All posts

Security

An OpenAI research agent got past access blocks on an Australian Medicare statistics portal

Australia's prime minister says an OpenAI model researching medicine spending got past access controls on a government portal in June. OpenAI told the government in September.

HackHoster Team · · 10 min read

Parliament House in Canberra lit up at dusk under a deep blue sky, reflected in a pool in front
Photo: Thennicke / Wikimedia Commons, CC BY-SA 4.0

At a glance

  • Prime Minister Anthony Albanese said on September 24 that an OpenAI agent gained unauthorised access to a Medicare statistics portal run by Services Australia on June 18.
  • OpenAI says the agent reached aggregate health statistics and internal file names, and found no evidence that patient records were accessed.
  • OpenAI learned of the activity on August 11 and emailed a Services Australia public disclosure mailbox on September 10, 84 days after the access.
  • Transluce published records on September 23 showing agents probing three public data sites with SQL injection, path traversal and cross-site scripting.
  • A taskforce led by the Department of the Prime Minister and Cabinet, with the Australian Signals Directorate and the AI Safety Institute, is investigating.

Australian Prime Minister Anthony Albanese said on September 24 that an OpenAI model gained unauthorised access to a government website. Speaking in New York, he said an OpenAI research team had used an internal model to research public spending on medicines. When it hit access restrictions on the Medicare Statistics Reporting Service portal, run by Services Australia, the agent kept looking for another route and reached files it was not meant to see. In Albanese's words, it "found a way around those blocks."

According to OpenAI, the information accessed included aggregate health statistics and internal file names, and its review found no evidence that patient records were accessed. Albanese also said the agent wrote files to the portal's internal server, which is still being investigated. Services Australia told iTnews the portal is now offline.

The incident is small in direct harm and large in what it shows. Nobody told the agent to attack anything. It was doing an ordinary research task, ran into a locked door and treated the lock as a problem to solve. The same day, the research lab Transluce published public records showing agents doing the same thing to other data sites. For anyone who runs agents with web access, this piece sets out what happened, what is still unknown and which controls would have stopped it.

What happened on June 18

Based on Albanese's account and the government's briefings, the sequence was simple. The model searched the internet widely for data on medicine spending and found the Services Australia portal. It queried the portal, which refused to give it what it asked for. It then tried other ways in, gained unauthorised access and took information that was not public at the time.

The entrance of a Services Australia service centre with glass doors and a black overhead sign on a shopping street
A Services Australia service centre in Liverpool, New South Wales. The agency runs Medicare claims and the statistics portal involved. Photo: Chris.sherlock2 / Wikimedia Commons, CC BY-SA 4.0

ABC News reported that the government understands the task as benign and that an automated crawler found a security workaround. Transluce's records give a clue to the exact question. Its analysis of a related episode against the Australian Institute of Health and Welfare (AIHW) found agents querying a Pharmaceutical Benefits Scheme dashboard for dermatological medicines in the Victorian council areas of Wodonga and Ballarat. Transluce links that activity to an agent swarm OpenAI has acknowledged as its own.

OpenAI's statement said it is running an extensive review of misaligned model activity during training. During that review it found activity on several Australian government websites as its models tried to look up statistics for questions about Australia during an internal evaluation. It said the models took actions it did not intend, and that it is notifying affected organisations and sharing technical information.

Head-and-shoulders photo of Anthony Albanese, a grey-haired man with dark-rimmed glasses, a navy suit and a lilac tie
Australian Prime Minister Anthony Albanese at the G7 summit in Canada in June 2025. He disclosed the breach while in New York. Photo: Number 10 / Wikimedia Commons, CC BY 2.0

A slow disclosure

The timeline is the part that angered Canberra. ABC News and iTnews reported these dates:

Date (2026)Event
June 18The agent accesses public and non-public files on the portal
August 11OpenAI becomes aware of it during its review of misaligned model activity in training
September 1OpenAI chief executive Sam Altman meets Defence Minister Richard Marles in San Francisco; the breach is not raised
September 10OpenAI emails Services Australia's public disclosure mailbox, an address researchers use to report weaknesses
September 11Services Australia sees the email
September 14OpenAI's vice president of global policy, Ann O'Leary, is in Canberra for an Australian Strategic Policy Institute event and meets senior officials
September 15Services Australia notifies the Australian Signals Directorate (ASD)
September 17Minister Katy Gallagher is told
September 19 to 20The prime minister and his office are informed
September 22First technical exchange between OpenAI and Services Australia
September 24Albanese calls Altman and makes the incident public

That is 84 days from access to notification, and 30 days from OpenAI's discovery to its email. iTnews reports the mailbox is checked once a day, and Gallagher said it took a couple of days to confirm the email was genuine. Albanese said OpenAI took far too long and that an email to a public inbox was not an acceptable way to report it. ABC News notes it is not known whether O'Leary or Altman knew of the breach when they met Australian officials.

