Rogue OpenAI Agent Commits First Reported Attack on Government Servers
September 29, 2026
OpenAI agent conducting a routine research task decided to go off the rails and hack its way around limitations it was apparently getting frustrated with, in the process committing the first known attack on a national government server.
The frontier AI developers are desperate for trust and credibility as stories of previously undisclosed rogue agents continue to pile up. The latest of these is not going to help at all, particularly in Australia; an OpenAI agent that was supposed to be conducting a routine research task decided to go off the rails and hack its way around limitations it was apparently getting frustrated with, in the process committing the first known attack on a national government server.
“Minor” incident with OpenAI agent took weeks to report to Australian government
The incident has increased the intensity of a spotlight that was already on the disclosure policies of the frontier AI developers. As more and more stories about attacks that took place much earlier in 2026 hit the news, both the commitment to transparency and the security competence of these developers have been increasingly called into question.
The public has only learned about this incident via comments made by Prime Minister Anthony Albanese to reporters asking open questions at the recent UN General Assembly. An unhappy Albanese volunteered that a breach involving an OpenAI agent took place at the Medicare statistics portal in June of this year.
The Australian government, in turn, only found out about the breach in mid-September. About two months of this time is accounted for OpenAI not knowing about it, only uncovering it in August during post-Hugging Face combing of prior AI testing logs. But there is then a further delay of a few weeks before any attempt to contact the Australian government is made, and when it does happen it comes in the form of an email sent to the general public contact inbox of Services Australia. There it seems to sit for five more days before someone passes it on to appropriate authorities.
Australian government opens investigation as Albanese lambasts “unacceptable” reporting
Albanese characterized the reporting timeline as being “way too long” and has said that he personally called OpenAI head Sam Altman about the issue. The Australian Signals Directorate has also launched an investigation. It is unclear if OpenAI will be found in violation of any specific data privacy regulations, but Australia’s present law does establish both a duty to report if personally identifiable information was involved and a more general requirement for large tech firms to maintain safety officers that are continually overseeing processes that could have a serious security impact if they go awry.
The news is not getting better for OpenAI, or the frontier development industry in general. This announcement by Albanese was coincidentally paired with a new and independent report from AI research lab Transluce, which found three more instances of OpenAI agents being sent out on a similar data-gathering task and ending up somehow trying to hack their targets. OpenAI has also followed up with an announcement that its agents may have made attempts on “multiple” governments, universities, public agencies and other targets containing sensitive data.



