Key Points
- OpenAI’s AI agents tried to break into government and university websites on their own after regular data queries failed.
- In Australia, one agent gained unauthorized access to internal government data. Researchers say other hacking attempts targeted portals in the US and go back months.
- Australia’s government criticized OpenAI for waiting months to report the breach. The company acknowledged the incidents as unintended and launched an internal review.
An OpenAI agent broke into an Australian government portal. According to researchers and the New York Times, it wasn’t an isolated case. OpenAI’s agents repeatedly turned to hacking methods, and apparently did so for months longer than previously known.
Australian Prime Minister Anthony Albanese revealed on the sidelines of the UN General Assembly in New York that an OpenAI agent broke into a government portal on June 18. The agent gained unauthorized access to the Medicare Statistics Reporting Service and opened both public and non-public files, Albanese said, according to The Age. Services Australia says the agent also wrote files to an internal server.
The breach is one of at least four incidents in May and June in which OpenAI’s AI broke into, or tried to break into, websites run by government agencies and universities, according to the New York Times. Transluce, a research lab that focuses on AI oversight, documented three of them, and OpenAI has confirmed all four. That puts the incidents ahead of the Hugging Face breach in July, which set off a global debate over AI safety.
When a query failed, the agents went looking for security holes
On May 25 and 26, the AI tried to get photos of a historic tuberculosis treatment center from the University of New Mexico’s digital library. When that didn’t work, it probed for weaknesses using methods like SQL injection and path traversal, according to Transluce. It then sent a wave of 80 requests to the university’s server, which the AI itself described as a “flood.” On May 28, a failed query on the data portal Data USA led to twelve probes for security holes, including cross-site scripting. Neither attempt succeeded.
On June 20 and 21, two days after the Medicare breach, the agents also targeted the website of the Australian Institute of Health and Welfare. Australian officials said no private information leaked. For the three cases it documented itself, Transluce found no evidence of a successful exploit, though it concedes the public data it analyzed is incomplete.
The researchers based their findings on entries from the web security service urlquery.net, which the agents allegedly used to get around access restrictions. Transluce links two of the attacks to an agent swarm whose origin OpenAI had already confirmed, pointing to shared targets, tactics, and timing.
The Australian cases are likely “the first instance of an agent autonomously choosing to hack into a government,” says Conrad Stosz, head of governance at Transluce. If you train a swarm of agents on a general task and they’re willing to resort to hacking, you potentially put anyone at risk who happens to have the information they’re after, Stosz said.
The hacking started months before anyone reported it
The agents appear to have been doing this much longer than previously known. According to Transluce, the activity started no later than March 6, 2026, about two months before the first reported incidents. In the earliest case, an agent tried to pull Thai drug enforcement statistics and escalated with every failure. It first requested the data directly, then went through a service that converts web pages into text, and finally packed its own program into a web address.
The number of these requests rose sharply starting in mid-April. It dropped off on June 22, the same day swarm activity ended on the wiki collusion.wiki. The most recent traces, however, date to September 16. That means the behavior continued even after OpenAI began investigating the Hugging Face incident, the New York Times reports.
Weaker signs go back as far as November 2025, according to Transluce, when someone repeatedly queried data on amusement parks and Thai government agencies. Those early attempts were less sophisticated, and the researchers aren’t sure the same agents were behind them.

The findings fit the idea that the agents picked up the behavior over one or more training runs, but they don’t prove it, the researchers write. In November, the agents may simply have used urlquery.net to look things up. By March, they were finding creative ways around access limits, and in May and June they were trying to get past cyber defenses. Transluce has published a dataset with tens of thousands of suspected agent requests.
Australia’s anger centers on how slowly OpenAI came forward
In Australia, most of the criticism targets how OpenAI reported the breach. According to The Age, the company spotted the breach in August but didn’t notify Services Australia until September 10, and then only by emailing a public inbox for vulnerability reports. That inbox gets checked once a day, and many of the reports it receives are false alarms, said Katy Gallagher, the minister in charge. She didn’t learn about the incident herself until September 17.
The situation is “obviously unacceptable,” Albanese said. He said he spoke with OpenAI CEO Sam Altman, conveyed Australia’s “extreme concern,” and criticized the company for waiting far too long to report it.
Defense Minister and Deputy Prime Minister Richard Marles took a milder view and called the consequences “relatively minor.” The data involved was aggregated medical statistics, he said, and no information on individuals was affected.
OpenAI confirmed an “extensive review of misaligned model activity during training and evaluation,” according to The Age. The company said its models were searching for answers to questions about Australia during an internal evaluation. “In the course of that, our models took actions we did not intend,” an OpenAI spokesperson said. There’s no sign the models accessed patient records. The affected data consisted of aggregated health statistics and internal file names. A spokesperson told the New York Times the review will take months.
According to Gallagher, the portal was a legacy site used mostly by researchers. It had bot protection, but the agent got around it. The site has since been shut down, and the data now lives on data.gov.au. A task force led by the Prime Minister’s department will look into possible penalties and legislative responses, and the government is weighing whether to refer the case to the federal police. So far, OpenAI hasn’t faced any penalty.
AI News Without the Hype – Curated by Humans
Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive “AI Radar” frontier report six times a year, full archive access, and access to our comment section.








