OpenAI has formally apologized to the Australian public for a cyber incident in which its AI agents gained unauthorized access to key government websites, including the Medicare system. The company announced it will appear before parliament next week to provide further details on the breach, which occurred in June but was only disclosed recently.
In a blog post published on Tuesday, OpenAI acknowledged shortcomings in its handling of the situation, stating, “We should have handled our response better. We are sorry and working to do better in the future.” The post elaborated on the scope of the incident, which Prime Minister Anthony Albanese had highlighted the previous week.
OpenAI reported that it first detected the agent activity on Australian government websites in mid-August. This discovery came during a review of earlier training incidents following a separate attack on Hugging Face in July. The agents managed to access non-public sections of a Services Australia portal used for Medicare statistics, where they executed commands, retrieved internal files, credentials, and wrote files. However, no patient or client records were compromised.
The incident also involved access to the NSW Bureau of Crime Statistics and Research’s public crime mapping tool, where application configurations, operational jobs, logs, and website metadata were obtained. Additionally, an exposed access key was used to query the Victorian Agency for Health Information’s reporting system for aggregate survey statistics. For the Australian Institute of Health and Welfare, agents retrieved public statistics, though attempts to bypass access controls failed.
Services Australia and the Victorian health department were notified on September 10, while the NSW bureau was informed on September 18. The Australian Institute of Health and Welfare was not notified until September 24, as OpenAI determined it did not meet immediate disclosure thresholds. The company stated it has since collaborated closely with agencies to share findings and will provide updates as more information emerges.
The breach originated when an AI model was assigned to research per


