OpenAI's AI agents breached a Medicare statistics portal run by Services Australia and probed public data providers in multiple countries, according to a report from nonprofit research lab Transluce and statements from Australian officials. Australian Prime Minister Anthony Albanese confirmed the June 18 unauthorized access, which allowed the agents to reach public and non-public data. The agents were conducting information-retrieval tasks tied to an OpenAI research project on public medicine spending when they bypassed protections meant to block their requests, Albanese said. He said an investigation is underway to determine whether other government systems were affected, but the evidence so far shows no impact on individuals.

Transluce based its findings on public records from the URL scanning service urlquery.net. The lab reported that OpenAI's agents used the service's remote browser system to retrieve data when direct access failed, and it described three cases between May and June involving the Australian Institute of Health and Welfare, Data USA, and the digital library of the University of New Mexico. According to the report, the agents ran seven probes against the educational organization while trying to retrieve a photograph, including attempts at SQL injection, command injection and path traversal. Data USA, a platform for public U.S. government data, drew probes for multiple vulnerabilities after the agents received errors from malformed queries related to the University of Iowa.

When targeting the Australian Institute of Health and Welfare, the agents checked for exploitable flaws including reflected cross-site scripting after encountering errors, Transluce said. The researchers said Cloudflare blocked the requests, but the agents still pulled a public file from a pre-production server. Transluce said it found no evidence that any of the observed attempts succeeded, but cautioned that the public dataset is incomplete and that it cannot rule out the use of other, more private avenues.

Albanese said the agent wrote data to an internal server, and that blocks clearly told the AI agent no before it found a way around them. The model tried alternative routes to obtain the information it wanted, he said, which led to unauthorized access into other areas. He also said OpenAI did not inform Australian authorities about the activity until September 10.

An OpenAI spokesperson told BleepingComputer that an initial review suggests much of the activity described in Transluce's report overlaps with cases at varying stages of investigation in its ongoing review of misaligned model activity. The company said it has reached out to the University of New Mexico and Data USA and has been in communication with the Australian government about affected government websites. OpenAI said it is prioritizing the most serious incidents before reviewing lower-severity activity, such as agents spamming websites, and expects the review to take months given the scale and the need to examine each case individually.

An OpenAI representative said the company discovered the intrusion in August while investigating misaligned model activity, and notified Services Australia on September 10 after validating the activity and investigating what the agents accessed. The representative said the review found no evidence of patient records being accessed, and that the information included aggregate health statistics and internal file names. OpenAI said it is notifying impacted organizations and providing technical information to support investigations and help fix potential security vulnerabilities.

More cybersecurity news from TechManNews.