100,000 Stolen ChatGPT Logins on the Dark Web
In June 2023, threat-intelligence firm Group-IB reported it had identified more than 100,000 devices whose saved ChatGPT credentials had been harvested by information-stealing malware and traded on dark-web marketplaces. OpenAI was not breached. The credentials were collected from individual users' infected machines — which makes the story a lesson about a new and valuable target rather than a new vulnerability.
Group-IB found the logins inside the logs of commodity infostealers — malware families such as Raccoon, Vidar, and RedLine that scrape saved passwords, cookies, and session data from a victim's browser and sell the bundle on. Their analysis covered roughly a year to May 2023, tallied over 101,000 compromised accounts, and found the Asia-Pacific region accounted for the largest share. This is an old, well-oiled criminal supply chain that had simply added a lucrative new item to its catalogue.
Why a chatbot login is worth stealing
A ChatGPT account is not valuable for the subscription. It is valuable for the history. At the time, ChatGPT retained users' conversations by default, and people had been pouring sensitive material into them: proprietary code, internal documents, business plans, customer details, credentials pasted in for “help.” A stolen login can be a window into everything a professional has discussed with the assistant — which, for some users, is a more revealing archive than their email.
Two problems wearing one trench coat
The incident stacks two familiar risks. The first is ordinary endpoint compromise: infostealers thrive on unmanaged devices, weak endpoint protection, and reused passwords. The second is the shadow-AI behaviour that makes the stolen account so valuable — employees feeding confidential data into a personal chatbot account that sits entirely outside corporate control. Neither is novel. Their combination is what turns a compromised laptop into a corporate data-exposure event.
Reducing the blast radius
- Enable multi-factor authentication on AI accounts. Stolen passwords alone should not grant access. OpenAI and others support MFA; require it.
- Provide managed, enterprise AI accounts. Business tiers offer central control, retention settings, and — critically — remove the reason for staff to use personal accounts that you cannot govern or revoke.
- Assume conversation history is sensitive. Set retention deliberately, and treat an AI account the way you treat a mailbox: a store of confidential data that needs protecting.
- Keep hammering endpoint hygiene. Infostealers are the root cause here. EDR, patching, and blocking credential theft at the endpoint prevent the logs from ever being created.
Group-IB's finding is a reminder that AI security is not only about the model — it is about the accounts, endpoints, and habits surrounding it. The most sensitive data your organisation has surrendered to an AI tool may be one infected laptop away from a dark-web listing. And you cannot protect the conversations, or price the risk, if you do not even know which staff are logging into which AI accounts with what data inside.