The Australian government has ordered federal departments and agencies to review older technology systems following the unauthorised access of a Services Australia Medicare statistics portal by an OpenAI agent.
Under PSPF Direction 002-2026, issued by the Department of Home Affairs on 29 September, Commonwealth entities must conduct a stocktake of legacy technology, set targets to reduce its use and develop risk management plans. Systems of Government Significance are to receive particular attention.
The directive follows the disclosure that an internal OpenAI model gained non-public access to the Medicare Statistics Reporting Service during an internal evaluation. OpenAI said the agent ran commands and retrieved internal files, credentials and statistics, but no individual Medicare records were accessed.
Australia’s latest cyber security posture report shows the wider scale of the legacy-technology issue. In 2025, 59% of Commonwealth entities said legacy technology had affected their ability to implement the Essential Eight cyber security measures. The report identified insufficient dedicated funding and a lack of viable replacements among the main reasons older systems remained in use.
The new review is intended to identify vulnerable systems before they can be exploited. Agencies are also being directed to strengthen vulnerability and patch management, particularly for older technology supporting public-facing and critical government services.
The government has previously said the Medicare incident did not involve personal Medicare information. A separate ABC report also confirmed that OpenAI disclosed another incident involving a NSW government website, where authorities said no personal information was accessed.
Australia By Aussie previously reported on the Medicare incident after Prime Minister Anthony Albanese said an OpenAI agent had accessed the portal. The new government-wide stocktake represents a further response to the cybersecurity risks exposed by the incident.
The government review is ongoing. The existence of legacy technology does not by itself establish that a particular system is insecure; cybersecurity risk depends on factors including patching, isolation, configuration and ongoing support.



