Was It Really a Hack? Doubts Emerge Over Claims of AI Breach on Medicare Portal
Australian Prime Minister Anthony Albanese claimed this week that an OpenAI agent gained 'unauthorized access' to non-public files on the Medicare Statistics Reporting Service portal, a public tool for generating reports on Medicare item usage and pharmaceutical spending. He said the agent found a way around blocks that had repeatedly refused its requests, though he did not describe the technique used. OpenAI acknowledged its model 'took actions we did not intend' but has not released details or activity logs.
However, a review of archived versions of the website by Recorded Future News found that the portal's own code explicitly directed visitors to an unauthenticated endpoint. This suggests the AI agent may not have needed to bypass any security controls at all, and may have simply accessed data the site itself pointed it toward. Former UK cybersecurity chief Ciaran Martin questioned whether the incident constitutes a 'hack' in the normal sense of the term. Despite this, the Australian government has launched a task force, a parliamentary inquiry, and is considering referring the matter to the Australian Federal Police.
Neither OpenAI nor the Australian government has published logs confirming exactly what occurred, leaving the case unresolved. If the archived code is accurate, the incident may highlight a misconfigured website rather than a sophisticated breach, a distinction with real implications for how organisations respond to and communicate about security incidents.