cd /news/ai-agents/openai-hacks-2nd-australian-governme… · home › topics › ai-agents › article
[ARTICLE · art-143777] src=abc.net.au ↗ pub= topic=ai-agents verified=true sentiment=↓ negative

OpenAI hacks 2nd Australian Government Department

OpenAI confirmed that a rogue agent accessed a second New South Wales government website, the National Parks and Wildlife Service (NPWS) web application, in June, and the NSW Premier's Department said it was notified only this week. The NSW Department of Climate Change, Energy, the Environment and Water is investigating with Cyber Security NSW, and OpenAI said it conducted an "urgent internal technical and legal review" and notified the Australian Signals Directorate, with no personal information accessed. The incident follows an OpenAI agent's access to the NSW Bureau of Crime Statistics and Research crime mapping tool and an Australian Medicare statistics portal on June 18.

read3 min views1 publishedOct 2, 2026
OpenAI hacks 2nd Australian Government Department
Image: source

In short: #

A second NSW government website has been accessed by a rogue OpenAI agent.

Both the government and the company have confirmed that no public information was accessed in the June incident.

The government was notified this week, with the company saying it conducted an "urgent internal technical and legal review".

OpenAI says a rogue agent accessed a second New South Wales government website in June, with authorities only informed of the "misalignment" this week.

The Premier's Department said the model entered a National Parks and Wildlife Service (NPWS) web application containing historical information and data on fires.

It said investigations have not found any unauthorised access to personal information.

In a statement, the department said the incident is understood to have happened in June, but OpenAI did not notify the government until yesterday.

"The NSW Department of Climate Change, Energy, the Environment and Water (DCCEEW) is working with Cyber Security NSW and its technology service provider to investigate the matter and assess its impact,"

A spokesperson for OpenAI confirmed the incident had taken place in June, but that no personal information had been accessed when a "model" had gone "beyond its intended use".

"After being made aware of this activity … we conducted an urgent internal technical and legal review to understand the nature of the activity against the research being carried out," the spokesperson said in a statement.

"As soon as that review was complete, we briefed the NSW Premier's Office and notified the Australian Signals Directorate.

"We sent a technical notification through the appropriate NSW Government channel and obtained details for the relevant NPWS contacts."

The spokesperson added the company followed up by providing a technical briefing and resources in line with its commitment to assisting where "misaligned activity has occurred".

"If our review identifies additional agencies, we will notify them promptly with the information available and keep them updated as we establish further facts."

'Not a malevolent company' #

The NSW Bureau of Crime Statistics and Research (BOCSAR) revealed an OpenAI agent accessed a public crime mapping tool to research public crime statistics last week.

NSW Premier Chris Minns said at the time that incident was concerning.

"The mere fact the agent was told not to access the information — it's not a malevolent company, they weren't attempting to steal confidential information — and they did it anyway, that's the power of artificial intelligence," he said.

"That's the battle that we'll have to contend with, because whilst this might have been contained to semi-public information that wasn't privacy related, it may get to the point where that information is released."

It also comes after OpenAI apologised for breaching an Australian Medicare portal, with company saying it wanted to "rebuild trust with the Australian people".

Prime Minister Anthony Albanese last week revealed that an OpenAI agent gained unauthorised access to the Medicare statistics reporting service portal on June 18.

The agent gained access to both public and non-public data, but no personal Medicare details were breached.

OpenAI said the incident occurred during a training exercise of an "internal-only OpenAI model", with the bot gaining access to non-public access to Services Australia Medicare's Statistics Reporting Service.

It then ran commands, retrieved internal files, credentials and statistics, as well as wrote files, according to the company.

── more in #ai-agents 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openai-hacks-2nd-aus…] indexed:0 read:3min 2026-10-02 · —