Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Security Education Videos Scams & Phishing Your Security Mobile Security Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
ChatGPT AI Platform Breached – Account Holder Data Sold On Dark Web
Facebook   X   LinkedIn   Email

ChatGPT AI Platform Breached – Account Holder Data Sold On Dark Web

March 9, 2024

Not long ago, more than 100,000 ChatGPT users learned their account credentials were for sale on the dark web. ChatGPT’s parent company, OpenAI, confirms the data breach occurred, but says it had nothing to do with a lack of data security on their part. Although the breach may be a blame game for now, there’s more to it than what’s bubbling on the surface.

Group-IB, a cybersecurity company, compiled a Threat Intelligence report on the ChatGPT breach, finding far more than account credentials were exposed. It seems the bad actors responsible also accessed chats and other communications stored in a user’s account.

Some of the content stored by ChatGPT users goes far beyond what’s personal, including company secrets, app developments, business plans, and what appears to be classified documents. The lesson here is the importance of taking great care about what data you choose to store, where you choose to store it, and the password and other protections you put in place to secure that account. Also keep in mind that with the availability of new products like ChatGPT, they’re learning from what you put into it. If you don’t want others to know your secrets, don’t put them in those programs.

In its report, Group-IB relays a statement by OpenAI regarding security practices of their ChatGPT platform as “OpenAI maintains industry best practices for authenticating and authorizing users to services including ChatGPT, and we encourage our users to use strong passwords and install only verified and trusted software to personal computers.” And if you haven’t changed your ChatGPT password, get right on it.

According to Group-IB, OpenAI is placing the lion’s share of blame on the availability of info-stealer malware like Raccoon and Vidar that are easily rented to anyone perusing the dark web.

The Security Web We Weave

Users of all kinds on platforms everywhere should know how critical strong passwords are for keeping our accounts and the information they hold secure. Also, how adding MFA (multi-factor authentication) to our logins adds a layer of identity verification and should always be used whenever possible. Also, the risks downloading apps and other software from third-party providers instead of the official sites can infect our device in a heartbeat.

Regardless of how this ChatGPT breach shakes out, it exposes the predictability of an unfortified user account being compromised at some point and how vulnerable the data stored in that account truly is. It’s up to all of us to strengthen our own account security using strong passwords and MFA – always and for every account. That’s because any amount of our hijacked PII, no matter what it is, can be used by hackers for more in-depth, future attacks.


How To Create A Strong And Unique  Password For Every Account

Education

How To Create A Strong And Unique Password For Every Account

Most of us know by now not to use the same passwords for different accounts; yet some of us still do. But users who continue to use passwords they know have been exposed in a hack are truly flirting with danger. In a recent study, Google found 1.5% of passwords are still being used despite those users knowing they’ve been compromised. A security researcher discovered more than 22 million unique passwords and over 770 million email addresses were made public on a popular hacker forum earlier this year. READ FULL STORY

The Most Hacked Apps To Get To Your Details

Mobile Security

The Most Hacked Apps To Get To Your Details

We share a lot these days. Some might even say we spout personal details like a water from a fire hydrant, especially when it comes to social media. For hackers, that means they have us all right where they want us. Researchers at TechShielder put in some work and found that there are a number of apps available to us that actually have been repeatedly compromised and share our personal information with plenty of others that we may not want to have our information. READ FULL STORY

Building Strong Passwords Using The “Don’ts” Of Password Security

Your Security

Building Strong Passwords Using The “Don’ts” Of Password Security

Much is made of the importance strong passwords give to online account security, and for good reason. That’s because password cracking is often the first step for a hacker looking to break into an account – your account. A formidable password can make a cybercriminal give-up and move onto the next potential victim. But what’s also important and often overlooked is what not to do when creating a password. Consider the “don’ts” of weak password creation as reminders of what not to do. READ FULL STORY

Top Phishing Scams Continue To Improve And Grow

Education

Top Phishing Scams Continue To Improve And Grow

Much to our dismay, cybercrooks keep finding ways to better the phishing tools they have and find other ways to include new and sneakier methods of thievery. Organizations and individuals are targets and money, identities, credentials, and more are stolen from both every day. Even cyber-savvy users can get caught in phishing scams if they don’t pay close attention to the signs and signals that something isn’t quite right. Reviewing the most pervasive phishing scams is always recommended. READ FULL STORY

AI ChatGPT And PaaS Merge, Further Weaponizing Email Phishing Campaigns

Your Security

AI ChatGPT And PaaS Merge, Further Weaponizing Email Phishing Campaigns

Hold on to your login credentials! A recent look at email phishing campaigns uncovered a 61% spike in attacks over the second half of last year. However, security pros find AI (artificial intelligence) is now accelerating these campaigns, and the number of attacks will significantly increase going forward. With the release of the AI ChatGPT platform coupled with PaaS (phishing-as-a-service) kit upgrades, email phishing is slated to be more pervasive and destructive than ever before. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...