Three months for OpenAI to alert Australia on Medicare hack, six days to alert ministers

0
1
Advertisement

Updated ,first published

No penalty has been imposed on US artificial intelligence corporation OpenAI after one of its AI agents infiltrated medicare in June, despite it only informing the federal government of the breach three months later, as the government seeks urgent advice on whether any offences were committed.

Prime Minister Anthony Albanese has launched a taskforce to examine the breach and determine whether existing processes are adequate for responding to AI-related cyber incidents, after it was revealed that it took six days for ministers to be alerted after Services Australia learned its websites had been hacked.

The government is also trying to determine if the matter should be referred to the Australian Federal Police.

Speaking to reporters in New York, Albanese said the incident involved an OpenAI agent gaining unauthorised access to the public-facing Medicare Statistics Reporting Service portal, where it accessed public and private files and wrote files to an internal server.

Advertisement

The Medicare website was breached on June 18, but the Commonwealth government was only informed after OpenAI emailed a public Services Australia inbox on September 10.

“This situation is obviously unacceptable,” Albanese said. “And today, I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident, and I also expressed my disappointment that it took the company way too long to inform the government what had occurred and the nature of the way that that notification occurred as well was unacceptable.”

Minister for Government Services Katy Gallagher revealed she was informed about the breach on September 17, six days after Services Australia discovered the alert in a public email inbox and two days after the Australian Signals Directorate was informed.

OpenAI chief Sam Altman.Bloomberg

Albanese said a forensic investigation was under way with the assistance of the Australian Signals Directorate.

Advertisement

“Evidence currently available is there is no broader compromise to the Services Australia network. Nonetheless, this situation is obviously unacceptable,” Albanese said.

AI agent ‘climbed the fence’

Speaking in Sydney, Acting Prime Minister Richard Marles said the impact of the incident was “relatively minor”.

“We are talking about aggregated medical statistics. No individuals’ medical data was accessed here. The system itself has not been in any way compromised,” he said.

“So the impact of this event is minor, but it is a very serious incident because, in an unintended way, an AI agent has entered into an Australian government website in a way which is unauthorised.”

Advertisement
Acting Prime Minister, Richard Marles during a press conference in Sydney, Thursday, 24 September, 2026. Prime Minister Anthony Albanese has revealed that an artificial intelligence agent developed by OpenAI infiltrated an Australian government website in June, accessing public and non-public files of the Medicare Statistics Reporting Service portal, administered by Services Australia. Photo: Sam Mooy / The Sydney Morning HeraldSam Mooy

Marles compared the portal’s security to a fence. The personal data of Australians held by government sat “inside a safe”, he said, and the most sensitive national security information “sits behind a fortress”.

“This AI agent scaled the fence, but it did scale it. And the point is, it was unintended. It wasn’t asked to,” he said.

Gallagher said the portal was a legacy website, used mostly by researchers and academics, and was “not in any way related to Medicare in terms of claims, payments, processing individual information”.

She said the site had protections against bots. “Unfortunately, this agent got around that.”

Advertisement

The portal has been shut down and its data moved to data.gov.au. Gallagher said she had asked whether $160 million allocated in the last budget to upgrade the cyber defences of Services Australia’s essential infrastructure could be brought forward. She has also asked for other legacy public-facing websites to be moved to secure platforms or decommissioned.

The timeline

On June 18, an OpenAI research team used an internal model to conduct internet-based research into the public medicine space. The AI agent encountered repeated blocks while seeking information from the Medicare portal but found ways around them, ultimately gaining unauthorised access to other areas.

“The AI agent found a way around those blocks, didn’t accept no for an answer,” Albanese said.

Advertisement

The agent then accessed public and non-public information and, according to Services Australia, also wrote files to an internal server.

In August, OpenAI discovered the breach and started an internal investigation to discover what information was accessed.

On September 10, OpenAI informed Services Australia of the breach via an email sent to a public inbox. The email was referred to the Australian Cyber Security Centre on September 15.

