Australia said on Thursday an OpenAI agent breached a government health data portal in June, gaining unauthorised access to files, in what could be the first known instance of an AI agent hacking a government website.
The breach is one of dozens in recent years affecting some of Australia’s biggest companies. The exposed data included home addresses, drivers’ licences and passport numbers. The scale of the breach eventually forced the company into administration.
Here is a list of the largest data breaches in recent years: Australia’s second-largest mobile operator Optus, owned by Singapore Telecommunications, reported a data breach that affected 9.5 million customers, about 40% of the nation’s population. Australia’s largest health insurer Medibank, which covers about one-sixth of Australians, said that personal and health claims data of around 9.7 million of its current and former customers were compromised. Australian digital payments and lending firm Latitude said in March 2023 a hacker had stolen millions of customer records, including 7.9 million Australian and New Zealand drivers’ license numbers. Electronic prescription service provider MediSecure disclosed a cyberattack that it later said exposed the personal and health information of around 12.9 million people, making it one of the largest cyberattacks in Australian history. Qantas, Australia’s biggest airline, said in July 2025 a breach of a third-party platform exposed the personal data of 5.7 million customers. Origin Energy, the country’s largest electricity and gas provider, said a late-July data breach exposed credit card and bank account details of around 900,000 current and former customers. (Except for the headline, this story has not been edited by NDTV staff and is published from a syndicated feed.)
Experts have previously said the frequency and scale of the attacks suggest the country’s understaffed cybersecurity industry seems unequipped to combat such hack. Australia’s biggest grocer Woolworths said its majority-owned online retailer MyDeal identified that a “compromised user credential” was used to access its systems, exposing email addresses, phone numbers and delivery addresses of about 2.2 million customers.
