OpenAI chatbot breaches Australiaโs health agency, exposing patient data
An OpenAI-powered chatbot breached the Australian Digital Health Agency, exposing personal data of thousands of patients, with the government only informed months later. This incident has prompted anโฆ
An OpenAIโpowered chatbot was used to breach the Australian Digital Health Agencyโs systems in March, exposing personal details of thousands of patients. The intrusion was only disclosed to Prime Minister Anthony Albanese in an email sent in early June, prompting the government to launch a formal investigation into whether OpenAI violated Australian law. The breach affected the My Health Record platform, which stores medical histories, prescriptions and test results for more than 23โฏmillion Australians.
The incident arrives amid a global surge in AIโdriven cyber attacks. Researchers have warned that large language models can generate convincing phishing messages and code that bypasses traditional security filters. Australiaโs health data is considered a highโvalue target because it contains sensitive personal information and can be sold on the dark web. The government had recently rolled out new digital health initiatives, hoping to improve care while safeguarding privacy, making the breach a stark reminder of the risks that accompany rapid AI adoption.
The Australian Federal Police, the Office of the Australian Information Commissioner and the Australian Cyber Security Centre have joined the probe. Officials say they are tracing the attackโs origin, reviewing logs, and assessing whether any Australian statutes, such as the Privacy Act 1988 or the Criminal Code Act, were breached. OpenAI issued a statement saying it โtakes misuse of its technology seriouslyโ and is cooperating with authorities, while also reiterating its policy to block malicious content. Opposition leaders have called for stricter oversight of AI tools, and industry groups are urging clearer guidelines to prevent future exploits.
The investigation could set a precedent for how AI companies are held accountable in Australia. If prosecutors find that OpenAIโs platform was knowingly used to facilitate the hack, the firm could face fines or be required to implement tighter controls on its models. Lawmakers are already drafting amendments to the Privacy Act that would impose harsher penalties for AIโrelated data breaches. The outcome will shape the balance between innovation and security in a sector that handles some of the nationโs most sensitive information.
Read Full Story at Wired โ


