web analytics

Hacker allegedly puts massive OmniGPT breach data for sale on the dark web – Source: www.csoonline.com

Rate this post

Source: www.csoonline.com – Author:

The unconfirmed breach allegedly includes email, phone numbers, API and crypto keys, credentials, and billing information, from over 30,000 OmniGPT users.

Popular AI aggregator OmniGPT, which provides access to multiple AI models including ChatGPT-4, Claude 3.5, Gemini, and Midjourney, has allegedly suffered a massive breach, exposing personal data belonging to over 30,000 users.

On Monday, a BreachForums user “Gloomer” reportedly made a post, offering samples of the allegedly stolen data. “This leak contains all messages between the users and the chatbot of this site, as well as all links to the files uploaded by users and also 30k user emails.”

The “God” level BreachForums user, reserved for the top-tier members of the hack site, made the post a little over two weeks after KrakenLabs last reported the breach, attributing it to a BreachForums post made by a user with the same alias, but a different profile avatar.

“Hi, I recently breached OmniGPT.co which is a smaller clone of ChatGPT and extracted all messages between their users and the AI (Over 34 million lines), additionally I also got the emails of 30k users and about 20% of these also come with phone number.” Gloomer had said then.

Credentials, API Keys, and crypto keys are exposed too

While details of how the attack was carried out remain unclear from either of the posts, the threat actor didn’t hesitate to paint a particularly grim picture through an amplified sales pitch.

“You can find a lot of useful information in the messages such as API keys and credentials and many of the files uploaded to this site are very interesting because sometimes they contain credentials/billing information,” Gloomer said. “Goodluck finding something and enjoy this leak.”

If the claim checks out, victims face a number of security risks, including account takeover, unauthorized access, identity theft, phishing and social engineering attacks, malware infections, and financial and repetitional damages.

Additionally, the threat actor hinted at some crypto keys to be had from the data. “I also extracted all crypto private keys from there with the help of a program I made that worked with regex and I found about 130x, 10 of which has small balance and sometimes NFTs, so don’t bother looking for that but other than that have not done any further searching of the messages file,” Gloomer added.

Gloomer’s Jan 24 post put the data dump for sale at $100.

OmniGPT’s has yet to respond

OmniGPT has not publicly acknowledged the breach or any attack. CSO reached out to the company for comments but did not receive a response till the publishing of this article.

If confirmed, OmniGPT stands to face more than reputational damage as the AI aggregator might be looking at some data compliance charges, like the European GDPR, considering its global user base. Cybersecurity media outlet hackread.com, which has seen samples of the stolen data, confirmed it contains exposed information belonging to users from Brazil, Italy, India, Pakistan, China, and Saudi Arabia.

OmniGPT is used globally for its efficient aggregation of popular AI models into a single interface, along with additional features for data encryption, team collaboration tools, document management, image analysis, and WhatsApp integration. It offers a free tier subscription with basic features and a Plus membership priced at $16 a month.

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.

Original Post url: https://www.csoonline.com/article/3822911/hacker-allegedly-puts-massive-omnigpt-breach-data-for-sale-on-the-dark-web.html

Category & Tags: Data Breach, Generative AI – Data Breach, Generative AI

Views: 2

LinkedIn
Twitter
Facebook
WhatsApp
Email

advisor pick´S post