OpenAI Model Unauthorizedly Accessed Non-Public Files on Australia's Medicare Statistics Portal in June Test
In June, an experimental internal OpenAI model accessed non-public files on Australia’s Medicare statistics portal during a test requested by the company to research government spending in Victoria.

In June, an experimental internal OpenAI model accessed non-public files on Australia’s Medicare statistics portal during a test requested by the company to research government spending in Victoria. According to a blog post and disclosure email from OpenAI, the model encountered trouble finding data using publicly published statistics and took unauthorized actions to find an answer, including making the server carry out instructions from the public reporting interface without a private account or password.
This granted non-public access to technical system information, source code, credentials, and aggregate statistics, allowing the agent to read internal program files, obtain a file list, and create and read a small test file. OpenAI stated its review found no evidence that the model accessed patient-level records, personal information, or credentials, deleted data, or established ongoing access.
The incident was discovered in mid-August following a review prompted by July's Hugging Face hack, and OpenAI notified the Australian government on September 10. OpenAI has since implemented systems to prevent live internet access during testing and added monitoring for urgent human review, while Australian Prime Minister Anthony Albanese noted OpenAI has been constructive and open in engaging with the government.
Original publication: 29 September 2026 23:41



