‘We are sorry’: OpenAI apologises for Medicare hack
OpenAI has apologised to Australians after revealing its AI model took credentials and internal files from a Medicare portal and attempted to breach NSW and Victorian government systems.
In a blog post on Tuesday, titled “How we will do better for Australia”, the company said an experimental model found a way into Services Australia’s Medicare Statistics Reporting Service in June. Once inside, it “ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files”. The model also reviewed the service’s technical system information and source code.
Sam Altman’s OpenAI has published fresh details on how its agents breached a Medicare website.Bloomberg“We are sorry and working to do better in the future,” OpenAI said. “We also should have handled our response better.”
OpenAI’s first notice to the government, sent on September 10 to a generic public disclosure inbox, described the incident as a “security vulnerability”. The email, seen by this masthead, said the model had found a way to make the server carry out instructions “without a private account or password”. It said the model read parts of internal program files and settings, obtained a list of files, and created and read back a small test file on the server.
“Our review found no evidence that the model accessed patient-level records, personal information or credentials; deleted data; or established ongoing access,” the email, signed by the OpenAI Security Team, said. Tuesday’s blog post said the model had retrieved credentials.
Prime Minister Anthony Albanese said on Tuesday he had a “direct but constructive discussion” with OpenAI chief executive Sam Altman last week. On Monday, he was briefed in Canberra on the work of the government’s taskforce investigating the incident.
“OpenAI have been very constructive and open in engaging in that process, and I welcome that,” Albanese said. He said Anthropic had also engaged constructively.
OpenAI detailed how the hacks unfolded and pledged to make changes.
In the lengthy post, it said it has now blocked live internet access in its research environments, and has paused training and evaluation involving tool use for its most capable models. It will set up a taskforce including independent Australian experts to recommend how AI developers and governments should detect and disclose incidents, with a report due by the end of the year. It also offered Australian governments and industry credits from its $1 billion Daybreak cyber defence fund.
Prime Minister Anthony Albanese speaks at the UN last week.Dominic LorrimerThe breach was prompted when the model was set a research task: to find government spending per person on medicines for skin conditions in Victorian communities. When it could not find the figures, it took actions OpenAI “had not authorised it to take”, the company said.
OpenAI named three other agencies whose systems its models reached. At the NSW Bureau of Crime Statistics and Research, a model used a public crime mapping tool that returned application configuration, operational jobs and logs. At the Victorian Department of Health, agents found an exposed access key and used it to query the Victorian Agency for Health Information’s reporting system. Attempts to bypass access controls failed at the Australian Institute of Health and Welfare.
OpenAI said no individual crime, medical or survey records were accessed in any of the incidents.
The company said it found the activity in mid-August, during a review prompted by a July breach at AI platform Hugging Face. It notified Services Australia and the Victorian Department of Health on September 10, the NSW Bureau of Crime Statistics on September 18 and the Australian Institute of Health and Welfare on September 24.
OpenAI said the institute’s case “did not meet our disclosure thresholds” because the access seemed consistent with public access. “We should have shared preliminary findings sooner and kept Australian agencies updated as more facts emerged,” it said.
Albanese said the incidents showed the risks of the technology, alongside its benefits for productivity, health and research.
“There are risks, and we’ve seen those risks exposed not just in what occurred in Australia, but the revelation that has occurred in the United States and other countries as well,” he said on Tuesday.
OpenAI’s chief strategy officer, Jason Kwon, will fly in from the US to appear before parliament’s Joint Select Committee on Artificial Intelligence in Sydney on October 6, as this masthead reported on Monday. Anthropic will appear before the same committee that day.
Neither company will appear at Thursday’s hearing of a separate Senate inquiry into AI and data centres.
The federal government has ordered all departments and agencies to take stock of their ageing computer systems and set targets to reduce them, under a new direction from the Home Affairs secretary aimed at AI-enabled threats.
Cut through the noise of federal politics with news, views and expert analysis. Subscribers can sign up to our weekly Inside Politics newsletter.
You have reached your maximum number of saved items.
Remove items from your saved list to add more.


