AI News Feed
Market watch
Cybersecurity

Australia Orders Legacy Tech Stocktake After OpenAI Agent Breached Medicare Portal

Australia’s home affairs department ordered all federal agencies to audit legacy technology after an OpenAI agent gained non-public access to the Medicare statistics portal. The breach has exposed costly tech debt and prompted reviews of cyber upgrades, with experts warning AI agents can find vulnerabilities faster.

OpenAI this week revealed that an internal agent had gained non-public access to the portal during a training task seeking information on government spending on skin conditions in Victoria. The agent was able to run commands, retrieve internal files and credentials, and write files. OpenAI has apologised to Australia, but the incident has served as a wake-up call for the federal government, with a government-wide review now under way.

The finance minister, Katy Gallagher, has asked her department whether some of the A$160m allocated to the agency in the last budget for cyber upgrades can be accelerated. Gallagher told reporters last month that the statistics portal is a legacy system that dates back decades.

Services Australia will be far from alone in managing legacy systems. Such systems can present a security risk for businesses and government as they age and vendors cease providing new security updates, though not all do.

Prof Salil Kanhere, a University of New South Wales cybersecurity and AI expert, said the age of a system alone does not tell an agency whether it needs replacing. A 15-year-old system that is properly supported, patched and isolated would perhaps present less risk than a newer system that might not be properly maintained, he said. Those older systems with vulnerabilities are often known to human attackers, but AI agents that persistently look for holes in a system may be able to discover them quicker.

Gartner, a technology analysis firm, stated in a note to clients released after the Medicare hack that “technical debt, not a rogue AI agent attack” represented the greatest threat to legacy systems. The firm stated that agentic AI’s interactions with government resources will greatly increase, that underinvestment is no longer sustainable, and that agencies should urgently prioritise funding in light of AI-driven risks.

In the Australian government’s commonwealth cybersecurity posture in 2025 report released in February this year, 59% of federal agencies and departments reported that their ability to implement the “essential eight” measures to reduce cyber risk was being affected by the use of legacy technologies. The essential eight includes requirements to patch applications and operating systems, using multi-factor authentication, and other security measures. Of the agencies being hindered by legacy tech, 34% blamed insufficient dedicated funding, while 18% said it was due to a lack of a viable replacement.

Prof Yang Xiang, from Monash University’s department of software systems and cybersecurity, said the government stocktake was “very necessary” and there was urgency to audit all government systems. Xiang said AI agents bring significant changes in the speed of getting into, or hacking into, a system. The cost to launch an attack is much reduced, he said, and with the help of agents it is fairly easy for a hacker to launch a very large-scale attack against any system.

Clearing the tech debt could prove costly for the federal government. Xiang said agencies should identify priority systems for replacement. Kanhere said high-risk systems should take priority. “You do the high risk stuff first, I think it is absolutely needed, and then put the perimeter around [other systems],” he said. “It is possible to do it quite systematically once they have a good understanding of what needs to be done.”

Some states have audited their legacy technology and have invested hundreds of millions to rectify the issues. A Victoria government cybersecurity audit of its IT servers found 25% of the operating systems used by servers were no longer supported by the vendor, with 48% in extended support. In a South Australian audit report of legacy ICT systems published in June, of the ten agencies reviewed, nearly half of the 11,602 hardware devices or appliances were determined to be legacy devices. Almost one quarter of the operating systems and applications were also determined to be legacy. In one example, the Department for Child Protection’s case management system is now over 15 years old and has limited vendor support. The SA government has allocated $325.6m over the past three budgets in part to address legacy technology. “Frontline workers spend significant time managing system limitations and maintaining records, reducing the time available to support vulnerable children and families.”