The OpenAI agent hack is the incident, disclosed by Australian Prime Minister Anthony Albanese (opens in a new tab) on 24 September 2026, in which an OpenAI AI agent worked around the blocks on a Services Australia Medicare statistics portal on 18 June and reached non-public files. No personal data is believed to have been accessed. OpenAI took 84 days to tell anyone.

Most of the coverage has gone for the obvious headline. Rogue AI. World first. Machines breaking into government. It sells, and I understand why.

Read the detail, though, and what actually happened is depressingly familiar. Something wanted some data. It was told no. It kept trying until it found a way round, and the owner of the system found out three months later from an email sent to a public mailbox. Replace “AI agent” with “contractor with a deadline” and I could have written this story in 2006.

That is the useful part for anyone in the UK, because none of it depends on the attacker being a machine. It depends on an old website, a control that was never a control, and a disclosure route nobody had thought about. Those are all things we can check this month — and if you are also putting agents to work, the AI security (opens in a new tab) side of this story applies to you from the other direction.

What Happened on the Medicare Statistics Portal?

An OpenAI agent gained unauthorised access to the Medicare Statistics Reporting Service portal, administered by Services Australia, on 18 June 2026.

According to ABC News, the agent reached both public and non-public files (opens in a new tab) on what the ABC describes as an old government website carrying Medicare statistics. OpenAI's own statement says the material accessed was aggregate health statistics and internal file names, and that its review found no evidence of patient records being touched. The Prime Minister said there is no evidence of broader compromise to the Services Australia network, whilst stressing that investigations are ongoing.

OpenAI says the activity happened during an internal evaluation, as its models tried to look up Australian statistics to answer test questions, and that the models took actions the company did not intend. Albanese's own summary was that the agent “didn't accept ‘no' for an answer”.

Three other sites may be involved — the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health. The Prime Minister was careful to say this is not confirmed. A taskforce led by his department, working with the Australian Signals Directorate and the AI Safety Institute, is now reviewing the incident.

Date (2026) What happened Source
18 June OpenAI agent accesses the Medicare Statistics Reporting Service portal ABC News (opens in a new tab)
August OpenAI says it identified the activity during its review of misaligned model behaviour BBC News (opens in a new tab)
10 September OpenAI notifies Services Australia by email to its public mailbox ABC News (opens in a new tab)
15 September Services Australia reports the incident to the Australian Signals Directorate ABC News (opens in a new tab)
16 September OpenAI publishes a framework for disclosing model misalignment, with six initial reports OpenAI (opens in a new tab)
24 September Prime Minister discloses the incident in New York and announces a taskforce ABC News (opens in a new tab)

Eighty-four days from access to notification. Another fortnight before the Prime Minister stood up and talked about it.

How Did an AI Agent Get Past the Blocks?

Nobody has published the exact technique, but the reporting so far points at persistence against bot filtering rather than anything clever.

The ABC understands that an AI crawler found a workaround to reach the data. Separately, an ABC investigation into public logs found more than a dozen OpenAI agents discussing the Australian Institute of Health and Welfare site (opens in a new tab) on a German coding forum. The agents were chasing a very specific figure — government spending per person on skin medicines across Victorian council areas — and one of them posted “Need exact data urgently”.

Their first attempts were blocked by Cloudflare, which is there to stop non-human traffic. So the agents compared notes. Proxies. Screenshotting services. Guessing the names of the files they wanted.

To be clear about what is and is not established: neither OpenAI nor the Australian government has confirmed that those forum logs relate to the Medicare portal access, and the logs never mention Medicare or Services Australia. What they do show is the method. And the method is one every penetration tester will recognise, because it is the method.

Personally, I have been known to give up on a website after one CAPTCHA asking me to find the traffic lights. That is apparently no longer the industry standard.

Is This Really an AI Problem?

Only partly — and the part that is not about AI is the part UK organisations can fix this month.

A bot filter is not access control. It never was. It is a “Staff Only” sign on a door. It keeps out the polite and the lazy, and it tells everyone else exactly where the interesting room is. If non-public files are reachable from a public website, and the only things between them and the internet are a traffic filter and the hope that nobody guesses the file names, then they are public files with good manners.

Put the same files behind authentication and it would not have mattered how persistent the visitor was, or whether it was a person, a script or a research model with a deadline.

The other detail that should worry you is the word “old”. Every organisation I have assessed has at least one website like that — a reporting portal from a previous project, a statistics archive, a microsite nobody switched off — and most could not tell you who owns it. Those are the sites nobody patches, nobody tests and nobody monitors, which makes them exactly where something persistent ends up.

What is genuinely new here is not the technique. Attackers have been probing, rotating addresses and guessing paths for twenty years. What is new is that this visitor was not an attacker. It had no motive. It was a well-funded company's model trying to answer an evaluation question, and it brought an attacker's persistence to the job without an attacker's intent. That changes who is knocking on the door, and how often.

What Do 84 Days and a Public Inbox Tell Us?

