OpenAI says it's your fault your ChatGPT account got breached

OpenAI logo on wall
Dette AI-verktøyet lover å skulle omskape tekst til 3D-rendering på bare et par minutter – men det har sine begrensninger. (Image credit: Shutterstock.com / rafapress)

OpenAI has hit back after more than 100,000 user accounts were leaked on the dark web, with more expected to come. 

A representative from the company behind the highly popular AI writer ChatGPT told Tom's Hardware that it employs industry-standard security practices, and that the leak is "the result of commodity malware on people’s devices and not an OpenAI breach."

They added that, "We are currently investigating the accounts that have been exposed. OpenAI maintains industry best practices for authenticating and authorizing users to services including ChatGPT, and we encourage our users to use strong passwords and install only verified and trusted software to personal computers."

Racoon, Vidar, RedLine

Cybersecurity firm Group-IB detailed the leak in its Threat Intelligence report, finding that the stolen credentials belonged to users who logged into ChatGPT at any point between June 2022 and May 2023, with more predicated to leak from this and following months too.

Group-IB also added that logs from May contained the highest number of compromised ChatGPT accounts, and that the Asia-Pacific region has the highest concentration of credentials up for sale. 

Additional information in the logs that contained the ChatGPT accounts include lists of domains visited and the IP addresses of the users. 

Most of the leaked credentials were found within logs that were breached using various related info stealers, one of which being the infamous Racoon, which was used to compromise 78,348 accounts. 

Racoon is particularly dangerous due to its popularity and ease of use. Threat actors can pay a subscription to use it, and there are no real technical skills required to use it. Like other info stealers, Racoon also comes with other dangerous capabilities that allow cybercriminals to launch subsequent attacks automatically.

Vidar malware was also used to steal ChatGPT accounts, although it was responsible for far less than Racoon, only used to access 12,984 accounts. RedLine malware followed with 6,773 accounts falling to its ways.

Access to the logs also means that bad actors have access to your conversation history with the chatbot too, which could be especially damaging if you are using it at work and sharing trade secrets with it.

TOPICS
Lewis Maddison
Reviews Writer

Lewis Maddison is a Reviews Writer for TechRadar. He previously worked as a Staff Writer for our business section, TechRadar Pro, where he had experience with productivity-enhancing hardware, ranging from keyboards to standing desks. His area of expertise lies in computer peripherals and audio hardware, having spent over a decade exploring the murky depths of both PC building and music production. He also revels in picking up on the finest details and niggles that ultimately make a big difference to the user experience.

Read more
SearchGPT OpenAI
Hackers offer 20 million OpenAI credentials for sale, but it says there's no evidence of a breach
Sam Altman and OpenAI
Open AI bans multiple accounts found to be misusing ChatGPT
DDoS attack
ChatGPT security flaw could open the gate for devastating cyberattack, expert warns
A person using DeepSeek on their smartphone
DeepSeek ‘incredibly vulnerable’ to attacks, research claims
Shadowed hands on a digital background reaching for a login prompt.
Private API keys and passwords found in AI training dataset - nearly 12,000 details leaked
DeepSeek
Experts warn DeepSeek is 11 times more dangerous than other AI chatbots
Latest in Pro
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Customer service 3D manager concept. AI assistance headphone call center
The era of Agentic AI
International Space Station
Is the moon too far for your data? IBM's Red Hat is teaming up with Axiom Space to send a data center into space
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
A hand reaching out to touch a futuristic rendering of an AI processor.
Balancing innovation and security in an era of intensifying global competition
Latest in News
MacBook Air mute key
The new M4 MacBook Air finally fixes an Apple keyboard annoyance that's been around for decades
A collage of Ellie and Joel in The Last of Us season 2
The Last of Us season 2's new trailer teases a huge showdown between Bella Ramsey's Ellie and Pedro Pascal's Joel, but the big moment I'm waiting for is still being held back
Apple iPhone 16 Pro Max REVIEW
New iPhone 17 Air leak may have revealed some key specs – and how it compares to the iPhone 17 Pro Max
Gaming with AI
I asked Gemini to play a text-based adventure game with me and the AI whisked me away to a word-based fantasy
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price