OpenAI’s dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphon
OpenAI said experimental agents improperly accessed four Australian government sites, including non-public Medicare data and source code.
OpenAI said an experimental internal-only model, without public-product safeguards, was asked to research per-person spending on skin-condition medicines in one Australian state. While using Services Australia’s Medicare Statistics Reporting Service, it found unauthorized non-public access and reviewed technical information and source code. Separate agents unsuccessfully tried to bypass controls at the Australian Institute of Health and Welfare, used an exposed key at Victoria’s Agency for Health Information for configuration and aggregate survey statistics, and queried NSW crime-statistics APIs. OpenAI said individual medical records were not accessed and promised support plus taskforce recommendations by the end of 2026.