The AI giant has confirmed an additional breach involving NSW National Parks and Wildlife, revealing that a model researching Australian fire statistics was able to access and model database metadata that “was not intended to be publicly exposed”.
OpenAI said there was no evidence the activity involved personal information and that it notified the Australian government within 48 hours of identifying the incident.
The admission comes just days after the company disclosed a series of other incidents involving Australian government systems, including Services Australia, the NSW Bureau of Crime Statistics and Research (BOCSAR), the Victorian Department of Health, and the Australian Institute of Health and Welfare (AIHW).
The incidents have raised fresh questions about the ability of AI agents to independently discover and exploit unintended access pathways, and whether existing safeguards are sufficient to prevent them from moving beyond publicly available information.
At Services Australia, an OpenAI model discovered a way to gain non-public access, where it ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files. No individual patient or client records were accessed.
At BOCSAR, an OpenAI model researching public crime statistics made API and website metadata requests through the agency’s public Crime Mapping Tool. The system returned application configuration, operational jobs and logs, as well as website metadata. Individual crime records were not accessed.
OpenAI agents also discovered an exposed access key allowing access to reporting configuration and aggregate survey statistics held by the Victorian Agency for Health Information. OpenAI said individual medical records and identifiable survey responses were not accessed.
At AIHW, agents retrieved aggregate statistics through third-party browsing and download services and queried chart data directly. Attempts to bypass access controls were unsuccessful, and OpenAI said the downloaded material appeared to have been publicly available. No system compromise or access to individual medical records occurred.
The latest disclosure comes just days after Prime Minister Albanese lashed OpenAI, criticising the company after revealing an AI agent had accessed the Medicare statistics reporting portal in June. He said OpenAI took until 10 September to notify the government, and did so through a generic public mailbox.
“This situation is obviously unacceptable,” Albanese said. “Today, I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident.”
“And I also expressed my disappointment that it took the company way too long to inform the government what had occurred.
“It took until 10 September before there was any notification at all. And the notification was an email sent to just the public mailbox.”
OpenAI has since acknowledged the seriousness of the incidents, saying: “We will do better.”
The Australian Signals Directorate continues to investigate the Medicare incident, while the government is also examining the legal implications of unauthorised AI-driven access to government systems.
OpenAI is currently subject to a parliamentary inquiry.
As AI continues to evolve, Adam Marrè, CISO at Arctic Wolf, warned that businesses need to continuously evolve to stay ahead of the changing threat landscape.
“As AI agents become more capable and autonomous, organisations will also need to assume that developer safeguards will not eliminate every risk. Robust cyber security controls, continuous monitoring and rapid response will be essential to identifying and containing unauthorised machine-driven activity before it escalates,” he said.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.