OpenAI agent breached Australian government health website, Albanese says
An OpenAI agent gained “unauthorized access” to “non-public files” from an Australian government he 2026-9-24 12:45:52 Author: therecord.media(查看原文) 阅读量:0 收藏

An OpenAI agent gained “unauthorized access” to “non-public files” from an Australian government health website in June, Prime Minister Anthony Albanese said Wednesday.

The agent — an AI system designed to carry out tasks autonomously — accessed a public portal for Medicare statistics, Albanese said at a press conference in New York while attending the U.N. General Assembly.

The website portal it accessed lets users generate reports on Australia’s public health insurance system and pharmaceutical spending. Albanese said his government could not find a precedent for the incident, although he stopped short of claiming it was a world first.

The prime minister’s disclosure followed his speech at the General Assembly, where he described Australia as “an acknowledged first mover and world leader in digital safety” while warning that AI was posing a range of potential cross-border risks.

It is the latest to be disclosed in a series of incidents in which agentic AI models from Google, Anthropic, OpenAI and Meta reached real-world systems during security evaluations.

In most cases, the models gained access through basic techniques such as guessed passwords or exposed credentials. In one exception, OpenAI said its models exploited two previously unknown vulnerabilities to access AI platform Hugging Face.

Albanese did not say whether the OpenAI agent used compromised credentials or exploited a previously unknown vulnerability to reach the Medicare portal.

He said the agent had been researching public health spending and that after the portal repeatedly blocked its requests, the agent found a way around those blocks. Albanese did not describe the specific technique it used.

OpenAI’s agent “accessed both public and non-public files,” the prime minister said. Services Australia, the department which runs the platform, advised that the agent also wrote files to an internal server. A forensic investigation into the breach, aided by the Australian Signals Directorate, is underway.

“No personal information is believed to have been accessed at this stage, but investigations are ongoing,” said Albanese. “Nonetheless, this situation is obviously unacceptable.”

He said other systems may have also been affected, including the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health.

OpenAI criticism

Albanese criticized both the delay and the way OpenAI notified the government about its agent’s activities. Although the incident took place in June, the company’s first notification was provided on September 10 in an email to a public mailbox.

OpenAI said it did not become aware of the activity until August. The company said it had been validating and investigating the facts of the breach — including what information had been accessed — before it informed the Australian government.

OpenAI’s chief executive, Sam Altman, met with Australia’s deputy prime minister Richard Marles on September 1, but he did not at that time disclose anything about the incident or the company’s ongoing investigation.

Albanese said he spoke to Altman by phone on Wednesday “to express Australia’s extreme concern about this incident.” Asked whether Altman apologized, Albanese said he clearly accepted that the company had not done well enough.

In a statement to Recorded Future News, an OpenAI spokesperson said the company is conducting an extensive review of misaligned model activity during training and evaluation, and is notifying third parties when it identifies potential effects on their systems.

The spokesperson said the company had “identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation. 

“In the course of that, our models took actions we did not intend,” they said.

It, again, did not identify the nature of the unintended actions. OpenAI said its review found no evidence that patient records were accessed in the Australian incident, and the information obtained included aggregate health statistics and internal file names.

The company said its initial notification followed the standard industry practice of direct outreach between security practitioners through designated inboxes. It described that as the first step in an ongoing technical engagement.

OpenAI added it maintained close, regular contact with the Australian Signals Directorate throughout the disclosure process and had been sharing technical findings under the agency’s guidance.

Following the breach, Albanese announced the launch of a task force led by his department to review whether existing government processes are adequate for AI-related cyber incidents. The task force will include the National Cybersecurity Coordinator, the Office of AI, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia.

The Australian government said it will also seek urgent advice on whether any criminal offenses occurred in the breach, and if so whether the matter should be referred to the Australian Federal Police.

Recorded Future

No previous article

No new articles

Alexander Martin

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79


文章来源: https://therecord.media/openai-australia-health-breach
如有侵权请联系:admin#unsafe.sh