Thousands of OpenAI credentials found for sale on the dark web

darkweb
(Image credit: Archive)

Interest in artificial intelligence tools on the dark web has spiked as cybercriminals look to get their hands on users’ sensitive data, experts have warned.

Figures from threat exposure management company Flare identified more than 200,000 OpenAI credentials for sale on the dark web, each with the potential of enabling a hacker to pry open company secrets and personal information.

To blame for the exposure of these credentials is info-stealing malware, the logs of which likely include even more information that was not intended to be viewed by others.

Your ChatGPT login could be for sale

While the number of at-risk credentials is insignificant in comparison to the number of users (an estimated 100 million for ChatGPT), the figure is up from the approximately 101,000 credentials that were identified tucked away inside the logs of info-stealing malware earlier in June.

At the same time, a malicious ChatGPT alternative that has been trained using data about malware has been gaining popularity. With a few simple prompts, screenshots show the AI chatbot generating convincing-looking attacks that threat actors could use to share with victims via emails, ads, or web pages.

In response to previous cases of dark web-hosted credentials, OpenAI told Tom’s Hardware:

“OpenAI maintains industry best practices for authenticating and authorizing users to services including ChatGPT, and we encourage our users to use strong passwords and install only verified and trusted software to personal computers.”

Rather than a flaw in OpenAI’s system, victims are having their credentials exposed via info-stealing malware that could be coming from a range of entry points, including fake ads and scam emails designed to plant malware on host devices.

Flare recommends that those who consider themselves to be at risk conduct regular dark web monitoring and to use the most up-to-date endpoint protection software, many of which in recent months have been given AI boosts to improve detection. Companies are also urged to practice good Internet hygiene and to refresh staff training periodically.

Via Bleeping Computer

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
SearchGPT OpenAI
Hackers offer 20 million OpenAI credentials for sale, but it says there's no evidence of a breach
DeepSeek
Experts warn DeepSeek is 11 times more dangerous than other AI chatbots
Shadowed hands on a digital background reaching for a login prompt.
Private API keys and passwords found in AI training dataset - nearly 12,000 details leaked
A person using DeepSeek on their smartphone
DeepSeek ‘incredibly vulnerable’ to attacks, research claims
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
DDoS attack
ChatGPT security flaw could open the gate for devastating cyberattack, expert warns
Latest in Pro
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
AI quantization
What is AI quantization?
US flags
US government IT contracts set to be centralized in new Trump order
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Google Gemini AI
Gmail is adding a new Gemini AI tool to help smarten up your work emails
Latest in News
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space