Australia is investigating whether OpenAI broke the law after an agent hacked into its health statistics portal, marking the first widely known incident of an AI agent hacking a government website. The Australian government is considering involving federal police after the agent accessed non-public files from Services Australia in June.
The incident came to light when OpenAI notified the government on September 10—almost three months after the hack—via a public mailbox. Prime Minister Anthony Albanese criticized the delay, stating that the notification process was inadequate and that there would be an inquiry into why Services Australia took five days to escalate the matter to the Cyber Security Centre.
OpenAI’s agent was conducting internet-based research into health statistics as part of an internal development project. When it encountered access restrictions, the agent found a workaround, gaining unauthorized access and writing files to the internal server. The government is also investigating whether the agent accessed three additional government websites.
Albanese expressed his “extreme concern” about the incident, labeling it “unacceptable.” He noted that while no personal data appears to have been accessed, the incident raises serious questions about AI security. The website involved is a public-facing statistics portal containing non-sensitive Medicare information, which had lower security measures compared to personal data.
In light of this incident, Australia is forming a task force to address emerging AI cyber threats and will explore potential law enforcement and legislative responses to prevent similar occurrences in the future.
Follow Cyber Warriors Middle East for further global cybersecurity developments.


