Australia Orders Federal Agencies to Audit Old Tech After AI Agent Exploited Medicare Systems
A government-wide stocktake of ageing technology is now mandatory for all 194 Australian federal entities, after an AI-assisted attack exposed how outdated systems make government networks easier to breach.

Key points - The Australian home affairs department has ordered all federal government agencies to conduct a "legacy technology stocktake" and produce a plan to reduce old systems to within each agency's risk tolerance. - Australia's Cyber Security Posture in 2025 report, published by the Australian Signals Directorate (ASD), covers 194 federal entities. - Australia's own cyber authority warns that keeping old technology without adequate protections raises both the likelihood and the cost of any breach. - Replacing ageing systems before they become a liability is described by the ASD as the single most effective mitigation available.
Australia's home affairs department has told every federal government agency to take stock of its old technology and produce a concrete plan to reduce it, following an attack in which an AI agent broke into systems connected to Medicare, the country's public health insurance program. Reported first by Guardian Australia, the directive asks each agency to bring its reliance on old systems down to a level its own risk tolerance can justify.
On 17 September we published two separate stories on Australia's legacy infrastructure problem: the head of Australia's signals agency warning that crumbling old systems are giving AI-assisted attackers a growing opening, and a parallel piece on the agency chief's call for a formal AI early-warning network. The stocktake order is Canberra acting on exactly that warning.
The ASD's annual Commonwealth Cyber Security Posture in 2025 report maps the security health of the entire federal government across 194 entities. The picture it draws is uncomfortable.
What is "legacy technology" and why does it matter?
Legacy technology is old software or hardware the manufacturer no longer updates or supports. Like a lock where the maker stopped producing replacement parts years ago: it functions until it doesn't, and when it fails, no official fix exists.
The ASD's own practitioner guidance on managing legacy IT risks is direct. Old technology raises the chance of a breach. When one happens, it tends to be more damaging and more expensive to contain. Every mitigation short of replacement buys only temporary relief.
The Medicare incident illustrates that dynamic precisely. An AI agent, meaning software that takes actions autonomously rather than simply answering queries, found and exploited weaknesses in systems not designed with automated attacks in mind. Our 17 September story on AI agents as the dominant CISO worry showed this concern was already at the top of security leaders' lists before the Medicare breach made it a political fact.
Who is affected, and what should ordinary Australians do?
Anyone using Medicare, or any federal digital service, has a stake in whether the underlying systems are secure. Watch for unexpected contact claiming to be from Services Australia or Medicare, particularly anything asking you to confirm personal details via a link. Criminals routinely follow high-profile government incidents with phishing campaigns: fake messages designed to trick people into surrendering passwords or identification numbers.
Contact the relevant agency directly using a number from its official website, never from the message itself.
How bad is the underlying problem?
Across 194 federal entities, the ASD is explicit: organisations keeping old technology without adequate mitigations accept both security risk and financial risk, because recovering from an incident almost always costs more than a planned replacement.
| Category | Entity count (as of 30 June 2025) |
|---|---|
| Commonwealth companies | 18 |
| Total | 194 |
Canberra is counting the bill before deciding how to pay it. Stretched across 194 entities, that bill is going to be considerable, and the Medicare incident has made it politically impossible to keep deferring.
What to watch: whether agencies produce funded remediation plans or paper compliance. A stocktake that ends in a spreadsheet nobody acts on solves nothing.