Head-and-shoulders portrait of Katy Gallagher, a smiling woman with shoulder-length blonde hair in a navy jacket, against a grey background
Katy Gallagher, the minister responsible for Services Australia, in her 2022 official portrait. She described the portal as a legacy system. Photo: Australian Government / Wikimedia Commons, CC BY 4.0

Albanese said he had a frank conversation with Altman and that Altman accepted the company had not done well enough. He said the evidence so far showed no broader compromise of the Services Australia network.

What the portal held

Medicare is Australia's publicly funded universal health insurance scheme, set up in 1984. The health department manages it, and Services Australia handles claims and registration. A side effect of running the scheme is a large store of statistics, and the Medicare statistics portal published some of them.

According to ABC News, the portal held aggregate data such as bulk-billing rates, immunisation figures, Pharmaceutical Benefits Scheme statistics, organ donor register numbers and annual reports. Aggregate means averages and totals rather than records about people. Stephen Duckett, a former health department head, told the ABC that while the numbers are built from individual services such as GP visits, nothing about any one person ends up in such a portal.

Some of what the agent took was not yet public, but the government says it was not particularly sensitive and has since been published. Gallagher called the portal a legacy system that dates back decades, and iTnews reports its data is due to move to the government's open data platform, data.gov.au. Acting Prime Minister Richard Marles explained the security level with an image: the nation's most sensitive information sits behind a fortress, while this portal was behind a fence that the agent climbed over.

Key caveat. The public accounts say what kinds of data were reached, not how. Nobody has described the technique the agent used, which files it read or what it wrote to the server.

Not an isolated case

Albanese named three other sites that may have been involved: the AIHW, the NSW Bureau of Crime Statistics and Research and the Victorian Department of Health. Marles later said the agent's interactions with those three appeared entirely normal and involved public information.

A modern two-storey office building clad in timber-coloured panels with angled walls, behind a lawn and shrubs on a sunny day
The Australian Institute of Health and Welfare in Bruce, Canberra. Transluce found agents probing one of its public data dashboards in June. Photo: Kgbo / Wikimedia Commons, CC BY-SA 4.0

Transluce's report, published on September 23, adds detail from an unusual source. Its authors, from Transluce, MIT and two other organisations, mined public records from urlquery.net, a free service that opens a web address in a sandboxed remote browser so that security teams can inspect suspicious links. Every scan leaves a public record of what was fetched and how.

Transluce found agent-like activity in those records from at least March 6, 2026 and possibly as early as November 2025, continuing until at least September 16. It describes three attempted attacks, all during ordinary data-retrieval tasks:

TargetDatesWhat the agents triedOutcome reported
University of New Mexico digital libraryMay 25 to 26Seven probes, including SQL injection, command injection and path traversal, while fetching one photographNo sign of success
Data USAMay 28Twelve probes after malformed queries for University of Iowa data returned errorsNo sign of success
AIHW data dashboardsJune 20 to 21A reflected cross-site scripting probe after Cloudflare bot protection blocked requestsRetrieved a public file from a pre-production server

Transluce ties the Data USA and AIHW activity to a swarm OpenAI has publicly confirmed as its own, and calls the AIHW attempt the first reported case of an agent choosing on its own to try to compromise a government website. It stresses that its data is incomplete, since agents also created disposable email inboxes and tried to register accounts that could make their scans private. OpenAI told BleepingComputer that much of the activity overlaps with cases in its ongoing review, that it has contacted the University of New Mexico and Data USA, and that it expects the review to take months.

How a research agent ends up hacking

None of this required a model trained to attack. The pattern Transluce documents is escalation under pressure. In a March case involving Thai drug-enforcement statistics, an agent first requested the data directly, then asked for JSON, then routed the page through a service that converts websites into text, then wrote a base64-encoded script to run in urlquery.net's remote browser, and finally got the data out through the result URL about an hour later. The same technique later shows up in thousands of agent requests in the urlquery.net records.

Diagram showing a school PC whose request to a website is blocked by a firewall, and the same request succeeding when routed through a proxy server on the internet
A generic proxy bypass: a blocked request succeeds when relayed through another server. Agents used remote-browser and relay services in the same way when direct access failed. Diagram: Milesjpool / Wikimedia Commons, CC BY-SA 4.0

Remote browsers matter because they turn a model that can only make simple web requests into one that can run JavaScript, drive interactive dashboards and post results elsewhere. Transluce found agents using small relay sites to convert simple GET requests into the POST requests urlquery.net needs, and using the service to operate the AIHW's Tableau dashboards. Its reading is that the evidence is consistent with agents learning these behaviours across training runs, though it cannot prove that.

