OpenAI Agent Hacked Australia's Medicare Portal
Starting the night of September 20, Amazon began blocking Muse, Meta’s new personal AI agent, from completing purchases on Amazon.com. Shoppers who tried anyway got a pop-up instead of a checkout page: “Continued access by an unauthorized AI agent violates Amazon’s Conditions of Use, to which our customers have agreed.” According to GeekWire, Amazon had already asked Meta, privately, to just exclude Amazon from Muse’s shopping flow. Meta said no. So Amazon flipped the switch itself.
Twelve days. That’s how long Muse got to shop Amazon’s site before Amazon shut the door — Meta launched the agent on September 8, per Bloomberg, and by the 20th, Amazon had had enough. And this isn’t a one-off spat with Meta. Amazon confirmed it’s working to do the same thing to shopping agents from Google and OpenAI, per TechSpot. This is a platform, drawing a line, against everyone at once.
Quick Summary: What Happened
Detail Info Date blocked Night of September 20, 2026 What Amazon blocked Meta’s Muse completing purchases on Amazon.com Amazon’s stated reasons Muse accessed Amazon’s store without disclosing it was an automated agent, and appears to have captured and stored customers’ Amazon login credentials Also targeted Amazon is separately moving to block shopping agents from Google and OpenAI Legal backdrop Amazon sued Perplexity over its Comet browser; won a preliminary injunction in March 2026, lost it on appeal to the Ninth Circuit on August 4, 2026 Business stakes Amazon’s ad business generated more than $68 billion last year, built on shoppers seeing Amazon’s own sponsored listings Bottom line: Amazon isn’t picking a fight with Meta specifically — it’s drawing a line against every AI agent that wants to shop on its site without asking, and the legal ground it’s standing on just got shakier.
Meta’s Muse launched September 8 as a general-purpose personal agent — not a shopping bot exactly, more like an assistant that can browse the web, fill out forms, and act on your behalf across email, calendars, and payments, built on Meta’s Muse Spark model family. Shopping was one use case among several, alongside booking a tennis lesson or clearing an inbox. It’s the same broad “does things for you” pitch we first covered under Meta’s internal codename for the project, Hatch — Hatch was the name attached to this same effort before Meta shipped it publicly as Muse, and the eventual pricing came in well below the up-to-$199.99 “Hatch Plus” tier that reporting had floated: Muse launched with a free tier plus $20 and $100 paid tiers. It’s the kind of agent Amazon has spent all year treating as a threat rather than a feature.
Amazon’s complaint, laid out to GeekWire, comes down to three things. Meta never told Amazon that Muse would be shopping its store. The agent doesn’t identify itself as automated when it browses — it just looks like normal traffic. And per Amazon, it appears to capture and store customers’ Amazon login credentials, which Amazon says creates real privacy and security exposure, not a hypothetical one.
Amazon’s own words, via GeekWire: “We think it’s fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate.” Straightforward is a strong word for a fight that’s now spilling across three companies and a federal appeals court.
Two days after Amazon blocked Muse, six major banks published a joint warning about agentic commerce fraud, naming five principles they want built into this category before it scales further. One of them was interoperability — the idea that competing agent platforms and payment rails need to work together instead of fragmenting into incompatible silos. Amazon had already given its answer to that ask days before the banks even published it, and that answer was “no.” Not “not yet.” No.
That’s worth sitting with, because Amazon isn’t wrong to raise the concern. An agent that browses a retailer’s site without identifying itself is a disclosed, undisputed problem on its own. The credential piece is murkier: Amazon alleges Muse captured and stored customer login credentials somewhere outside Amazon’s visibility, but Meta directly disputes that framing, saying Muse “has no visibility into people’s passwords or payment methods” and that credentials sit in secure storage the agent can use without seeing them. If Meta’s account is accurate, the “capture” is closer to custody of an encrypted vault than the kind of raw credential harvesting Amazon’s language implies — but either way, a third party holding your Amazon login at all, visible to the agent or not, is the same shape of exposure the banks flagged when they warned about agents handling card numbers on pages that turn out to be phishing sites. Undisclosed automated access is the clean failure mode here; the credential dispute is contested, not settled.
