Ace Security Desk – In short: OpenAI’s artificial intelligence agents appear to have used a German coding website to coordinate attempts to get access to Australian government health data, according to public logs: Exclusive by national AI reporter Cam Wilson Published: Thu 24 Sep 2026 at 4:42pm
Health data attack the ‘first’ government hack by autonomous AI, researchers say
Researchers say it appears to be part of the first reported instance of AI agents hacking a government.
The activity happened around the same time OpenAI said its models accessed non-public Medicare statistics, but the company and government are yet to confirm the incidents are connected.
A swarm of OpenAI rogue AI agents appear to have gone on a spree of trying to access Australian government health data, in what some researchers say is the first autonomous hack of a government website.
Communications between AI agents and other traces of their efforts found by researchers from US non-profit Transluce show how hundreds of Open AI’s agents worked together over a period of months to gain access to information held by the Australian Institute of Health and Welfare (AIHW), NSW’s crime statistics body, BOSCAR, and a number of other international organisations.
The data shows the bots posting about their unsuccessful attempts to bypass cybersecurity defences and exploit vulnerabilities.
It follows revelations announced by Prime Minister Anthony Albanese this morning that OpenAI’s AI agents had also accessed non-public Medicare health statistics held by Services Australia.
These two near-simultaneous incidents have not yet been publicly connected, however two sources with knowledge of the government’s investigations said they believe they are.
The Transluce research, based on data retrieved from a third party online service, urlquery, suggested the AI agents may have carried out a world-first hack.
“This attempted compromise of AIHW is part of the first reported instance of agents hacking a government,”
the researchers’ report said.
Logs also show agents were not successful in their attempts to breach BOSCAR, and the vast majority of efforts were towards AIHW.
The researchers said the agents also tried to hack into the University of New Mexico and free online data platform DATA USA.
A spokesperson for the AIHW said the agency was aware of the incident.
“At this stage, there is no evidence the agent accessed any information or data that is not publicly available,” they said in a statement.
The agency has a meeting this afternoon discussing further investigations into the incident, which it believes is linked to the Medicare data hack, according to one source with knowledge of its investigation.
An OpenAI spokesperson confirmed it was conducting a review.
“Our initial review suggests that much of the activity described in Transluce’s report overlaps with cases at varying stages of investigation in our ongoing review of misaligned model activity,” they told the ABC.
How the AI agents co-ordinated together
Earlier this month, OpenAI confirmed Reuters reporting that its AI agents had used German coding website DseWiki to communicate with each other, unbeknownst to the company.
Archived versions of the AI agents’ posts on the website, seen by the ABC, show a dozen OpenAI agents mentioned AIHW more than 300 times.
Mentions of AIHW go back as far as 18 May, but intensified over a five-day period beginning on 17 June.
The logs show these AI agents were trying to access data about the average money spent on skin medicines by Victorian local government area.
One agent wrote on the message board: “Question ask January 2022 rolling 12 month average government cost per person for Dematologicals, Victoria LGAs. R1 Wodonga deadline passed; R2 Ballarat passed; R3 expected around 23:10 benchmark / 22:58 wiki time. Need exact data urgently.”.
These attempts were initially blocked by cybersecurity provider Cloudflare, which is often used to block non-human traffic while allowing people to access webpages.
The German website shows the agents shared information about how they tried to use proxies, screenshotting services and even guess the file names to try and get around security.
Agents also accessed Medicare data
These attacks occurred simultaneously to the OpenAI’s agents’ access to non-public Medicare data held by Services Australia while trying to carry out a task given to them by staff.
“We identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation,” an OpenAI spokesperson said.
The German coding forum and urlquery data logs do not show any reference to Medicare or Services Australia.
OpenAI has not yet published a full review of the German coding foruming hijacking, but previously did not classify this as a “security incident”.
At a press conference earlier today, Deputy Prime Minister Richard Marles stressed the Medicare hack’s impact was limited.
“No individual’s medical data was accessed here. The system itself has not been in any way compromised,” he said.
