Over 100,000 ChatGPT Accounts Hacked
ChatGPT users have had their data stolen in malware attacks. In the last year over 100,000 users had their data stolen. This was revealed following research into dark web transactions.
The cyber intelligence firm Group-IB discovered the compromised data. It was found within the logs of info-stealing malware. The logs were being traded on various underground websites.
An info-stealer is a form of malware that targets account data stored on web browsers. We have always discouraged this practice for this very reason. Account data can include passwords, cookies, browsing history and bank payment details.

The research suggests that the attackers targeted users’ ChatGPT login credentials. However, this is only the start. Once inside users’ systems, criminal hackers can access previous conversations and prompts. These in turn can reveal valuable information.
This situation is the latest in a series of security concerns regarding machine learning technology. The popularity of AI has soared this year. However, the pace of adoption has been matched by reports of their vulnerabilities.
In May 2023 alone, more than a quarter of the stolen data discovered came from threat actors posting almost 27,000 pieces of data.
How was this allowed to happen?
The criminals’ technique is very simple. The criminals purchase off-the-shelf info-stealing malware. This then extracts login credentials from a web browser’s SQLite database and then decrypts the stolen information.
This means that the attackers could steal information from ChatGPT without breaching its systems.
It seems that this isn’t news! ChatGPT’s parent company, OpenAI, confirmed as much in a statement issued this morning, with a spokesperson saying:
“The findings from Group-IB’s Threat Intelligence report [are] the result of commodity malware on people’s devices and not an OpenAI breach. We are currently investigating the accounts that have been exposed. OpenAI maintains industry best practices for authenticating and authorising users to services including ChatGPT, and we encourage our users to use strong passwords and install only verified and trusted software to personal computers.”
What are they saying here? It’s not their fault?
Group-IB’s research says that the majority of breaches came via Raccoon Stealer, a type of info-stealer that’s typically delivered via email. You or they can pay $75 (about £58) to access the malware for a week or $200 (£156) for a month. Sounds like a bargain? It might well be, but perhaps not.
This is relatively inexpensive for malware. However, the dark web is saturated with stolen login credentials. Therefore, compromised data won’t sell for much.
Costs will vary greatly depending on the types of data. However, among the 100,000 stolen credentials, it’s unlikely that many will sell for more than a few pints or dollars.
ChatGPT and a cyber security risk?
The big question!
Some say that AI will costs jobs. Probably true, as a recent survey suggested that 47% of admin tasks could be replaced by AI. Who really knows?
There is no doubt that AI is useful, but at what cost?
Like any technology, it is only as good as the operator. As a result, the technology is “designed to work on very specific problems in very specific environments”, and it requires human intervention to parse the information provided by AI.
Indeed, these issues mirror the industry’s general concern about the way people view cyber security technology. Chatbots are impressive, but they’re not able to take the human out of the equation, whether that’s providing automated responses to prompts or analysing information security risks.
We cannot deny the benefits that the technology will provide to businesses. However, we must exercise care regarding the way we use it and the information we hand over.
ChatGPT and the GDPR
As I have said in previous articles, any intelligencer tool can be used defensibly and offensively, so be aware. The tool itself may not be secure, which is my immediate worry. What it can be used for is another.
There is no doubt that AI has serious potential but anything with the level of power can be used in two ways.
AI can and does gather data from many sources which means your organisation might hold personal data without your knowing so. This means your business might hold data for which you have no legal basis for processing. If you can’t inform the individual, then a breach of the GDPR occurs. There are real challenges to be faced with the rise of AI in a GDPR world.
Leave a Reply