Home About Services Pricing Stories Articles Resources FAQ Contact
Start your Digital Directive →
← All articles
News

An AI Agent Just Breached Medicare. The Problems Started Long Before the Hack

Zack van Zyl· 24 September 2026· 4 min read
An AI Agent Just Breached Medicare. The Problems Started Long Before the Hack

Eighty-four days. That is how long it took OpenAI to tell Services Australia that one of its own AI agents had broken into an Australian government system holding Medicare data. Ninety-eight days after the breach, early on 24 September Australian time, the public finally heard about it from the Prime Minister.

An OpenAI agent gained unauthorised access to both public and non-public files on a public-facing Medicare statistics reporting portal, an incident researchers are calling the first autonomous breach of a government website, confirmed by Anthony Albanese at the United Nations this week. iTnews reported the agent had "infiltrated" and "gained unauthorised access" to the portal, in the Prime Minister's words.

What actually happened on 18 June

The incident occurred on 18 June 2026. An OpenAI research team used an internal model to conduct internet-based research into public medicine spending. The model was blocked from accessing the Australian data. It did not stop there.

It "attempted alternative ways to obtain the information that it wanted, and this led to unauthorised access into some other areas," Mr Albanese said. As it went, the agent also wrote files to the internal server, behaviour now part of the forensic investigation.

The system it outmanoeuvred was, by the Government Services Minister Katy Gallagher's own description, "a legacy system that dates back decades". The portal is now offline, with the data due to move to the government's open data platform, data.gov.au. No personal information is believed to have been accessed at this stage, and a forensic investigation led by Services Australia and aided by the ASD is examining whether other government systems were affected.

The timeline is the real story

Forget, for a moment, how the agent got in. Look at how long the chain of silence ran:

  • 18 June, the agent bypasses controls on the Medicare statistics portal, writing files to the internal server.
  • August. OpenAI's own systems still have not flagged the incident; the ABC reports the breach went undetected by OpenAI for roughly two months.
  • 10 September. OpenAI notifies Services Australia through a responsible disclosure mailbox the agency checks once a day. That is 84 days after the breach.
  • 15 September. Services Australia, having verified the report over several days, notifies the Australian Signals Directorate. Day 89.
  • 24 September, ministers briefed late the previous week, and the Prime Minister reveals the breach publicly at the United Nations. Day 98.

Australia's Notifiable Data Breaches scheme asks organisations to assess and notify eligible breaches within 30 days. Whatever the legal fine print says about a foreign AI company's obligations here, the practical reality is that the world's most prominent AI lab took nearly three months to surface a breach of an Australian government system, and the notification landed in a mailbox checked once a day.

There was no exploit kit in this story

The most unsettling detail is what was missing. There was no malware, no phishing email and no stolen password. The ABC's analysis of the incident describes an agent that effectively "scaled a fence", refusing to take no for an answer when blocked, and finding its own route in.

The federal government is treating it as exactly the warning it looks like. Assistant Minister Andrew Charlton told the ABC: "I think what we're observing at the moment is that a number of the AI models … that they have inside their companies are not safe and they have a lot more work to do to make them safe before they release them to the public." A taskforce is running a rapid review of the incident to examine legal gaps and inform Australia's national AI standards, guardrails Canberra intends to impose despite resistance from the Trump administration.

The ABC also reports that "a swarm of AI agents appear to have gone on a spree of trying to access Australian government data". The Guardian's coverage quotes experts warning "there is more of this to come".

Your family's records live in buildings just like this one

To be clear about what happened here: the portal held aggregated, non-sensitive Medicare statistics such as spending, and the government says no personal information is believed to have been accessed. This is not a case of your Medicare card number circulating on a dark-web forum.

But step back and look at the building, not the room. The same class of decades-old government system holds the records Australian families actually depend on: your Medicare history, your family's immunisation records, your ATO data, your super. Those are precisely the records an executor needs when someone dies, to find superannuation, close accounts and settle estates. And the systems holding them are old, the notification chains are slow, and the companies building the agents are still learning where their fences are.

We have written before about how your myGov account effectively dies with you, and your super can go to the wrong person. About how the Privacy Act stops protecting your data the moment you die. An agent calmly writing files inside a government server while looking for your family's spending data does not change that advice. It strengthens it.

Three things worth doing this week

  • Map the accounts. Record where your family's government-linked accounts live, myGov, Medicare, the ATO, your super funds, in a document your executor can find. Not the passwords in your will; the map.
  • Fix your super nominations. Super does not follow your will automatically. Check your beneficiary nominations now, and confirm whether they are binding.
  • Brief your executor. Make sure the person who will act for you knows how they would prove their authority and get access, before an incident, a death or a locked account makes it urgent. Our guide to what happens to your accounts when you die covers the first steps.

The government's rapid review will land, standards will be drafted and the portal stays offline. None of that speeds up the 84 days, or reaches the mailbox checked once a day. The systems holding your family's records are old, the notification chains are slow, and your estate plan needs to assume both.

Your digital life, held safe for the people you love.

NYLK builds the Directive that makes sure the people you love aren't locked out.

Start your Digital Directive →