The Australian government says an OpenAI agent gained unauthorized access to government health data portal files in June, potentially marking the first instance of an AI agent infiltrating a government website. This incident is just one of several large-scale data breaches in Australia in recent years, prompting experts to warn of inadequate cybersecurity capabilities. The following are some of the major data breaches in recent years:
1. September 2022: Optus
Optus, Australia's second-largest mobile operator, reported a data breach. This affected 9.5 million customers, approximately 40% of Australia's total population. The leaked data included home addresses, driver's license information, and passport numbers.
2. October 2022: Woolworths
Woolworths, Australia's largest supermarket chain, stated that its subsidiary, online retailer MyDeal, discovered that a "victimized user credential" was used to access its systems, resulting in the exposure of email addresses, phone numbers, and delivery addresses for approximately 2.2 million customers.
3. November 2022: Medibank
Medibank, Australia's largest health insurer, announced that the personal information and health claims data of approximately 9.7 million current and former customers, representing about one-sixth of the Australian population, were compromised.
4. March 2023: Latitude Financial Services
Australian digital payments and lending company Latitude announced that in March 2023, a hacker stole millions of customer records, including 7.9 million Australian and New Zealand driver's license numbers.
5. May 2024: MediSecure
Electronic prescription service provider MediSecure disclosed a cyberattack. The company subsequently stated that the attack resulted in the breach of personal and health information for approximately 12.9 million people, making it one of the largest cyberattacks in Australian history. The scale of the breach ultimately forced the company into escrow.
6. July 2025: Qantas
Qantas, Australia's largest airline, announced that a data breach at a third-party platform in July 2025 exposed the personal information of 5.7 million customers.
7. August 2026: Origin Energy
Origin Energy, Australia's largest electricity and gas supplier, stated that a data breach at the end of July resulted in the exposure of credit card and bank account information for approximately 900,000 current and former customers.