• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

ChatGPT Vulnerability May Have Exposed Users’ Payment Information

You are here: Home / General Cyber Security News / ChatGPT Vulnerability May Have Exposed Users’ Payment Information
March 29, 2023

A ChatGPT vulnerability might have uncovered payment-relevant facts of some clients of the AI instrument, as nicely as allowing for titles from some energetic user’s chat record to be viewed, OpenAI has disclosed.

In a weblog post published on March 24, 2023, the business offered particulars of a facts breach induced by a bug in an open up resource library, which forced it to consider ChatGPT quickly offline on Monday March 20.

Right after patching the vulnerability, OpenAI was able to restore each the Chat GPT company and, later on, its chat history feature, with the exception of a few hrs of background.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


The company, co-started by Twitter and Tesla CEO Elon Musk, said the bug “may have induced the accidental visibility of payment-similar information of 1.2% of the ChatGPT As well as subscribers who were being active in the course of a particular 9-hour window.”

In this window prior to ChatGPT currently being taken offline on March 20, it was feasible for some people to see yet another active user’s initially and previous name, email deal with, payment handle, the last 4 digits of a credit rating card quantity and credit score card expiration day. Nevertheless, OpenAI emphasised that “full credit card quantities had been not exposed at any time.”

The firm added that the number of consumers whose facts was exposed in this way was “extremely low” and “we are confident that there is no ongoing risk to users’ facts.”

Impacted shoppers have been notified that their payment facts may possibly have been exposed.

The knowledge could have been accessed in two means for the duration of a precise 9-hour window:

  • Opening a subscription confirmation email despatched on March 20 in between 1.00-10.00am PST. This is since some of these e-mail produced throughout that window ended up sent to the completely wrong buyers as a outcome of the bug, exhibiting their payment info.
  • In ChatGPT, clicking on ‘My account,’ then ‘Manage my subscription’ through the identical timeframe, which could have displayed the payment information of a further lively ChatGPT user.
  • OpenAI admitted it is attainable these issues could have transpired prior to this 9-hour window, but have not verified any occasions of this.

    The vulnerability was identified in the Redis shopper open up-supply library, redis-py. It was brought on by OpenAI inadvertently introducing a modify to its server that brought about a spike in Redis request cancellations, making a smaller possibility of every connection returning bad info.

    The AI chatbot’s developers use Redis to cache user data in their server, to prevent obtaining to test the database for each and every ask for.

    OpenAI apologized for the breach and outlined ways it has taken to make improvements to its units. These incorporate adding redundant checks to be certain the data returned by the Redis cache matches the requesting user and programatically inspecting its logs to make absolutely sure that all messages are only offered to the appropriate person.

    The company mentioned: “Everyone at OpenAI is committed to preserving our users’ privacy and keeping their knowledge safe and sound. It is a obligation we acquire amazingly severely. Sad to say, this week we fell quick of that determination, and of our users’ expectations. We apologize once more to our users and to the complete ChatGPT community and will do the job diligently to rebuild have confidence in.”

    A amount of security issues have been raised about ChatGPT pursuing the chatbot’s extremely publicized launch in November 2022. These contain fears it will be utilized to develop malware and subtle phishing campaigns as the technology matures.

    In addition, details privacy authorities have criticized OpenAI’s facts-scraping method to obtain the knowledge ChatGPT is based mostly on.

    Editorial impression credit history: AlpakaVideo / Shutterstock 


    Some elements of this short article are sourced from:
    www.infosecurity-magazine.com

    Previous Post: «Cyber Security News Tech Industry Bids to Tackle Cyber-Mercenary Epidemic
    Next Post: Multi-cloud ‘over-permissioning’ causing cyber risk headaches for businesses multi cloud ‘over permissioning’ causing cyber risk headaches for businesses»

    Reader Interactions

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    Primary Sidebar

    Report This Article

    Recent Posts

    • Enzo Biochem Hit by Ransomware, 2.5 Million Patients’ Data Compromised
    • US and Korean Agencies Issue Warning on North Korean Cyber-Attacks
    • Malicious PyPI Packages Use Compiled Python Code to Bypass Detection
    • New Botnet Malware ‘Horabot’ Targets Spanish-Speaking Users in Latin America
    • The Importance of Managing Your Data Security Posture
    • Camaro Dragon Strikes with New TinyNote Backdoor for Intelligence Gathering
    • Insurers Predict $33bn Bill for Catastrophic “Cyber Event”
    • Chinese Phishing Gang “PostalFurious” Expands Campaign
    • Kaspersky Says it is Being Targeted By Zero-Click Exploits
    • North Korea’s Kimsuky Group Mimics Key Figures in Targeted Cyber Attacks

    Copyright © TheCyberSecurity.News, All Rights Reserved.