The email went to an address used to report suspected vulnerabilities in Services Australia’s systems. Gallagher said the inbox was checked once a day. “Sometimes many of them are hoaxes,” she said. Services Australia first looked at the email on September 11 and took a couple of days to verify it before alerting the Australian Signals Directorate.

Advertisement

Gallagher said she was told around September 17, and held discussions with Marles, Home Affairs Minister Tony Burke, Services Australia and the Australian Signals Directorate over the weekend. Albanese was briefed last weekend.

The first technical exchange between OpenAI and Services Australia, in which the agency sought OpenAI’s logs, was on Tuesday. Gallagher said another meeting was needed because some of Services Australia’s questions had not been resolved.

Taskforce to investigate breach

The government taskforce will include the National Cyber Security Coordinator, the Office of AI, the Australian Signals Directorate, the Australian AI Safety Institute and Services Australia.

Marles said the taskforce would be led by the Department of Prime Minister and Cabinet. It would examine the government’s “posture in respect of emerging AI cyber threats” and the security of government networks.

Advertisement

The review will examine possible law enforcement and legislative responses, as well as whether penalties are applicable to OpenAI.

The incident will be referred to parliament’s Joint Select Committee on Artificial Intelligence.

OpenAI’s response

The tech company has confirmed it is conducting an “extensive review of misaligned model activity during training and evaluation” and that third parties were being notified of potential breaches.

OpenAI said its models had accessed “several Australian government websites and services” during an internal evaluation. The models were trying to look up answers and statistics for questions about Australia.

Advertisement

“In the course of that, our models took actions we did not intend,” an OpenAI spokesperson said.

The company said its review found no evidence that patient records had been accessed. It said the information accessed included aggregate health statistics and internal file names.

Prime Minister Anthony Albanese in New York on Wednesday.Dominic Lorrimer

Marles said OpenAI had been “working with us very cooperatively” since it made contact. “They have clearly notified us of this, and engagement with them has been critical to understanding what has occurred. We are grateful for that,” he said.

But he said the way the government was first notified was “not good enough”.

Advertisement

The political reaction

Opposition Leader Angus Taylor on Thursday cast doubt on the timing of the announcement, while his colleagues called for a wide-ranging audit of government security systems.

“The government needs to explain when it first became aware of the breach, exactly what information was accessed, what vulnerability was exploited, how they’re closing it.”

Marles said ministers had known about the breach for less than a week and wanted to be confident of its impact before going public. “An email goes to effectively a public email address within Services Australia, and 14 days later, we are standing before you,” he said.

“To have gone public without all the facts at hand or without that level of confidence would, I think, have been reckless.”

Advertisement

Trump’s defence of AI

On Monday, Albanese co-signed a joint statement with 21 other nations at the United Nations General Assembly calling for urgent regulation and guardrails on artificial intelligence.

US President Donald Trump addressing the UN General Assembly on Tuesday (US time).Bloomberg

Despite persistent questioning, Albanese would not reveal whether he discussed the breach in his conversation with Trump on Wednesday (Australian time).

“I do it privately … I have a relationship with President Trump, where we have conversations, and … to some people’s surprise, it must be said, have a very good relationship because we do have a relationship.”

Additional reporting: Jack Gramenz

Advertisement

Rob HarrisRob Harris is the national correspondent for The Sydney Morning Herald and The Age based in Canberra. He is a former Europe correspondent.Connect via email.
David SwanDavid Swan is the technology editor for The Age and The Sydney Morning Herald. He was previously technology editor for The Australian newspaper.Connect via X or email.
Nick NewlingNick Newling is a federal politics reporter for The Sydney Morning Herald and The Age.Connect via X or email.

From our partners

Advertisement
Advertisement

Disclaimer : This story is auto aggregated by a computer programme and has not been created or edited by DOWNTHENEWS. Publisher: www.smh.com.au