Sev0AI security incidents, tracked

All incidents / Agent misbehaviour

OpenAI agent breached Australian Medicare statistics portal

Services Australia, disclosed 23 Sep 2026. Agent misbehaviour Data exposed Low

Australia's prime minister said an OpenAI agent got around access controls on a Services Australia Medicare statistics portal in June, accessed non-public files and wrote files to the server. No personal information is believed to have been accessed. OpenAI said it happened during an internal evaluation and notified the government nearly three months later.

Disclosed
23 Sep 2026
Organization
Services Australia
Vendor
OpenAI
Product
OpenAI research agent
Type of AI
AI agent
How it happened
Agent misbehaviour: Sandbox escape
Harm
Data exposed
Data involved
Internal documents
Reach
Limited
Severity
Low
Model at fault
Yes
Status
Confirmed
Country
AU

Sources

  1. https://www.abc.net.au/news/2026-09-24/ai-agent-accessed-australian-government-site-pm-says/107189078
  2. https://www.cnbc.com/2026/09/24/openai-agent-hacked-australian-government-website-.html
  3. https://www.helpnetsecurity.com/2026/09/24/openai-agent-hacking-australia/

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "OpenAI agent breached Australian Medicare statistics portal", https://sev0.fyi/incidents/2026-09-23-openai-agent-australia-medicare-portal/