First Hugging Face, Now Australia: OpenAI Agents Hack Their Way Into A Government
An artificial intelligence giant waited nearly three months to report that its agents broke into a foreign government website.
Dylan Kresak·Sep 25, 2026·3 min read
🌐Foreign Affairs
Sponsored
An artificial intelligence giant waited nearly three months to report that its agents broke into a foreign government website.
OpenAI’s agent gained unauthorized access to Australia’s Medicare Statistics Reporting Service portal on June 18, but the company did not notify the Australian government until Sept. 10, acting Prime Minister Richard Marles said, according to a Thursday press conference transcript. The incident marks another publicly reported case of OpenAI’s agents breaking into outside systems, after they hacked New York City-based startup Hugging Face in July.
“It was not sitting behind a particularly high fence. This AI agent scaled the fence, but it did scale it,” Marles said, according to the transcript. “And the point is it was unintended. It wasn’t asked to. That’s our concern here.”
The Deputy Prime Minister — acting as Australia’s head government while Prime Minister Anthony Albanese was attending the United Nations General Assembly — explained that while this incident had a minor impact and no individual’s medical data was accessed, the situation is still serious.
“n an unintended way, an AI agent has entered into an Australian Government website in a way which is unauthorised,” Marles said.
Sponsored
First Hugging Face, Now Australia: OpenAI Agents Hack Their Way Into A Government — IJR
The portal “did have protections in place. Unfortunately, this agent got around that,” Minister for Government Services Katy Gallagher added.
OpenAI notified Services Australia of the hacking incident through a public email inbox that is checked once a day.
“It’s not good enough that that’s how we first became notified of it,” Marles stated.
The Department of the Prime Minister and Cabinet referred the Daily Caller News Foundation to its announcement of the government’s rapid review and Thursday’s press conference with Marles and Gallagher who are both members of the Australian Labor Party.
The rapid review will be led by the Department of the Prime Minister and Cabinet and will decide whether Australia’s laws can adequately handle cyber incidents caused by AI technologies, according to the announcement of the review.
OpenAI, Hugging Face, and Services Australia each did not respond to the DCNF’s request for comment.
“t took the company way too long to inform the government what had occurred,” Australian Prime Minister Anthony Albanese said in a Wednesday press conference announcing the rapid review taskforce, according to an ABC News (Australia) broadcast posted on YouTube. “he nature of the way that that notification occurred as well, was unacceptable.”
The agent was looking up public medicine spending for an OpenAI test when the Medicare portal blocked it, Marles and Gallagher said. Furthermore, the agent visited three other Australian government sites, but only pulled public data from those sites.
OpenAI has been “very cooperative in terms of the engagement that we are having with them now,” Marles said.
Marles met with OpenAI CEO Sam Altman in person earlier in September, prior to the company notifying the Australian government of the incident. The incident was also not discussed in the meeting, he said at Thursday’s press conference.
Nonprofit research lab Transluce found that OpenAI agents tried and failed to break into public data sites in three separate instances between May and June, according to a Wednesday report. The targets were the University of New Mexico library, Data USA and Australia’s Institute of Health and Welfare.
All content created by the Daily Caller News Foundation, an independent and nonpartisan newswire service, is available without charge to any legitimate news publisher that can provide a large audience. All republished articles must include our logo, our reporter’s byline and their DCNF affiliation. For any questions about our guidelines or partnering with us, please contact [email protected].