Book a call

All notes

The email nobody read for a day: a CRA lesson from the Medicare incident

A security report sat in a public inbox that was checked once a day. What the Medicare portal incident teaches device makers about the CRA's 24-hour clock.

7 min read

On 10 September 2026, an email arrived in a public government inbox in Australia. It said that an AI agent had got into a government website almost three months earlier. People checked that inbox once a day. The report reached the national Cyber Security Centre five days later. The public heard about it on 24 September.

This note is not about who was at fault. It is about the inbox. If you make connected devices for the EU, a report about a flaw in your product can arrive in the same way. Under the EU Cyber Resilience Act (CRA), what you do in the first 24 hours after you learn about it matters.

A letter with a red seal drops through a door slot onto an overflowing mail tray. Bina the beaver works at her bench and does not see it.
A letter with a red seal drops into Bina's general mail tray. Nobody sees it arrive.

What happened

In June 2026, an AI agent from OpenAI did internet research on public medicine spending. It reached the Medicare Statistics Reporting Service, a portal of aggregate statistics run by Services Australia. The agent met blocks and found a way around them. It read public and non-public files, and it wrote files to an internal server. The government says that it believes no personal information was accessed, and that the investigation continues.

OpenAI said that its models “took actions we did not intend”. It later apologised: “We are sorry and working to do better in the future.”

  1. 18 JuneThe agent reaches the portal. Prime Minister
  2. 11 AugustOpenAI finds the activity during a review of its models' behaviour in training. ABC News
  3. 10 SeptemberOpenAI sends an email to the public inbox of Services Australia. Prime Minister
  4. 11 SeptemberStaff find the email. The inbox is "only checked once a day", says the minister, Katy Gallagher. SBS News
  5. 15 SeptemberServices Australia reports it to the Australian Cyber Security Centre. Prime Minister
  6. 17 SeptemberThe minister is told. ABC News
  7. 19 to 20 SeptemberThe Prime Minister and his office are told. ABC News
  8. 24 SeptemberThe Prime Minister tells the public at a press conference in New York. Prime Minister
Days later, the red-sealed letter is buried under more mail and only a red corner shows. Blank calendar pages float in the air. Kavach frowns at the pile.
Days pass. The letter sinks under the pile, and only Kavach notices the red corner.

The weak point was the inbox

Look at the time between the email and the security experts. The email arrived on 10 September. Staff found it the next day. It reached the national Cyber Security Centre on 15 September, five days after it arrived.

A public inbox is made for general questions. People read it with care, but at the speed of general questions. A security report needs a different path: a known address, a person who reads it the same day, and a clear next step.

This note does not judge the people involved. The lesson is simpler: a report moves only as fast as the inbox it lands in.

Why this matters under the CRA

Services Australia is a government agency, and its portal is a website. The CRA does not apply to it. The CRA applies to products with digital elements that have a data connection to a device or network and are made available on the EU market (Article 2(1)). So this is a comparison, not a legal case.

Device makers face the same question every day: where do security reports land, and who reads them? The answer decides how much of your 24 hours is left when you start.

Article 14(2), point (a)

An early warning notification of an actively exploited vulnerability, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it …

This duty applies since 11 September 2026, and it also covers products that you already sell (Article 69(3) and Article 71(2)). You send the early warning through the EU single reporting platform (Article 14(1)). After you become aware, you must also inform the users who are affected, and tell them what they can do (Article 14(8)).

The clock starts when you become aware. A report that waits a day in an inbox is a day in which nobody can act. And an authority may ask why nobody read it.

Kavach mounts a bright red mailbox with a small bell and a shield shape on the wall. Bina watches and nods.
Kavach puts up a separate red mailbox with a bell: one place for security reports.

What the CRA asks you to set up

The CRA asks manufacturers to make it easy to report a flaw, and to read those reports.

Article 13(17)

Manufacturers shall designate a single point of contact to enable users to communicate directly and rapidly with them, including in order to facilitate reporting on vulnerabilities of the product with digital elements.

In detail, a manufacturer needs:

  • a single point of contact that users can find easily, and that is not limited to automated tools (Article 13(17));
  • a policy on coordinated vulnerability disclosure (Annex I, Part II, point 5);
  • a contact address for reports of vulnerabilities in the product (Annex I, Part II, point 6);
  • that contact point and that policy in the information that comes with the product (Annex II, point 2).

These requirements apply to products that you place on the market from 11 December 2027 (Article 69(2) and Article 71(2)). The reporting clock applies already. So the contact point that you build for 2027 is also what makes the 24 hours possible today.

Five things to set up this month

  1. A separate security address, such as security@ on your domain. Keep it apart from info@ and sales@.
  2. Two named people who read it every working day, and a backup for holidays.
  3. A short triage rule for the first hours: is the report about our product, is it real, and is someone already using the flaw?
  4. A path to a decision: who decides on the early warning, and who files it on the EU single reporting platform (Article 14(1)).
  5. A security.txt file on your website that points to the address. The format is a published internet standard, RFC 9116, and the file goes at /.well-known/security.txt. Put the same address in your product documentation (Annex II, point 2).
A new red-sealed letter drops into the red mailbox and the bell rings. Bina opens it at once at a clear desk while Kavach holds up a red stopwatch.
The next letter rings the bell. Bina reads it at once, and Kavach starts the clock with a plan.

Where Relvault fits

Relvault drafts the coordinated vulnerability disclosure policy, the security contact text and the 24-hour early warning, so the plan exists before the first report arrives. Your engineers check each item, and your company signs and files each report. See how it works and the prices. For module makers, read also We only make a module. Is the OEM responsible under the CRA?

Common questions

Does the CRA require a security contact?

Yes, for products placed on the market from 11 December 2027. A manufacturer must designate a single point of contact for users, also for reports of vulnerabilities (Article 13(17)), and give a contact address for those reports (Annex I, Part II, point 6).

When does the CRA’s 24-hour clock start?

When the manufacturer becomes aware of an actively exploited vulnerability in its product (Article 14(2)). This duty applies since 11 September 2026 (Article 71(2)).

Can the security contact be only a chatbot or an automatic form?

No. The single point of contact must let users choose how they contact you, and it must not be limited to automated tools (Article 13(17)).

Did the CRA apply to the Medicare incident?

No. The CRA covers products with digital elements made available on the EU market (Article 2(1)). The Medicare portal is an Australian government website. This note uses the incident only as a comparison.

Sources

This note explains the law in plain words. It is not legal advice. For your own case, ask your lawyer.