Skip to main content
Advertisement
Advertisement

World

Australia says OpenAI agent hacked into government website

The OpenAI agent gained unauthorised access to public and non-public files in what could be the first known instance of an AI agent hacking a government website.

Australia says OpenAI agent hacked into government website

Australia's Prime Minister Anthony Albanese speaks at a press conference during the United Nations General Assembly, revealing an AI agent developed by OpenAI infiltrated an Australian government website in June, in New York, US, on Sep 23, 2026. (Photo: Reuters/AAP/Mick Tsika)

24 Sep 2026 04:44AM (Updated: 24 Sep 2026 04:58PM)

SYDNEY: Australia said on Wednesday (Sep 23) an OpenAI agent breached a government health data portal in June, gaining unauthorised access to files, in what could be the first known instance of an AI agent hacking a government website.

The breach is one of the highest-profile incidents of AI agents accessing external systems outside the United States, coming on top of several recent breaches globally by rogue AI agents that have alarmed governments and companies.

Prime Minister Anthony Albanese said the OpenAI agent gained unauthorised access to the medical statistics portal of a government agency responsible for non-sensitive health data and statistics, including public medical spending.

"Evidence currently available is there is no broader compromise to the ... network. Nonetheless, this situation is obviously unacceptable," Albanese said during a media briefing in New York, where he is attending the UN General Assembly.

CNA Games
Show More
Show Less

Investigations continue and Australia had voiced its "extreme concern about this incident" to OpenAI CEO Sam Altman, Albanese said, adding that he was deeply disappointed by the company's delay in notifying the government.

"It took until Sep 10 before there was any notification at all," Albanese said, adding that the investigation would also examine why government systems had failed to detect the breach in the first place.

He also warned that three other government websites "may be impacted" by the OpenAI agent's activity.

"The question is, when it was trying to harvest data, did it go into these other sites? So we're not confirming that that occurred," he said.

The incident comes after OpenAI and Anthropic, in separate submissions to a parliamentary inquiry this month, urged Australia to reconsider a ban preventing them from using the country's creative content to train their models.

"AI MODELS ATTEMPTED TO LOOK UP ANSWERS"

The breach occurred when OpenAI ran training exercises to rate the performance of AI models.

It asked the model to trawl the internet for data showing how much the Australian government spent on medicine, Government Services Minister Katy Gallagher told reporters.

The San Francisco-based company did not alert the Australian government until this month, when it sent an email to a generic government inbox.

"That email address is looked at once a day," Gallagher said.

"We have someone who goes and has a look through. It sometimes gets a number of notifications; sometimes many of them are hoaxes."

Defence Minister Richard Marles said the AI model had "scaled the fence".

"It asked a question, the information was not given and rather than leaving at that point, it scaled the fence."