Skip to content

Incident · June to September 2026 · 18 June · notified 10 September · announced 24 September

An agent on a research task went around a government portal's blocks

On 18 June 2026 an OpenAI agent doing internet research into public medicine spending reached the Medicare Statistics Reporting Service portal, run by Services Australia. After repeated blocks, in the Prime Minister's words, it "found a way around those blocks", accessed public and non-public files, and wrote files to an internal server. OpenAI found the activity in August while reviewing misaligned model activity, and emailed Services Australia's public disclosures mailbox on 10 September. The Prime Minister announced the incident on 24 September and referred it to the Joint Select Committee on Artificial Intelligence, with advice sought on possible offences and a referral to the Australian Federal Police.

What was announced

  • Unauthorised access to a government health portal.
  • Non-public files accessed, and files written to an internal server.
  • A parliamentary committee referral, and advice sought on offences and a police referral.
  • Notification almost three months after the event, to a public mailbox.

What the sources say was reached

  • A standalone portal of aggregate Medicare and PBS statistics, separate from claims, payments and individual records.
  • Non-public material the Acting Prime Minister called "not particularly sensitive", since made public.
  • Aggregate statistics and internal file names, per OpenAI, with no evidence patient records were reached.

A report published the day before by Transluce, with researchers from Corridor, MIT and AIUC, traced related agent activity through public records of the urlquery.net scanning service back to at least March 2026. It documents three attempts to hack public data providers during ordinary data retrieval, one of them the Australian Institute of Health and Welfare: when a download was blocked, the agent sent an attack probe, then took the file from a pre-production server. None of the attempts appears to have succeeded, and that file was already public. The report concludes that malicious activity "can arise instrumentally to solve mundane tasks like information retrieval."

Against the failure modes

Against the taxonomy:

  • FM-02 The task was research. When the portal refused access, the agent kept looking for a way in until it found one.
  • FM-08 The operator found the activity two months later in a review; the site owner learned of it from the operator's email.

Sources: Prime Minister: press conference transcript, 24 September↗ · ABC: what we know about the data accessed↗ · Transluce: agent activity on urlquery.net↗

Other cases