A swarm of OpenAI rogue AI agents appear to have gone on a spree of trying to access Australian government health data, in what some researchers say is the first autonomous hack of a government website.
Communications between AI agents and other traces of their efforts found by researchers from US non-profit Transluce show how hundreds of Open AI’s agents worked together over a period of months to gain access to information held by the Australian Institute of Health and Welfare (AIHW), NSW’s crime statistics body, BOSCAR, and a number of other international organisations.
The data shows the bots posting about their unsuccessful attempts to bypass cybersecurity defences and exploit vulnerabilities. It follows revelations announced by Prime Minister Anthony Albanese this morning that OpenAI’s AI agents had also accessed non-public Medicare health statistics held by Services Australia.
Read more…
Source: ABC News
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- ASD: Careful Adoption of Agentic AI Services
May 1, 2026
Agentic artificial intelligence (AI) systems increasingly operate across critical infrastructure and defence sectors and support mission-critical capabilities. As agentic AI systems play a growing operational role, it is crucial for defenders to implement security controls to protect national security and critical infrastructure from agentic AI-specific risks. Agentic AI can automate repetitive, well-defined and low-risk tasks. However, ...
- Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations
April 6, 2026
The financially motivated cybercriminal actor tracked by Microsoft Threat Intelligence as Storm-1175 operates high-velocity ransomware campaigns that weaponize N-days, targeting vulnerable, web-facing systems during the window between vulnerability disclosure and widespread patch adoption. Following successful exploitation, Storm-1175 rapidly moves from initial access to data exfiltration and deployment of Medusa ransomware, often within a few days and, ...
- Adelaide University new system designed to protect drones from cyber threats
February 25, 2026
Adelaide University researchers have initiated the development of a world-first cybersecurity system designed to protect drones from increasingly sophisticated cyber threats. A new study led by the Industrial AI Research Centre and published in the international journal Computers and Industrial Engineering, paves the way for safer and more resilient unmanned aerial systems (UAS) that are less ...
- Australia: Cyber attack takes major chicken processor Hazeldenes offline leaving businesses without meat
February 23, 2026
A cyber attack at major chicken meat processor Hazeldenes in central Victoria has led it to shutdown its wi-fi system on site, and a shortage of chicken at pubs and butchers across the state. Retail and industry have told the ABC that the chicken meat processor has been unable to fill some orders because it cannot ...
- Australia: Age verification errors see some under-16s retain access to banned social media platforms
December 11, 2025
It’s day one of the social media ban and, unsurprisingly, it hasn’t been a smooth launch. Many children have already been able to get around the ban in various ways, with age assurance systems misclassifying users and workarounds such as VPNs and make-up tricks being used. The government admitted the ban would not be perfect or ...
- US, UK, and Australia sanction Russian ‘bulletproof’ web host used in ransomware attacks
November 19, 2025
The governments of the United States, United Kingdom, and Australia have sanctioned a Russian “bulletproof” web hosting company and several of its related firms for allegedly being used to launch ransomware attacks against U.S. victims and critical infrastructure. In a statement Wednesday, the U.S. Treasury said it imposed coordinated sanctions on the Russia-based web host ...
