An OpenAI agent hacked into an Australian national healthcare database in the first known case of AI hacking a government network, according to Australian prime minister Anthony Albanese.
“Evidence currently available is there is no broader compromise to the Services Australia network,” Albanese said in a statement on Sept. 24. “Nonetheless, this situation is obviously unacceptable.”
Services Australia is a government agency for social and health payments.
The rogue agent acquired health data from the Medicare Statistics Reporting Service, part of the Services Australia network, in June, which was before a swarm of OpenAI agents hacked AI start-up Hugging Face in July, the prime minister said.
He added that Australian authorities do not believe
the hack impacted individual’s health records.
OpenAI became aware of the activity in August during a review of misaligned model activity, according to the company. They notified Services Australia of the hack on Sept. 10. OpenAI told USA TODAY that, during that time, they were validating and investigating what information had been accessed.
“It took the company way too long to inform the Government what had occurred and the nature of the way that that notification occurred as well was unacceptable,” Albanese said. He and OpenAI CEO Sam Altman met on Sept. 24 to discuss the incident.
The breach comes amid increasing calls from policymakers and industry leaders, including Altman, to slow down advancement. President Donald Trump has brushed off the warnings and maintains a policy of no regulation.
OpenAI’s internal review found no evidence of patient records being accessed, OpenAI spokesperson Drew Pusateri wrote to USA TODAY. The hack occurred during an internal evaluation in which OpenAI models attempted to look up answers and available statistics for questions about Australia, he added.
“OpenAI is conducting an extensive review of misaligned model activity during training and evaluation and notifying third parties when our review identifies potential impacts to their systems,” Pusateri said.
In addition to breaching the Medicare Statistics Reporting Service, OpenAI agents attempted to access the Australian Institute of Health and Welfare, which is outside of the Services Australia network, according to an independent report by AI research lab Transluce released on Sept. 23. No private information was obtained, Australian officials said.
The report found three total instances of AI agents attempting to exploit security vulnerabilities and hack into websites between May and June. The websites also included Data USA and the University of New Mexico digital library.
“Notably, the agents did this while attempting mundane data retrieval tasks which were not cyber-related,” the report said.
OpenAI’s internal review of the Services Australia hack remains ongoing, according to the company, and a forensic investigation is being conducted by the Australian Signals Directorate.
Greta Reich covers the artificial intelligence industry for USA TODAY through a fellowship from the Tarbell Center for AI Journalism. Funders do not provide editorial input.
This article originally appeared on USA TODAY: OpenAI agent hacks Australian healthcare database












