1 Decrypt's Art, Fashion, And Entertainment Hub
vickeycastigli edited this page 2 months ago


A hacker said they purloined private details from millions of OpenAI accounts-but scientists are doubtful, and the business is investigating.

OpenAI states it's investigating after a hacker claimed to have actually swiped login qualifications for 20 countless the AI company's user accounts-and put them up for sale on a dark web forum.

The pseudonymous breacher posted a puzzling message in Russian marketing "more than 20 million gain access to codes to OpenAI accounts," calling it "a goldmine" and offering potential purchasers what they claimed was sample data containing email addresses and passwords. As reported by Gbhackers, morphomics.science the full dataset was being used for sale "for simply a few dollars."

"I have over 20 million gain access to codes for OpenAI accounts," emirking wrote Thursday, according to a translated screenshot. "If you're interested, reach out-this is a goldmine, and Jesus concurs."

If legitimate, this would be the third major security event for the AI business since the release of ChatGPT to the public. Last year, a hacker got access to the business's internal Slack messaging system. According to The New York City Times, the hacker "took details about the style of the business's A.I. technologies."

Before that, in 2023 an even simpler bug including jailbreaking triggers permitted hackers to obtain the personal data of OpenAI's paying consumers.

This time, however, security researchers aren't even sure a hack took place. Daily Dot press reporter Mikael Thalan wrote on X that he found invalid email addresses in the expected sample information: "No proof (recommends) this alleged OpenAI breach is legitimate. At least 2 addresses were invalid. The user's only other post on the forum is for a stealer log. Thread has given that been deleted as well."

No proof this supposed OpenAI breach is legitimate.

Contacted every email address from the purported sample of login qualifications.

At least 2 addresses were invalid. The user's only other post on the forum is for a stealer log. Thread has actually given that been deleted also. https://t.co/yKpmxKQhsP

- Mikael Thalen (@MikaelThalen) February 6, 2025

OpenAI takes it 'seriously'

In a statement shared with Decrypt, an OpenAI representative acknowledged the situation while maintaining that the company's systems appeared safe and secure.

"We take these claims seriously," the spokesperson said, adding: "We have not seen any evidence that this is connected to a compromise of OpenAI systems to date."

The scope of the alleged breach triggered concerns due to OpenAI's huge user base. Millions of users worldwide count on the business's tools like ChatGPT for service operations, instructional functions, and content generation. A legitimate breach might expose personal discussions, commercial jobs, and other delicate information.

Until there's a final report, some preventive procedures are always suggested:

- Go to the "Configurations" tab, log out from all linked gadgets, and make it possible for two-factor authentication or 2FA. This makes it essentially impossible for a hacker to gain access to the account, even if the login and passwords are compromised.