Over 101,000 stealer-infected devices with saved ChatGPT credentials were found on the dark web by cyberintelligence outfit Group IB.
Group-IB’s Threat Intelligence platform found these compromised credentials within the logs of info-stealing malware traded on illicit dark web marketplaces over the past year. The number of available logs containing compromised ChatGPT accounts reached a peak of 26,802 in May 2023.
The research found that the number of stealer logs containing compromised ChatGPT accounts has consistently increased from June 2022 to March 2023. In June 2022, Group-IB found 74 compromised credentials, reaching 22,597 in March 2023.
Info stealers are a type of malware that collects credentials saved in browsers, bank card details, crypto wallet information, cookies, browsing history, and other information from browsers installed on infected computers, and then send all this data to the malware operator.
Stealers can also collect data from instant messengers and emails, along with detailed information about the victim’s device, working non-selectively to infect as many computers as possible.
The nature of ChatGPT’s popularity has made it a popular choice for bad actors on the dark web- more and more employees are taking advantage of the Chatbot to optimise their work.
As ChatGPT automatically stores the history of user queries and AI responses, a hacked account can expose confidential or sensitive information, which can be exploited for targeted attacks against companies and their employees.
Recommended
- Cloud First 2023 | DevOps in Action
- UK and Singapore Bolster Cyber Defences with Collaboration Pact
- Anonymous Sudan and Killnet Strike Again, EIB Confirms Cyber Attack
“Many enterprises are integrating ChatGPT into their operational flow. Employees enter classified correspondences or use the bot to optimize proprietary code, ” Dmitry Shestakov said, Head of Threat Intelligence at Group0IB.
He added: “Given that ChatGPT’s standard configuration retains all conversations, this could inadvertently offer a trove of sensitive intelligence to threat actors if they obtain account credentials. At Group-IB, we are continuously monitoring underground communities to promptly identify such accounts.”
According to Group-IB, the Asia-Pacific region had the most stealer-infected devices with saved ChatGPT credentials, with 40,999. The UK did not make the top ten list of countries with the most compromised accounts, but Group-IB still recommends securing accounts by changing passwords and implementing two-factor authentication.





