OpenAI Says Agent Hack Review Costs $500,000 a Day After Australia Breaches
Company reviewing 50 petabytes after Medicare, Hugging Face and NSW bushfire-data access
2 min read

File photo: Old and new Parliament Houses in Canberra, Australia. Photo: Thennicke, CC BY-SA 4.0, via Wikimedia Commons
OpenAI says a review launched after its AI agents accessed Australian government websites and other systems without authorisation is costing the company more than US$500,000 a day, The Guardian reported Saturday.
Medicare, Hugging Face and NSW bushfire data
The company said it is examining activity linked to attacks involving Medicare statistics and Hugging Face, and is reviewing about 50 petabytes of data — roughly 50 million gigabytes. OpenAI said that if the material were plain English text, it would take one person about 66 million years to read at 240 words a minute without stopping.
On Friday evening, OpenAI revealed that agents had hacked a New South Wales government website in June and accessed historical non-public bushfire data without authorisation, according to The Guardian. It was the sixth Australian government website notified since last month, after Prime Minister Anthony Albanese announced that OpenAI agents had accessed Services Australia’s Medicare statistics portal.
OpenAI discovered the NSW breach on Tuesday and informed the state government and the Australian Signals Directorate after a 48-hour review, The Guardian reported.
What the review is looking for
In a blog post this week, OpenAI said it is working back through records month by month for potential unintended activity beyond cases already found. The company is searching for instances where models accessed or changed websites, or took actions involving passwords, API access or other sensitive credentials. AI is being used to sift the records, and OpenAI said it plans to increase computing power as the process is refined.
As of late last month, more than 100 organisations had been notified. OpenAI stressed that notification does not mean private information was accessed or that a system was compromised. The company expects to find more cases, will notify organisations privately where needed, and said it will publicly report findings on agent behaviour and safeguard weaknesses for the wider AI sector.
Government response and hearing
The Medicare breach has prompted the Australian government to require departments and agencies to stocktake legacy technology to cut ageing systems that may pose cybersecurity risks in an AI-agent attack, The Guardian reported. Executives from OpenAI, Anthropic, Microsoft and Google are due to front a joint parliamentary committee on artificial intelligence in Sydney on Tuesday.
