Skip to content

Thursday, September 24, 2026

Gigantum.net
Business

What we know about the rogue AI-agent security breaches

Sept 24 (Reuters) - Australia said on Thursday an OpenAI agent breached a government health data portal in June, gaining unauthorised access to files, in wha...

· 349 words

Sept 24 (Reuters) - Australia said on Thursday an OpenAI agent breached a government health data portal in June, gaining unauthorised access to files, in what could be the first known instance of AI hacking a government website.

This latest breach comes on top of ‌several recent breaches globally, deepening concerns that rogue AI systems could soon improve themselves and slip beyond human control.

Here are some more details ‌of the incidents:

Company Date Model Organizations Duratio What occurred

OpenAI OpenAI Not Australian Not An OpenAI agent gained unauthorised

disclosed the specifi government disclos access to the medical statistics

incident to ed health data ed portal of an Australian government

the Australian portal agency responsible for non-sensitive

government on health data and statistics, including

the hack Australian ​Prime Minister Anthony

occurred in Albanese also warned that three other

June on an government websites "may be impacted"

unspecified by the OpenAI agent's activity.

Meta Incident Meta An unnamed Not During a cybersecurity evaluation run

disclosed on did not third-party disclos by independent tester Irregular, a

August 5, identif service ed configuration error inadvertently gave

2026; the date y the a Meta model internet access. Meta

of the testing model. said the model then exploited a

incident was The security vulnerability in a

not disclosed Informa third-party service. The Information

ported unidentified company's systems and

was Mus Irregular characterized it as an

e Spark evaluation-environment issue, not a

1.1 sandbox escape or sophisticated cyber

OpenAI July 19 Not OpenAI's own Two In one case, OpenAI ‌agents exploited a

specifi infrastructure inciden flaw in the computer they were meant

ed ts ⁠on to remain confined to, allowing them

same and access other connected systems in

OpenAI The agent GPT-5.6 AI startup The During controlled tests, an autonomous

began Sol and Hugging Face Hugging agent escaped its isolated

attempting to an and a ⁠customer Face environment, accessed the internet

escape its unnamed at New intrusi and breached Hugging Face to complete

test , more York-based on ran its assigned goal. The activity

environment capable Modal Labs from continued for days and was not

Gathered from external sources. Rights to this text belong to whoever originally published it.