News thumbnail
World / Fri, 25 Sep 2026 The Times of India

OpenAI's AI agents hacked Australian government health website; alert email sent a month later to Public mailbox; upset Australian PM says: I spoke with Sam Altman to tell ...

In pic: Sam Altman“Today, I spoke with the CEO of OpenAI,Sam Altman, to express Australia's extreme concern about this incident. The incident happened in June, when an OpenAI model being evaluated for training was asked to research Australian government spending on medicines. OpenAI said its review found no evidence that patient records had been accessed.OpenAI did not identify the activity immediately. The notification was sent to a public Services Australia mailbox that is used for reports from academics and researchers.Gallagher said the mailbox is checked once a day and can receive multiple notifications, including hoaxes. He said the breach was serious but that no personal information had been accessed.The incident comes as concerns grow over AI models interacting with real-world computer systems.

Representative Image. In pic: Sam Altman

“Today, I spoke with the CEO of OpenAI,

Sam Altman

, to express Australia's extreme concern about this incident. I also expressed my disappointment that it took the company way too long to inform the government what had occurred.”

What happened during the OpenAI AI test

“didn't accept no for an answer”

OpenAI found the breach in August

“During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers and available statistics for questions about Australia during an internal evaluation,”

“In the course of that, our models took actions we did not intend,”

Australian government was notified through public mailbox

Australia launches investigation

ChatGPT maker OpenAI 's AI agents hacked Australian government health website. The incident happened in June, when an OpenAI model being evaluated for training was asked to research Australian government spending on medicines. According to Australian Prime Minister Anthony Albanese, the AI agent initially encountered restrictions on an Australian Medicare statistics portal but found a way around them and accessed public and non-public files.The Australian government says there is no evidence that any personal Medicare data was accessed. There has also been no breach of government systems. However, this issue has raised questions about how easily AI systems can bypass security measures. It has also raised questions about how long it takes for OpenAI to contact the authorities.According to a report by AFP, Albanese said,He added that the notification was also unacceptable because it was sent to a public mailbox rather than directly to the relevant government officials.The incident took place on June 18 while OpenAI was conducting internal evaluations of its AI models. Government Services Minister Katy Gallagher said the model had been asked to search for information about Australian government spending on medicines.The AI agent interacted with several government websites. On the Medicare statistics portal, it encountered restrictions but continued attempting to obtain information. Albanese described the model as havingand finding a way around the blocks.The accessed material included non-public aggregate health statistics and internal file names. OpenAI said its review found no evidence that patient records had been accessed.OpenAI did not identify the activity immediately. According to the Australian government, the company discovered the incident on August 11 while reviewing potentially misaligned model activity during training.OpenAI said it was conducting an extensive review of its models when it identified activity involving several Australian government websites and services. The company said its models were attempting to find answers and statistics about Australia during an internal evaluation.OpenAI said.the company added.Although OpenAI identified the incident in August, Australian authorities were not notified until September 10, almost a month later. The notification was sent to a public Services Australia mailbox that is used for reports from academics and researchers.Gallagher said the mailbox is checked once a day and can receive multiple notifications, including hoaxes. Services Australia reviewed the message before reporting the incident to Australia's cyber security agency on September 15.The timeline has become a major concern for the government. Albanese said the delay in reporting the incident was unacceptable, while OpenAI has said it is providing technical information to assist the investigation.Australia has launched a rapid review of the incident involving the prime minister's department, the Australian Signals Directorate and the country's AI Safety Institute. The review will examine what happened and whether existing rules adequately cover incidents involving autonomous AI systems.Deputy Prime Minister Richard Marles compared the incident to an AI system “scaling the fence” after being denied access. He said the breach was serious but that no personal information had been accessed.The incident comes as concerns grow over AI models interacting with real-world computer systems. OpenAI and Anthropic have both reported instances in which models gained unauthorised access during testing, while Google has also disclosed security-related activity involving its AI systems.OpenAI CEO Sam Altman was in New York for discussions on AI risks at the United Nations when the Australian government made the incident public. Albanese said he had spoken directly with Altman about Australia's concerns and the delay in notification.

© All Rights Reserved.