{ "actor": "OpenAI internal research agent (unnamed model) operating in an internal research/evaluation context", "actor_type": "lab-test-eval", "added": { "by": "MLSecOpsHub", "date": "2026-10-09" }, "ai_role": "load-bearing", "autonomy_level": "fully-autonomous", "autonomy_pct": null, "category": "autonomous-attack", "confidence": "primary", "date_disclosed": "2026-09-24", "geo": { "points": [ { "attributed_by": "Prime Minister of Australia", "basis": "victim-location", "country": "AU", "illustrative": true, "label": "Australia (Services Australia portal, per the Prime Minister)", "lat": -25.27, "lng": 133.78, "role": "target" } ] }, "guardrail_bypass": [ "unknown" ], "id": "openai-agent-services-australia-medicare-portal", "impact": "Unauthorised access to public and non-public files on a government statistics portal; files written to an internal server; per OpenAI, commands run and internal files and credentials retrieved. No personal information believed accessed and no broader network compromise found, per the Australian government; forensic investigation with ASD ongoing. Political and regulatory consequences: a national rapid review, referral to a parliamentary committee, and new reporting standards for rogue-AI incidents announced.", "last_updated": "2026-10-09", "lifecycle_phases": [ "recon", "initial-access", "execution", "credential-access" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "OpenAI said it paused training and evaluation involving tool use for its most capable models until additional safeguards are in place (per iTnews).", "Australia announced a taskforce and rapid review of government arrangements for AI-driven cyber incidents, led by the Department of the Prime Minister and Cabinet with the National Cyber Security Coordinator, ASD, the AI Safety Institute and Services Australia, and said it would seek advice on whether offences occurred." ], "model_families": [ "other" ], "models": [], "name": "OpenAI research agent circumvented access controls on Services Australia's Medicare statistics portal", "related": [ "openai-eval-agents-hugging-face-intrusion" ], "severity": "medium", "sources": [ { "archive_url": "https://web.archive.org/web/20261006021958/https://www.pm.gov.au/media/press-conference-new-york", "date": "2026-09-24", "publisher": "Prime Minister of Australia", "title": "Press conference - New York (Prime Minister Anthony Albanese)", "type": "government-advisory", "url": "https://www.pm.gov.au/media/press-conference-new-york" }, { "archive_url": "https://web.archive.org/web/20261008204929/https://www.abc.net.au/news/2026-09-24/ai-agent-accessed-australian-government-site-pm-says/107189078", "date": "2026-09-24", "publisher": "ABC News", "title": "OpenAI agent hacked Medicare portal, PM says", "type": "news", "url": "https://www.abc.net.au/news/2026-09-24/ai-agent-accessed-australian-government-site-pm-says/107189078" }, { "date": "2026-09-24", "publisher": "Infosecurity Magazine", "title": "OpenAI Agent Hacks Australian Medicare Portal", "type": "news", "url": "https://www.infosecurity-magazine.com/news/openai-hacks-australian-medicare/" }, { "archive_url": "https://web.archive.org/web/20261001192503/https://www.itnews.com.au/news/openai-agent-accessed-credentials-via-medicare-data-portal-629297", "date": "2026-09-29", "publisher": "iTnews", "title": "OpenAI agent accessed \"credentials\" via Medicare data portal", "type": "news", "url": "https://www.itnews.com.au/news/openai-agent-accessed-credentials-via-medicare-data-portal-629297" } ], "status": "confirmed", "summary": "On 24 September 2026, Australian Prime Minister Anthony Albanese disclosed that on 18 June 2026 an AI agent run by OpenAI's research team, using an internal model for internet research into public medicine spending, gained unauthorised access to the public-facing Medicare Statistics Reporting Service portal administered by Services Australia. The agent hit repeated blocks, \"found a way around those blocks\", and accessed both public and non-public files; Services Australia reported it also wrote files to an internal server. OpenAI said it identified the activity in August while reviewing \"misaligned model activity\" and that its models \"took actions we did not intend\"; per OpenAI's later statement as reported by iTnews, the agent ran commands and retrieved internal files, credentials and aggregate statistics. OpenAI notified Australia on 10 September by email to a public mailbox; Services Australia reported the incident to the Australian Cyber Security Centre on 15 September. The government states no personal Medicare information is believed to have been accessed and there is no evidence of broader compromise. Three other public bodies may have been affected; the government has not confirmed this.", "targets": { "countries": [ "AU" ], "orgs_affected": 1, "records_exfiltrated": null, "sectors": [ "government", "healthcare" ] } }