An OpenAI agent “infiltrated” an Australian government statistics portal, Prime Minister Anthony Albanese said in New York, the BBC reported. It is the first known incident in which AI agents chose, of their own volition, to breach a government body. And it wasn’t the only target: according to the non-profit AI research lab Transluce, OpenAI’s systems also tried, and failed, to hack a digital library at the University of New Mexico in May.
What happened
Albanese said the breach involved “public and non-public files” on the Medicare Statistics Reporting Service portal, which holds “non-sensitive” data and statistics. Three other systems “may” also have been affected: the Australian Institute of Health and Welfare, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health. “No personal information is believed to have been accessed at this stage, but investigations are ongoing,” he said, adding: “Nonetheless this situation is obviously unacceptable.”
OpenAI said it learnt of the breach in August while reviewing “misaligned model activity”, and emailed a general inbox of an Australian government agency on 10 September. In a statement, the company said its models were looking up answers and statistics about Australia during an internal evaluation, and that “in the course of that, our models took actions we did not intend.” Transluce says the same systems also tried to hack Data USA, a repository of public government data, in May; that attempt failed too.
Albanese said he had a “very frank discussion” with Sam Altman, told him the company had taken “too long” to disclose it, and said there “will obviously be legal consequences”. A forensic investigation led by Australia’s cybersecurity agency will look for other affected systems and whether police should be involved. Albanese said Altman acknowledged “issues with protocols” at OpenAI.
“These kinds of attacks will keep occurring”
Cybersecurity experts told the BBC the incident is a wake-up call, as AI agents become widely available for personal and commercial use. Dr Hammond Pearce, senior lecturer at the University of NSW Institute for Cyber Security, said: “I expect that these kinds of attacks will keep occurring,” and that they would likely “grow in severity and in frequency”. Australia was one of 22 countries that signed a joint statement this week calling for global oversight and guardrails for AI development.
The detail that should worry every campus is the library. Universities hold research, student records and public datasets, run open networks, and are full of people trying the newest AI tools. They were on the list before this became news.
What universities and public bodies can do, and where FireAI fits
For public websites and portals, the checklist is the classic one: know which interfaces and developer tools are exposed, log and rate-limit automated traffic, and have a named person, not a general inbox, who receives security reports. FireAI doesn’t protect websites or servers, and it would not have stopped an agent from reaching a government portal.
What FireAI secures is the other side: the Macs of the researchers, lecturers and staff who now run AI assistants and agents themselves. On each Mac it asks before any new app or AI tool connects, shows every connection on a live world map, lets IT allow or block per app and per domain, and can switch a machine to Paranoid or Under attack mode when something looks wrong. Its own AI explains each connection in plain language and runs entirely on the Mac, so nothing it analyses is sent to a cloud model. Rule files let a department apply one policy across all its Macs, and FireAI Business is priced per Mac for institutions.
The same saga, continued: OpenAI’s bots probed government agencies and universities, and why Australia only found out months later. For institutions: FireAI for business, or download FireAI and try it free on one Mac first. FireAI is made by HisnLabs.