AI Security Breach: OpenAI's Stolen Credentials and the Rise of WormGPT

OpenAI credentials are being sold on the dark web, with over 200,000 credentials available as stealer logs. Threat actors are increasingly interested in generative AI tools like OpenAI's ChatGPT, using them to create convincing phishing emails tailored to specific targets. Cybercriminals have even developed a malicious alternative called WormGPT, trained on malware-focused data, which shows potential for sophisticated phishing and business email compromise (BEC) attacks. The use of generative AI in BEC attacks allows for more persuasive and strategically cunning messages, posing a significant threat to organizations. Defending against this emerging threat requires training employees to verify urgent messages and improving email verification processes.
- OpenAI credentials stolen by the thousands for sale on the dark web BleepingComputer
- WormGPT: What to know about ChatGPT's malicious cousin ZDNet
- ChatGPT's evil twin WormGPT is secretly entering emails, raiding banks New York Post
- LLMs and AI positioned to dominate the AppSec world Help Net Security
- ChatGPT goes bad: WormGPT is an AI tool 'with no ethical boundaries' Tom's Guide
Reading Insights
0
11
2 min
vs 3 min read
79%
504 → 104 words
Want the full story? Read the original article
Read on BleepingComputer