25 September 2026

8 min read

AI agent hacks Australian government Medicare portal | Cyber Intelligence Briefing – 25 September 2026

September 2026
Cyber Intelligence Briefing

Top news stories this week

  1. Unhealthy obsession. AI agent hacks Australian government Medicare portal
  2. Background check.  FBI investigates alleged breach of recruitment portal
  3. Ripple effect. DriveWealth breach exposes customer data across trading platforms, impacting Revolut, Hatch and Stake
  4. DarkWeb drama. Cybercrime feud unfolds as ShinyHunters target Cl0p
  5. Redirect and conquer. Elsevier platforms hijacked to display LAPSUS$ message
  6. Control, don’t delete. Human error disrupts healthcare and finance

1. Australian government healthcare portal compromised by rogue AI Agent

OpenAI has disclosed to the Australian government that an agent gained unauthorised access to a statistics portal for Australia's universal healthcare scheme Medicare. The incident occurred during agent testing last June and was discovered in August during an internal review of misaligned activity following the Hugging Face incident. Technical details of the incident are limited, but there are indications that the breached systems were poorly protected.

So what?

The incident raises serious questions about legal accountability for unintended actions of AI agents. It highlights the importance of basic cyber security hygiene to defend against misaligned agentic activity and the need for frontier labs to take governance and oversight more seriously.

[Researcher: James Tytler]  


2. FBI investigates alleged breach of recruitment portal

Cybercriminal group ShinyHunters claims to have exploited a vulnerability in Oracle PeopleSoft to access FBI recruitment systems and steal over 2 TB of employee and applicant data. The FBI is investigating unauthorised activity, but has not yet verified the group’s claims or confirmed that any stolen data originated from bureau systems. The FBIJobs portal was briefly defaced before being taken offline, suggesting some level of compromise, although the extent of any data exposure remains unclear.

So what?

This incident highlights the risk of third-party platforms and peripheral systems. Cyber practitioners must treat peripheral systems as high-value environments, especially when they aggregate sensitive data, connect to sensitive internal systems and/or are internet facing.

[Researcher: Steve Ross]  


3. DriveWealth breach exposes customer data across trading platforms, impacting Revolut, Hatch and Stake

DriveWealth, the US brokerage platform providing stock trading services for fintech and payment providers including Revolut, Stake and Hatch, suffered a social engineering attack that exposed historic customer data. While Hatch said portfolio values and cash balances were affected, Revolut stated that only customers who traded US stocks were impacted and that its own systems were not compromised.

So what?

The incident marks Revolut's second customer data security incident in a month When an organisation's own systems are not affected, such incidents can still result in significant reputational damage.

[Researcher: Milda Petraityte]


4. Cybercrime feud unfolds as ShinyHunters target Cl0p.

Cybercrime group ShinyHunters claims to have breached and defaced the leak site operated by the Cl0p ransomware gang. The group allegedly exploited a vulnerability in the platform hosting the site, gaining access to data and infrastructure used to support Clop's extortion operation. ShinyHunters has since listed Cl0p as a victim on its own leak site, demanding an eight-figure ransom and threatening to publish allegedly stolen information if its demands are not met.

SO WHAT? 

While threat actors are busy targeting each other rather than victims, the feud shows how fragmented and unpredictable cybercriminal ecosystems have become. Organisations should be cautious when assessing extortion claims, as stolen data may be traded or reused between multiple criminal groups.

[Researcher: Jenny Eysert]


5. Elsevier platforms hijacked to display LAPSUS$ message

Academic publishing giant Elsevier confirmed that several of its platforms were temporarily compromised after users were redirected to a page branded by the LAPSUS$ cybercriminal group. The incident affected select web properties. Elsevier stated there was no indication that customer data, research content, or core operational systems were compromised, describing the event as a limited-duration traffic redirection rather than a deeper network intrusion

So What?

Even a limited attack can quickly become a public event, allowing threat actors to shape the narrative, attract media attention and cause disproportionate reputational impact. 

[Researcher: Gabriella Nolan]


6. Human error disrupts healthcare and finance 

Staff reusing a set of computer instructions for another hospital system accidently overwrote more than a decade’s worth of maternity data belonging to the Nottingham University Hospitals NHS Trust. Although crucial clinical information was recovered, some data was irretrievably lost. 

Separately, a managing director at investment bank Morgan Stanley’s Hong Kong office mistakenly emailed clients an internal document revealing details of over a hundred deals, including price-sensitive information. Regulators have reportedly asked for details about the incident.

SO WHAT? 

Although to err is human, often clients, patients and regulators may not forgive easily. Some basic controls may have mitigated these events – in the case of the former, a policy against reusing code or instructions, and in the case of the latter, tagging documents with appropriate sensitivity labels that can be checked before sending.

[Researcher: Lester Lim]

SUBSCRIBE TO RECEIVE OUR WEEKLY CYBER THREAT INTELLIGENCE BRIEFING VIA EMAIL

The S-RM Cyber Intelligence Briefing is a weekly round-up of the latest cyber security news, trends, and indicators, curated by our intelligence specialists.

To discuss this briefing or other industry developments, please reach out to one of our experts.

Editors

Share this post

Subscribe to our insights

Get industry news and expert insights straight to your inbox.