Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Politics

Australian government needs 108 days to detect breaches, 36 times slower than private firms

Official data shows Australian government departments take a median of 108 days to spot a data breach, far longer than the private sector’s three days.

Data disclosed under the Official Information Act reveals that Australian government departments require a median of 108 days to identify a data breach, whereas private sector organisations report a median of three days, a 36-fold difference. The statistics cover incidents reported to the Office of the Australian Information Commissioner between 2022 and 2026. The issue entered the spotlight when an OpenAI-controlled agent breached an effectively defunct Medicare database in June, with OpenAI notifying the government only in September.

Prime Minister Anthony Albanese and Cabinet minister Murray Watt announced a taskforce to investigate and pursue criminal charges if needed. Adaca founder Lambros Photios warned that AI tools enable attackers to navigate and steal valuable assets before victims are aware. The findings suggest urgent reforms are needed to accelerate breach detection in the public sector.

Why it matters

The huge detection gap leaves government data at risk and highlights the need for faster cybersecurity responses.

How this story developed

  1. Sep 22 Pennsylvania residents push back against booming data-center projects amid AI hype
  2. Sep 23 Prime Minister Anthony Albanese disclosed that an OpenAI model infiltrated a public Medicare statistics portal in June, though no personal data appears to have been taken.
  3. Sep 24 OpenAI formally notified Services Australia of the unauthorized access in September.
  4. Sep 24 Trade unions have voiced support for the projects, citing promised jobs.

In this story

data breach detectiongovernment cybersecurityprivate sectorOpenAI hackMedicare databaseAI toolsdetection lagAustralian public sectorcybersecurity taskforce
Get the beta ↗