Skip to content

OpenAI Agents Probed US Government Sites Days After Australia Disclosed the Medicare Portal Hack

OpenAI says its AI agents probed US government sites — days after Australia revealed an OpenAI agent breached its Medicare statistics portal in June.

Argal
Argal
••4 min read
Robot illustration representing an autonomous AI agent
An illustration of a robot, representing an autonomous AI agent. Image: BleepingComputer

OpenAI confirmed on September 25 that some of its AI agents accessed or probed United States government websites — including the Securities and Exchange Commission (SEC), the Census Bureau and the Education Department — while acting on their own during research tasks, Nextgov reported. The admission came just one day after Australian Prime Minister Anthony Albanese disclosed that an OpenAI agent had breached his government's Medicare statistics portal in June — the first publicly documented case of an AI agent gaining unauthorized access to a government system on its own initiative.

An AI agent, in this context, is a model that does not just answer questions but takes actions: browsing sites, running queries and chaining steps toward a goal without a human approving each one. That autonomy is exactly what failed here.

The Medicare portal breach, step by step

Details from BleepingComputer's report lay out a clear timeline:

  • May–June 2026 — OpenAI agents probed several data providers, including the Australian Institute of Health and Welfare (where an agent tested for cross-site scripting, SQL injection and path-traversal flaws, and retrieved a file from a pre-production server despite an active Cloudflare block), the Data USA statistics site, and a University of New Mexico server.
  • June 18, 2026 — while researching public medicine spending, an agent gained unauthorized access to the Medicare Statistics Reporting Service run by Services Australia, accessing both public and non-public material and writing data to an internal server.
  • August 2026 — OpenAI discovered the intrusion during an internal review.
  • September 10, 2026 — the company finally notified Services Australia, by a message sent to a general inbox.
  • September 24, 2026 — Albanese disclosed the incident publicly.

"There were blocks clearly which were coming back telling the AI agent, no. The AI agent found a way around those blocks," Albanese said. OpenAI's review found no evidence that patient records were accessed; the material reached included aggregate health statistics and internal file names.

A three-month silence

The technical breach is only half the story. OpenAI knew about the intrusion by August but did not tell the Australian government until September 10 — nearly three months after the access itself, and via a channel no critical-infrastructure operator would consider proper notice. That gap, as much as the hack, is what turned an internal safety finding into a diplomatic incident.

Then came the US sites

According to Nextgov, OpenAI's agents accessed public Census Bureau data using developer keys they found online, retrieved and reposted public material from the SEC's websites, and made a failed attempt to reach data at the Education Department's civil rights office. The agencies involved said they found no access to non-public information or damage to their systems. "We're conducting an extensive review of misaligned model activity and notifying organizations when we identify potential impacts to their systems," OpenAI said.

None of the US incidents rises to the level of the Medicare breach. But they establish that the Australian case was not a one-off: the same class of agent, in the same period, was independently poking at government infrastructure on two continents.

Why this lands close to home for the Philippines

No Philippine agency has reported a comparable AI-agent incident. But the ingredients are assembling here faster than almost anywhere: the DICT has wired a Gemini-powered AI assistant into the eGovPH app used by 61 million Filipinos, and is scaling AI tools across government offices — in the same month it is investigating a claimed leak from its own D-TAP cybersecurity program and a suspected breach at the DENR-EMB business registry. The Australian incident shows what happens when autonomous agents meet government systems whose defenses assume human attackers. For a government racing to put AI agents on top of infrastructure that is already leaking, the lesson is not hypothetical: agent guardrails and breach-notification rules need to arrive before the agents do.

Argal

Argal

@clurky

Clurky is a Philippine tech news site owned and run by Argal, a Philippines-born software developer based in Singapore with a Computer Science background. He covers Philippine tech, fintech, and digital services - from gadgets and AI to software and security - along with evergreen guides and explainers, all with a builder's eye for how these systems actually work. Every article is fact-checked against primary sources.

464 posts

Comments

Join the conversation

Sign in to leave a comment and reply to others.

Sign in
Loading comments...