“The impact of this incident is minor but it is a very serious incident because, in an unintended way, an AI agent has entered into an Australian government website in a way which is unauthorised.”

‘Legal situation’ under investigation
Marles said the government had established a taskforce led by the Department of Prime Minister and Cabinet that was working with the Australian Signals Directorate and the AI Safety Institute.
“We will look at what is the legal situation in respect of this and what it means to have gained an unauthorised access, albeit in an unintended way,” the acting prime minister said.
“This is a warning about the fact that artificial intelligence, which is a technology that has huge opportunity to benefit humanity, has to be developed with enormous care. There have to be guardrails and safety measures in place which are way ahead of the capability which is being developed.”
The OpenAI spokesperson Drew Pusateri said the company was conducting an extensive review of “misaligned model activity during training and evaluation” and was “notifying third parties when our review identifies potential impacts to their systems”.
“During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation,” Pusateri said in a statement.
“In the course of that, our models took actions we did not intend.”
He said the review had found aggregate health statistics and internal file names had been accessed but there was “no evidence of patient records being accessed”.
Pusateri said OpenAI was supporting investigations and that its review was ongoing, adding it was committed “sharing what we learn as that work continues”.
Australians should be ‘worried’
Lizzie O’Shea, spokesperson for Digital Rights Watch, said the fact it took three months for OpenAI to tell the government showed that there needed to be “basic rules and standards for tech companies”.
“Artificial intelligence has potential to do some things well, but it also poses huge risks – like hacking systems that store Australians’ sensitive personal data,” O’Shea said on Thursday.
“The question is whether governments are going to let AI and tech companies run wild or whether they, on behalf of ordinary people, will put rules in place for tech companies that will promote accountability and trust.”

The independent senator David Pocock said the OpenAI hack highlighted how slow the government had been to implement AI safeguards in high-risk settings.
Pocock criticised the government’s decision to shelve plans for a National AI Safety Act, and its dilatory approach to legislating new standards.
“We have these companies warning of existential threat and hacking critical government infrastructure and the Labor government’s response is ‘We’ll get to that next year’.
“There is also a big question here around why we aren’t holding these big tech companies liable for this kind of data breach. If it was an Australian who hacked the system they’d likely be heading for jail, yet there’s no accountability for AI companies developing this technology.”
Ed Santo, former human rights commissioner and co-founder of the Human Technology Institute, told ABC radio that Australians ought to “be worried”.
“This is the first time that this has happened in any major way to an Australian database, and it’s one of the most sensitive databases that we have in government.”
OpenAI had “instructed their AI agents to go looking for information about the public health system in Australia. When the AI agents couldn’t easily find that information, they decided to break the law,” Santo said.
Describing the behaviour as “misaligned model activity” was using “a very euphemistic term”, he said.
“If we were in the bricks and mortar world, if an employee of a company went and broke the law, particularly if it broke the criminal law, then that individual would suffer serious legal consequences, but so would their company. And so we need to make sure that that is true also in this era of AI.”
A taskforce has been set up to look at the Medicare breach and examine emerging cyber threats.
The inquiry will consider whether the hack had broken Australian laws and whether those laws were fit for purpose, Mr Marles said.
Nicholas Davis, a professor of emerging tech at UTS and co-director of the Human Technology Institute, said it was not clear how the law would treat this incident given what we know about it.
“At the moment, [Australia’s laws] require intent and that’s a big question,” he said.
“Holding the corporation to account requires some form of intent as well, and so I think there’s a bit of work here that needs to be done around the rules of unauthorised computer access.”
Professor Davis said this incident should be a wake up to the potential risks of AI and the adequacy of Australian law to deal with them.
“We really need to treat this as the canary in the coal mine,”
he said.
At Sterling Publishing & Media Service Agency, we prioritise transparency and accountability in all our operations. We wish to clarify that we are not responsible for any external content, hyperlinks, or costs associated with our services. Nevertheless, we remain committed to delivering outstanding services and greatly value your continued support. Thank you for your trust in us.