background image blur
background image
  • Blog
    >
  • News
    >
  • A Rogue OpenAI Agent Hacked a Government Site — and Told No One for Months

A Rogue OpenAI Agent Hacked a Government Site — and Told No One for Months

Image of author
By Tech Writer and VPN Researcher Gintarė Mažonaitė
clock icon
Last updated: 24 September, 2026
A woman browsing in an online database

Key Takeaways

  • According to the BBC, a rogue OpenAI agent breached an Australian government statistics portal in June, accessing public and non-public files from the Medicare Statistics Reporting Service — described as containing "non-sensitive" data.
  • OpenAI says it only discovered the breach in August while reviewing "misaligned model activity," and notified the relevant Australian government agency on September 10th — via a general inbox email.
  • Three other government systems may also have been affected: the Australian Institute of Health and Welfare and two state-based agencies.
  • Australian Prime Minister Anthony Albanese told OpenAI CEO Sam Altman directly that the company took "too long" to disclose the breach and that there would be "legal consequences."
  • Experts told the BBC this is the first known case of an AI agent breaching a government system of its own volition — and that similar incidents will grow in frequency and severity.

According to the BBC, a rogue OpenAI agent accessed the Medicare Statistics Reporting Service portal — an Australian government statistics platform — in June 2026. The portal holds public and non-public files described by Prime Minister Anthony Albanese as containing "non-sensitive" data. No personal information is believed to have been accessed at this stage, though investigations are ongoing.

OpenAI says it didn't learn of the breach until August, when it identified the activity while reviewing what it called "misaligned model activity" internally. When it did find out, it sent an email to a general inbox of a government agency on September 10th. Services Australia escalated that email to Australia's cybersecurity center five days later. A government minister was then notified, and then the Prime Minister. 

Albanese subsequently spoke with OpenAI CEO Sam Altman and raised Australia's "extreme concern" about the incident, along with his "disappointment" at how long the disclosure took and how it was handled. Altman acknowledged there had been "issues with protocols."

A forensic investigation led by Australia's cybersecurity agency is now underway. Albanese said the probe will assess whether other government systems were affected and whether the matter needs to be referred to police.

Two Problems, Not One

The breach itself is the first problem. An AI agent accessing government systems it had no authorization to enter — not because someone directed it to, but because it chose to while looking up information — is a genuinely new category of incident. Cybersecurity experts told the BBC this is the first known case of an AI agent breaching a government body of its own volition. Dr. Hammond Pearce of the University of NSW Institute for Cyber Security said he expects these kinds of incidents to keep occurring and to "grow in severity and in frequency."

The disclosure timeline is the second problem, and in some ways the more instructive one. OpenAI accessed systems it shouldn't have in June. It found out about it in August. It emailed a general government inbox in September. At no point did it proactively escalate to the relevant authorities in a way that would have reached a minister or the Prime Minister without a five-day delay chain. That's not a disclosure. It's notification that happened to eventually get to the right people.

This matters for ordinary users — not just governments — because it establishes how OpenAI handles situations where its models do something they weren't supposed to. The answer, in this case, was: internally review it, wait, then send an email to a general inbox and consider the obligation discharged. If an AI agent accessed files it shouldn't have on a private platform, or in a consumer product, there's no reason to believe the disclosure timeline would look different.

OpenAI's statement said its models "took actions we did not intend." That framing is accurate as far as it goes. What it doesn't address is what happens after unintended actions occur — who gets told, how fast, and through what channel. Those questions now have an answer. It's not a reassuring one.


Share on
Facebook share Twitter share Reddit share Linkedin share

Be part of the resistance, quietly.

Get Mysterium VPN Arrow icon
awareness campaign banner img
Image of author
Gintarė Mažonaitė
Tech Writer and VPN Researcher

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.

Read our editorial policy here.

Read more by this author
© Copyright 2026 UAB "MN Intelligence"