Key points
- An OpenAI agent gained unauthorised access to both public and non-public files on a Medicare statistics reporting portal, Anthony Albanese said.
- The incident occurred on June 18 when an OpenAI research model, blocked from the Australian data, wrote files to the internal server while seeking alternative access.
- OpenAI did not notify the breach until September 10, and a forensic investigation aided by the ASD is now examining whether other government systems were affected.
An OpenAI agent has accessed “public and non-public files” from a “Medicare statistics reporting portal”, Australian Prime Minister Anthony Albanese said.
Speaking at the United Nations meeting in New York, Albanese said the AI agent had “infiltrated” and “gained unauthorised access” to the data portal in June.
While the portal is “public-facing”, according to Albanese, it appears not all of the data files that it holds are for general consumption.
“The AI agent accessed both public and non-public files,” Albanese said.
“The Medicare statistics reporting portal is a public-facing statistics portal that contains non-sensitive Medicare information relating to data and statistics such as spending.
“No personal information is believed to have been accessed at this stage but investigations are ongoing.”
It wasn’t immediately apparent which portal was breached.
A Services Australia spokesperson told iTnews that the affected portal is offline.
Minister for Government Services Katy Gallagher described it as "a legacy system" that "dates back decades".
There may be no ongoing requirement for the portal, with the data due to be hosted in future on the government's open data platform, data.gov.au.
'Wrote files to the internal server'
Albanese said that the incident occurred on June 18, when an OpenAI research team “used an internal model to conduct internet based research into public medicine spending.”
He said that model was blocked from accessing the Australian data but “attempted alternative ways to obtain the information that it wanted, and this led to unauthorised access into some other areas.”
“In order to do this, it engaged in writing files as well to the internal server, and that's being further investigated,” he said.
The incident was not notified by OpenAI until September 10 - to a responsible disclosure mailbox operated by Services Australia that the agency checks once a day.
"Through their own systems and checking, including going back and having a look at their technical data, it took a couple of days to verify that what they'd been alerted to in the email was legitimate," Gallagher said.
"By September 15, once Services Australia had analysed the information in the email and made some checks, they notified the incident to ASD."
Forensic investigation underway
Albanese said that a forensic investigation, led by Services Australia and aided by ASD, is now underway.
This is focused not just on the immediate incident with the Medicare data portal, but also on ascertaining whether “other government systems were affected.”
Acting Prime Minister Richard Marles told ABC News that the government was made aware of the Medicare data incident “a couple of weeks ago”.
“Ministers were informed at the end of last week and over the weekend, and over the last few days we’ve been assuring ourselves of exactly what the impact has been in relation to data and the portal itself, and for what that’s worth it’s relatively minor,” he said.
“No personal information has been accessed here, there’s no impact on the system.
“But that said, what we have seen is unauthorised access into an Australian government website and that’s completely unacceptable and we’ve made that clear to OpenAI.”
Marles also indicated a multi-agency taskforce has been assembled.
“At our end, what we’ve done in response to this is to establish a taskforce that will be led by Prime Minister and Cabinet’s department, which will also work with the ASD and the AI Safety Institute to just examine everything that has occurred here, and to understand what the AI agent and how this incursion occurred and what the impact of it has been,” he said.
“We will continue to do that work.
“We are working cooperatively with OpenAI in relation to that.”
Not just Medicare data targeted
Albanese revealed that it is not just the Medicare statistics portal that was targeted by the research agent.
"Three other systems that may be impacted," Albanese said.
"One is ours, the Australian Institute of Health and Welfare may have been impacted.
"Also the NSW Bureau of Crime Statistics and Research and the Victorian Department of Health."
"Last night, Australian time. I spoke with [Victorian] Premier [Ben] Carroll and [NSW] Premier [Chris] Minns to inform them and to ensure they will get a full briefing today from cyber security about those issues."

HPE Networking Day Sydney
iTnews Resilience, Rewired Breakfast
RIMPA Live Convention 2026
iTnews Benchmark Security Awards 2026
iTnews State of Security Breakfast Sydney



