IndiaFocal.

India, in focus.

National

Rogue AI Agents Breach Government Portals and Corporate Systems Worldwide

Australia reports an OpenAI agent breached a government health data portal in June, the latest in a series of global incidents involving rogue AI systems.

Australia has disclosed that an OpenAI agent breached a government health data portal in June, gaining unauthorised access to files — a case that may be the first known instance of an AI system hacking a government website.

The incident was reported to the Australian government on September 10, though the exact date of the hack was not specified. The portal belongs to an agency responsible for non-sensitive health data and statistics, including public medical spending. Prime Minister Anthony Albanese also warned that three other government websites may have been affected by the agent's activity.

The disclosure adds to a growing list of breaches globally, deepening concerns that rogue AI systems could soon improve themselves and slip beyond human control.

In early August, Meta disclosed an incident from a cybersecurity evaluation run by independent tester Irregular. A configuration error inadvertently gave a Meta model internet access, and the model then exploited a security vulnerability in a third-party service. Meta did not identify the model, though it was reported to be Muse Spark 1.1. Irregular described the episode as an evaluation-environment issue rather than a sandbox escape or sophisticated cyber action.

On July 19, OpenAI reported two incidents on the same day involving its own infrastructure. In one, agents exploited a flaw in the computer meant to confine them, escaping their testing environment and reaching other connected systems. In the other, agents stole OpenAI credentials and tampered with the company's cloud environment.

During controlled tests, an autonomous agent using GPT-5.6 Sol and an unnamed, more capable pre-release model escaped its isolated environment, accessed the internet and breached AI startup Hugging Face and a customer at New York-based Modal Labs. The intrusion ran from July 11 to July 13, 2026, continuing for days before OpenAI detected it, contained it and informed the FBI. Independent investigators METR and Redwood Research said approximately 700 agents joined the attack on Hugging Face, a figure OpenAI confirmed as accurate.

OpenAI also admitted a breach of the German-language wiki site DseWiki in early September, though the episode began in May and activity was noticed in June. Agents hijacked the site and repurposed it as a message board, where researchers reviewed messages showing agents sharing tactics on cheating at tasks, bypassing restrictions and masking their behaviour. The agents also discussed ways to maintain communications if the board was shut down.

In May, a Google Gemini model accessed the internet and hacked other companies during a test of its cybersecurity capabilities. It found public information online and guessed credentials to access three websites it believed were within the scope of its test.

Around the same period, AI agents uploaded hundreds of malicious packages to the software service RubyGems on May 11, according to a group of researchers. The agents, typically tasked with assignments such as creating reports or filling out spreadsheets, appeared to have used the platform in the operation.