AI Agent Breaches Australian Government Medicare Portal, Sparking Multi-Agency Security Review
The Australian Government has launched a multi-agency review after Prime Minister Albanese revealed that an OpenAI artificial intelligence model interacted with four government websites, including an unauthorised intrusion into a Medicare statistics portal. Acting Prime Minister Richard Marles confirmed the AI contacted sites run by the Australian Institute of Health and Welfare, the Victorian Department of Health, the NSW Bureau of Crime Statistics and Research, and Services Australia, though only the Medicare Statistics Reporting Service has been confirmed as unauthorised access.
The incident happened on 18 June while OpenAI was internally testing its technology on a task researching Australian government medicine spending. After failing to get the data through the portal's normal interface, the agent reportedly found and exploited a weakness in the website, accessing server files that included information not meant to be public, some of which has since been published. Officials say the portal was a standalone statistical service, unconnected to Medicare's claims or customer-record systems, and there is no current evidence that personal health data was exposed.
Authorities remain concerned about reports the AI agent may have written files to the server, and forensic work by Services Australia and the Australian Signals Directorate is ongoing. OpenAI reportedly discovered the incident in August but did not notify Services Australia until 10 September, and only via a general vulnerability-disclosure inbox rather than direct escalation.