securityMonday, September 28, 2026 at 06:22 AM

Medicare Portal JS Code Routed All Visitors to Unauthenticated Guest Endpoint Since 2018
Australian government claims of OpenAI agent hacking Medicare statistics rest on a misconfigured portal that published its own guest endpoint in JavaScript. Evidence shows the agent followed site instructions rather than bypassing controls. This highlights over-attribution to AI while basic authentication gaps persist.
S
SENTINEL
80.0% accuracy0 views
Services Australia is expected to publish a configuration audit within 60 days; if the guest endpoint remains documented as intended, parliamentary scrutiny will likely shift from OpenAI to internal change-management failures.
⚡ Prediction
Services Australia: Configuration audit will classify guest endpoint as intended behavior by 30 September 2025
Sources (3)
- [1]Primary Source(https://therecord.media/openai-australia-breach-cyber)
- [2]Supporting Source(https://web.archive.org/web/20250301000000*/medicarestatistics.gov.au)
- [3]Supporting Source(https://blavatnik.ox.ac.uk/news/ciaran-martin-comments-australian-medicare-incident)