Government agencies will need to fortify their cybersecurity defences to guard against future attacks.
Fixing it could bring a big bill for taxpayers Home affairs department orders all federal government agencies to conduct review of ‘legacy technology’ amid fallout from AI agent hacks Get our breaking news email, free app or daily news podcast The Australian government faces significant “tech debt” that could bring a big bill for taxpayers after the OpenAI Medicare breach, as government agencies will need to fortify their defences against future attacks by AI agents.
This week, the home affairs department ordered all federal government agencies to conduct a “legacy technology stocktake” that requires a plan for each agency to “reduce legacy technology systems” to a level within the agency’s risk tolerance and appetite, the direction stated.
OpenAI this week revealed an internal agent had gained non-public access to the Services Australia Medicare statistics portal during a training task seeking information on government spending on skin conditions in Victoria.
The agent was able to run commands, retrieve internal files, credentials, and write files.
Sign up for the Breaking News Australia emailWhile OpenAI has apologised to Australia for the incident, it has served as a wake up call for the federal government, with the government-wide review now under way.
The finance minister, Katy Gallagher, asked her department whether some of the A$160m funding allocated to the agency in the last budget for cyber upgrades can be accelerated.
The statistics portal, Gallagher told reporters last month, is a “legacy system.” “It dates back decades.” Services Australia will be far from alone in managing legacy systems.
They can – but not all do – present a security risk for businesses and government as they age and vendors cease providing new security updates.
Prof Salil Kanhere, a University of New South Wales cybersecurity and AI expert said the age of the system alone does not tell an agency whether it needs replacing.
“A 15-year-old system that is properly supported, patched and properly isolated would perhaps present less risk than even a newer system that might not be properly maintained,” he said.
Those older systems with vulnerabilities are often known to human attackers, but AI agents persistent in looking for holes in a system may be able to discover them quicker.
Rogue AI hacks government system for first time - The Latest Gartner, a technology analysis firm stated in a note to clients released after the Medicare hack that “technical debt, not a rogue AI agent attack” represented the greatest threat to legacy systems.
“Agentic AI’s interactions with [government] resources will greatly increase,” the firm stated.
“Underinvestment is no longer sustainable and agencies should urgently prioritise funding in light of AI-driven risks.” In the Australian government’s commonwealth cybersecurity posture in 2025 report released in February this year, 59% of federal agencies and departments reported their ability to implement the “essential eight” measures to reduce cyber risk was being affected by use of legacy technologies.
The essential eight includes requirements to patch applications and operating systems, using multi-factor authentication, and other security measures.
Of those agencies being hindered by legacy tech, 34% blamed insufficient dedicated funding, while 18% said it was due to a lack of a viable replacement.
Prof Yang Xiang, from Monash University’s department of software systems and cybersecurity, said the government stocktake was “very necessary” and there was urgency to needing to audit all government systems.
“The agents bring significant changes in terms of the speed of getting into – hacking into – the system,” he said.
“The cost to launch an attack is much reduced to launch an attack and with the help of agents, it is fairly easy for the hacker to launch a very large scale atack against any systems.” skip past newsletter promotion after newsletter promotion Clearing the tech debt could prove costly for the federal government, but Xiang said agencies should identify priority systems for replacement.
Kanhere said high-risk systems should take priority.
“You do the high risk stuff first, I think it is absolutely needed, and then put the perimeter around [other systems],” he said.
“It is possible to do it quite systematically once they have a good understanding of what needs to be done.” Some states have audited their legacy technology and have invested hundreds of millions to rectify the issues.
A Victoria government cybersecurity audit of its IT servers found 25% of the operating systems used by servers were no longer supported by the vendor, with 48% in extended support.
In a South Australian audit report of legacy ICT systems published in June, of the ten agencies reviewed, nearly half of the 11,602 hardware devices or appliances were determined to be legacy devices.
Almost one quarter of the operating systems and applications were also determined to be legacy.
In one example, the Department for Child Protection’s case management system is now over 15 years old, and has limited vendor support.
The SA government has allocated $325.6m over the past three budgets in part to address legacy technology.
“Frontline workers spend significant time managing system limitations and maintaining records, reducing the time available to support vulnerable children and families.” A 2025 Queensland government audit of IT systems found more than half of the 57 systems audited are at the end of life.
Many of the systems identified by the government in 2012 as needing to be replaced were still in operation in 2025, including a patient administration system at Queensland Health, a forensic register at the Queensland Police Service, and a trust accounts system for young people in detention.
The Queensland government in the 2025 budget allocated $1bn over four years for IT investment, including replacing or updating legacy systems.
The Australian Cyber Security Centre said in recent guidance that the most effective way to mitigate risks associated with legacy IT is to replace it, and where it cannot be replaced, then legacy technology should potentially be segregated or isolated from the broader department network to restrict access to the rest of the department.
Explore more on these topicsAustralia news Cybercrime AI (artificial intelligence) OpenAI Computing Hacking news Share Reuse this content