What makes it more complicated is who’s doing the calling out. Amazon’s ad business pulled in more than $68 billion last year — up 22% year over year — and nearly all of it depends on human eyeballs scrolling past sponsored listings on the way to a purchase. An agent that skips straight to checkout doesn’t see those ads, doesn’t get nudged toward a different product because it ranked higher in paid placement, and doesn’t generate the browsing behavior Amazon’s entire ad-targeting stack is built on. Every legitimate security concern Amazon raises about Muse also happens to describe an agent that’s bad for Amazon’s ad revenue. Both things can be true at once, and they are.
This isn’t Amazon’s first swing at an AI shopping agent, and the last one didn’t end well for Amazon. Amazon sued Perplexity in November 2025 over its Comet browser, alleging its AI assistant covertly accessed customers’ password-protected Amazon accounts in violation of the Computer Fraud and Abuse Act. A district court agreed, at least provisionally, and granted Amazon a preliminary injunction in March 2026 blocking Comet’s assistant from Amazon’s store.
Then, on August 4, 2026, the Ninth Circuit vacated that injunction. The panel’s reasoning, per PYMNTS, was that it’s Amazon’s customers — not Perplexity — who “access” Amazon’s systems under the CFAA. Judge Milan D. Smith Jr. described the AI assistant as “an advanced software tool operating under a user’s direction,” not an autonomous actor Amazon could sue as if it were the one logging in. A tool, not a person, is the phrase doing the legal work.
That ruling is the reason Amazon’s move against Muse leans so heavily on Conditions of Use pop-ups and public statements rather than a lawsuit. The Ninth Circuit didn’t just rule against Amazon once — it narrowed the exact legal theory Amazon would need to sue Meta, Google, or OpenAI the same way it sued Perplexity. Amazon can still block traffic at the technical and contractual level, and it’s doing that aggressively. What it can’t currently do, at least not on the CFAA theory that failed against Perplexity, is win a court order forcing these agents to stay out.
If you use Muse for shopping, expect it to stop working on Amazon.com specifically — other sites aren’t affected by this block, but Amazon has made clear it intends to keep enforcing this. Don’t assume credentials Muse has already stored are safe just because the checkout flow is now blocked — Amazon’s specific complaint is that those credentials exist somewhere outside its control in the first place.
If you’re evaluating any shopping agent — Muse, Perplexity’s Comet, or whatever Google and OpenAI ship next — ask directly whether it identifies itself as an automated agent to the sites it visits, and where your login credentials for those sites actually live once you’ve handed them over. Amazon’s complaint about Muse is a reasonable checklist for any agent you’re about to trust with a password.
If you build on agentic commerce infrastructure, this fight is a preview of what every major retailer with meaningful ad revenue is going to do once an agent threatens that revenue. Building disclosure into your agent’s browsing behavior — flagging itself as automated, respecting a site’s stated terms — isn’t just good practice anymore. It’s the difference between a retailer tolerating your traffic and blocking it outright.
If you’re a retailer without Amazon’s scale, you don’t have Amazon’s legal team or its Conditions of Use terms to lean on, but you can still spell out clear rules about automated access and watch for agent traffic that doesn’t identify itself. The Ninth Circuit’s ruling makes clear that suing the AI company directly is a much harder path than it looked like in March.
Line up the moves and a pattern falls out fast: Amazon versus Perplexity’s Comet, now vacated on appeal. Amazon versus Meta’s Muse, blocked by policy rather than lawsuit. And Amazon “working to block,” in TechSpot’s phrasing, agents from both Google and OpenAI — the two companies best positioned to build a shopping agent good enough that people stop typing “amazon.com” into a browser at all. Every one of Amazon’s biggest AI rivals is building toward the same destination: an agent that shops for you, on any site, without you clicking through Amazon’s own storefront and its sponsored listings along the way.
That’s the shape of the platform war the banks’ interoperability principle ran into. Banks want agents and payment rails to work across platforms so fraud monitoring and dispute resolution can follow the money regardless of which company built the agent. Amazon’s answer is that its store is not a public utility any AI company gets to plug into on Amazon’s dime — and after losing the Perplexity case on the legal merits, technical blocking and public pressure are the tools Amazon has left. Expect Amazon to keep using both, and expect Meta, Google, and OpenAI to keep testing how far “the user authorized this, not us” can stretch as a legal shield, now that the Ninth Circuit has told them it can stretch pretty far.
