200k Compromised OpenAI Credentials Available for Purchase on the Dark Web
cpomagazine.com
cpomagazine.com
I assumed there was a data breach, but no, this is just 200k credentials stolen from people's computers with normal malware. There are billions of credentials available for sale on the dark web. This particular set doesn't seem significant at all besides that anything with OpenAI gets extra clicks these days.
I don’t disagree with your premise otherwise, and grant that I might be racing to begin with.
Everything else, including your OpenAI account, are accessible via that email account + a password reset.
While there will be some people using the same password (I doubt many) the people selling them will no doubt have already validated and removed these from the set as they are obviously much more valuable.
> Finding your email password might let me see some memos, but ...
Well, it’s clear you don’t work in IT.
I’ve combed through thousands of credential dumps to perform password stuffing attacks and the success rate is always very low.
I would be shocked if the sellers hadn’t already taken any credentials that work against the associated email account out before they listed the dumps for sale, given that email account access is way more valuable than access to someone’s OpenAI account.
I know smart people work there, some friends included, but OpenAI was never a product-led startup, they were a research org. Ignoring the closed vs open debate for a moment: for all the talk of focus, focus, focus from YC, it seems unfocused to ship their models from a home-rolled platform when they could just get MS to foot the engineering and infra work. Is any of their platform stuff a real asset to OpenAI proper? Have MS do the cloud stuff, just pass them product design.
just my 2c from the outside.
Don’t outsource your money making department to a big tech company. They’ll screw you over, even if they don’t mean to.
I accidentally deleted my chat history because of the confusing UX.
From the article:
> However, the ChatGPT parent company clarified the compromised login credentials were not the result of any OpenAI data breach. Instead, they were the by-product of commodity malware-based log harvesting.
> didn't do anything wrong here besides have a ton of users
Passwords aren't a trivial part of this. OpenAI offers login with Google/Apple/MS. Managing their own passwords as well wasn't a mandatory part of the product, but a trade off: they probably got more users, but also more complexity and risks.
But still no, a malware thst grabs passwords doesn’t mean you can blame a company for using passwords.
I had the same thought as you at first, and many people speculated they’d shutter ChatGPT in favor of the API being served to others. But while anyone can sell an API, making a consumer product people want is just too rare to give it up. It’s better to learn how to service consumers and satisfy the demand.
Everyone was quick to point out that the API costs of a chatGPT clone were a fraction of the cost of ChatGPT+. So why would they focus on research and API development? I worry that they were so successful with this LLM that they’ll forget to keep researching other stuff.
1. I have found ChatGPT is very good at parroting back decent quality from learning from structured data. For example, learning reasonable code completions as well as answering technical questions. I find ChatGPT very good resource to have inside VSCode instead of switching to google. 6-7/10 I will accept GPTs output in Copilot.
2. My guess is that Microsoft's pretty chunk of profit is from selling Developer software(or so it is trying to do).
Put 1 + 2 together and you have a pretty compelling product play.
The stolen OpenAI credentials were stolen using Raccoon Infostealer (78,348), Vidar (12,984), and RedLine (6,773) malware variants.
Just my 2 cents.
>Microsoft comes under blistering criticism for “grossly irresponsible” security
It's also good marketing. For the people who use ChatGPT every day, they're a known quantity, unreliable as it is. Other companies need to show that they're better.
These are both similar advantages to what Google has with their search engines.
[1] https://auth0.com/docs/authenticate/database-connections/pas...
> India occupied the top spot with 12,632 OpenAI credentials listed on the dark web, followed by Pakistan (9,217), Brazil (6,531), Vietnam (4,771), and Egypt (4,588), while the United States was sixth with 2,995 compromised accounts.
Nothing to worry about unless you had malware on your computer -- sniffing all your data, OpenAI credentials included. It is only news because ChatGPT logs potentially have exploitable data in them.
Another misleading headline -- OpenAI has not been compromised.
Can you access logs of the chat over the API? I assume it’s just news because it’s a popular business (and everyone was using the API to recreate chatgpt so there were a million projects that could be exploited).
Has anyone written any infosec articles discussing this? Has assimov or the Simpsons poked fun at this as a danger yet?
Hmm, well the only other recent event regarding that email account was that I used it to register on a discord server.
Correct. The credentials were stolen off the client's side and then they were all aggregated into a dump.
But if you're worried and in the US, a privacy.com card could be used to protect you regardless.