Site navigation

Over 100k ChatGPT Credentials Found on Dark Web

Elizabeth Greenberg

,

chatgpt dark web
The demand for stolen ChatGPT credentials are growing in popularity on the dark web. 

Over 101,000 stealer-infected devices with saved ChatGPT credentials were found on the dark web by cyberintelligence outfit Group IB.

Group-IB’s Threat Intelligence platform found these compromised credentials within the logs of info-stealing malware traded on illicit dark web marketplaces over the past year. The number of available logs containing compromised ChatGPT accounts reached a peak of 26,802 in May 2023.

The research found that the number of stealer logs containing compromised ChatGPT accounts has consistently increased from June 2022 to March 2023. In June 2022, Group-IB found 74 compromised credentials, reaching 22,597 in March 2023.

Info stealers are a type of malware that collects credentials saved in browsers, bank card details, crypto wallet information, cookies, browsing history, and other information from browsers installed on infected computers, and then send all this data to the malware operator.

Stealers can also collect data from instant messengers and emails, along with detailed information about the victim’s device, working non-selectively to infect as many computers as possible.

The nature of ChatGPT’s popularity has made it a popular choice for bad actors on the dark web- more and more employees are taking advantage of the Chatbot to optimise their work.

As ChatGPT automatically stores the history of user queries and AI responses, a hacked account can expose confidential or sensitive information, which can be exploited for targeted attacks against companies and their employees.


Recommended


“Many enterprises are integrating ChatGPT into their operational flow. Employees enter classified correspondences or use the bot to optimize proprietary code, ” Dmitry Shestakov said, Head of Threat Intelligence at Group0IB.

He added: “Given that ChatGPT’s standard configuration retains all conversations, this could inadvertently offer a trove of sensitive intelligence to threat actors if they obtain account credentials. At Group-IB, we are continuously monitoring underground communities to promptly identify such accounts.”

According to Group-IB, the Asia-Pacific region had the most stealer-infected devices with saved ChatGPT credentials, with 40,999. The UK did not make the top ten list of countries with the most compromised accounts, but Group-IB still recommends securing accounts by changing passwords and implementing two-factor authentication.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data