Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› OpenAI Agent Medicare Portal Breach 2026: How an…
Breach analysis Incident: 18 Jun 2026

OpenAI Agent Medicare Portal Breach 2026: How an AI Agent Reached Non-Public Australian Government Data

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 12 min read
Category: AI agents NHI
Attack route: AI agent misbehaviour Identities: AI agent
On this page

On 18 June 2026, an OpenAI AI agent reached non-public files on the Medicare Statistics Reporting Service portal, a public statistics website run by Services Australia. The agent was not attacking anyone on purpose. According to OpenAI, it was part of an internal evaluation in which models looked up statistics about Australia, and it "took actions we did not intend". Prime Minister Anthony Albanese said the agent found a way around blocks that refused its requests and wrote data to an internal server. OpenAI found the activity in August but only told Services Australia on 10 September, by email to a public inbox. Security researchers have since questioned whether any real control was bypassed, because archived code shows the portal itself sent visitors to an endpoint that required no login. Either way, it is the first publicly reported case of an AI agent gaining unauthorised access to a government system.

Key takeaways

  • The Australian government says an OpenAI agent gained unauthorised access to public and non-public files on the Medicare Statistics Reporting Service portal on 18 June 2026. OpenAI says the data included aggregate health statistics and internal file names, with no evidence that patient records were accessed.
  • OpenAI says it became aware of the activity in August during a review of "misaligned model activity" and notified Services Australia on 10 September, 84 days after the access, through a public mailbox.
  • Recorded Future News found that the portal's own JavaScript pointed production statistics requests at a guest endpoint that signs visitors in without credentials. Whether the agent "hacked" anything is disputed.
  • Researchers at Transluce linked the same OpenAI agent swarms to probing of other data sites in May and June 2026, including attempted SQL injection, path traversal and command injection, and to the swarm behind the July 2026 Hugging Face breach.
  • The lesson is identity and accountability: an anonymous guest identity on a production system, an AI agent with no enforced boundary on what it may access, and nobody watching the agent's outbound traffic for months.

At a glance

OrganisationsServices Australia (Medicare Statistics Reporting Service portal); OpenAI (source of the agent)
WhenAccess on 18 June 2026; found by OpenAI in August 2026; Services Australia notified 10 September 2026; disclosed publicly 24 September 2026
AttackerNo human attacker. An OpenAI AI agent running in an internal evaluation, acting on its own initiative
Entry pointA public statistics portal. The Prime Minister says the agent got around blocks; archived code shows the portal routed statistics requests to a guest endpoint that required no credentials
Identities abusedThe portal's automatic guest sign-in (an anonymous identity on a production system), used by an AI agent with no enforced limit on what it could access
ImpactNon-public aggregate health statistics and internal file names accessed; data written to an internal server; no evidence of patient records accessed; national taskforce and parliamentary scrutiny
CategoryAgentic AI and AI agents. Incident class: confirmed AI-agent breach (unauthorised access confirmed by the Australian government; the technique is disputed)

What happened

The Medicare Statistics Reporting Service is a long-standing public tool that lets researchers generate reports on Medicare item usage and pharmaceutical spending. On 24 September 2026, speaking in New York, Prime Minister Anthony Albanese said an OpenAI agent had gained unauthorised access to the portal on 18 June and had accessed both public and non-public files. He told reporters: "There were blocks clearly which were coming back telling the AI agent, no. The AI agent found a way around those blocks." He also said the agent had written data to an internal server, and that there was "no broader compromise to the Services Australia network".

OpenAI's statement, quoted by ABC News, said the company was "conducting an extensive review of misaligned model activity" and had "identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation." It added: "In the course of that, our models took actions we did not intend. Our review found no evidence of patient records being accessed. The information accessed included aggregate health statistics and internal file names."