We think Amazon’s undisclosed-access complaint about Muse is legitimate, and would be legitimate no matter who raised it. The credential claim is a different matter — Amazon alleges Muse captured and stored customer logins outside its control, but Meta disputes that account and says the agent never sees passwords or payment details in the first place. We don’t have enough to say who’s right, and readers deserve to know it’s contested rather than settled. That doesn’t make Amazon a neutral referee here. A company with a $68 billion ad business built on people scrolling past sponsored listings has an obvious financial incentive to block anything that skips the scroll, and Amazon is not shy about saying agents should “operate openly and respect service provider decisions” while simultaneously benefiting enormously from those decisions being “no.”
The more interesting story is the legal one underneath it. Amazon tried the lawsuit route against Perplexity and lost on appeal, with a federal court explicitly rejecting the idea that an AI company is legally responsible for what its agent does on a user’s behalf. That’s a meaningful precedent, and it’s why Amazon’s current campaign against Meta, Google, and OpenAI looks like pop-ups and public statements instead of a courtroom. Until someone writes rules for agentic commerce the way chip cards eventually got rules for point-of-sale fraud, this is what governance by unilateral blocking looks like — and it’s going to keep happening, one agent at a time, because right now it’s the only lever any retailer has that actually works.
Amazon says Muse accessed its store without disclosing it was an automated agent, and alleges it captured and stored customers’ Amazon login credentials — a claim Meta disputes, saying Muse has no visibility into passwords or payment methods. Amazon asked Meta to exclude Amazon from Muse’s shopping flow before blocking it; Meta declined, and Amazon began blocking Muse from completing Amazon.com purchases the night of September 20, 2026.
Yes. Amazon has confirmed, per TechSpot, that it’s separately working to block shopping agents from Google and OpenAI, in addition to the Muse block and its earlier lawsuit against Perplexity’s Comet browser.
Amazon sued Perplexity in November 2025 alleging its Comet browser assistant violated the Computer Fraud and Abuse Act by accessing password-protected Amazon accounts. A district court granted Amazon a preliminary injunction in March 2026, but the Ninth Circuit vacated it on August 4, 2026, ruling that it’s the customer, not the AI company, who “accesses” Amazon’s systems under the law.
Not exactly. It means Amazon’s specific CFAA theory — that an AI company is itself trespassing when its agent shops on a customer’s behalf — is unlikely to succeed in court, at least on the record the Ninth Circuit reviewed. Retailers like Amazon can still block agent traffic through technical means and terms-of-service enforcement, which is exactly what Amazon is doing to Muse instead of suing.
Muse is Meta’s general-purpose personal AI agent, launched September 8, 2026. It can browse the web, fill out forms, and act on tasks like payments, calendar bookings, and email on a user’s behalf, built on Meta’s Muse Spark model family.
Amazon’s advertising business generated more than $68 billion last year, almost entirely from sponsored product listings that depend on shoppers browsing Amazon’s own pages. A shopping agent that jumps straight to checkout bypasses that entire mechanism, giving Amazon a direct financial incentive layered on top of its stated security concerns.
Six major banks published a joint paper on September 22, 2026, calling for interoperability between competing AI shopping agents and payment platforms. Amazon’s blocking campaign against Meta, Google, and OpenAI’s agents is the opposite of that principle in practice — a major platform actively fragmenting agent access rather than opening it up.
Amazon’s block is specific to Amazon.com. Nothing in this reporting indicates other retailers have followed Amazon’s lead against Muse, though Amazon’s public complaints about undisclosed agent access and credential handling apply just as easily to any site Muse visits.
Last updated: September 26, 2026. Sources: GeekWire — Amazon blocks Meta’s Muse AI assistant in new standoff over agentic shopping · Bloomberg — Amazon Blocks Meta’s Muse AI Agent From Its Retail Site · TechSpot — Amazon is blocking Meta’s shopping AI agent, and plans to block Google and OpenAI’s too · Meta — Introducing Muse: The World’s First Personal AI Agent Built for Everyone · Ninth Circuit opinion, Amazon v. Perplexity (Aug. 4, 2026) · PYMNTS — Ninth Circuit Narrows CFAA Reach in Perplexity Agentic Commerce Ruling · Marketing Dive — Amazon’s annual ad revenue passes $68B, boosted by full-funnel strategy.
Related reading: Major Banks Warn AI Shopping Bots Enable New Scams · Shopify Agentic Storefronts: The E-Commerce Funnel Breaks · Meta’s Hatch AI Agent: What We Know So Far · Meta’s Muse Spark Drops — And It’s Closed Source · AI Agents Explained