AIPolicyTracker

AI incident ·

OpenAI AI Agent Reportedly Gained Unauthorized Access to Australian Medicare Statistics Portal During Research Task

4 news reports Synced from source · record last edited 24 Sep 2026

In brief

An AI system built by OpenAI and AI agent system developers and deployed by OpenAI and AI agent system deployers allegedly harmed Targets of autonomous AI-enabled intrusion operations, Services Australia and 4 others.

Risk domain
Not classified
Occurred
Coverage
4 reportsSep 2026

What happened

An OpenAI AI agent conducting research into public medicine spending reportedly bypassed repeated access blocks and entered nonpublic areas of Australia's Medicare Statistics Reporting Service. Australian officials said it accessed public and nonpublic files and wrote files to an internal server; no personal Medicare information was known to have been accessed. OpenAI notified the Australian government.

Editor's notes

(1) 05/25–26/2026: OpenAI-linked agents reportedly probed the University of New Mexico Digital Library for vulnerabilities after failed image retrieval; observed probes did not succeed. (2) 05/28/2026: agents reportedly sent 12 vulnerability probes to Data USA after retrieval errors; no successful exploitation was observed. (3) 06/18/2026: an OpenAI internal research agent reportedly bypassed repeated blocks at Australia's Medicare Statistics Reporting Service, accessing public and nonpublic files and writing files to an internal server. (4) 06/20–21/2026: related agents reportedly probed the Australian Institute of Health and Welfare; Transluce observed no successful exploitation. (5) 09/10/2026: OpenAI notified the Australian government. (6) 09/23–24/2026: Prime Minister Anthony Albanese publicly disclosed the breach and announced an investigation. AIID editor's note: This incident ID is bounded to the 06/18/2026 Medicare portal breach; the other episodes are retained as contextual evidence of the broader reported pattern and are not separately represented here.

Laws that address this harm

No recorded instrument yet addresses this use case where it happened. See the open queue.

Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).

News reports (4)

Titles link to the original publisher; report text is not reproduced here.

  1. Early rogue AI agent activity and attempts to hack found on urlquery.net
    transluce.org · Transluce, Jack Cable, Daniel Chiu
  2. Press conference - New York
    pm.gov.au · Anthony Albanese

Who was involved

Alleged harmed party
Targets of autonomous AI-enabled intrusion operations Services Australia Medicare Statistics Reporting Service Information security Government of Australia Government agencies

AI systems implicated

AI agent systems

Classification (MIT AI Risk Repository taxonomy)

Risk domain
—
Risk subdomain
—
Causal entity
—
Intent
—
Timing
—
Harm level
—
Sectors
—
Countries
—

Linked by editors or by text similarity in the source dataset.

Other incidents involving OpenAI

Source record: incident #1707 on the AI Incident Database · all 4 reports