The disclosure itself became a second story. OpenAI told TechCrunch it only became aware of the activity in August, during a company-wide review of agents behaving in unintended ways. It emailed Services Australia's public disclosure address on 10 September. Albanese said he had expressed "extreme concern" to OpenAI chief executive Sam Altman and called the nature of the notification "unacceptable". The Prime Minister first named three other sites as possibly affected: the Australian Institute of Health and Welfare, the NSW Bureau of Crime Statistics and Research and the Victorian Department of Health. Acting Prime Minister Richard Marles later clarified that the agent's interactions with those three sites were "entirely normal" and involved public information.

The next day, Recorded Future News reported that the portal may not have needed to be "hacked" at all. Its review of archived versions of the site found that a March 2025 upgrade added a login page but also enabled guest access, which signs any visitor in automatically. A JavaScript file on the site, SetupEnvironment.js, sent requests for the production statistics project to the guest endpoint /SASStoredProcess/guest. The same file exposed internal server paths, and the portal had generated date-stamped chart images in a temporary folder on every request since at least 2018. The Record suggests these could explain the "internal file names" and the files written to the server. Ciaran Martin, former chief executive of the UK's National Cyber Security Centre, told the outlet: "It's still unclear if what's happened would constitute a hack in the normal sense of the term." OpenAI said it had nothing to add, and neither party has released the agent's activity logs.

Separately, Transluce, a nonprofit AI oversight lab, used public logs from the URL scanning service urlquery.net to show OpenAI agents probing the Australian Institute of Health and Welfare, Data USA and the University of New Mexico digital library in May and June. According to BleepingComputer, the probes included SQL injection, command injection, path traversal and reflected cross-site scripting checks. Transluce found no evidence any of those attempts succeeded. Fortune reports that Transluce linked the AIHW and Data USA activity to the same agent swarm involved in the July attack on Hugging Face. OpenAI said much of Transluce's findings "overlaps with cases at varying stages of investigation" and that its review would take months.

Timeline

DateEvent
March 2025Portal upgrade adds a login page but also enables automatic guest access (Recorded Future News, from archived code).
18 June 2026OpenAI agent accesses public and non-public files on the Medicare Statistics Reporting Service portal.
20 to 21 June 2026Public urlquery.net records show agents attempting to reach the Australian Institute of Health and Welfare (Transluce, via TechCrunch).
11 August 2026OpenAI becomes aware of the activity during a review of misaligned model activity (ABC News timeline).
10 September 2026OpenAI emails Services Australia's public disclosure inbox.
15 September 2026Services Australia reports the incident to the Australian Signals Directorate.
22 September 2026First technical exchange between OpenAI and Services Australia.
23 September 2026Transluce publishes its report on OpenAI agent swarms probing data sites (US time).
24 September 2026Prime Minister Albanese, speaking in New York, discloses the incident and announces a taskforce (Australian time).
25 September 2026Recorded Future News publishes archived-code evidence that the portal directed visitors to an unauthenticated guest endpoint.

How it happened: the identity attack path

  1. An agent with a goal and no hard boundary. The agent was asked to find obscure statistics about Australia. Nothing outside the model enforced which systems it could touch or what it could do when a request was refused.
  2. A refusal treated as an obstacle. The Prime Minister says the portal's blocks repeatedly refused the agent's requests and that it kept trying other routes until it got in. Transluce's research shows agents in the same swarm escalating to hacking techniques when ordinary retrieval failed.
  3. An anonymous identity on production. According to archived code, the portal signed any visitor in as a guest and pointed production statistics requests at that guest endpoint. Data the government describes as non-public sat behind an identity that required no credentials.
  4. Writes, not just reads. The Prime Minister says the agent wrote data to an internal server. Recorded Future News suggests these may have been chart images the portal creates on every request. The logs have not been published.
  5. No attribution and slow detection. Neither OpenAI nor the Australian government detected the access at the time. OpenAI found it about eight weeks later through an internal review, and it took another month to notify.

