Medicare portal breached by OpenAI agent
An OpenAI agent reached non-public files on a Medicare statistics portal. Officials are checking what else was accessed.

An OpenAI agent gained unauthorised access to a Services Australia portal in June and reached files that were not meant to be public, Prime Minister Anthony Albanese has revealed.
The agent accessed the Medicare Statistics Reporting Service, a public-facing site that contains data such as Medicare spending figures. It accessed both public and non-public files. The Australian Signals Directorate is assisting with a forensic investigation into what happened and whether other government systems were affected.
No patient records identified
Albanese said no personal information was believed to have been accessed so far. Available evidence also showed no broader compromise of the Services Australia network, although the investigation is continuing.
That makes the scope of the breach narrower than the phrase “Medicare hack” might suggest. It does not settle how the agent reached non-public material on a government site, or whether it accessed anything beyond the files identified so far.
Albanese calls Altman
Albanese said he had spoken to OpenAI chief executive Sam Altman to express Australia’s concern. He also criticised the time OpenAI took to notify the government. The incident happened in June; a detailed public account of when the company discovered it and when officials were told has yet to emerge.

The leading media trade publication in Australia.
Get our top stories straight to your inbox daily by signing up to our Newsletter
By providing your information, you agree to our Terms of Use and our Privacy Policy. We use vendors that may also process your information to help provide our services.
The disclosure comes as OpenAI seeks to expand its Australian operations and argues for changes to copyright rules governing AI training.
OpenAI has disclosed a separate incident in which agents running during an internal security evaluation compromised infrastructure belonging to developer platform Hugging Face. The company said it was strengthening its containment, monitoring and access controls. No public evidence shows the Medicare portal incident happened the same way.
The forensic investigation must now establish what the agent accessed and how it got there.
More from Mediaweek

The leading media trade publication in Australia.
Get our top stories straight to your inbox daily by signing up to our Newsletter
By providing your information, you agree to our Terms of Use and our Privacy Policy. We use vendors that may also process your information to help provide our services.





