SA marked safe but it’s ‘just the beginning’ of AI cyber breaches

The state government is confident no SA agencies were breached by AI agents, as experts issue “massive warnings” about future cyber attacks.

Sep 24, 2026, updated Sep 24, 2026
Two of South Australia's top artificial intelligence experts have issued major warnings over a Medicare breach. Graphic: James Taylor/InDaily
Two of South Australia's top artificial intelligence experts have issued major warnings over a Medicare breach. Graphic: James Taylor/InDaily

Prime Minister Anthony Albanese has revealed an OpenAI agent “infiltrated” the Medicare Statistics Reporting Service portal administered by Services Australia, raising concerns for South Australia’s data security.

A state government spokesperson today confirmed to InDaily that SA has not been affected by the breach and the government remained “committed to building a safe, secure and resilient digital future for all South Australians”.

“We are investing in critical whole-of-government capabilities to strengthen the protection, monitoring and resilience of government systems and services, while supporting agencies to continuously improve their cyber security maturity,” the spokesperson said.

But experts have warned about further cybersecurity attacks from AI agents, which are systems and programs capable of autonomously performing tasks on behalf of a user, with major global companies including Microsoft and Uber using the agents for tasks like financial analysis.

Adelaide University AI expert professor Vitomir Kovanovic told InDaily the breach was “massively concerning” and should serve as a major warning sign to both state and federal governments.

“This is going to be happening more and more. No government in the world can protect against future hacking,” Kovanovic said.

“Certainly whatever was accessed with the AI breach wasn’t supposed to be accessed, and it is a massive problem.”

Kovanovic said the state government’s Royal Commission into AI “should have been done two years ago” and that Australia was “lagging behind” in cybersecurity.

“When it comes to hacking in cybersecurity, you need to be lagging just one version of software behind, and you have certain bugs and exploits in your systems,” Kovanovic said.

“The problem with AI systems is it’s very hard to code common sense. When you give a task to another person, you can assume they have reasonable common sense. But AI doesn’t have that.

“He will do anything you request for him to do. Indeed, you have some limitations, but from time to time, they will start ignoring them, or not be aware that hacking is wrong.”

Flinders University senior lecturer Dr Naeem Janjua told InDaily that today’s news was “just the beginning of cybersecurity concerns with the rise of agentic AI”.

Stay informed, daily

“The way technology has matured over the last few years, even a person who doesn’t have deep knowledge of how to create these attacks can use these AI models using very plain English prompts to guide the agents,” Janjua said.

Janjua said the best way to defend against AI was by investing in more AI.

“It is concerning, and we need to put in more investments in sovereign AI,” Janjua said.

“We need to push more funding, especially research funding, into projects where we can better handle these AI agentic technologies. 

“Currently, most of these agentic frameworks are developed by overseas companies. We need to basically establish research centres and institutes where we develop our own technologies.”

The Medicare breach occurred in June, but the government was only recently informed of the cyber attack.

Albanese said he had spoken to OpenAI’s chief Sam Altman and expressed “extreme concern”.

“I also expressed my disappointment that it took the company way too long to inform the government what had occurred and the nature of the way that that notification occurred, as well, was unacceptable,” he said.

Albanese said the AI agent accessed public and non-public files. It was conducting research into public medical spending when it found a way to break through privacy protections.

“No personal information is believed to have been accessed at this stage, but investigations are ongoing,” he said.

-with AAP

Want to see more stories from InDaily SA in your Google search results?

  1. Click here to set InDaily SA as a preferred source.
  2. Tick the box next to "InDaily SA". That's it.
News