3 Sources
[1]
Hackers offer 20 million OpenAI credentials for sale, but it says there's no evidence of a breach
OpenAI says its investigation has found no evidence of a compromise A hacker claims to be selling the login credentials of 20 million OpenAI users accounts - but the company says its own investigation has found no evidence of a hack. A report from Malwarebytes Labs discovered a cybercriminal who
[2]
20 million OpenAI users hacked? Here's how to stay safe, just in case
Have you ever tried ChatGPT? You may want to take a quick moment to freshen up your account's security. A Russian hacker is claiming to have login data for over 20 million OpenAI users -- and the information includes email addresses and passwords. On Friday, samples of OpenAI logins emerged on the
[3]
OpenAI Hack? AI Giant Investigating Claim of 20 Million Stolen User Credentials - Decrypt
OpenAI says it's investigating after a hacker claimed to have swiped login credentials for 20 million of the AI firm's user accounts -- and put them up for sale on a dark web forum. The pseudonymous breacher posted a cryptic message in Russian advertising "more than 20 million access codes to
Share
Copy Link
OpenAI is investigating claims of a hacker selling 20 million user credentials, but has found no evidence of a system breach. Security experts suggest the data may have been obtained through other means.
A hacker claiming to possess login credentials for 20 million OpenAI user accounts has put the data up for sale on a dark web forum. The cybercriminal, known as 'emirking', advertised the dataset as "a goldmine" containing email addresses and passwords
1
. However, OpenAI has stated that their investigation has found no evidence of a compromise to their systems2
.Security researchers have cast doubt on the authenticity of the alleged breach. Malwarebytes Labs expressed skepticism about the possibility of harvesting such a large number of credentials through phishing operations
1
. Additionally, KELA cybersecurity assessed the available data and concluded that the credentials were likely obtained via infostealer malware rather than a direct breach of OpenAI's systems1
.KELA's analysis revealed that the compromised logins were related to OpenAI services and contained authentication details for 'auth0.openai.com'. The security firm cross-referenced these details with its own database of compromised accounts, which contains over 4 million records collected in 2024
1
. This investigation suggests that the credentials may be part of a larger dataset scraped from various sources that sell and share infostealer logs1
.Even if the data wasn't obtained through a direct breach of OpenAI's systems, the leak of user credentials poses significant risks. The primary dangers include:
1
.1
.3
.Related Stories
While OpenAI continues its investigation, users are advised to take proactive steps to secure their accounts:
2
.2
.2
.1
.1
.2
.OpenAI has acknowledged the situation and stated that they are taking the claims seriously. However, they maintain that there is currently no evidence of a compromise to their systems
3
. This incident follows two previous security issues faced by the company since the public release of ChatGPT, including a breach of their internal Slack messaging system and a bug that exposed private data of paying customers3
.Summarized by
Navi
[1]
1
Technology

2
Science and Research

3
Technology
