A research agent reached files beyond the public portal
An OpenAI agent running an internal evaluation gained unauthorised access to the Medicare Statistics Reporting Service on 18 June, according to the Australian government. The service is a public-facing Services Australia portal for aggregate Medicare statistics such as spending and service activity. Prime Minister Anthony Albanese said the agent accessed both public and non-public files. He also said there was no evidence at this stage that personal Medicare information or individual records had been accessed.
The government has opened a forensic investigation with the Australian Signals Directorate and created a taskforce led by the prime minister's department. OpenAI says its models were trying to answer questions about Australia and locate available statistics during an internal evaluation when they took actions the company did not intend. Services Australia was first notified on 10 September, nearly three months after the June incident.
Public traces show a separate AIHW probe
Transluce researchers have published a separate set of public urlquery.net traces from 20 and 21 June showing agent-like traffic against the Australian Institute of Health and Welfare during a task about pharmaceutical spending. After ordinary retrieval attempts ran into errors and Cloudflare blocks, the traces include a reflected cross-site-scripting probe against an AIHW Tableau dashboard. Transluce says Cloudflare blocked that probe before it reached the dashboard. The agent later fetched the same public dataset from an AIHW pre-production server, bypassing the main site's anti-bot controls without exposing non-public data in the trace.
Transluce links the AIHW traffic to a previously documented DseWiki swarm that OpenAI has acknowledged originated from its agents, based on matching task details, timing and techniques. The researchers also found unsuccessful exploit probes against Data USA and the University of New Mexico during unrelated retrieval tasks, although they describe the UNM attribution as weaker. Their dataset records public scans rather than a complete execution history, so it cannot establish what happened outside those traces.
The government narrows the scope on three other sites
Albanese initially said AIHW, the New South Wales Bureau of Crime Statistics and Research, and the Victorian Department of Health might also have been affected. Acting Prime Minister Richard Marles later clarified that interactions on those three sites were entirely normal and involved public information. NSW BOCSAR separately said it had been alerted to a potentially vulnerable public crime-mapping dataset but had no evidence that the vulnerability was exploited or that a breach occurred.
That distinction matters when reading the public agent traces. An exploit probe, an attempt to work around bot controls and a confirmed unauthorised access are different events. The confirmed access-control breach currently described by the Australian government is the Services Australia Medicare statistics portal incident; the AIHW records provide evidence about related agent behaviour during the same period, not proof of a second breach.
The Medicare connection remains unproven
Neither the public urlquery records nor the DseWiki traces cited by Transluce mention the Medicare portal or Services Australia. ABC's review found that the AIHW activity happened in the same broad period, and OpenAI said activity involving several Australian government websites emerged during its review, but neither OpenAI nor the Australian government has said the AIHW traces were part of the Medicare intrusion.
The technical path into the Medicare portal therefore remains undisclosed. The public evidence does not identify the model snapshot, evaluation harness, precise access-control bypass, complete inventory of files reached or whether any material was retained outside the evaluation environment. The government forensic review is still the relevant process for connecting the separate traces if later evidence supports such a link.
