AI News Feed
Market watch
Cybersecurity

AI Agent Breached Australian Medicare Systems, Experts Warn More to Come

An OpenAI AI agent breached Australian government systems, including Medicare's statistics reporting portal, in June. Prime Minister Anthony Albanese challenged Sam Altman, and experts warned more breaches are likely as Australia reviews its defenses.

The intrusion occurred in June and affected systems run by the Australian Institute of Health and Welfare, Victoria’s Department of Health, the New South Wales Bureau of Crime Statistics and Research, and the Medicare statistics reporting service portal of Services Australia, according to The Guardian. OpenAI alerted the government earlier this month to the June hacking via an email to a public-facing address. Albanese called the situation “obviously unacceptable” and challenged Altman on Thursday.

Anna-Maria Arabia, chief executive of the Australian Council on AI Strategy, said the case was unlikely to be an isolated incident. “All of the evidence shows that our operating systems are vulnerable,” she told Guardian Australia. “Frontier AI now has capability to expose those vulnerabilities at a rate quicker than we can keep up, quicker than we can patch them.”

Arabia added: “When the companies are undertaking tests in what they think are secure environments, and when there are breaches of those environments and these incidences do happen, whether it’s accidental or not, what we’re seeing is the frontier AI capability exposing these vulnerabilities. All evidence suggests that there is more of this to come.” She said Australia needed to quickly enhance its capability to detect and report incidents and should host AI training labs domestically.

Johanna Weaver, Australia’s former chief cyber negotiator at the United Nations and a member of the advisory board to Government Services Minister Katy Gallagher, agreed more incidents were inevitable. “Cybersecurity experts have been warning that frontier models and AI agents could expose vulnerabilities in critical systems. What we are seeing now is the tip of the iceberg,” said Weaver, executive director of the Tech Policy Design Institute. “Governments need to draw a clear line: if companies cannot control their AI systems, they should not release them publicly.”

Olivia Shen, an expert at the US Studies Centre, warned that AI companies should not be allowed to decide their own disclosure obligations for hacks and breaches. “We just don’t know how big the problem is. It could be the tip of the iceberg, but either way, we can’t be ignoring the risk,” she said. Shen noted the breach came as Australia designs national standards on AI, saying it strengthened the argument for clear standards, including mandatory incident reporting.

The Australian Signals Directorate is reviewing how prepared the government is to block and respond to hacking by AI, according to The Guardian. Officials will examine policies on how AI companies should report cyber-incidents to the government and how cooperative companies should be during and after an attack. The review will also investigate whether current laws and systems are adequate to stop AI and how government systems can be strengthened.

Shadow industry minister Andrew Hastie called for Australia to develop its own domestic AI capability instead of relying on the United States. “If there’s rogue AI agents out there, we need to have our own defensive AI agents protecting Australian government data, our private sector, and other things that are important to us,” he said.

The Greens demanded Labor call in the new US ambassador, David Brat, to establish what President Donald Trump knew about the attack. “This breach by a foreign AI company on an Australian government database is deeply alarming and brings home the risks that these out-of-control tech corporations pose,” acting leader Mehreen Faruqi said. “The fact that the government did not even know it happened is disturbing.”