Australia has seen many major data breaches in recent years with millions of customers affected by telecommunications, healthcare, retail, financial services, airlines and energy companies. The recent OpenAI agent/government health data portal incidents have once again raised concerns about the country’s cybersecurity preparedness and the risks associated with increasingly powerful AI systems.
Australian authorities said today an OpenAI agent hacked the government health data portal in June and had unauthorised access to files. The breach has been described as a watershed in cybersecurity because it could represent the first such instance of an AI agent being used to hack a government website. The incident also comes as large-scale cyberattacks have been taking place with many millions of Australians' sensitive data being affected.
The recent development has added another layer to Australia’s cybersecurity concerns. Traditional cyber attacks have exposed huge amounts of personal and financial data, but AI systems may also increase organisational challenges to protect databases and portals for sensitive data.
One of Australia’s biggest recent breaches occurred in September 2022 when telecommunications company Optus reported that 9.5 million customers had been affected by a cyberattack. The breach exposed personal information including home addresses, driver’s licence and passport numbers. The magnitude of the breach was one of the biggest breaches in Australia’s history.
One month later Woolworths’ online retail business MyDeal suffered another big incident as well. A compromised user credential was used to gain access to the company’s systems in October 2022. A database of about 2.2 million customers was exposed, including email addresses, phone numbers and delivery information.
Healthcare companies have also been affected in November 2022 by a major breach. Medibank, one of Australia’s largest health insurers, found that personal information and health claims data belonging to more than 9.7 million current and former customers had been compromised. The incident underlined the serious risks of healthcare databases that hold very sensitive personal information.
In March 2023, digital payments and lending company Latitude Financial Services detailed another large-scale cyberattack. The company said millions of customer records were stolen (including drivers licence numbers of about 7.9 million people in Australia and New Zealand). The incident showed how cybercriminals could harness financial and identity information.
In May 2024, another significant healthcare-related cybersecurity crisis hit Australia when electronic prescription provider MediSecure revealed that it had been targeted for a cyberattack. The company said personal and health information on about 12.9 million people had been compromised and went into administration.
In July 2025, the airline industry was the next major target. Qantas, the largest airline in Australia, disclosed that a third-party platform breach exposed the personal information of approximately 5.7 million customers. The incident highlighted the cybersecurity risks companies do encounter in external technology providers and third-party systems.
More recently, Origin Energy reported a significant incident in August 2026. The country's largest electricity and gas provider said a late-July data breach had exposed credit card and bank account information belonging to around 900,000 current and former customers.
Together, these incidents illustrate the numerous sectors that have experienced significant cybersecurity incidents in Australia. Telecom companies, retailers, insurers, financial companies, healthcare services, airlines and energy firms have been affected.
The latest incident in government health portals may also be a concern because it raises questions beyond conventional data security. AI agents may become increasingly capable of performing complex tasks online and governments and companies may need to strengthen security measures around authentication, access permissions, monitoring and sensitive databases.
Australia’s recent history of cyber incidents also demonstrates how important it is to protect personal information in government and private systems. Millions of records can be exposed in some individual breaches so cybersecurity is definitely a big concern for those who collect sensitive customer and citizen data.