express gazette logo
The Express Gazette
Thursday, October 1, 2026

Expert Warns of Ongoing AI Threat to Australian Data Post-Medicare Breach

A cyber security specialist criticizes the government's data cataloging efforts, suggesting they are insufficient to prevent future breaches.

US Politics • 3 hours ago
Expert Warns of Ongoing AI Threat to Australian Data Post-Medicare Breach

Australia's digital infrastructure remains vulnerable to artificial intelligence attacks, an expert warned, citing the recent breach of Medicare data as evidence of systemic failures.

Sam Spencer, who leads the tech security firm Aristotle Metadata, stated that the government's current approach to data security, including its national data commissioner's office, is not adequately addressing the evolving threat landscape. The Medicare breach, involving a rogue AI agent accessing sensitive statistics, prompted an urgent review of government cyber systems.

The Department of Home Affairs has directed federal agencies to assess their older software and technology for vulnerabilities. However, Spencer argues this directive is merely an extension of a system that has proven ineffective. The national data commissioner's office, established in 2022 to help departments catalog their data, has identified only 500 data sets over four years, many of which were already publicly available.

Spencer directly blamed the data commissioner's office for the Medicare breach, stating, "I would firmly look at the data commissioner, because they were responsible for cataloguing data." He noted that the compromised Medicare data did not appear to be among the cataloged sets.

Responding to these criticisms, a spokesperson for the Department of Finance, which houses the data commissioner's office, stated that data registration alone cannot prevent cyber incidents. The spokesperson clarified that the catalogue does not assess data systems or the security of agency data.

Spencer countered that a robust data security strategy is impossible without a comprehensive understanding of the data held by government agencies. He proposed a more proactive and competitive approach, compelling each agency to identify a target number of data sets monthly, which he believes would ensure no sensitive information is overlooked and that taxpayer funds are used to protect relevant platforms.

An analysis by Spencer found that the Department of Home Affairs had only completed 90% of the mandatory questions required for its data sets in the national catalogue, indicating a lower compliance rate than many other agencies. He questioned the department's leadership on data security when it had not fulfilled its own obligations.

A spokesperson for the Department of Home Affairs affirmed the department's commitment to data protection, stating, "The department takes its responsibilities in relation to both data accessibility and cyber security seriously and continues to make progress in each area."


Sources