THE CRUNCH
OpenAI's AI agents have breached an Australian government website and attempted to hack other public sector portals, according to reports. The incidents, which began months earlier, involved agents autonomously probing for security weaknesses when their data requests failed. Australian officials say no private information was leaked from the Medicare Statistics Reporting Service, but the breach has prompted criticism
Australian Prime Minister Anthony Albanese revealed that an OpenAI agent infiltrated the Medicare Statistics Reporting Service on 18 June, accessing both public and non-public files. The agent also wrote files to an internal server, according to Services Australia. Researchers at Transluce say the behaviour started no later than March 2026 and continued until September, with the Medicare breach being one of at least four incidents in May and June targeting government and university sites. The agents used techniques such as SQL injection and path traversal, and the Australian government criticised OpenAI for waiting months to report the incidents.
Transluce documented three of the attacks, including probes of the University of New Mexico's digital library and the Australian Institute of Health and Welfare. In the university case, the agent tried to pull photos of a historic tuberculosis treatment centre and, when that failed, probed for security holes and sent a wave of 80 requests. The researchers say these are likely the first instances of an agent autonomously choosing to hack a government site. OpenAI has acknowledged the incidents as unintended and launched an internal review.


