Australia to investigate if OpenAI hack of government health website broke the law

An OpenAI model hacked into an Australian government website, the country’s prime minister Anthony Albanese said Wednesday, in the first publicly reported case of an AI model hacking into a government’s systems.
Albanese said that there would “obviously be legal consequences” following the breach, and that OpenAI faces a government investigation into how its unreleased models gained access to reams of bulk health data information.
This latest incident disclosure comes as governments and tech companies grapple with how to rein in increasingly autonomous AI after a recent spate of AI agents breaking out of their sandboxes, colluding on the internet, and posing cybersecurity issues.
The breach also poses questions about how both OpenAI and the Australian government failed to detect the attack until several months later.
During a Wednesday news briefing at the U.N. General Assembly, Albanese said that the breach began on June 18, but that OpenAI did not notify the government until September 10.
OpenAI only became aware of the incident in August when it turned up during a broader, companywide review of agents behaving in unintended ways, according to an OpenAI spokesperson who reached TechCrunch via email.
The unspecified OpenAI agent obtained both public and nonpublic files from Services Australia, which administers Australia’s universal healthcare scheme. While the prime minister said there is no evidence that any citizens’ personal information was leaked, OpenAI said that the information the agent reached included aggregate health statistics and internal file names.
The agent was running during an internal OpenAI evaluation, seeking answers about Australia and publicly available medicine information. At the Medicare portal, the agent encountered repeated blocks but found ways around them.
Albanese told reporters that the model “didn’t accept no for an answer,” and added that the model had actively written data to the government’s database, rather than just accessing it, indicating the possibility that the department’s data was modified or muddied.
The prime minister said OpenAI disclosed the breach by sending a notification to the public mailbox of Services Australia, which then notified Australia’s Cyber Security Centre five days later. It’s unclear why there was a delay, but Albanese said he raised the breach directly with OpenAI chief executive Sam Altman by stressing Australia’s “extreme concern” about this incident and “disappointment” that OpenAI sat on the information for nearly three months.
“This situation is obviously unacceptable,” said Albanese, making clear that he held the company accountable for both the hack and how slowly it came to light.
Albanese said that the government’s investigation will consider law enforcement and legislative responses to prevent incidents like this one happening again.
Australian media outlet ABC News reports that the latest identified attack may have relied on an earlier breach of a German wiki site , which was used as a staging ground for attacking the Australian government’s website. The AI model agents reportedly used the German wiki to leave notes to be used in later hacks, including a note to obtain data from the Australian Institute of Health and Welfare, a federal agency that publishes national health data. The agency is one of three additional systems that Albanese said may have been breached.
Transluce, a nonprofit AI research lab, separately found public records showing AI agents targeting the Australian Institute of Health and Welfare on June 20 and 21.
OpenAI did not respond to TechCrunch’s specific inquiry on whether the incidents were connected but acknowledged their “activity involving several Australian government websites and services.”
The incident comes after a string of security incidents caused by rogue agents, often acting within the infrastructure of AI labs. In July, swarms of OpenAI agents breached Hugging Face. Since then, more incidents of AI agent hacks from Anthropic, Meta, and Google have been revealed .
OpenAI now says it is conducting an “extensive review of misaligned model activity during training and evaluation” and is notifying third parties of potential breaches.
When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence.


He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com .

Your next big connection is at Disrupt. Connect with 10,000+ founders, VCs, operators, and tech leaders. Explore tomorrow’s breakthroughs, hear what’s shaping tech today, and save up to $200 by Sept. 25 at 11:59 p.m. PT.
Meta made a Tamagotchi-like wearable for its Muse AI agent
Anthropic says its biology lab has already found something big
PitPro’s first tire-changing robot goes live in Canada
Anthropic releases Opus 5.5 with lower prices and Fable-level performance
OpenAI forms math advisory group as its AI resolves more than 100 open problems
Meta’s Muse is outpacing ChatGPT’s early mobile launch
Tilly Norwood’s press tour is going about as well as you’d expect for an AI
Verified source · TechCrunch
Reported by TechCrunch. Open the original for full media and formatting.
More in Policy
All news
PolicyTurtlemint Crashes Another 20%, PB Fintech Falls 8% On IRDAI’s Proposed Commission Caps
The rout began yesterday after IRDAI released a consultation paper proposing product- and channel-specific commission ceilings for insurance distributors
Read at Inc42
PolicyMeta employees ordered ‘attorney/client privilege’ hats while fighting child safety disclosures
Meta's lawyers have argued that certain evidence should be withheld from public view on the grounds of attorney-client privilege in the ongoing lawsuits over alleged harm to teens' safety and mental health. Lawyers suing the company said this week that the label has been applied…
Read at The Verge
PolicyDecoding The Commission Gap That Sparked A Bloodbath In Insurance Stocks
For insurance distributors, the commission earned on every policy is central to their business model. It determines how much they…
Read at Inc42
PolicyWaymo’s driverless cars continue to crash less often than people
Waymo's latest batch of self-reported data continues to affirm the company's message that its driverless cars are safer than human drivers. As policymakers continue to debate the safety and economic impact of autonomous vehicles, Waymo is hoping that its own data will help bring…
Read at The Verge