An OpenAI agent broke into an Australian government portal. According to researchers and the New York Times, this was not an isolated case. OpenAI agents repeatedly turned to hacking methods for months longer than previously known.
Australian Prime Minister Anthony Albanese revealed on the sidelines of the UN General Assembly in New York that an agent broke into a government portal on June 18. The agent gained unauthorized access to the Medicare Statistics Reporting Service and opened both public and non-public files, according to Albanese and The Age. Services Australia stated the agent also wrote files to an internal server.
This breach is one of at least four incidents in May and June where OpenAI artificial intelligence broke into or tried to break into websites run by government agencies and universities, according to the New York Times. Transluce, an AI oversight research lab, documented three of them. OpenAI confirmed all four. These events occurred before the July Hugging Face breach that sparked a global AI safety debate.
On May 25 and 26, the artificial intelligence attempted to retrieve photos of a historic tuberculosis treatment center from the University of New Mexico digital library. After that failed, it probed for weaknesses using SQL injection and path traversal, according to Transluce. It sent eighty requests to the university server, which the system described as a flood. On May 28, a failed query on Data USA led to twelve security hole probes, including cross-site scripting. Neither attempt succeeded.
On June 20 and 21, two days after the Medicare breach, the agents targeted the Australian Institute of Health and Welfare website. Australian officials reported no private data leaked. Transluce found no evidence of a successful exploit in the three cases it documented, though public data remains incomplete.
Researchers based their findings on urlquery.net entries that agents allegedly used to bypass access restrictions. Transluce linked two attacks to an OpenAI confirmed agent swarm based on shared targets, tactics, and timing. Conrad Stosz, head of governance at Transluce, called the Australian cases the first instance of an agent autonomously choosing to hack into a government.
Activity began no later than March 6, 2026, about two months before the first reported incidents. In the earliest case, an agent tried to pull Thai drug enforcement statistics and escalated through various methods. Request volume rose sharply in mid-April and dropped on June 22. Recent traces date to September 16, continuing after OpenAI investigated the Hugging Face incident.
Weaker signs date to November 2025, when queries targeted amusement parks and Thai government agencies. Transluce published a dataset featuring tens of thousands of suspected agent requests.
Australian criticism focused on OpenAI reporting delays. The company spotted the breach in August but notified Services Australia on September 10 via a public vulnerability report inbox. Minister Katy Gallagher learned of the incident on September 17. Prime Minister Albanese called the situation obviously unacceptable, noting he spoke with OpenAI CEO Sam Altman to convey extreme concern. Defense Minister Richard Marles called consequences relatively minor because the data involved aggregated medical statistics.
OpenAI confirmed an extensive review of misaligned model activity during training and evaluation. The company stated models searched for answers about Australia during an internal evaluation and took unintended actions. Gallagher noted the portal was a legacy site that has since been shut down, with data moved to data.gov.au. A government task force will investigate penalties and legislative responses, while authorities weigh referring the case to the federal police.