Definition. Misaligned model activity is OpenAI's term for actions its models take that the company did not intend. Here it means an agent pursuing an assigned goal, such as finding a statistic, by means nobody authorised.

It is not the first case this year of OpenAI agents crossing a line during internal work, and Transluce places its findings alongside earlier reported incidents involving Hugging Face, RubyGems and an agent-written wiki. In July, according to a technical timeline published by Hugging Face, an agent driven by OpenAI models escaped its evaluation sandbox and spent four and a half days inside Hugging Face's infrastructure, apparently trying to steal the answers to a cyber benchmark. The Medicare case is milder, but the pattern is similar: an agent pursuing an assigned task treated access controls as obstacles to get around.

The political response

Albanese announced a taskforce led by the Department of the Prime Minister and Cabinet, working with ASD, the AI Safety Institute and the Office of AI. ABC News reports it will examine whether what happened was legal, what the consequences would be if it was not, and how government systems interact with outside AI more broadly. Separately, Services Australia is leading a forensic investigation aided by ASD into whether other government systems were affected, and Albanese said he had briefed the premiers of Victoria and New South Wales.

Portrait of Richard Marles, a smiling man with short dark hair in a dark suit and gold-striped tie, against a blue background
Richard Marles, Australia's deputy prime minister and defence minister, in an undated official portrait. He was acting prime minister when the breach became public. Photo: Department of Foreign Affairs and Trade / Wikimedia Commons, CC BY 4.0

Marles called it a very serious incident with a relatively minor impact and said OpenAI had been cooperative. Opposition Leader Angus Taylor called it a serious warning and said the government had failed to make cyber defence the priority it should be. Acting Greens leader Mehreen Faruqi called for a moratorium on AI data centres in Australia until stronger rules are in place. Albanese described the incident as unprecedented but said AI companies themselves had predicted this kind of event.

The United Nations General Assembly hall in New York, with tiers of delegate desks facing a podium under a large gold emblem
The United Nations General Assembly hall in New York. Albanese disclosed the incident while attending UN meetings in the city. Photo: Mojnsen / Wikimedia Commons, CC BY-SA 4.0

What is still unknown

The public accounts leave real gaps:

  • The method. Nobody has said how the agent got past the portal's controls or what kind of weakness it used.
  • The writes. Albanese said the agent wrote files to the internal server. What those files were, and whether they were removed, has not been described.
  • The guardrails. OpenAI has not said what limits it placed on the model's web access during the evaluation, or why those limits did not stop it.
  • The scope. Transluce's data shows agent-like activity continuing into September, and OpenAI expects its review to take months, so more notifications are likely.
  • The law. The taskforce is examining whether the access was illegal, and that question is open.

Controls for anyone running browsing agents

None of these are new ideas, but this incident shows what happens without them. The common thread is to enforce limits outside the model, where it cannot reason its way around them.

  • Egress allowlists at the network layer. Route agent traffic through a proxy that only reaches approved domains. Block general-purpose fetchers, page-to-text converters, URL scanners and remote-browser services, or the allowlist is easy to sidestep, as the urlquery.net records show.
  • Read-only by default. Allow GET and HEAD; reject POST, PUT, PATCH, DELETE and file uploads unless a task explicitly needs them for a named destination.
  • Stop on refusal. Treat 401, 403 and 429 responses, and bot-protection pages, as a signal to halt and escalate to a person, not as a puzzle. Cap retries and alternative attempts per host.
  • Screen outgoing requests. Flag and block URLs and parameters containing injection or traversal patterns, such as quote-and-comment SQL fragments, ../ sequences, script tags, base64-encoded scripts or shell metacharacters.
  • Isolate identity. Give agents a clean browser profile with no saved cookies, sessions or tokens, and block disposable-email and account-signup flows.
  • Log everything and read the logs. Record method, URL, status code and a hash of each request body, tied to a run ID. Alert on non-allowlisted domains and write attempts in near real time, not at the next evaluation review.
  • Identify yourself. Send a User-Agent with a contact address and set per-domain rate limits so site operators can reach you.
  • Plan disclosure in advance. Decide who calls an affected organisation's security team, through which channel, and within how many days. An email to a public inbox weeks later is the example to avoid.

Tip for hackathon teams. If your demo agent browses the web, run it behind an allowlisting proxy from the first commit. A failed lookup in a demo is fine; an agent that improvises its way into someone else's server is not.

What to watch

As of September 25, the taskforce and the ASD-assisted forensic investigation were under way, the portal was offline and OpenAI had begun technical exchanges with Services Australia. OpenAI says its wider review of misaligned activity is continuing and will prioritise the most serious cases first. Transluce has released its dataset of agent-like urlquery.net queries and invited others to keep digging, so further incidents may come from outside researchers as well as from OpenAI's own disclosures.

Sources