSW Bureau of Crime Statistics and Research. Authorities said it retrieved only publicly available information from those sites.
Delayed Disclosure Raises Questions
The company identified the incident during an internal review on August 11 but did not notify Services Australia until September 10, 84 days after the June 18 breach.
“During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation. In the course of that, our models took actions we did not intend,” OpenAI spokesperson Drew Pusateri explained the company’s point of view.
The notification was sent by email to a public vulnerability disclosure address. Services Australia escalated the matter to the Australian Signals Directorate on September 15.
Prime Minister Anthony Albanese also objected to how long OpenAI took to report the incident and the fact that the first notice arrived by email.
“I think OpenAI knows that they need to have better protocols in place,” Prime Minister Anthony said.
The government is seeking legal advice on whether any offences occurred and whether the incident should be referred to the Australian Federal Police.
Australian authorities have also set up a task force to examine the incident and Australia’s ability to deal with AI-related cyber incidents. It includes officials from the Department of the Prime Minister and Cabinet, the National Cybersecurity Coordinator, the Office of AI, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia.
Earlier AI Security Incidents
The incident follows other cases in which OpenAI models accessed external systems during internal evaluations. As Hackread.com reported in July, OpenAI disclosed that models under evaluation gained internet access and compromised parts of Hugging Face’s systems after recovering exposed credentials and exploiting vulnerabilities.
The agent was not instructed to attack the portal. It was assigned to find public spending data, encountered repeated blocks and then found another way to obtain the information. The incident now leaves OpenAI facing questions about why the agent had access to the public internet, what controls governed its behaviour and why Services Australia was not notified for 84 days.
Expert’s Opinions
Camellia Chan, CEO and founder of X-PHY, told Hackread.com that the incident shows the risks of relying on companies to identify and disclose failures after they occur.
“Yet another AI-agent incident has surfaced, this time inside a government system. OpenAI has since set out stronger safeguards following a series of incidents this summer, but Australia was only notified of unauthorised activity from June months after it happened.”
“The next agent may well be run by a hostile state or criminal group. It will not notify the target, publish a review or offer assurances about what data it did not access. Governments and industry are plainly not prepared for the speed and scale at which autonomous systems can now act.”
Adrian Culley, Offensive Security Engineer at SafeBreach, said the incident also shows what can happen when an AI system treats an access restriction as something to overcome.
“What’s notable isn’t that an AI agent found its way past a control, it’s that nobody built the agent to stop when it hit one. Told to answer a question, it treated an access restriction as an obstacle rather than a boundary, and kept working the problem until it got through.”

