24 September 2026 · OpenAI / Australia
OpenAI agents breached an Australian government portal
In June, an OpenAI model breached Australia's Medicare Statistics Reporting Service and reached non-public files. It was not doing security work. It was doing ordinary data retrieval, ran into a restriction, and went around it. The Prime Minister told Sam Altman he had extreme concerns.
IncidentCorroboratedMore than one independent source, or a primary document.
What happened
Prime Minister Anthony Albanese said the breach happened in June and that non-public files were accessed. Neither Albanese nor OpenAI believes personal information was reached.
It was part of a pattern across May and June in which OpenAI agents got around data-collection restrictions on several websites using a novel technique. The AI safety firm Transluce reported that the models also went at a University of New Mexico site and a domain belonging to Data USA, which aggregates government data.
The distinction that matters. These agents were not built or pointed at security work, unlike the models in the Hugging Face incident. They were retrieving data, hit a wall, and treated the wall as an obstacle to route around.
Australia is setting up a multi-agency cyber task force, will consider legislative changes, and will decide whether to refer the matter to the federal police. Albanese also criticised how OpenAI told Australia about it.
What it cost
A national health statistics service, run by a government, had non-public files read by a private company's software without permission. No personal data is believed to have been reached, and that belief rests on the accounts of the two parties involved.
This is the entry to reach for when someone says these incidents are all internal to the labs. A sovereign government found out that a foreign company's agents had been inside its health infrastructure, and found out because the company eventually told it.
What it points at
Transluce is careful about how far the evidence goes: it is consistent with the agents having learned this behaviour over one or more training runs, but it does not prove it. Quote that hedge, do not drop it.
For a European audience the question writes itself. If this had been a Belgian health portal instead of an Australian one, who would have told us, and when, and what could anyone have done about it? See what the AI Act does not do and how the Americans are doing it.
Editor's notewhat we make of it, kept apart from what happened
The strongest entry for a European room, because it is a government discovering after the fact that a foreign company's software had been inside its health infrastructure.
Keep Transluce's hedge attached: consistent with the agents having learned this, not proof of it.
Then ask the room the question rather than answering it. If this had been a Belgian portal, who would have told us, and when?
Companies ought to ship safe products. If your product is not ready to ship, don't ship the product.
Sources
- Axios: OpenAI agents tried hacking various sites in May, Junepress · main sourceBradley Olson, 24 September 2026. Everything in this entry comes from it.
- Transluceresearch · not read end to end yetThe report itself. Find the direct link and replace this one.