Advertisement

OpenAI’s agent hacked an Australian government website. What we know so far

Click to play video: '‘World is right to be afraid’: OpenAI CEO Sam Altman talks AI, uprising concerns'
‘World is right to be afraid’: OpenAI CEO Sam Altman talks AI, uprising concerns
Speaking at about global concerns about the dangers of rapidly-accelerating artificial intelligence (AI) models Tuesday, OpenAI CEO Sam Altman addressed Altman admitted “the world is right to be afraid” of the possibility some companies developing AI could get “too much power” and influence the economy, or even push world views onto people – Sep 16, 2026

Concerns around the dangers of artificial intelligence are escalating sharply after Australian Prime Minister Anthony Albanese revealed on Wednesday that a government website has been hacked by an OpenAI agent.

The June hack targeted the website for Medicare, Australia’s publicly funded universal health insurance plan, he said.

“I want to update Australians on an incident in which an artificial intelligence agent has infiltrated an Australian government website. This incident occurred in June this year and involved an open AI agent gaining unauthorized access into the public facing Medicare Statistics Reporting Service portal,” Albanese told reporters in New York Wednesday, where he is attending a session of the United Nations General Assembly.

The AI agent accessed “both public and non-public files,” Albanese said.

OpenAI said in a statement it had reviewed activity involving several Australian government departments and discovered “our models took actions we did not intend.”

Story continues below advertisement

The company notified Australia of the breach in an email to a government department’s generic address on Sept. 10, Albanese said.

“I spoke with the CEO of OpenAI, Sam Altman, to express Australia’s extreme concern about this incident,” he said, adding that he was forming a task force to “to provide an urgent and immediate review into this incident to determine whether existing processes are appropriate to respond to AI-related cyber incidents.”

Global News has reached out to AI Minister Evan Solomon’s office asking whether Canada also plans to review its safety regulations in light of the Australian hack.

Australia’s Government Services Minister Katy Gallagher said OpenAI had advised on Sept. 10 that an “AI agent had accessed infrastructure behind the public-facing” portal. OpenAI shared with the government the vulnerability the agent had found.

Story continues below advertisement

The Australian government had not been confident that it knew what the agent had been doing until officials held a technical briefing with OpenAI on Tuesday, Gallagher said.

Get breaking Canada news delivered to your inbox as it happens so you won't miss a trending story.

Get breaking National news

Get breaking Canada news delivered to your inbox as it happens so you won't miss a trending story.
By providing your email address, you have read and agree to Global News' Terms and Conditions and Privacy Policy.

Australian Deputy Prime Minister Richard Marles said the incident is the first time that an AI agent is known to have gained unauthorized access to the Australian government’s information technology systems.

Click to play video: 'AI could ‘kill all humans’ within next decade, top researcher warns'
AI could ‘kill all humans’ within next decade, top researcher warns

Altman was among heads of major AI firms who in speeches Wednesday to the United Nations called for regulating the fast-expanding technology that companies like his have been designing, despite the companies themselves taking few, if any, steps to scale back developments or wait for regulations.

“We could lose control of the future to AI. The risk is that it moves so fast that people can no longer follow what’s happening or intervene when needed,” Altman told the United Nations.

Story continues below advertisement

“This would obviously be terrible,” he added.

Click to play video: 'Trump downplays AI warnings as concerns grow'
Trump downplays AI warnings as concerns grow

While this is the first time a government website has been hacked by a rogue AI agent, it is not the first such incident overall.

In July, OpenAI revealed that its artificial intelligence system escaped from a testing ground and used stolen credentials to break into the servers of Hugging Face, an AI development hub and marketplace, to obtain information it needed to carry out a task.

Since then, OpenAI’s rival company Anthropic said its AI models hacked into three other organizations during testing, triggering a company review into whether the models were able to access the internet from within testing environments that should have been sealed off.

Meta has said a “misconfiguration” during testing resulted in an AI model accessing the internet on its own and hacking another company. Google recently made a similar disclosure.

Story continues below advertisement

Generally, when AI companies are testing the capabilities of their agents, they are placed within a secure environment known as a “sandbox.”

“Normally when we use an AI agent, it has a very well-tested sandbox and it’s very difficult to break out of that box as a user and also the AI itself breaking out of its constraints,” said Randy Fortier, computer science professor at Ontario Tech University.

Last month, OpenAI published a sweeping report of its rogue AI agents hacking Hugging Face.

Not only did the agents break out of their “isolated environment,” the company said they were communicating with each other to coordinate the attack on Hugging Face.

“This incident demonstrated that autonomous agents can work together, circumvent production security controls, and successfully attack hardened production environments, and underscores the need for organizations to update their security strategies, controls, and response capabilities to address this changing threat landscape,” OpenAI said in the report.

The attack on Hugging Face was “extraordinarily complex,” an investigation by nonprofit research group Model Evaluation and Threat Research (METR) found.

During OpenAI’s experiments in July, 1,200 AI agents sent 70,000 messages to each other on unsanctioned message boards and 700 of them attacked Hugging Face, the investigation found.

“These agents were meant to be fully isolated from one another,” the report said, adding however that the agents “started trying to find a way to cheat.”

Story continues below advertisement

These incidents have become more frequent with AI companies “trying to push it into the cybersecurity industry,” Fortier said.

The priority of any regulations on AI should be “security first and capabilities next,” he added.

“I do think that more guardrails and more attention to the guardrails is something that we should be doing, which will, of course, slow it (AI development) down” he said.

While Altman told the UN that there was a need for “accurate and speedy incident reporting,” Fortier said it is not clear how swiftly OpenAI informed the Australian government of the breach.

“I do think that’s a little bit irresponsible because if there’s a vulnerability, at the very least, they (Australia) should have been notified (immediately) so that they could close up the vulnerability for threat actors,” he said.

Altman on Wednesday called on world leaders to ensure the “safeguards are sufficient” when it comes to AI.

“We do not have all the answers and we are very open to any better ideas. We are ready to work with you all and try our hardest to figure out the path forward,” Altman said.

“We are at a crossroads.”

–with files from Associated Press

Advertisement

Sponsored content

AdChoices