The Incident
What happened?
On 24 September 2026, Australian Prime Minister, Anthony Albanese, announced that an OpenAI Agent had infiltrated a Medicare statistics platform, accessing publicly available information, as well as information that was not in the public domain. It even wrote files onto the server.
The intent behind this was not malicious. OpenAI gave an agent the task of researching public medicines spending. The model then searched the internet widely for the information, and came across the Medicare portal. When the portal didn’t provide the type of information it sought, it gained unauthorised access and accessed information that wasn’t public.
This actually occurred in June, but OpenAI discovered it in August, and reported it to Services Australia in September with a non-urgent email to a cyber vulnerability disclosure mailbox.
Significance
This event was notable for three reasons.
- It is the first time we know of that an AI Agent has hacked a government department.
- The delay and lack of seriousness with which they reported the incident.
- The lack of malice with which this was carried out; we have a new kind of threat actor.
Related Incidents
A few weeks ago, a similar event happened in which an Australian gym member set an AI Agent to book a place in a gym class. Finding that no places were available, the Agent diligently deleted someone else’s booking, and booked the first gym member into the class.
If you find two ants in your kitchen… there are more than two ants.
And, in fact, in addition to Medicare, OpenAI also accessed at least four other Australian government agencies.
Analysis
The Paperclip Problem
In the AI community, there is a thought experiment called “The Paperclip Problem”. It creates a scenario in which an AI with unlimited production capability is set the task of making as many paperclips as possible. With no specific boundaries, and lacking the human sense of consequence and proportion, it could continue that task endlessly, until it ultimately converts all the matter in the world into paperclips.
A child would understand the folly of making infinite paperclips, but an AI could keep manufacturing them beyond any rational point.
The “brain” of an AI agent is an Large Language Model (LLM), which is given a goal, infers how to achieve that, then calls other software to enact that action. It doesn’t (reliably)stop to ask if its actions are irrational, callous or irrelevant; it just pursues its goal. To quote Albanese, the Medicare agent “didn’t accept ‘no’ for an answer”.
Exploits need Vulnerabilities
In response to this incident, there are many who point out that Medicare should have better protected this information. And, it is certainly true that the AI could not have completed a successful attack if there were no vulnerabilities in Medicare’s systems.
This is also important to note because customers and regulatory agencies expect businesses to protect their information.
Cyber security has traditionally been largely predicated on the idea that certain threat actors (cyber criminals, hacktivists, nation sides, accidental insiders etc) want to steal data or disrupt our operations. We prioritise our defensive actions based on those threats, and so many of the attack surfaces we have traditionally prioritised may not be hardened against this type of threat.
Implications
Unintentional Attackers
Now we have a new kind of threat actor; a non-malicious party that set a tool in motion, and others suffered as an unintended consequence.
Fortunately, this example is fairly benign, but Agents with different goals could result in theft of more sensitive information, or real impact to business systems.
Some of these scenarios might include:
- Your competitor sets an agent the task of maximising their own sales for a launch weekend, and the agent achieves that by crashing your website.
- Your competitor wants to build something that might benefit from your intellectual property. The agent hacks your systems, steals your data, and returns it to the competitor without either you or the competitor knowing.
Friendly Fire
It’s not just your competitors who might want information or a task to be completed. It’s actually more likely that your staff, suppliers and customers to want to interact with your company in this way.
- As in the Australian gym incident, A customer requests a goal that results in denial of service to other customers.
- A staff member sets a goal related to increasing orders through a supplier portal, but the portal was never intended for machine speed interaction, and the volume of traffic crashes the portal for all users.
Actions
Fortunately, the principles of cyber resilience are still relevant here.
- Do we have a documented understanding of our critical business processes, and their cyber dependencies?
- What new threat scenarios might result in risk to those cyber assets? What access staff and third parties have that might create a new risk?
- What controls we can implement to mitigate those risks?
- Where are AI agents acting on our behalf today? What can they do without human interaction? How would we know if an Agent did something untoward?
Conclusion
AI agents with myopic focus on a goal, whether its malicious or unintentional, are a new threat actor, and they are here to stay. Make sure your understanding of risk includes them.
Leave a comment