News: 1687255693

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Over 100,000 compromised ChatGPT accounts found for sale on dark web

(2023/06/20)


Singapore-based threat intelligence outfit Group-IB has found ChatGPT credentials in more than 100,000 stealer logs traded on the dark web in the past year.

The amount of stolen accounts steadily climbed from 74 in June 2022 to 26,902 in May 2023. April 2023 was an outlier – a moderate decline was seen in the number of accounts, before peaking the very next month.

"Group-IB's experts highlight that more and more employees are taking advantage of the Chatbot to optimize their work, be it software development or business communications," [1]said the company, adding that demand for account credentials was gaining "significant popularity."

[2]

ChatGPT stores user query history and AI responses by default. Access to the history could expose company or personal secrets.

[3]

[4]

"Many enterprises are integrating ChatGPT into their operational flow. Employees enter classified correspondences or use the bot to optimize proprietary code," said Group-IB head of threat intelligence Dmitry Shestakov.

Both [5]Apple and [6]Samsung have banned company use of ChatGPT over security issues. In the case of the latter, employees accidentally [7]leaked secrets.

[8]Samsung puts ChatGPT back in the box after 'code leak'

[9]Darkweb credit card marts in decline across Asia, researchers claim

[10]Apple becomes the latest company to ban ChatGPT for internal use

[11]AI is going to eat itself: Experiment shows people training bots are using bots

The problem is particularly rife in the heavily populated Asia Pacific region, which accounted for over 40 percent of stolen ChatGPT accounts in the time period Group-IB tracked.

India suffered the most compromised accounts (12,632), a tidbit that resonates with previous findings that the [12]subcontinent is a prime target for data theft, thanks to its size and heavy use of infotech.

[13]

Most logs (78,348) were breached using the Racoon info stealer, with Vidar accounting for 12,984 and Redline for 6,773.

Shestakov told The Register : "Racсoon is one of the most popular stealers on the market distributed under the MaaS model due to its simplicity. Released in June 2022, the new version of Raccoon was tailored better to the needs of operators and offered cybercriminals a higher level of customization and the ability to handle excessive loads."

Group-IB advises the usual procedures to mitigate thievery: update passwords regularly and implement two-factor authentication, and of course, maybe buy some of their products. ®

Get our [14]Tech Resources



[1] https://www.group-ib.com/media-center/press-releases/stealers-chatgpt-credentials/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZJHNIGR7elhNMdxAJhMU1wAAANM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZJHNIGR7elhNMdxAJhMU1wAAANM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZJHNIGR7elhNMdxAJhMU1wAAANM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2023/05/19/apple_chatgpt/

[6] https://www.theregister.com/2023/05/02/samsung_generative_ai_ban/

[7] https://www.theregister.com/2023/04/06/samsung_reportedly_leaked_its_own/

[8] https://www.theregister.com/2023/05/02/samsung_generative_ai_ban/

[9] https://www.theregister.com/2023/06/09/group_ib_apac_incident_prevalence/

[10] https://www.theregister.com/2023/05/19/apple_chatgpt/

[11] https://www.theregister.com/2023/06/16/crowd_workers_bots_ai_training/

[12] https://www.theregister.com/2023/06/09/group_ib_apac_incident_prevalence/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZJHNIGR7elhNMdxAJhMU1wAAANM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[14] https://whitepapers.theregister.com/



I'm trying to be surprised

Will Godfrey

... but failing completely.

"I would like Chat-GPT to"

Eclectic Man

"Compromise Chat-GPT accounts and sell them to crooks for money."

Oops, sorry, is that not allowed?

Mine's the coat with the tin-foil hat in the pocket.

Re: "I would like Chat-GPT to"

b0llchit

Use 50% of the accounts to generate text which you feed to the other 50% of the accounts. The results are then swapped and fed to feed the feed feeding the feeder's feed to feed the feeding feeder feed feed feed feed feed feed feed feeeeeeed meeeee!

Re: "I would like Chat-GPT to"

Zippy´s Sausage Factory

That comment is either inspired by Philip K Dick, or the "buffalo buffalo buffalo" sentence, I'm not sure which.

Is this worse that other products?

AndersH

100k accounts doesn't sound like a big number given how many total accounts there are. Is there evidence that ChatGPT is worse than other products?

Re: Is this worse that other products?

IGotOut

Probably not, but no point ignoring the problem, sorry, challenge.

Re: Is this worse that other products?

AndersH

Indeed, however, the actual problem, which is that some people's computers aren't secure and have been infected by password "stealers", isn't addressed. Look at the other comments for evidence of what people have taken from this article.

Re: Is this worse that other products?

TheGriz

LOL, it's worse simply because IT IS an LLM driven bot. There is NOTHING "intelligent" about these things. They don't "think" any more than a toaster really. Imagine a tech toaster, that has a base of data about what kind of bread is toasted, how dark or light it's being toasted, and oh that data comes from other people's toasters all around the world. So that makes it a BETTER toaster? Not really. (think about it)

Re: Is this worse that other products?

AndersH

The article is about 100k account details being available for sale. What does that have to do with the functionality of the LLM?

Re: Is this worse that other products?

Derezed

Given that God is infinite, and that the universe is also infinite... would you like a toasted teacake?

Won't get anything from me

Anonymous Coward

I tried ChatGPT, asked it about my own published work and it got it completely wrong. Tried asking it to help write a report as well, just to see what would happen, and sure enough it was totally unusable. But I would never tell it anything secret. So if my account got compromised, have fun wasting your time reading through my rubbish. By the way I always use different passwords on every account I create. And I very much doubt my account was compromised in the first place because I run secure operating systems and I'm hard to phish, but, if it was compromised, they won't get anything worth their time off me I'm afraid.

Oh but I can tell you right now the secrets of most companies. Are you ready? Here's the company secrets: "our source code is a mess, our processes are on fire and we've got loads of internal problems". Seriously, for every company worried about their amazing technology being stolen by a competitor, there are dozens of other companies whose actual reason for keeping things secret is, they want the world to think they're better than they really are, and more transparency will hurt that illusion. So if I have to sign an NDA I'm like "don't worry, your secret is safe with me, I'm not going to go telling everyone how bad your codebase is...."

Re: Won't get anything from me

Version 1.0

"The question of whether computers can think, is like the question of whether submarines can swim." - Edsger W. Dijkstra

Offer void where prohibited by law.