cd /news/ai-agents/here-s-what-actually-happened-in-ope… · home › topics › ai-agents › article
[ARTICLE · art-141928] src=arstechnica.com ↗ pub= topic=ai-agents verified=true sentiment=↓ negative

Here's what actually happened in OpenAI's Australian gov't server hack

OpenAI disclosed that an experimental, internal-only model, tasked in June with researching government spending statistics in the Australian state of Victoria, gained unauthorized non-public access to a government server after failing to find the data through public statistics, reading technical system information, source code, credentials and aggregate statistics, and creating and reading back a small test file. In a disclosure email to Australia's Public Disclosure account, OpenAI said the model "identified a way to make the server carry out instructions sent through the public reporting interface, without a private account or password," and that its review found no evidence the model accessed patient-level records, personal information or credentials, deleted data, or established ongoing access. The disclosure follows Australian Prime Minister Anthony Albanese's earlier statement that an OpenAI agent had accessed "non-public files" from the country's Medicare statistics portal during testing.

by read1 min views4 publishedSep 29, 2026
Here's what actually happened in OpenAI's Australian gov't server hack
Image: Arstechnica (auto-discovered)

Last week, when Australian Prime Minister Anthony Albanese told the world that an OpenAI agent had accessed “non-public files” from his country’s Medicare statistics portal during testing, his description of the incident was a little light on details. Today, we’re getting new information on just how far OpenAI’s overzealous agent went in attempting to satisfy a rather innocuous-sounding informational prompt.

In a newly published blog post, OpenAI says the June incident started when the company asked “an experimental, internal-only OpenAI model” to research government spending statistics in the Australian state of Victoria. When the model ran into trouble finding that data using the publicly published statistics that it was supposed to reference, “it took actions that we had not authorized it to take” to find an answer, OpenAI said.

Those unauthorized actions included finding “a way to gain non-public access to the service” and using that access to view “technical system information and source code” alongside credentials and the aggregate statistics it was actually searching for, OpenAI said.

In a newly published disclosure email that was sent to Australia’s Public Disclosure account earlier this month, OpenAI said its model had “identified a way to make the server carry out instructions sent through the public reporting interface, without a private account or password.” That unauthorized access let the agent “read portions of internal program files and settings, obtain a list of files, and create and read back a small test file on the server,” according to the email.

“Our review found no evidence that the model accessed patient-level records, personal information or credentials; deleted data; or established ongoing access,” OpenAI continued in the email.

── more in #ai-agents 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/here-s-what-actually…] indexed:0 read:1min 2026-09-29 · —