An OpenAI model researching Australian public healthcare costs reached areas of the Medicare Statistics Reporting Service that the government says were not public, prompting Prime Minister Anthony Albanese to say on September 24 that it had accessed a government website “in a way which is unauthorised”—an incident widely reported as a “hack.” But the system it reached was also a public statistics portal designed to give researchers, journalists and anyone else downloadable health-program data through an anonymous reporting endpoint.
The established record is narrower than the rhetoric. OpenAI says its model accessed aggregate health statistics and internal file names, while Albanese says it also wrote files to an internal server, an allegation still under forensic investigation and not corroborated in OpenAI’s published account. Both sides say there is no evidence that personal Medicare or patient records were accessed.
OpenAI says the activity happened during an internal evaluation in which its models were trying to find answers about Australia. That is the company’s account, and it says the models “took actions we did not intend.”
“The information accessed included aggregate health statistics and internal file names. Our overall review is ongoing, and we remain committed to transparency about these issues and to sharing what we learn as that work continues.” — OpenAI statement, reported by Cyber Daily
The Medicare statistics portal’s public data service
The target was the Medicare Statistics Reporting Service, operated by Services Australia. The agency says the service offers “instant access” to statistics on Medicare benefits, pharmaceutical benefits, immunisation, organ donation and related programs; users can download data as CSV files for analysis. It explicitly identifies health professionals, researchers, journalists and the general public as intended users.
That does not mean every file on the host was public, nor that an automated model was authorised to probe beyond the report tool. It does mean that “hack” compresses two materially different questions: whether a model used a public reporting service as designed, and whether it crossed into data or functions the service was not meant to expose.

The historical interface was built to turn user-selected inputs into aggregate reports. A 2015 archived Medicare page invited users to enter Medicare item numbers, select a time period and geography, then click “Create Report.” It offered breakdowns by patient age range and gender, but as counts, percentages and per-capita figures, not individual records.
A 2026 web archive shows the public reporting interface still running on an anonymous /SASStoredProcess/guest route: the reporting tool accepted requests without a user login. That guest endpoint is evidence of a public front door; it is not evidence that every directory, administrative function or file on the server was public.
Nor was the address hidden. The service’s fully formed report URLs, program path and query parameters intact, are indexed by search engines and reproduced as data-source citations in published work, including a peer-reviewed 2025 paper in the ANZ Journal of Surgery.
OpenAI has not said how its model reached the service, and no source confirms the route. Two ordinary explanations fit the evidence, and neither requires defeating a security control. One is live web search: a model researching Australian medicine spending would be served these URLs directly, though with the service now offline, what search returned in June cannot be re-checked. The other is more telling. Because the exact address is copied verbatim into published reference lists, it is almost certainly in the text these models are trained on. On that route the model would not need to find the link at all; it would already carry it.
The hostname is itself a clue to the system’s age. The portal remained on humanservices.gov.au after the former Department of Human Services became Services Australia on February 1, 2020.
The government has not identified the allegedly non-public files, said whether they sat behind an access-control system, or explained how the model reached them. Until it does, “non-public” identifies a disputed boundary, not a disclosed technical path.
An 84-day disclosure gap
The access occurred on June 18, and OpenAI notified Services Australia on September 10: 84 days between access and notice, calculated from those two dates. Albanese said he raised the delay directly with OpenAI chief executive Sam Altman in New York.
“This situation is obviously unacceptable.” — Anthony Albanese, reported by Cyber Daily
The notification went to a public Services Australia mailbox, reportedly one commonly used by researchers to flag possible vulnerabilities. Services Australia found the email the following day, and the incident was reported to the Australian Signals Directorate on September 15. SBS reported that the inbox was checked once daily.

That delay is the cleanest established failure in OpenAI’s conduct. A company that discovers its model may have gone beyond intended access should not wait nearly three months to tell the system owner, then send the warning to an ordinary public mailbox. The problem is not that OpenAI used a public statistics site; it is that its model may have gone further and the company left the operator to discover the risk long after the fact.
The government’s own account creates the sharper unresolved question. Albanese said the model, after being blocked from the Australian data, tried alternatives and “engaged in writing files as well to the internal server.” iTnews reported that assertion as part of an investigation still under way. OpenAI’s description mentions aggregate statistics and internal file names, not writing to a server.
