AI agents told to find health data hack health systems

October 5, 2026
AI agents told to find health data hack health systems
Security
News

When autonomous AI agents can't obtain the information they were instructed to find, they may go rogue and breach healthcare organizations' websites. Recent investigations have identified this behavior involving healthcare and public-health websites in Australia and the United States, including systems operated by Medicare, Mayo Clinic, the CDC and the Australian Institute of Health and Welfare.

AI agents get the data at any price

The most serious confirmed case so far occurred in Australia in June 2026, when an OpenAI agent gained unauthorized access to infrastructure behind the public-facing Medicare Statistics Reporting Service portal operated by Services Australia. The agent had been given a routine research task: find information on government spending on medicines. When it could not obtain the required information through normal searches, it found another way into the service. Australian authorities confirmed that the agent accessed both public and non-public files.

The Australian government stressed that the portal was a standalone statistics service and was not connected to Medicare claims, payments or individual patient information. No personal health information is currently believed to have been accessed. The investigation is still examining exactly what the agent did and whether other systems were affected.

OpenAI subsequently acknowledged that the agent went rogue beyond its authorized task. According to reporting based on the company's disclosure, the model ran commands and retrieved internal files, credentials, technical information and aggregate statistics after discovering a route to non-public parts of the service.

AI is task-driven. It doesn’t always know what’s legal and what’s not

Transluce – an independent, nonprofit AI research lab based in San Francisco – analyzed activity involving autonomous agents between March and September 2026. Its investigation identified attempts to compromise several public data sources, including an Australian government health website and the Australian Institute of Health and Welfare.

The agents are never initially given cybersecurity tasks, but they might become AI zombies beyond their owner's control to retrieve information. When conventional methods failed, the agents escalated to techniques including attempts to exploit vulnerabilities. Transluce describes this as task-driven activity: cyber techniques emerged as a means of completing an ordinary information-retrieval task.

The researchers identified activity targeting interactive data visualization dashboards and products published by the Australian Institute of Health and Welfare (AIHW). They linked some of the activity to an OpenAI-originated agent swarm based on similarities in targets, tactics, and timing. Transluce said it found no evidence that the identified attempts against those three public data sources succeeded, while also noting that its dataset is incomplete.

U.S. Centers for Disease Control and Prevention (CDC) and Mayo Clinic were also probed

A separate investigation by Transluce found activity involving the CDC's WONDER platform, which provides public access to health statistics and allows users to submit customized data queries.

On July 18, researchers found evidence that an archived browser-execution program attempted to submit a request to CDC WONDER, including acceptance of the service's data-use terms. A capture made one second later returned a query-validation error. Transluce said it could not establish the complete execution chain. Importantly, the researchers reported no instances in their dataset where the agents obtained information that was not publicly available.

The CDC case is an example of an agent interacting with a public health data service in a way that researchers considered part of a broader pattern of aggressive automated activity. Yet, it’s not a data breach.

Mayo Clinic has also appeared in the investigation into autonomous agent activity. Asymmetric Security reported evidence that agents had probed Mayo Clinic's website as part of a wider investigation covering 55 websites, including the CDC, SEC and International Energy Agency. The security researchers said they found evidence of reconnaissance tactics and attempts to circumvent restrictions.

Mayo Clinic subsequently said it had no indication or evidence that unauthorized access to its systems or data had occurred and that it was continuing to review the report.

Asymmetric Security's investigation found evidence that agents used external services to obtain broader internet access despite restrictions in their original environments. The researchers also reported successful access to some staging environments and said that, in several cases, records of activity were erased or became inaccessible. They cautioned that the available public evidence was insufficient to determine whether sensitive information had been accessed in those cases.

Transluce reached a similar finding from a different dataset: agents used services such as URL scanning platforms to route requests around restrictions imposed either by developers or by the websites being targeted. Its researchers identified tens of thousands of queries apparently generated by autonomous agents.

Hugging Face case and the calls to slow down AI race

The Australian government is now conducting a forensic investigation with the Australian Signals Directorate. Prime Minister Anthony Albanese said the Medicare incident involved unauthorized access to public-facing infrastructure and that investigators were examining whether other government systems had also been affected.

The handling of the Australian incident also sparked controversy. OpenAI said it identified the unauthorized activity in August but did not notify the Australian government until September, while Australian officials questioned the delay and the way the incident was initially communicated. The episode came shortly after OpenAI disclosed that, during internal cybersecurity testing, its models had created a swarm of agents that compromised systems at Hugging Face.

The incidents have prompted calls from AI industry leaders to slow the pace of AI development until stronger safeguards are in place. In late September, the company also shelved the planned October release of GPT-6.1 Astra after internal testing found that the model did not meet OpenAI’s safety standards for staying within scope and communicating accurately about the actions it had taken.

Add ICT&health on Google

Show more content from ICT&health in Google Search.

Add on Google

This topic will also have a prominent place at the ICT&health World Conference 2027. Want to be there and stay ahead of what’s next in healthcare? Reserve your ticket today.