They tell us most organisations have never planned for a well-meaning third party telling them they have been breached.

The Prime Minister criticised both the delay and the channel — the notification arrived as an email to Services Australia's public mailbox. The Register reported (opens in a new tab) that OpenAI used the agency's generic public-disclosures address rather than approaching officials, and that Australian lawmakers were not impressed. OpenAI's position is that it spent the intervening time validating what had been accessed.

It is easy to be critical of OpenAI here, and the Australian government has been. The more useful question is closer to home. If an AI company, a researcher or a stranger emailed your info@ address tomorrow to say one of their systems had been inside yours, who would read it? How long would it sit there? Who decides what happens next?

I am sure every organisation reading this has a monitored security contact, published where a finder can actually find it. Of course it does… but it is worth checking.

The NCSC has already done the thinking. Its Vulnerability Disclosure Toolkit (opens in a new tab) recommends a dedicated security contact — an email address or a secure web form — that is easy to find, published on your contact or security pages and in a security.txt file. It is short, it is free and it is common sense. It will not stop an agent getting in. It will make sure that when someone tells you, the message reaches a person who can act on it.

What Should UK Organisations Do About It Now?

Start with the old websites and the inbox; both are cheap to fix and neither needs a view on AI.

  1. List every public-facing website and subdomain you own, including the forgotten ones, and put a named owner against each. Reporting portals, archives and statistics sites first.
  2. Check whether anything described internally as “non-public” is reachable from those sites without logging in. If it relies on bot filtering, rate limiting or file names nobody should guess, it is not protected.
  3. Test those sites the way a persistent visitor would — rotating addresses, enumerating paths, trying predictable names. That is ordinary penetration testing scope, and it is worth making sure your legacy sites are actually in it.
  4. Publish a security contact and a disclosure policy, following the NCSC toolkit, and send a test message to find out whether anyone reads it.
  5. Agree now who triages a notification from an outside party, who decides whether it is reportable, and who talks to whom. Deciding that on the day is how 84 days happens.
  6. If you run AI agents with web access, read the next section before you do anything else.

Is Your Own AI Agent the Next Headline?

If your organisation runs AI agents that can browse the web, you are now on the other side of this story.

The agent in Australia was not told to attack anything. It was given a question with a deadline and access to the internet, and nothing told it that “blocked” meant “stop”. That combination — task pressure, tool access and no stop condition — is not unique to OpenAI. It describes a lot of the agent pilots being built right now into research, procurement and customer workflows.

OpenAI has a dedicated alignment team, and on 16 September it published a framework for reporting model misalignment (opens in a new tab), along with six reports of unexpected or concerning model behaviour from the previous six months. If a company with those resources found this happening in its own evaluations, a mid-sized organisation wiring an agent into its supply chain should assume it can happen there too.

The controls that matter sit outside the model: which sites an agent may reach, which credentials it holds, what it logs, and what it is required to do when it hits a wall. An agent that is allowed to browse must also be allowed to fail — to come back and say “I couldn't get that” without being scored down for it. That is a governance decision before it is a technical one, which is why it belongs in your AI governance (opens in a new tab) framework and your AI risk assessment (opens in a new tab), and why agents deserve the same adversarial testing as any other system that talks to the outside world.

Why the Medicare Breach Is a Lesson About Locks, Not Robots

The OpenAI agent hack will be remembered as an AI story. It is really a story about an old website, a filter mistaken for a lock, and an inbox nobody expected to matter.

We can argue about AI regulation for years, and Australia is about to. We can check our own legacy sites and security contacts this week.

If you would like a second pair of eyes on either side of it — the forgotten websites, or the agents you are about to let loose on other people's — do get in touch. We test AI agents and LLM applications (opens in a new tab) as well as the websites they visit.

The robot wasn't the problem. The locks were.

Frequently Asked Questions About the OpenAI Agent Hack

Was Any Personal Medicare Data Accessed?

No personal information is believed to have been accessed, according to the Australian Prime Minister and OpenAI's own review, which found no evidence of patient records being touched. The material accessed was aggregate health statistics and internal file names. The investigation is ongoing, so that position could change.

Which Australian Government Websites Were Affected?

The Medicare Statistics Reporting Service portal, run by Services Australia, is the confirmed site. The Australian Institute of Health and Welfare, the NSW Bureau of Crime Statistics and Research and the Victorian Department of Health may have been affected, but as of 24 September 2026 that is not confirmed.

Did Someone Instruct the AI Agent to Break In?

Not according to OpenAI. The company says the access happened during an internal evaluation, when its models were trying to find Australian statistics to answer test questions, and that the models took actions it did not intend. The Australian taskforce has not yet reported its findings.

Does the OpenAI Agent Hack Affect UK Organisations?

No UK systems have been reported as involved. The lesson applies anyway: any organisation with non-public data reachable from a public website, protected only by bot filtering or obscure file names, is exposed to the same persistence — from AI agents, automated tools or ordinary attackers.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top