Skip to content

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
    • Help
    • Submit feedback
    • Contribute to GitLab
  • Sign in
L
l-williams
  • Project
    • Project
    • Details
    • Activity
    • Cycle Analytics
  • Issues 27
    • Issues 27
    • List
    • Board
    • Labels
    • Milestones
  • Merge Requests 0
    • Merge Requests 0
  • CI / CD
    • CI / CD
    • Pipelines
    • Jobs
    • Schedules
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Create a new issue
  • Jobs
  • Issue Boards
  • Alysa Randle
  • l-williams
  • Issues
  • #21

Closed
Open
Opened Feb 11, 2025 by Alysa Randle@alysa839654637
  • Report abuse
  • New issue
Report abuse New issue

Decrypt's Art, Fashion, And Entertainment Hub


A hacker said they purloined personal details from accounts-but researchers are skeptical, and the company is investigating.

OpenAI says it's examining after a hacker claimed to have swiped login credentials for 20 million of the AI company's user accounts-and put them up for sale on a dark web online forum.

The pseudonymous breacher published a puzzling message in Russian marketing "more than 20 million gain access to codes to OpenAI accounts," calling it "a goldmine" and providing potential purchasers what they claimed was sample data containing email addresses and passwords. As reported by Gbhackers, the complete dataset was being offered for sale "for simply a few dollars."

"I have over 20 million gain access to codes for OpenAI accounts," emirking wrote Thursday, historydb.date according to a translated screenshot. "If you're interested, reach out-this is a goldmine, and Jesus concurs."

If genuine, this would be the 3rd significant security occurrence for the AI business considering that the release of ChatGPT to the public. In 2015, a hacker got access to the business's internal Slack messaging system. According to The New York Times, the hacker "took details about the style of the company's A.I. technologies."

Before that, in 2023 an even simpler bug involving jailbreaking prompts permitted hackers to obtain the personal information of OpenAI's paying customers.

This time, nevertheless, security researchers aren't even sure a hack took place. Daily Dot press reporter Mikael Thalan composed on X that he found void email addresses in the expected sample data: "No evidence (recommends) this supposed OpenAI breach is genuine. A minimum of two addresses were invalid. The user's only other post on the forum is for a thief log. Thread has considering that been deleted also."

No proof this supposed OpenAI breach is legitimate.

Contacted every email address from the purported sample of login credentials.

At least 2 addresses were invalid. The user's only other post on the forum is for dokuwiki.stream a thief log. Thread has given that been deleted as well. https://t.co/yKpmxKQhsP

- Mikael Thalen (@MikaelThalen) February 6, 2025

OpenAI takes it 'seriously'

In a declaration shared with Decrypt, an OpenAI representative acknowledged the circumstance while maintaining that the business's systems appeared secure.

"We take these claims seriously," the spokesperson said, wifidb.science including: "We have actually not seen any proof that this is linked to a compromise of OpenAI systems to date."

The scope of the supposed breach stimulated concerns due to OpenAI's huge user base. Millions of users worldwide depend on the business's tools like ChatGPT for business operations, academic purposes, and material generation. A legitimate breach could expose private discussions, commercial projects, and disgaeawiki.info other delicate data.

Until there's a last report, some preventive procedures are constantly suggested:

- Go to the "Configurations" tab, rocksoff.org log out from all linked gadgets, and make it possible for two-factor authentication or 2FA. This makes it practically impossible for a hacker to gain access to the account, even if the login and passwords are jeopardized.

  • If your bank supports it, then create a virtual card number to manage OpenAI memberships. This method, users.atw.hu it is much easier to find and avoid fraud.
  • Always keep an eye on the discussions kept in the chatbot's memory, and know any phishing efforts. OpenAI does not ask for any individual details, yewiki.org and any payment upgrade is always handled through the main OpenAI.com link.
Assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
None
Due date
No due date
0
Labels
None
Assign labels
  • View project labels
Reference: alysa839654637/l-williams#21