OpenAI confirms ChatGPT data breach
OpenAI, creator of artificial intelligence (AI)-powered chatbot ChatGPT, has confirmed that a bug in the chatbot’s source code may have caused a data leak.
The remarkable chatbot, ChatGPT, has been all over the news since its release several months ago, receiving both positive and negative coverage.
A user can do amazing things with ChatGPT, but at the same time there are concerns over safety, privacy, and its use by cybercriminals and online scammers.
According to OpenAI, a bug in the AI’s source code resulted in a breach of sensitive data. The vulnerability was in the Redis memory database, which OpenAI uses to store user information. The threat actors were able to access the open-source library and view users’ chat history.
Furthermore, approximately 1.2% of ChatGPT Plus subscribers who were active on March 20th may have had payment information compromised due to the bug. The incident exposed names, email addresses, payment addresses, credit card types, and the last four digits of credit card numbers.
OpenAI stated that only a few number of users were affected and that the vulnerability was patched shortly after discovery. The company has assured users that there is no ongoing risk to users’ data.
The company apologized to its users and to the entire ChatGPT community and assured that they will work diligently to rebuild trust.
On April 11, OpenAI announced that it would be partnering with bug bounty platform Bugcrowd to launch a bug bounty program. The program is part of OpenAI’s commitment to secure AI and to recognize and reward the valuable insights of security researchers who contribute to keeping their technology and company secure.
Through the bug bounty program, individuals can report any security flaws, vulnerabilities or bugs found within its systems for a monetary reward.
Image Credits : Rhyno Cybersecurity















Comments