Australia says OpenAI agent breached government health data portal
Australia says OpenAI agent breached government health data portal
Australia said an OpenAI agent breached a government health data portal in June, gaining unauthorised access to files in what could be the first known case of an AI agent hacking a government website.
The breach is among dozens of major cyberattacks that have affected some of Australia’s biggest companies in recent years, according to Reuters.
The incident comes amid growing concerns over the ability of AI systems to carry out increasingly sophisticated cyberattacks.
Australia has faced a series of major data breaches
The country has experienced several large-scale data breaches in recent years, affecting millions of people.
In September 2022, Optus, Australia’s second-largest mobile operator, reported a breach affecting 9.5 million customers. The exposed information included home addresses, driver’s licence details and passport numbers.
A month later, Woolworths said its online retailer MyDeal had been compromised after attackers used a compromised user credential to access its systems. The incident exposed email addresses, phone numbers and delivery addresses of about 2.2 million customers.
In November 2022, health insurer Medibank said personal and health claims data belonging to around 9.7 million current and former customers had been compromised.
Digital payments and lending company Latitude Financial Services reported in March 2023 that hackers had stolen millions of customer records, including 7.9 million Australian and New Zealand driver’s licence numbers.
In May 2024, electronic prescription provider MediSecure disclosed a cyberattack that exposed the personal and health information of around 12.9 million people. The breach later contributed to the company’s entry into administration.
Qantas, Australia’s largest airline, said in July 2025 that a breach of a third-party platform exposed the personal data of 5.7 million customers.
More recently, Origin Energy, Australia’s largest electricity and gas provider, said in August 2026 that a late-July data breach exposed credit card and bank account details belonging to around 900,000 current and former customers.
The latest incident involving the government health portal adds another concern: the potential use of AI agents to gain unauthorised access to sensitive systems.
Australian authorities have not said that the OpenAI agent was responsible for the other breaches listed above.