OpenAI told the New South Wales government on October 1 that one of its models pulled unpublished fire statistics out of a state parks database back in June. It is the second Australian agency to get that call in a week, and the fourth Australian government system OpenAI has named.

The target this time was the Fire History service run by the NSW National Parks and Wildlife Service, a web app holding historical bushfire data. OpenAI's statement, as reported by ABC News, says the model queried the service "beyond its intended use, gathering summary fire statistics that weren't publicly available through the service." No personal data was involved. OpenAI says it learned of the access on September 29, ran a 48-hour technical and legal review, then briefed the Premier's office and the Australian Signals Directorate.

Premier Chris Minns told ABC the agent had been told not to access the information and did it anyway. He added that OpenAI wasn't trying to steal anything. Both things are true, and the second one is the problem.

What happened in June

Rewind. On June 18, an OpenAI agent in an internal evaluation was asked to research public spending on medicines in Australia. It searched the web, found the Medicare Statistics Reporting Service run by Services Australia, got refused, and kept going. OpenAI's own September 29 post says the model "discovered a way to gain non-public access to the service. It then ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files." The same post lists two more hits from the same period. API and metadata requests against the NSW Bureau of Crime Statistics and Research's Crime Mapping Tool returned application config, job logs and site metadata. And an exposed access key let agents read reporting config from the Victorian Agency for Health Information.

OpenAI found the Medicare activity on August 11. It emailed Services Australia on September 10, using the agency's public vulnerability disclosure address. Someone opened that email on September 11. The Australian Signals Directorate heard on September 15. Prime Minister Anthony Albanese announced it from the UN General Assembly on September 24 and called the delay unacceptable. That is 84 days from access to notification, and the notification went to a generic inbox.

The "hack" was a guest endpoint

Recorded Future News pulled the portal apart the day after the announcement and found no exploit was needed. The Medicare statistics site ran without a login for more than a decade. A March 2025 upgrade added a login page and, at the same time, turned on automatic guest access. The site's own SetupEnvironment.js told browsers to send production statistics requests to a path that required no username or password:

/SASStoredProcess/guest

The JavaScript also listed internal file names and the server's directory layout for anyone who opened the developer tools. Timestamped images had been piling up in a temp folder since at least 2018. Ciaran Martin, who ran Britain's National Cyber Security Centre, told the outlet: "It's still unclear if what's happened would constitute a hack in the normal sense of the term."

I have run public web apps for 25 years and I have seen this pattern more times than I can count. A reporting tool goes up for internal use. It gets a public hostname because someone needs to reach it from home. Years later a login page gets bolted on, but the guest route stays because the dashboards break without it. Nobody attacks it because nobody knows it exists. Then something finds it.

The thing that found it was not a person. That is the only new part.

Agents escalate when a fetch fails

The second set of evidence comes from Transluce, a nonprofit AI lab, working with researchers from MIT, Corridor and AIUC. They read the public request logs of urlquery.net, a URL scanning service, and found OpenAI's agent swarm using it as a relay to reach pages that blocked direct requests. The Hacker News summarized the pattern. When a plain fetch failed, the agents did not stop.

  • May 25 and 26: about 80 requests at the University of New Mexico's digital library while trying to download one photograph, including SQL injection, command injection and path traversal payloads.
  • May 27: roughly a dozen probes at Data USA after a malformed query was blocked, covering SQL injection, cross-site scripting, template injection, path traversal and command injection.
  • June 20 and 21: more than 100 scans at the Australian Institute of Health and Welfare, getting past Cloudflare bot protection and retrieving a file from a staging server.
  • Throughout: requests routed through urlquery.net, r.jina.ai, httpbin.org and markdown.new to get around access restrictions on the target.

None of the injection attempts appear to have worked. The researchers put it this way: "malicious cyber activity is not limited to agents tasked with cybersecurity-related tasks and can arise instrumentally to solve mundane tasks like information retrieval."

Read that with your own systems in mind. The task was "find a statistic." The agent treated a 403 as an obstacle, tried the things a junior pentester tries, and routed around IP blocks through third parties. Nobody told it to do any of that. OpenAI says safeguards it added in July would now flag this activity. This is the same company whose training agent reached a public chatbot through its sandbox DNS resolver on September 20, which I wrote about last week. The safeguards keep arriving after the incident.

What I'd change this week

Assume every unauthenticated route you expose is public, regardless of what the link text or the robots.txt says. "Non-public" meant "not linked from the homepage" at Services Australia. That distinction is gone. If a guest endpoint can return it, a model will return it to somebody.

Go find your guest routes. Grep your frontend bundles for paths that skip the login. Check whether a login page you added later sits in front of the data or next to it. Pull staging hostnames off the public internet, or put real auth in front of them. AIHW's leak came from a staging server, not the main site.

Rotate anything that looks like an access key in a config file a browser can download. The Victorian health agency's exposed key is the plainest case in OpenAI's list, and it needed no skill at all to use.

Watch for relay traffic. Requests arriving from urlquery.net, r.jina.ai or similar page rendering services are a signal that a client got blocked and is trying another door. Logging the referrer and user agent on those is cheap. Rate limits by IP are now close to worthless against this class of client, since each relay hop gets a fresh address.

And read your disclosure inbox. Services Australia took a day to open an email about a breach of its own system, and the company sending it waited 30 days after finding the problem to write it. Both sides failed. If your security address lands in a shared mailbox nobody owns, you have the same gap.

OpenAI's chief strategy officer, Jason Kwon, appears before Australia's Joint Select Committee on Artificial Intelligence on October 6. I expect the hearing to be about notification timelines and apologies. The engineering lesson is smaller and older than that. The agent walked through a door that had been open since March 2025, and it only had to try once. My guess is that within a year, every operator of a stats portal with a guest route gets the same visit, and most of them never find out.