OpenAI discloses another Australian government hack

October 2, 2026

The OpenAI logo is displayed on a smartphone screen resting on a reflective surface with the company's logo projected onto it in Creteil, France, on October 1, 2026, as OpenAI begins rolling out Dots in ChatGPT, its new system of autonomous AI agents.

OpenAI has disclosed another case of an AI agent accessing an Australian government system without permission. This time, it retrieved historical bushfire data that wasn't publicly available.

According to The Guardian, the breach occurred in June and involved New South Wales' National Parks and Wildlife Service, part of the state's Department of Climate Change, Energy, the Environment and Water.

OpenAI says it discovered the breach on Tuesday, Sept. 29, and conducted a 48-hour review before notifying the NSW government on Thursday, Oct. 1. The company told the government that its agent had acted beyond its intended use. "The results we reviewed do not show that the model retrieved any personal information," an OpenAI spokesperson told The Guardian. The department is investigating with the state's cybersecurity agency, and the Australian Signals Directorate has also been notified.

If this sounds familiar, that's because Australia is already dealing with the fallout from a similar incident. As Mashable previously reported, an internal OpenAI model breached Services Australia's Medicare statistics reporting portal on June 18 while researching public healthcare spending.

When it encountered restrictions, the agent found ways around them, accessing public and non-public files and writing files to the government server. There was no evidence that it accessed individuals' private health information.

Australian Prime Minister Anthony Albanese called the incident "obviously unacceptable" and raised Australia's concerns directly with OpenAI CEO Sam Altman. Albanese also criticized the notification process. OpenAI said it discovered the Medicare breach in August but waited until Sept. 10 to alert the government, initially emailing a public Services Australia address.

"We clearly cannot rely on these multinational big tech companies to comply with even the most minimal of social obligations, such as notifying when, or even taking enough care to notice if, their products are hacking government systems," Australian Greens MP Abigail Boyd said.

The model also interacted with three other Australian government bodies, though those interactions appeared to involve only public information.

The further investigation should help establish how the agent got in. The bigger question is how OpenAI will stop another one from doing the same — and catch it sooner if it does.


Disclosure: Ziff Davis, Mashable's parent company, in April 2025 filed a lawsuit against OpenAI, alleging it infringed Ziff Davis copyrights in training and operating its AI systems.

Previous Article
Apple will update Macs to protect users from AI agents with full disk access
Apple will update Macs to protect users from AI agents with full disk access

Apple is going to roll out update to "Full Disk Access" as a result of AI agents.

Next Article
Kelly Clarkson loves AI. People online do not love her for that.
Kelly Clarkson loves AI. People online do not love her for that.

Kelly Clarkson draws backlash for admitting she loves AI on Matt Rogers and Bowen Yang's "Las Culturistas" ...