Skip to content
Information Technology

ESET Rapid Response to “Over 100,000 ChatGPT accounts were stolen via info-stealing malware”

ESET 3 mins read

ESET Rapid Response to “Over 100,000 ChatGPT accounts were stolen via info-stealing malware”

 

Commentary by Jake Moore, Global Security Advisor at ESET

According to Bleeping Computer, over the past year, ​more than 101,000 ChatGPT user accounts have been stolen by information-stealing malware to dark web marketplace data.

Jake Moore says “People may not realize that their ChatGPT accounts may, in fact, hold a great amount of sensitive information that is sought after by cybercriminals. It stores all input requests by default and can be viewed by those with access to the account.”

Cyberintelligence firm Group-IB reports having identified over a hundred thousand info-stealer logs on various underground websites containing ChatGPT accounts, with the peak observed in May 2023, when threat actors posted 26,800 new ChatGPT credential pairs.

“Furthermore, info stealers are becoming more prominent in ChatGPT compromises and even used in malware-as-a-service attacks. Info stealers focus on stealing digital assets stored on a compromised system looking for essential information such as cryptocurrency wallet records, access credentials and passwords, and saved browser logins.”

Regarding the most targeted region, Asia-Pacific had almost 41,000 compromised accounts between June 2022 and May 2023, Europe had nearly 17,000, and North America ranked fifth with 4,700.

“The fact that a regular user with free access doesn’t have the option to enable 2FA/MFA makes the service increasingly vulnerable. Therefore, it might be a wise idea to disable the chat saving feature unless absolutely necessary and use one of the single sign-on options you trust the most (currently Google, Microsoft or Apple), which uses 2FA.”

Information stealers are a malware category that targets account data stored on applications such as email clients, web browsers, instant messengers, gaming services, cryptocurrency wallets, and others.

“The more data that chatbots are fed, the more they will be attractive to threat actors, so it is also advised to think carefully about what information you input into cloud-based chatbots and other services.”

Source: https://www.bleepingcomputer.com/news/security/over-100-000-chatgpt-accounts-stolen-via-info-stealing-malware/

 


About us:

Jake Moore is a highly respected figure in the field of cybersecurity, renowned for his expertise and valuable contributions to the industry. As the Global Cybersecurity Advisor for ESET, Europe's leading cybersecurity company, he plays a pivotal role in shaping the company's strategic initiatives and ensuring the highest level of online protection for individuals and organizations.

With a wealth of experience under his belt, Jake's career in cybersecurity began during his 14-year tenure in the police force. Serving as an integral member of the Digital Forensics Unit and Cyber Crime Team in Dorset, he investigated numerous computer crimes, diligently gathering digital evidence for a wide range of offenses, from fraud to murder. His time spent in Crown Court, providing expert testimony and analysis, solidified his reputation as a meticulous and knowledgeable cybersecurity professional.

In recognition of his exceptional skills, in 2016, Jake was selected by his police force to lead a pioneering Home Office initiative. This scheme aimed to bolster local communities' resilience against the escalating cyber threats by funding the implementation of cyber security advisors in various police forces across the country. Jake's role involved visiting companies throughout the county, proactively assisting them in safeguarding their digital infrastructure against online dangers.

Jake's vast repertoire of captivating stories showcases the intricate workings of the cybersecurity realm. From harrowing accounts of botched murder investigations to the risks associated with encryption breaches, his narratives shed light on the critical importance of maintaining robust online defenses. Furthermore, his expertise in social engineering and ethical network penetration testing has proven invaluable in enlightening businesses that were previously unaware of the threats they faced. He eagerly shares these captivating tales through public talks and webinars, providing valuable insights into the ever-evolving cybersecurity landscape.

A sought-after speaker, Jake captivates audiences at prestigious business events and conferences across the United Kingdom. His engaging presentations combine informative content with a highly entertaining delivery style, making complex concepts accessible to all. From large corporations like Vodafone, The Bank of England, and Facebook, to smaller enterprises seeking to bolster their digital security, Jake has delivered hundreds of talks, empowering businesses to better protect themselves in an increasingly interconnected world.

If you are keen on hearing one of Jake's compelling talks and gaining practical knowledge on enhancing your business's cybersecurity posture, do not hesitate to reach out.

 

More from this category

  • Information Technology
  • 05/12/2023
  • 03:37
Reach

Reach Announces Platform-Agnostic Global Tax Compliance Solution

Offered worldwide, this revolutionary service ensures ecommerce businesses are fully compliant with sales tax, VAT, GST and duties, with Reach assuming all liabilities and compliance risk.CALGARY, AB / ACCESSWIRE / December 4, 2023 / Already a worldwide leader in providing Merchant of Record services to global businesses, Reach is excited to announce the worldwide expansion of its revolutionary global tax compliance solution. Unlike competing services, the Reach platform is a standalone service that can be seamlessly integrated into a merchant's existing ecommerce infrastructure without the need for additional coding or technical lift. This service not only eliminates one of the…

  • Information Technology
  • 05/12/2023
  • 00:07
Wiz

Wiz Acquires Raftt, Bolsters CNAPP Offering for Cloud and Kubernetes Developers

Cloud security provider grows its platform with acquisition of Raftt, deepening platform support for shift-left initiativesNEW YORK, NY / ACCESSWIRE / December 4, 2023 / Cloud security leader Wiz has acquired Raftt, a cloud-native platform for developer collaboration. Recently, Wiz expanded its Cloud Native Application Protection Platform (CNAPP) to empower developers. Today's acquisition further enhances Wiz's Secure Cloud Development capabilities, which enable developers to build securely across the software development lifecycle.Wiz's CNAPP - which is ranked #1 by customers and used by 40% of the Fortune 100 - already has a strong developer base: more than 50% of Wiz users…

  • Information Technology
  • 01/12/2023
  • 01:07
Cleverbridge

Cleverbridge Launches CleverInsights to Deliver Accurate, AI-Powered Analytics for Subscription Businesses

The product's easy-to-use dashboards empower companies to accurately benchmark and forecast performance, calculate robust customer health scores, and more.COLOGNE, GERMANY / ACCESSWIRE / November 30, 2023 / Cleverbridge, a growth engine for global technology companies, today announced the launch of CleverInsights, an advanced analytics suite that leverages AI and 18+ years of eCommerce data to provide unparalleled visibility into recurring revenue, retention, and other essential subscription metrics. Pre-built dashboards for benchmarking, forecasting, anomaly detection, and customer health scoring empower organizations to derive deep insights and optimize performance in near real-time amid an uncertain and ever-changing business environment. These features streamline…

Media Outreach made fast, easy, simple.

Feature your press release on Medianet's News Hub every time your distribute with Medianet. Pay per release or save with a subscription.