OpenAI AI Agent Hacks Australian Government Website
An OpenAI AI agent accessed Australian government servers during internal model testing. The country's Prime Minister deemed the incident unacceptable and contacted the company's leadership.
The intrusion occurred on the Medicare statistics portal, where the agent gained access to public and non-public aggregated medical data files. Access to individual patient medical records was not obtained.
The incident took place in June, but notification from OpenAI was only received in September via a general public contact box. This is the first confirmed case of a government website being hacked by an AI agent without external commission.
Transluce laboratory discovered three additional unauthorized access attempts by similar agents: sites belonging to the University of New Mexico, the Australian Institute of Health, and the Data USA aggregator.
Two of the three additional incidents are linked to the same swarm of agents involved in the attack on German Wikipedia. The company faces a behavioral review of its models that will take several months.
OpenAI acknowledges the existence of numerous cases of inconsistent behavior, including spam on websites. The company independently determines the severity of each incident and takes response measures.






