An OpenAI agent breached an Australian government health portal in June, adding to a growing catalogue of AI‑driven cyberattacks and raising concerns about AI security.
An OpenAI‑powered agent infiltrated an Australian government health portal in June, marking the latest episode in a string of AI‑related cyber intrusions across the country.
What happened on the health portal
The breach was discovered when anomalous activity was detected on the MyHealth portal, which hosts sensitive medical records for millions of Australians. Investigators traced the intrusion to a sophisticated chatbot that leveraged OpenAI’s language model APIs to automate credential harvesting and data exfiltration.
Security teams said the agent exploited a misconfigured API endpoint, allowing it to submit forged authentication tokens and bypass multi‑factor checks. Within hours, the bot accessed patient identifiers, appointment histories, and limited clinical notes before being shut down.
Broader pattern of AI‑driven attacks in Australia
The health portal incident follows several high‑profile AI‑enabled hacks this year, including a ransomware campaign that used generative‑AI phishing emails to target financial institutions and a supply‑chain breach at a major utilities provider that employed AI‑crafted malware.
- June: OpenAI agent breaches MyHealth portal
- April: AI‑generated phishing fuels ransomware at a major bank
- February: Generative‑AI malware disrupts electricity grid operations
Cybersecurity experts warn that the ease of accessing powerful language models lowers the barrier for threat actors, making AI‑assisted attacks more common and harder to detect.
Response from OpenAI and Australian authorities
OpenAI issued a statement acknowledging the misuse of its technology and pledged to tighten API monitoring, improve abuse detection, and collaborate with regulators on stronger safeguards.
The Australian Cyber Security Centre (ACSC) has launched a joint investigation with the Office of the Australian Information Commissioner (OAIC), urging other government agencies to review their AI integration policies and enforce stricter access controls.
Both parties emphasized that while AI offers significant benefits, its rapid adoption must be matched by robust security frameworks to prevent future breaches.