OZZZER · AI NEWS2 of 3 free stories opened
← Back to AI News

Governance · 2 Oct 2026 · 17:00 CEST

OpenAI’s Medicare attack has exposed Australia’s ‘tech debt’. Fixing it could bring a big bill for taxpayers

Guardian AI · 2 Oct 2026 · 17:00 CESTRead original at Guardian AI ↗
Share
LinkedInXFacebookWhatsApp
OpenAI’s Medicare attack has exposed Australia’s ‘tech debt’. Fixing it could bring a big bill for taxpayers

Publisher preview · OZZZER analysis pending editorial review.

PUBLISHER ARTICLE PREVIEW

From the original article

Home affairs department orders all federal government agencies to conduct review of ‘legacy technology’ amid fallout from AI agent hacks

The Australian government faces significant “tech debt” that could bring a big bill for taxpayers after the OpenAI Medicare breach, as government agencies will need to fortify their defences against future attacks by AI agents.

This week, the home affairs department ordered all federal government agencies to conduct a “legacy technology stocktake” that requires a plan for each agency to “reduce legacy technology systems” to a level within the agency’s risk tolerance and appetite, the direction stated.

OpenAI this week revealed an internal agent had gained non-public access to the Services Australia Medicare statistics portal during a training task seeking information on government spending on skin conditions in Victoria. The agent was able to run commands, retrieve internal files, credentials, and write files.

While OpenAI has apologised to Australia for the incident, it has served as a wake up call for the federal government, with the government-wide review now under way.

The finance minister, Katy Gallagher, asked her department whether some of the A$160m funding allocated to the agency in the last budget for cyber upgrades can be accelerated.

The statistics portal, Gallagher told reporters last month, is a “legacy system.”

Services Australia will be far from alone in managing legacy systems. They can – but not all do – present a security risk for businesses and government as they age and vendors cease providing new security updates.

Prof Salil Kanhere, a University of New South Wales cybersecurity and AI expert said the age of the system alone does not tell an agency whether it needs replacing.

“A 15-year-old

Source

Guardian AI · 2 Oct 2026 · 17:00 CEST

Open the original at Guardian AI ↗