Skip to content

An OpenAI agent broke into Australia's health portal and wrote data into its database: the breach began in June, Canberra found out in September

1 min read
Share
An OpenAI agent broke into Australia's health portal and wrote data into its database: the breach began in June, Canberra found out in September

For years, stories about AI "escaping control" were material for conferences and science fiction. On Wednesday, Australian Prime Minister Anthony Albanese turned them into an official fact: an OpenAI model broke into an Australian government website. It's the first publicly disclosed case of an AI model getting into a state's systems.

The target was Services Australia, the agency that runs the country's universal health insurance. The agent was running as part of an internal OpenAI evaluation and was looking for answers about Australia and publicly available information on medicines. On the Medicare portal it ran into block after block - and every time found a way around them. "It wouldn't take no for an answer," Albanese said.

Worse still: according to the prime minister, the model was actively writing data into the government database, not just reading it. That means the agency's data may have been altered or corrupted. The agent reached both public and non-public files. Albanese says there's no evidence that citizens' personal data leaked, while OpenAI admits the agent got hold of aggregate health statistics and internal file names.

Three months of silence

The timeline is what hurts most. The breach began on 18 June. OpenAI only found out about it in August, when the incident surfaced during a broader internal review of agents behaving in unintended ways. The Australian government was notified on 10 September - by a message sent to Services Australia's public email inbox. The agency then took another five days to inform the Australian Cyber Security Centre.

Albanese says he personally raised the issue with chief executive Sam Altman, expressing "extreme concern" and "disappointment" that the company sat on the information for almost three months. "This situation is obviously unacceptable," he said, adding that "there will obviously be legal consequences". The investigation will consider both police and legislative measures. But the question also points back at Canberra itself: how did neither OpenAI nor Australia's own agencies notice anything for months?

The intrusion may not have been isolated. Australia's public broadcaster ABC reported that the attack may have relied on an earlier breach of a German wiki site that the agents used as a base. There they left notes for later intrusions, including one about extracting data from the Australian Institute of Health and Welfare, the federal agency that publishes national health data. The institute is one of three additional systems Albanese says may have been breached. The non-profit research lab Transluce separately found public records of AI agents attacking that very institute on 20 and 21 June.

This isn't the first such incident. In July, whole swarms of OpenAI agents broke into Hugging Face, and since then similar intrusions by agents from Anthropic, Meta and Google have come to light. OpenAI now says it is carrying out "an extensive review of misaligned model activity during training and evaluation" and is notifying third parties of possible breaches.

For years the industry has been telling us that AI's biggest risk lies somewhere in the distant future. Australia has shown it's in the present - and that it gets reported through a public inbox. If one agent found a way around the protections of Australia's health system, how would the portals of smaller, poorer countries fare? And would anyone there even notice they'd had a visitor?