OpenAI Medicare hack

OpenAI Agent’s Medicare Hack Exposes Growing Threat to Government Systems

September 24, 2026James Hughes

5 min read

Prefer TechResearch on Google

In Focus 

  • An OpenAI agent hacked Medicare systems in June

  • The AI firm notified the Australian Government about the incident on September 10

  • The rogue agent also accessed three other government systems 

An OpenAI agent hacked into Medicare, Australia’s universal healthcare system, during training in June. The AI agent accessed public and non-public files in Medicare’s statistics reporting service portal. Australia’s Prime Minister Anthony Albanese admonished OpenAI for what he called an “obviously unacceptable” breach. 

OpenAI’s rogue agent also accessed the Australian Institute of Health and Welfare, the Victorian Department of Health, and the New South Wales Bureau of Crime Statistics and Research.

How Did OpenAI Notify the Government About the Breach?

According to Albanese, OpenAI did not notify the Australian government about the AI hacking incident until September 10, about three months after the incident. The AI firm sent a message to a generic email address, which is monitored once a day.

Services Australia notified the Australian Signals Directorate about the incident on September 15. The minister in charge of government services, Katy Gallagher, did not know that an OpenAI agent had hacked the Australian government website until September 17. Initial interaction between the Australian government and OpenAI took place on September 22. 

"Today, I spoke with the CEO of OpenAI, Sam Altman, to express Australia's extreme concern about this incident. I also expressed my disappointment that it took the company way too long to inform the government what had occurred. It took until September 10 before there was any notification at all, and the notification was an email sent to just the public mailbox,” the Prime Minister said on September 23, as reported by AFP. 

How Did the OpenAI Agent Hack Medicare Systems?

OpenAI’s AI agent hacked the government website when the company asked its models to search the internet for data about how much the Australian government spent on medicine during testing. 

The AI developer, whose agents hacked Hugging Face systems in July, claimed it did not detect the rogue activity until August, when it conducted an "extensive review" of its models. OpenAI CEO Sam Altman acknowledged the risk posed by AI systems this week when he addressed the UN Security Council. 

“There are many things that AI cannot and should not automate. As AI systems become more capable and more autonomous, they can move faster than our institutions or make decisions that people no longer understand or control,” Altman said.

News that an OpenAI agent hacked Medicare systems comes amid mounting concerns over the power of advanced models. Recently, the EU President Ursula von der Leyen said self-improving models pose apparent risks.

What Actions Will the Australian Government Take? 

Albanese, who is currently in the U.S., noted that there was no evidence the AI tool accessed personal information and that other services had not been compromised. The Prime Minister plans to establish a taskforce to immediately review the hacking incident. 

The taskforce will assess the reporting requirements for AI-related vulnerabilities and cyber-incidents and information-sharing responsibilities for government officials. It will also review obligations for AI firms to report future incidents, legal provisions, and mechanisms for enhancing protections against hacking. 

Newsletters

See More

Get tomorrow's biggest tech conversations in your inbox today

No newsletter selected

James Hughes - TechResearch

James Hughes

James Hughes is an IT Professional who specializes in computer networking and cyber security. He has vast experience in IT audit, compliance, and computer server and database management. James taps his wide knowledge of IT processes including security incident management and response, vulnerability assessment, disaster recovery, and data loss prevention to educate business through writing.