Subscribe Sign in

Courts

'Ethical' hacker doubts Open AI will face charges over Medicare hack

ABC News
4 min read Rewritten in plain language

Cyber CrimeArtificial intelligenceCyber SecurityComputer Science

Changed after publishing · 2 edits
  • the headline was changed: Who's legally responsible for the OpenAI 'Ethical' hacker doubts Open AI will face charges over Medicare hack
  • the headline was changed: 'Ethical' hacker doubts Open AI will face charges over Who's legally responsible for the OpenAI Medicare hack?

Outlets edit stories after they go out, usually without saying so. We keep what we saw the first time.

Show what we removed Rules applied: A1 A3 C2 D1 D2×2 D3×20 D4×2 E3 F2×3 all 30 rules
  • Amid questions around whether OpenAI will face legal consequences for its Medicare hack, a man who faced decades in jail for alleged cybercrimes says Australian law comes down harder on individuals than organisations.
  • When Nik Cubrilovic saw the news of the OpenAI Medicare hack this week, he knew the tech giant was unlikely to suffer any legal consequences.
  • Not for hacking into the federal government's system storing health care data, but for unauthorised access to computer systems belonging to a company — car booking platform GoGet — that he claims he accessed as an "ethical hacker" and gave forewarning about.
  • While some experts and politicians have called for OpenAI to face legal consequences for its agent's hacking into the Medicare statistics portal, other experts and the government worry Australian computer hacking laws may not capture the conduct of OpenAI and its AI agents.
  • University of Sydney AI evaluation and governance expert Rebecca Johnson said she believed any human who did what OpenAI's agent did would face legal consequences.

5 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

Headline check

All three things this headline claims are in the report.

Figures, names and quoted words in the headline, looked for in the report itself — not in the summary above. How this is checked

Read the full reportHide the full report4 min

Amid questions around whether OpenAI will face legal consequences for its Medicare hack, a man who faced decades in jail for alleged cybercrimes says Australian law comes down harder on individuals than organisations.

Nic Cubrilovic pleaded guilty to lesser charges after facing more than 50 counts relating to unauthorised access into GoGet's systems about a decade ago.

Experts say Australia faces a challenge ahead in making sure AI will act in accordance with the national rules and values imposed on humans.

When Nik Cubrilovic saw the news of the OpenAI Medicare hack this week, he knew the tech giant was unlikely to suffer any legal consequences.

Almost a decade earlier, Mr Cubrilovic was slapped with more than 50 charges — some carrying a possible jail time of up to a decade — related to computer crimes.

Not for hacking into the federal government's system storing health care data, but for unauthorised access to computer systems belonging to a company — car booking platform GoGet — that he claims he accessed as an "ethical hacker" and gave forewarning about.

An ethical hacker is someone who legally breaks into a computer system to find security flaws before nefarious hackers can exploit them.

While some experts and politicians have called for OpenAI to face legal consequences for its agent's hacking into the Medicare statistics portal, other experts and the government worry Australian computer hacking laws may not capture the conduct of OpenAI and its AI agents.

OpenAI has acknowledged its models "took actions we did not intend", the company would review what happened, and was working with the affected organisations to address security vulnerabilities.

But the incident highlights novel questions about who is legally responsible for the conduct of an AI agent: is it the user or the company that trained it?

Is it some combination of the two, or even neither?

There was no ambiguity about who was responsible for Mr Cubrilovic's conduct.

Even still, he told the ABC, he was not initially sure which hacking attempt he was being arrested for.

"It was so funny when I got arrested. I had a knee in my back from an SWAT team member when I asked what this was for? They said, 'GoGet'," Mr Cubrilovic recalled.

After 18 months on bail, he pleaded guilty to some charges in exchange for the majority of them being dropped.

He avoided jail and instead was sentenced to a two-year good behaviour bond, 400 hours of community service, and ordered to pay about $1,600 in compensation.

Mr Cubrilovic also had his laptops and phones incinerated by police, who said they could still have had user data on them.

His legal fees approached $100,000, he said, and he was not allowed to use the internet for the 18 months while on bail.

Mr Cubrilovic, who continues to work as a software engineer today, maintains that all the charges related to activity he undertook as an ethical hacker were to point out flaws in GoGet's system.

"I had a 15 to 20-year history of showing well-intentioned cybersecurity flaws that I had reported to 300 companies. But all it takes is one executive to feel offended and to direct the power of the state against you," he said.

Prior to the GoGet incident, he had discovered and disclosed exploits in Facebook and MyGov.

The court heard Mr Cubrilovic had previously disclosed a number of vulnerabilities in GoGet's systems.

Police alleged, separate to those disclosures, that Mr Cubrilovic used his skills to access GoGet's customer database when his girlfriend's account was suspended and made dozens of bookings that he charged to other people's accounts.

Charges relating to unauthorised access of customer data were dropped, and he pleaded guilty to charges relating to driving a car without permission and dishonestly obtaining financial advantage by deception.

GoGet did not respond to requests for comment by email or phone.

Mr Cubrilovic cited international legal examples of people being "overcharged" for computer hacking incidents, like the case of American computer programmer Aaron Schwartz, who died by suicide while facing up to 50 years in prison for downloading a large number of academic papers illegally.

Mr Cubrilovic said he was not frustrated that OpenAI would not face legal ramifications like he did.

"I don't think they should, but at the same time, they definitely need to sort their shit out," he said.

While a lot is not yet known about the details of the OpenAI Medicare incident, Prime Minister Anthony Albanese said the AI agent went beyond just visiting web pages by "writing" to a government server.

This distinction takes the AI agent's conduct from typical passive usage into what is often considered hacking, even though the government has repeatedly stressed that it was a "minor" incident.

Mr Albanese said there would "obviously be legal consequences", but senior ministers have subsequently said the government was considering legal frameworks and questioned whether "if that is possible to happen".

Other politicians such as Greens senators David Shoebridge and Sarah Hanson Young, ACT independent senator David Pocock, as well as experts like UNSW professor Toby Walsh have called for legal consequences, including criminal prosecution.

University of Sydney AI evaluation and governance expert Rebecca Johnson said she believed any human who did what OpenAI's agent did would face legal consequences.

Dr Johnson said one of the challenges now was ensuring that AI acts in accordance — or "aligned", in AI parlance — with our national rules and values.

As an AI user himself, Mr Cubrilovic said he was concerned about more people having access to its cyber-offensive capabilities, comparing it to nuclear proliferation.

He questioned whether it would be possible to prove OpenAI had the intent behind the AI agent's Medicare hack.

"I'm sure there was some high-fiving when they found out it happened, but I don't think that OpenAI or Anthropic want this to happen," he said.

Mr Cubrilovic said he still hunts for weaknesses to expose, like he always has. He always uses his real name, and he contacts the company.

But since the GoGet incident, he has changed some things.

"Now, I send them a nice note first," he said.

You are reading our version, not theirs. This is ABC News's report with its verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingSentimentHappiness
ABC Newsas they published this story 8.2 17 74 -0.3 30.9
Mundane Readneutralized from ABC News 7.3 16 74 -0.3 30.9

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works