OpenAI Agent Hacked Australian Government Health Website

September 24, 2026 by and

An OpenAI model hacked an Australian government website earlier this year, marking one of the first known cyberattacks by artificial intelligence on a government database.

The AI system gained unauthorized access to files on a website for reporting healthcare statistics, Prime Minister Anthony Albanese said on Thursday. There’s no evidence that the personal information of Australian citizens was compromised in the hack on June 18, Albanese said, speaking in New York.

The news of the hack came just hours after heads of AI companies urged world leaders to work together to address the possibility that AI systems outpace human control. An attack on a government brings new focus to that risk, after a series of incidents this summer in which OpenAI models broke into online resources of outside companies, most notably with the case of Hugging Face, a website hosting AI datasets.

“This is the first public instance of a government being breached by an AI model without malicious actors’ orders,” said Charles Li, chief analyst of TeamT5, a Taiwanese cyber research group.

The government is also concerned about how it took months for OpenAI to inform Canberra about the incident, Deputy Prime Minister Richard Marles said. The breach is being investigated to better understand what happened and see if any laws were broken, he said.

“This is a warning about the technology being developed without safeguards and without guardrails in place,” Marles said in Sydney on Thursday, calling the intrusion “utterly unacceptable.”

The breach adds to a series of recent online hacks carried out by AI models made by OpenAI, Anthropic PBC and Meta Platforms Inc., causing widespread concern about the security risks posed by the increasingly powerful technology.

Anxiety about AI’s existential risks gained momentum this month, driven by the high-profile departure of Anthropic employee Jacob Coxon, who accused AI companies of “gambling with our lives” in a resignation post he shared on social media.

In the past weeks, numerous AI company leaders, including OpenAI Chief Executive Officer Sam Altman and Anthropic CEO Dario Amodei, have urged slowing the pace of the development of the technology to address its increasingly unpredictable risks — though they diverge on exactly how it should be handled.

Read more: Trump Dismisses AI Safety Alarm, Says US Already Has Tools to Police Industry

Between May and June, AI models likely from OpenAI also unsuccessfully attempted to hack the websites of three other public data providers, according to research firm Transluce. The agents did this while attempting relatively mundane data retrieval tasks that weren’t cyber-related, the researcher said.

“Agents attempted to hack into them when other methods of collecting the data they sought failed,” Transluce said on its website. “Notably, the tasks the agents were trying to solve were not cyber-related; the agents resorted to hacking tactics while working on ordinary data retrieval tasks.”

Marles said the Australia breach is the first known time that an AI model has gained access to its government systems. The model accessed four state and federal government websites requesting data but only hacked into one of them, he said.

OpenAI took three months to notify Canberra about the unauthorized access, Albanese said. OpenAI said that between discovering the breach in August and notifying the Australian government on Sept. 10, it was validating and investigating the facts and what information had been accessed.

The PM said he had spoken with OpenAI’s Altman to express “extreme concern about this incident.”

“I also expressed my disappointment that it took the company way too long to inform the government what had occurred,” Albanese said at a press conference on the sidelines of the United Nations General Assembly.

The AI system was assigned to find information and “there were blocks clearly which were coming back telling the AI agent, no. The AI agent found a way around those blocks,” Albanese said. “The model attempted alternative ways to obtain the info that it wanted, and this led to unauthorized access into some other areas.”

A forensic examination, aided by the Australian Signals Directorate, is underway to ascertain more information about the breach.

In a statement, OpenAI said its “extensive review of misaligned model activity” had identified actions involving “several Australian government websites and services,” which its models had accessed when they attempted to look up statistics to answer questions about Australia during an internal evaluation.

“In the course of that, our models took actions we did not intend,” a spokesperson for OpenAI said in the statement.

Albanese said he needed to be reassured that the correct protocols to manage AI were in place.

“Mr. Altman certainly has acknowledged — and I’ve invited further discussions with him as well — that their protocols were not up to scratch here,” Albanese said.

The Australian leader’s comments come as OpenAI urges the US to lead a global effort to set standards for AI.

Rival Anthropic’s technology has also figured in undermining online security, with a hacker last year using its Claude model to carry out a series of attacks against Mexican government agencies, resulting in the theft of a trove of sensitive tax and voter information, according to cybersecurity researchers.

Amodei and Altman have both expressed concern about the potential threat of self-improving AI systems outrunning human oversight and control.

Photograph: Anthony Albanese, Australia’s prime minister, during a news conference in Sydney, Australia, on Monday, Dec. 15, 2025; photo credit: Brent Lewin/Bloomberg