News: 1709792828

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Here’s something else AI can do: expose bad infosec to give cyber-crims a toehold in your organization

(2024/03/07)


Stolen ChatGPT credentials are a hot commodity on the dark web, according to Singapore-based threat intelligence firm Group-IB, which claims to have found some 225,000 stealer logs containing login details for the service last year.

Group-IB reported finding those logs in its annual High Tech Crime Tends [1]report published last week. The document alleges it found the logs for sale on the dark web between January and October 2023.

Keep in mind these are stealer logs containing credentials, not username/password pairings – meaning there may be far more than 225k credential sets available for misuse.

[2]

According to Group-IB, it found around 130,000 of the ChatGPT credential-containing logs in the five months from June to October, 2023, representing a 36 percent increase in the number of logs found in the prior five-month period between January and May of last year.

[3]

[4]

"With more employees relying on ChatGPT for work optimization and its storage of past interactions, compromised logins could expose sensitive information, posing significant security risks for businesses," Group-IB [5]warned in a blog post summarizing its report.

[6]OpenAI shuts down China, Russia, Iran, N Korea accounts caught doing naughty things

[7]How 'sleeper agent' AI assistants can sabotage your code without you realizing

[8]Google password resets not enough to stop these info-stealing malware strains

[9]Cybercrooks are telling ChatGPT to create malicious code

This isn't the first time Group-IB has reported the theft of ChatGPT credentials. In June of last year the firm revealed it had spotted [10]more than 100,000 stealer logs containing ChatGPT usernames and passwords on the dark web – but that was for an entire year, between June 2022 and May 2023. The number of logs containing ChatGPT credentials has been steadily [11]increasing , with just 74 logs posted in June 2022, and 26,802 published in May 2023.

It's worth noting that the data presented last June overlaps with the period of this latest report, which covers January to October 2023. Of the more than 100,000 previously reported logs containing ChatGPT credentials, 95,827 were discovered from January to May.

"The sharp increase in the number of ChatGPT credentials for sale is due to the overall rise in the number of hosts infected with information stealers, data from which is then put up for sale on markets or in [underground clouds of logs]," Group-IB explained in its report.

[12]

As we reported recently, ransomware actors are [13]increasingly relying on infostealers to gain initial footholds into victim networks. We've also noted recently that cyber baddies have begun [14]seeing a role for LLMs like ChatGPT in illicit online activity.

In other words, it's probably a good idea to enable multifactor authentication and regularly change those ChatGPT passwords – especially if you're using it for work. ChatGPT retains logs of questions put to it, its responses and user data – all valuable information in the wrong hands.

OpenAI didn't respond to questions for this story. ®

Get our [15]Tech Resources



[1] https://www.group-ib.com/landing/hi-tech-crime-trends-2023-2024/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZemeYc0SVtuT7XcQwnUTpAAAAQw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZemeYc0SVtuT7XcQwnUTpAAAAQw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZemeYc0SVtuT7XcQwnUTpAAAAQw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.group-ib.com/media-center/press-releases/hi-tech-crime-trends-2023-2024/

[6] https://www.theregister.com/2024/02/15/openai_microsoft_spying/

[7] https://www.theregister.com/2024/01/16/poisoned_ai_models/

[8] https://www.theregister.com/2024/01/02/infostealer_google_account_exploit/

[9] https://www.theregister.com/2023/01/06/chatgpt_cybercriminals_malicious_code/

[10] https://www.theregister.com/2023/06/20/stolen_chatgpt_accounts/

[11] https://www.group-ib.com/media-center/press-releases/stealers-chatgpt-credentials/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZemeYc0SVtuT7XcQwnUTpAAAAQw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://www.theregister.com/2024/02/29/infostealers_increased_use/

[14] https://www.theregister.com/2024/02/17/ai_models_weaponized/

[15] https://whitepapers.theregister.com/



"With more employees relying on ChatGPT"

Pascal Monett

Why are more employees relying on a beta service that makes stuff up ?

The only thing they're really doing is giving their time and data for free to a service which, once declared in production, will gouge them for their own work on a monthly subscriptoin basis.

Re: "With more employees relying on ChatGPT"

Yorick Hunt

Sounds like they're talking about journalists and lawyers.

I wonder if my hobby

Anonymous Coward

of posting tens of thousand of bogus credentials into ChatGPT will have any effect ?

IIf nothing else it's a good test for a candidate: write a script that generates inane questions and peppers then with random private keys. You have 15 minutes.

Doctor Syntax

It looks like it's going to be another of those gifts that keeps on giving.

I don't kill flies, but I like to mess with their minds. I hold them above
globes. They freak out and yell "Whooa, I'm *way* too high."
-- Bruce Baum