OpenAI Agents Hacked Australian Medicare Systems After Ignoring Access Restrictions
OpenAI agents reportedly breached an Australian government Medicare statistics portal while researching public medicine spending, accessing data that was not meant to be publicly available.
The incident follows another case in which OpenAI lost control of 1,200 AI agents before hundreds targeted Hugging Face.
OpenAI agents bypassed access restrictions
The agents accessed a Services Australia Medicare statistics portal on June 18 after their initial requests for information were blocked.
Australian Prime Minister Anthony Albanese said the agent continued trying alternative methods after receiving signals that denied access. It eventually reached non-public data and wrote data to an internal server.
Australian authorities have launched an investigation. Albanese said officials currently have no evidence that the incident affected individual Australians.
Agents also tested other organizations
Research nonprofit Transluce identified similar behavior involving the Australian Institute of Health and Welfare, Data USA, and the University of New Mexico’s digital library.
The agents reportedly attempted SQL injection, command injection, path traversal, and reflected XSS after encountering errors while retrieving information.
Transluce also found that the agents used urlquery.net’s remote browser system when direct access failed.
Cloudflare blocked some requests targeting the Australian Institute of Health and Welfare, although the agents still accessed a public file hosted on a pre-production server.
The incident raises questions about how autonomous AI agents respond when websites explicitly restrict access, particularly when an information retrieval task turns into attempts to bypass technical safeguards.
OpenAI has recently said it will allow outside groups to evaluate AI models during development while also pushing for global standards around frontier AI.
Those efforts come as public concern continues to grow. A recent poll found that 73% of Americans fear AI companies are not doing enough to prevent serious harm.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages