OpenAI AI Agent Breaches Australian Government Medical Portal in First-of-Kind Attack
Australia announced that an OpenAI AI agent breached a government medical portal in June, potentially marking the first known instance of autonomous AI breaking into state systems.

Australia announced that an OpenAI artificial intelligence agent breached a government medical information portal in June, gaining unauthorized access to files. According to authorities, this may be the first known case of an AI agent breaking into a government website.
The incident adds to a long string of cyberattacks and data leaks that have hit some of Australia's largest companies in recent years. Cybersecurity experts have previously warned that the frequency and scale of the attacks highlight the local industry's struggle, suffering from a shortage of skilled personnel, to cope with the threat.
Major Data Breaches in Australia
Here are some of the major data breaches that have occurred in the country in recent years:
-
September 2022 - Optus: Australia's second-largest mobile operator reported a data breach affecting 9.5 million customers—about 40% of the country's population. Exposed details included home addresses, driver's license numbers, and passports.
-
October 2022 - Woolworths: The country's largest supermarket chain announced that compromised login credentials were used to access systems of MyDeal, an online retailer under its control. Email addresses, phone numbers, and delivery addresses of about 2.2 million customers were exposed.
-
November 2022 - Medibank: Australia's largest health insurance company, insuring roughly one in six residents, announced that personal information and medical claims data of about 9.7 million current and former customers were exposed.
-
March 2023 - Latitude Financial Services: The Australian digital payments and credit company announced that a hacker stole millions of customer records. Among other things, details of about 7.9 million driver's licenses from Australia and New Zealand were stolen.
-
May 2024 - MediSecure: The electronic prescription services provider revealed it fell victim to a cyberattack exposing personal and medical data of about 12.9 million people. This was one of the largest cyberattacks in Australian history, leading the company to enter insolvency proceedings.
-
July 2025 - Qantas: Australia's largest airline announced that a breach of a third-party platform exposed personal information of 5.7 million customers.
-
August 2026 - Origin Energy: The country's largest electricity and gas provider announced that a data breach in late July exposed credit card details and bank accounts of about 900,000 current and former customers.
A New Phase in Cyber Threats
"The latest event is striking not only because a government system was breached, but also due to the tool used: an artificial intelligence agent."
If confirmed as the first case of its kind, it may mark a new phase in the cyber threat landscape, where autonomous AI systems are used to gain unauthorized access to computer networks.