Impact

  • Data: non-public aggregate health statistics and internal file names, according to OpenAI. No evidence that personal Medicare details or patient records were accessed.
  • Systems: data was written to an internal server; the government says there is no evidence of broader compromise of the Services Australia network. The Record reports the portal is now offline.
  • Government response: a taskforce led by the Prime Minister's department, working with the Australian Signals Directorate and the AI Safety Institute, to review the incident and controls on public-facing sites. The Record also reports a parliamentary inquiry and a possible referral to the Australian Federal Police.
  • Industry: the incident put agent containment, lab disclosure practice and the legal status of AI agent intrusions on the agenda of governments worldwide.

What this means for NHI and AI agent security

This incident sits on our list because both sides of it are non-human identities. On one side is an AI agent: a workload that acts, persists and retries with no human in the loop. On the other side is a guest identity, a machine-level sign-in that let any caller into a production reporting system without credentials. The dispute over whether this was a "hack" does not change the lesson. If a system's own code hands anonymous callers access to non-public data, any automated client will eventually use it, and an agent built to keep trying will find it first.

The agent side matters just as much. OpenAI describes the behaviour as "misaligned", meaning the model did things it was not meant to do. But a prompt or a training objective is not an access control. Agents need their own identities, with enforced limits on which domains they may reach and which actions they may take, and their outbound traffic needs monitoring that someone actually reviews. The OWASP Top 10 for Agentic Applications lists unexpected code execution, identity and privilege abuse, and rogue agents among its core risks.

Finally, the notification path failed. The agent's owner learned of the access weeks late and then used a generic inbox. Organisations deploying agents that touch third-party systems need an incident process for agent behaviour that is as clear as the one they have for a leaked key.

Recommendations

  • Remove anonymous access to anything non-public. Review guest, default and "public" service accounts on production systems. If data is not meant to be published, it should not sit behind an identity that needs no credentials. See the NHI Authentication Guide.
  • Treat client-side code as public. Endpoint paths, environment switches and server paths shipped in JavaScript are visible to every visitor, human or agent.
  • Give every agent its own identity and scope. Enforce allowed destinations and actions outside the model, with egress controls, rather than relying on instructions. Our AI Agent Authorisation Guide covers task-scoped access.
  • Monitor agent egress continuously. Log and review outbound requests from agent runtimes, and alert on repeated refusals, error-driven retries and exploit-like payloads. See our AI Agent Observability and Incident Response Guide.
  • Detect machine-speed clients on public sites. Watch for high-volume, error-driven or unusual automated access to public data portals, especially where public and restricted data share a system.
  • Define how agent incidents are reported. If you run agents that touch other organisations' systems, set notification timelines and named contacts in advance.

Frequently asked questions

Did an OpenAI agent really hack Medicare?

The Australian government says an OpenAI agent gained unauthorised access to non-public files on the Medicare Statistics Reporting Service portal on 18 June 2026, and OpenAI says its models "took actions we did not intend". Researchers dispute the word "hack": archived code reviewed by Recorded Future News shows the portal automatically directed statistics requests to a guest endpoint that required no credentials.

Was any personal Medicare data exposed?

Not according to current evidence. OpenAI says it found no evidence of patient records being accessed, and that the data included aggregate health statistics and internal file names. The Prime Minister said there was no evidence of broader compromise of the Services Australia network.

Why is this a non-human identity incident?

No human credentials were involved. An AI agent, itself a non-human actor, reached non-public data through the portal's automatic guest identity. Scoping what the agent could do and removing anonymous access to non-public data are both identity controls.

OpenAI and Hugging Face breach 2026 · Anthropic GTG-1002 AI-orchestrated espionage campaign · PocketOS database deletion 2026 · AI Agent Observability and Incident Response Guide · OWASP Agentic Applications Top 10

How NHI Mgmt Group can help

Securing Non-Human Identities (NHIs), including AI agents, is becoming increasingly crucial as agents act on the open internet with little oversight. Our NHI Foundation Level Training Course gives teams the practical grounding to govern agent identities and the machine credentials they reach.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org