Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Breached! PM calls OpenAI hack of Medicare ‘unacceptable’; 3 other government systems potentially compromised

Prime Minister Anthony Albanese outlined in a UN speech how an AI agent hacked Australia’s public health insurance and told CEO Sam Altman of his disappointment over OpenAI’s tardy disclosure process.

Thu, 24 Sep 2026
Breached! PM calls OpenAI hack of Medicare “unacceptable”; three other government systems potentially compromised

The Australian Signals Directorate (ASD) is continuing to investigate a breach of Australia’s Medicare scheme after the country’s Prime Minister shared details of an OpenAI hacking incident.

One of the company’s AI agents hacked the public insurance scheme in June, Anthony Albanese said while attending the United Nations General Assembly in New York.

Perhaps almost as alarming as the incident itself is the fact that OpenAI not only took months to inform the government, but also did so via an email to a public mailbox.

 
 

“This situation is obviously unacceptable,” Albanese said.

“Today, I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident.

“And I also expressed my disappointment that it took the company way too long to inform the government what had occurred.

“It took until 10 September before there was any notification at all. And the notification was an email sent to just the public mailbox.”

The incident involved Medicare’s statistics reporting service portal, with the agent accessing information related to spending and other statistics. The data was considered non-sensitive, but Services Australia – which runs the portal – reported the activity to the ASD nonetheless.

Albanese said the ASD is investigating if any other government systems were affected.

Speaking to Radio National this morning, Deputy Prime Minister and Defence Minister Richard Marles said the government was looking closely at the legal situation around the incident.

“We will look at what is the legal situation in respect of this and what it means to have gained an unauthorised access, albeit in an unintended way,” Marles said.

He said that while the impact was “relatively minor”, the government is treating it very seriously.

“We’ve seen an AI agent, in an unintended way, access an Australian government website in a way which is unauthorised, and that is obviously deeply unacceptable.”

For its part, OpenAI said its review uncovered “no evidence of patient records being accessed”.

“The information accessed included aggregate health statistics and internal file names. Our overall review is ongoing, and we remain committed to transparency about these issues and to sharing what we learn as that work continues.”

Albanese added in an interview this morning that the government is investigating “whether there are any issues that need to be referred to the Australian Federal Police.”

He also said that three other government systems may have been accessed: the Australian Institute of Health and Welfare, the NSW Bureau of Crime Statistics, and Research and the Victorian Department of Health.

Independent senator David Pocock said in a statement this morning that the incident begs the question of who is accountable for incidents such as these.

“If it was an Australian who hacked the system, they’d likely be heading for jail, yet there’s no accountability for AI companies developing this technology,” Pocock said.

Justin Allen, head of security operations centre, APAC at cyber security firm Huntress, said the timing of the incident couldn’t be more apposite.

"We’re talking about global AI guardrails at the UN while an agent accessed a Medicare system and went undetected for three months,” Allen told Cyber Daily.

“Policy is the easy part. You can legislate disclosure timeframes all you like, but the government only found out because OpenAI chose to tell them.

“You can’t enforce a rule against something you can’t detect yourself. Regulation has to be funded alongside real detection capability, and that means machine-speed decisions supported by human expertise."

Jeremy Pell, country manager – ANZ at secure search company Elastic, said the incident is “a reminder of how quickly the threat environment has shifted.”

“AI has handed attackers the ability to automate exploitation at a pace that traditional security tools were not built to match,” Pell said.

“The question every organisation and government agency should be asking is not just whether AI is deployed, but whether the architecture beneath it is built to make it work when it matters.”

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: