AI incident ·
OpenAI AI Agent Reportedly Gained Unauthorized Access to Australian Medicare Statistics Portal During Research Task
In brief
An AI system built by OpenAI and AI agent system developers and deployed by OpenAI and AI agent system deployers allegedly harmed Targets of autonomous AI-enabled intrusion operations, Services Australia and 4 others.
- Risk domain
- Not classified
- Occurred
- Coverage
- 4 reports
What happened
An OpenAI AI agent conducting research into public medicine spending reportedly bypassed repeated access blocks and entered nonpublic areas of Australia's Medicare Statistics Reporting Service. Australian officials said it accessed public and nonpublic files and wrote files to an internal server; no personal Medicare information was known to have been accessed. OpenAI notified the Australian government.
Editor's notes
(1) 05/25–26/2026: OpenAI-linked agents reportedly probed the University of New Mexico Digital Library for vulnerabilities after failed image retrieval; observed probes did not succeed. (2) 05/28/2026: agents reportedly sent 12 vulnerability probes to Data USA after retrieval errors; no successful exploitation was observed. (3) 06/18/2026: an OpenAI internal research agent reportedly bypassed repeated blocks at Australia's Medicare Statistics Reporting Service, accessing public and nonpublic files and writing files to an internal server. (4) 06/20–21/2026: related agents reportedly probed the Australian Institute of Health and Welfare; Transluce observed no successful exploitation. (5) 09/10/2026: OpenAI notified the Australian government. (6) 09/23–24/2026: Prime Minister Anthony Albanese publicly disclosed the breach and announced an investigation. AIID editor's note: This incident ID is bounded to the 06/18/2026 Medicare portal breach; the other episodes are retained as contextual evidence of the broader reported pattern and are not separately represented here.
Laws that address this harm
No recorded instrument yet addresses this use case where it happened. See the open queue.
Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).
News reports (4)
Titles link to the original publisher; report text is not reproduced here.
Who was involved
- Alleged deployer
- OpenAI AI agent system deployers
- Alleged developer
- OpenAI AI agent system developers
- Alleged harmed party
- Targets of autonomous AI-enabled intrusion operations Services Australia Medicare Statistics Reporting Service Information security Government of Australia Government agencies
AI systems implicated
Classification (MIT AI Risk Repository taxonomy)
- Risk domain
- —
- Risk subdomain
- —
- Causal entity
- —
- Intent
- —
- Timing
- —
- Harm level
- —
- Sectors
- —
- Countries
- —
Related incidents
Linked by editors or by text similarity in the source dataset.
- Bots Allegedly Made up Roughly Half of Twitter Accounts in Discussions Surrounding COVID-19 Related Issues
- Facebook’s Political Ad Detection Reportedly Showed High and Geographically Uneven Error Rates
- University of Illinois' Proctorio Remote-Proctoring Deployment Reportedly Raised Student Rights Concerns
Other incidents involving OpenAI
- AI Agent Appearing to Originate from OpenAI Reportedly Attempted to Hack U.S. Department of Education Civil Rights Website
- OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation
- OpenAI-Linked AI Agents Reportedly Used German Programming Wiki DSEWiki for Coordination and Restriction Evasion
- OpenAI Allegedly Did Not Alert RCMP After ChatGPT Flagged Violent Chats Before British Columbia School Shooting
- ChatGPT Was Reportedly Used in Planning School Stabbing in Pirkkala, Finland, That Injured Three Pupils
- ChatGPT Was Alleged to Have Reinforced Pittsburgh Man's Stalking and Threats Against Women
Source record: incident #1707 on the AI Incident Database · all 4 reports