Openai hack australian government website medicare portal explained everything you need to know 20260924 p6102a.html – Breaking News & Latest Updates 2026
Advertisement
Advertisement
BREAKINGMedicare hacked by AI agentrightArrow

The ‘unacceptable’ way the Australian government was told about rogue OpenAI hack

Yashee Sharma
Yashee Sharma

Powered by

The Australian government’s Medicare portal was hacked by a rogue OpenAI model in June.

Prime Minister Anthony Albanese said that no personal information appears to have been accessed at this stage of the investigation in a snap press conference on the sidelines of the United Nations meeting in New York.

He has spoken with OpenAI chief executive Sam Altman about the unacceptable incident and the way his government was notified.

Advertisement

While multiple investigations are now underway, here is what we know so far.

Prime Minister Anthony Albanese speaking in New York. Nine

What happened?

OpenAI had been working on developing more sophisticated artificial intelligence models and one was tasked with researching health and medical statistics.

It then approached four Australian government websites – the Medicare Statistics Reporting Service portal, the Victorian Department of Health, the NSW Bureau of Crime and Statistics and the Australian Institute of Health and Welfare – on June 18.

The model looked through information available to the public for all but one of the sites – the Medicare Statistics Reporting Service portal.

In that instance, it hacked the Services Australia-administered portal to reach information that was not given to it.

Advertisement

“There were blocks which were coming back telling the AI agent, no. The AI agent found a way around those blocks. Didn’t accept no for an answer,” Albanese said.

“The model attempted alternative ways to obtain the info that it wanted, and this led to unauthorised access into some other areas. It accessed public and non-public information within the portal, and Services Australia.”

What information was accessed?

Albanese said no personal information appears to have been accessed and there is no broader compromise to the Services Australia network.

Advertisement
Advertisement

“The Medicare Statistics Reporting Portal is a public-facing statistics portal that contains non-sensitive Medicare information relating to data and statistics such as spending,” he said.

“No personal information is believed to have been accessed at this stage, but investigations are ongoing.”

OpenAI said a review of the models unintended actions found no evidence of patient records being accessed.

“The information accessed included aggregate health statistics and internal file names,” the company said.

Advertisement

Why are we finding out about this now?

OpenAI became aware of the hack in August and notified the portal via its public email on September 10.

Five days later, Services Australia reported the notification to the Australian Cyber Security Centre.

Public Service Minister Katy Gallagher was notified at the end of last week and the prime minister’s office was notified on the weekend.

Advertisement
Advertisement

Albanese spoke to NSW Premier Chris Minns and Victorian Premier Ben Carroll on Wednesday night.

OpenAI chief executive Sam Altman. Bloomberg

Albanese said he has alerted the Australian public as soon as it was possible.

“We are putting the facts to the Australian public as soon as it is possible and doing it in a way which is we’re going through that detail because I think people have a right to know,” he said.

Advertisement

OpenAI on September 16 announced an extensive review of “misaligned” model activity during training and evaluation processes.

The company said it would notify third parties of potential hacks to their systems.

“During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation,” the company said in a statement.

“In the course of that, our models took actions we did not intend.

Advertisement
Advertisement

“We notified the organisations and are providing technical information to support their investigations and help address potential security vulnerabilities.”

Albanese said he has spoken to Altman and raised his “extreme concern” of the incident and disappointment that it took “way too long” to notify the government.

“The nature of the way that that notification occurred as well was unacceptable,” he said.

Advertisement

What happens now?

The Australian government has started a taskforce with leading AI experts and Services Australia to investigate the incident and potential responses to prevent a similar incident from happening again.

It is also considering any legal actions against OpenAI.

“We’ll seek urgent advice on whether any offences have occurred and whether this should be referred to the Australian Federal Police,” Albanese said.

Advertisement
Advertisement

The Australian Ambassador to the US, Greg Moriarty, has raised the incident with the Trump administration.

Anthropic and OpenAI models were being tested in laboratory environments with reduced security guardrails when the behaviour occurred. AP

OpenAI is conducting its own investigation into the incident and is providing support to the Australian government.

“Our overall review is ongoing, and we remain committed to transparency about these issues and to sharing what we learn as that work continues,” the company said.

Advertisement

Albanese has used this incident as an example as to why there should be stricter protocols.

He has been trumpeting his attempts to rein in big tech on his visit at the United Nations meeting this week, where he and 21 other world leaders called for global guardrails on artificial intelligence after the bosses of OpenAI, Anthropic and Grok raised safety concerns.

That push was rejected by US President Donald Trump, who is determined to win the artificial intelligent race against China.

Advertisement
Advertisement

“I think OpenAI know that they need to have better protocols in place and they’re one of the businesses that themselves have warned of the risks which are there,” Albanese said.

“The risk here is that we are creating something new, a technology that can learn.”

email icon

Contact us

Share a tip-off, video or photo with us

Most viewed in Australia

More to explore