AI/ML, Identity, Data Security, Application security![GenAI](https://image-optimizer.cyberriskalliance.com/unsafe/1920x0/https://files.cyberriskalliance.com/wp-content/uploads/2024/05/AdobeStock_603723456_Editorial_Use_Only-scaled.jpeg)
OpenAI claimed to have over 20M credentials stolen
![GenAI](https://image-optimizer.cyberriskalliance.com/unsafe/1920x0/https://files.cyberriskalliance.com/wp-content/uploads/2024/05/AdobeStock_603723456_Editorial_Use_Only-scaled.jpeg)
(Adobe Stock)
Cybernews reports that OpenAI had more than 20 million purportedly stolen account access codes that could be leveraged to circumvent authentication systems advertised for sale by the Russian threat actor dubbed "emirking" on BreachForums. Further investigation into emirking's claims is still underway but such an extensive OpenAI account credential theft may have been achieved by exploiting vulnerabilities or securing admin credentials to infiltrate the auth0.openai.com subdomain, according to Malwarebytes researchers, who noted that confirmation of the leak's legitimacy would suggest emirking's access to ChatGPT conversations and queries. With the alleged credential exfiltration posing an increased risk for social engineering attacks and API exploitation for premium subscription lures, OpenAI users have been urged to not only replace their passwords and activate multi-factor authentication but also be vigilant of suspicious account activity and attempted phishing using information they have provided to ChatGPT.
An In-Depth Guide to AI
Get essential knowledge and practical strategies to use AI to better your security program.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds