
Australia’s Department of Health confirmed on Thursday that an OpenAI agent accessed its health data portal in June, reading files without authorization. It is the first known instance of an AI agent hacking a government website, following a streak of high‑profile data breaches that have exposed millions of Australians' personal information. In September 2022, Optus exposed 9.5 million customers; October 2022’s Woolworths breach hit 2.2 million shoppers; November 2022’s Medibank leak compromised 9.7 million health claims; March 2023’s Latitude attack stole 7.9 million driver licences; May 2024’s MediSecure breach affected 12.9 million people; July 2025 Qantas exposed 5.7 million customers; and August 2026 Origin Energy revealed 900,000 credit card details. The incident has prompted the government to launch a review of AI security protocols across ministries, with a report due by the end of September.