sözaltı news World
World
EN AZ
OpenAI’s Medicare attack has exposed Australia’s ‘tech debt’. Fixing it could bring a big bill for taxpayers

OpenAI’s Medicare attack has exposed Australia’s ‘tech debt’. Fixing it could bring a big bill for taxpayers

theguardian.com 02.10.2026 17:00 4 views
Home affairs department orders all federal government agencies to conduct review of ‘legacy technology’ amid fallout from AI agent hacks

The Australian government faces significant “tech debt” that could bring a big bill for taxpayers after the OpenAI Medicare breach, as government agencies will need to fortify their defences against future attacks by AI agents. This week, the home affairs department ordered all federal government agencies to conduct a “legacy technology stocktake” that requires a plan for each agency to “reduce legacy technology systems” to a level within the agency’s risk tolerance and appetite, the direction stated. OpenAI this week revealed an internal agent had gained non-public access to the Services Australia Medicare statistics portal during a training task seeking information on government spending on skin conditions in Victoria.

The agent was able to run commands, retrieve internal files, credentials, and write files. While OpenAI has apologised to Australia for the incident, it has served as a wake up call for the federal government, with the government-wide review now under way. The finance minister, Katy Gallagher, asked her department whether some of the A$160m funding allocated to the agency in the last budget for cyber upgrades can be accelerated.

The statistics portal, Gallagher told reporters last month, is a “legacy system.” Services Australia will be far from alone in managing legacy systems. They can – but not all do – present a security risk for businesses and government as they age and vendors cease providing new security updates. Prof Salil Kanhere, a University of New South Wales cybersecurity and AI expert said the age of the system alone does not tell an agency whether it needs replacing.

Those older systems with vulnerabilities are often known to human attackers, but AI agents persistent in looking for holes in a system may be able to discover them quicker. Gartner, a technology analysis firm stated in a note to clients released after the Medicare hack that “technical debt, not a rogue AI agent attack” represented the greatest threat to legacy systems. The essential eight includes requirements to patch applications and operating systems, using multi-factor authentication, and other security measures.

Of those agencies being hindered by legacy tech, 34% blamed insufficient dedicated funding, while 18% said it was due to a lack of a viable replacement. Prof Yang Xiang, from Monash University’s department of software systems and cybersecurity, said the government stocktake was “very necessary” and there was urgency to needing to audit all government systems. Kanhere said high-risk systems should take priority.

A Victoria government cybersecurity audit of its IT servers found 25% of the operating systems used by servers were no longer supported by the vendor, with 48% in extended support. In a South Australian audit report of legacy ICT systems published in June, of the ten agencies reviewed, nearly half of the 11,602 hardware devices or appliances were determined to be legacy devices. Almost one quarter of the operating systems and applications were also determined to be legacy.

Extract — continue reading at the source.

Read full story