Back to News
SecurityAI Understanding briefing

Sydney man allegedly used ChatGPT to breach NSW court data

A Sydney man charged with accessing nearly 9,000 sensitive documents from a NSW courts website allegedly used ChatGPT to generate Python scripts for the mass download, according to court reports.

4 min readRead the primary source
Source-provided image accompanying Sydney man allegedly used ChatGPT to breach NSW court data
Source referenceSource recorded
Publisher
ia.acs.org.au
Source link
ia.acs.org.auhttps://ia.acs.org.au/article/2026/sydney-man-allegedly-used-chatgpt-in-court-data-breach.html
Source type
Linked source — primary-source status has not been established.

Story last revised

ContextUnderstand this in 60 seconds

Start here

Key terms

Generative AI
AI systems that produce new content such as text, images, audio, video, or code.
Prompt
The input instructions and context provided to a generative model.
Test yourselfAI Ethics Quiz

What happened

Christopher Duff, 40, appeared in Sydney's Downing Centre Local Court for a hearing regarding charges of accessing restricted data. Prosecutors alleged that Duff used OpenAI's ChatGPT to write Python code for scraper-style software that enabled the bulk downloading of approximately 9,000 sensitive documents from the NSW Online Registry in early 2025. The documents included apprehended violence orders and details of minors. Prosecutors intend to use Duff's conversations with ChatGPT as evidence, including instances where he allegedly sought legal advice and coaching on how to respond to police. The case is reported to be among the first in Australia to use generative AI interactions as evidence in a criminal data breach trial.

Christopher Duff, 40, pleaded not guilty to four counts of accessing restricted data involving nearly 9,000 sensitive documents from the NSW Online Registry, a portal for the NSW Department of Communities and Justice. The alleged breach occurred in early 2025, and Duff was charged in April 2025 after police seized two laptops from his home.

Prosecutors alleged that Duff used ChatGPT to generate Python scripts for scraper-style software, which allowed him to bulk download the data. The documents included sensitive information such as apprehended violence orders and details of minors. Duff's defense counsel noted that there may be no dispute over his responsibility for some of the conduct, but argued that prosecutors must prove he knew the access was unauthorized, rather than just being reckless.

Prosecutors plan to use Duff's conversations with ChatGPT as evidence, including instances where he allegedly sought legal advice and 'coaching' on what to say to police before declining to answer questions in a formal interview. This is reported to be among the first cases in Australia to use generative AI interactions as evidence in a criminal data breach trial.

The court heard that Duff was allegedly attempting to help a friend undergoing bankruptcy proceedings. Prosecutors mentioned examples from the United States where AI usage records were used in legal proceedings, including a case involving Anthropic's Claude AI and another involving ChatGPT in planning a vehicle explosion. The case has been adjourned for two weeks.

Source details: ia.acs.org.au

Why it matters

This case marks a significant development in the intersection of AI usage and criminal law, specifically regarding the admissibility of AI chatbot logs as evidence of intent and method. It highlights the practical security risks of using generative AI tools to create unauthorized access scripts, demonstrating that AI can lower the barrier to entry for sophisticated data breaches. The legal precedent being set in Australia regarding the use of AI-generated code and AI-mediated communications in court has broader implications for how AI tools are regulated and scrutinized in legal proceedings. It also underscores the need for individuals to understand the legal and ethical boundaries of AI assistance in potentially illegal activities.

The use of ChatGPT logs as evidence in a criminal data breach case sets a potential legal precedent in Australia. It raises questions about the admissibility of AI-mediated communications and AI-generated code in court, which could impact how AI tools are used and regulated in legal contexts.

The case highlights the security risks associated with using generative AI to create unauthorized access scripts. It demonstrates that AI can lower the technical barrier for data breaches, making it easier for individuals with limited coding skills to commit sophisticated cybercrimes.

The incident underscores the importance of understanding the legal and ethical boundaries of AI assistance. Individuals using AI for legal or technical advice must be aware that their interactions with AI tools may be subject to legal scrutiny and could be used as evidence against them.

The case may influence future rulings on the use of AI in criminal proceedings, potentially leading to new guidelines or regulations regarding the admissibility of AI-generated content and AI-mediated communications in court.

What to watch next

The outcome of the upcoming hearing, which has been adjourned for two weeks, will determine whether the court accepts ChatGPT logs as valid evidence. Legal experts will be watching to see if the prosecution can prove Duff's knowledge of the unauthorized nature of the access, as opposed to mere recklessness. This case may influence future rulings on the admissibility of AI-generated content and AI-mediated communications in criminal cases across Australia and potentially other jurisdictions.

The outcome of the upcoming hearing, which has been adjourned for two weeks, will be crucial in determining whether the court accepts ChatGPT logs as valid evidence. This decision could set a precedent for future cases involving AI-generated content and AI-mediated communications.

Legal experts will be watching to see if the prosecution can prove Duff's knowledge of the unauthorized nature of the access, as opposed to mere recklessness. This distinction is critical in determining the severity of the charges and the potential penalties.

The case may influence future rulings on the admissibility of AI-generated content and AI-mediated communications in criminal cases across Australia and potentially other jurisdictions. It could lead to new guidelines or regulations regarding the use of AI in legal proceedings.

The incident may also prompt further discussion and regulation around the use of AI tools in criminal activities, including the development of new laws or policies to address the unique challenges posed by AI-generated code and AI-mediated communications.

Related guides & quizzes

AI EthicsAI AgentsFuture of AITest what you know — try a free AI quizLook up an AI term in our glossary
Found this useful?