The write allegation is therefore the most serious-sounding part of the story and the least independently supported. The ASD-supported forensic investigation may establish it, or explain what “internal” and “non-public” meant on a host whose public interface was built around guest access. For now, the government has made the claim; the public has not been shown the evidence.
What an AFP referral would need to establish
Albanese said the government was considering whether the matter should go to the Australian Federal Police. A referral would begin an investigation; it would not establish that a criminal offence occurred. The Commonwealth Director of Public Prosecutions lists computer offences among matters that can be prosecuted under the Criminal Code.
The most relevant legal distinction is not whether a service belonged to government, but whether the data was legally restricted. Section 478.1 of Australia’s Criminal Code covers intentional or knowing unauthorised access to “restricted data,” defined as data protected by an access-control system. Other provisions address unauthorised access or modification that causes impairment.
That makes the missing technical details central. Investigators would need to determine what the model accessed, whether access controls existed, whether it bypassed them, and whether it modified anything. An anonymous reporting endpoint does not grant blanket permission to explore a host. But a government system offering health statistics through a guest route cannot make “unauthorised access” self-proving merely by calling the system public-facing after the fact.
The public record also leaves ownership obscure. Services Australia operates the statistics program, but no public forensic finding has assigned responsibility for the configuration or maintenance of this particular legacy application. The agency now faces the cost of a forensic review and an interrupted public service because a model found an old government reporting system that apparently did not make its boundary legible to machines, or, perhaps, to its operators.
The investigation will settle whether OpenAI’s model crossed a protected line. It will not change the other fact already on the record: the line sat behind a public statistics tool that had spent years inviting researchers to ask it questions.
Neglect is the likelier story than superintelligence
Strip out the word “hack” and the shape of this is mundane. A government reporting tool that hands out health statistics to anyone was left running without a login on a subdomain of a department—Human Services, then Services Australia—renamed and reorganised more than once since 2020. Its address sat in search results and in published reference lists, so reaching it needed no domain-guessing or covert step. On the available record, this reads less like an advanced model defeating a government’s defences and more like a model doing ordinary research and walking through a door nobody had locked.
That reframing does not excuse OpenAI’s 84-day silence, and it does not settle what the model did once inside. But it moves the first question. Before asking why an AI reached a government system, ask why a public health service was sitting on unmaintained legacy middleware, on a defunct department’s domain, with no authentication in front of it—and who was resourced to keep it current. An underfunded system that changed hands is not an exotic failure. It is the ordinary kind, and it is the one the “superintelligence hacked us” framing conveniently steps around.
Key Takeaways
- OpenAI says a model reached aggregate Medicare health statistics and internal file names during an internal evaluation answering questions about Australia; reports say it was researching public healthcare costs.
- The Medicare Statistics Reporting Service was designed to provide public aggregate data to researchers, journalists, health professionals and the public.
- A preserved public link shows the service used an anonymous
/SASStoredProcess/guestreporting route. - OpenAI notified Services Australia 84 days after the June 18 access, on September 10.
- Albanese’s claim that the model wrote files to an internal server remains under forensic investigation and is not corroborated by OpenAI’s public account.
Further Reading
- OpenAI hacked Medicare portal, Prime Minister Anthony Albanese says, ABC’s contemporaneous account of the access, notification timeline and government investigation.
- Australian Medicare data portal “infiltrated” by OpenAI agent, Reporting on Albanese’s internal-server allegation and the continuing forensic review.
- Medicare hack alert went to inbox checked once a day and took five days to be escalated, SBS reporting on the public mailbox and escalation timeline.
- Breached! PM calls OpenAI hack of Medicare ‘unacceptable’, OpenAI’s description of the information accessed and the government’s response.
- Medicare statistics, Services Australia, Services Australia’s description of the public statistics service and its users.
- Medicare Australia, Statistics, Item Reports, Archived 2015 reporting interface and instructions.
- Medicare Statistics Reporting Service archive, Archive of the public service before the incident.
- Criminal Code Act 1995, computer offences, Statutory definitions of restricted data and unauthorised access.
- Cybercrime, Commonwealth Director of Public Prosecutions, Overview of Commonwealth cybercrime offences.
- Green Endoscopy, ANZ Journal of Surgery, A peer-reviewed paper that cites the Medicare statistics service by its full anonymous report URL.
