Tech
EN AZ
OpenAI ‘sorry and working to do better’ after hack of Medicare and other Australian government websites

OpenAI ‘sorry and working to do better’ after hack of Medicare and other Australian government websites

theguardian.com 29.09.2026 04:10 5 views
Artificial intelligence firm to front parliament as it apologises to Australians for agent attack l, free app or daily news podcastOpenAI has

OpenAI has apologised to Australians for its agent attack on Medicare, and will front parliament next week, as the tech company revealed more details about its June hack of Australian government websites. In a blog post released on Tuesday, OpenAI said it should have handled its response better. We are sorry and working to do better in the future.” The company also provided more detail on the incident revealed by the Australian prime minister, Anthony Albanese, last week.

OpenAI said it became aware of agent activity on Australian government websites in mid-August after the company reviewed earlier training incidents after the Hugging Face attack in July. The agents gained non-public access to a Services Australia portal for Medicare statistics, and OpenAI said the agent was able to run commands, retrieve internal files, credentials, and write files, but no patient or client records were accessed. The NSW Bureau of Crime Statistics and Research’s public crime mapping tool was also accessed, with application configuration, operational jobs and logs and website metadata provided to the agency.

The agent discovered an exposed access key to query the Victorian agency for health information’s reporting system to access aggregate survey statistics. For the Australian Institute of Health and Welfare, OpenAI agents retrieved aggregate statistics, but separate attempts to bypass access controls were unsuccessful and the information obtained was publicly available. Services Australia and the Victorian health department were informed on 10 September, while the NSW bureau of crime stastistics was informed on 18 September.

The Australian Institute of Health and Welfare was not informed until 24 September, as OpenAI deemed it did not meet disclosure thresholds. The model had difficulty obtaining that information, and OpenAI said “it took actions that we had not authorised it to take” including accessing Services Australia’s Medicare statistics reporting service. OpenAI said it would commit resources and expertise to affected agencies, and provide Australian government agencies with support to build cyberdefences on critical infrastructure.

Australian government agencies and industries will also be given credits out of OpenAI’s US$1bn (AU$1.4bn) Daybreak fund, which lets those organisations use frontier AI for cyberdefence, and to harden their systems by reviewing code and system configurations for potential vulnerabilities that can then be patched. The company said it would also establish a taskforce with Australian expertise to develop practical policy recommendations on managing risk with AI agents. OpenAI’s chief strategy officer, Jason Kwon, will appear at the Joint Select Committee on AI on Tuesday next week.

Guardian Australia reported on Monday that Anthropic would also appear at this hearing, but not at a Senate inquiry into AI and datacentres this week. Albanese who was in the United States last week when he announced the hack, said at the time he had spoken with OpenAI’s chief executive, Sam Altman, “to express Australia’s extreme concern about this incident”. On Tuesday, Albanese said OpenAI had been “very constructive and open in engaging” since the incident, as had Anthropic.

Extract — continue reading at the source.

Read full story