
AI Security Breach: OpenAI's Stolen Credentials and the Rise of WormGPT
OpenAI credentials are being sold on the dark web, with over 200,000 credentials available as stealer logs. Threat actors are increasingly interested in generative AI tools like OpenAI's ChatGPT, using them to create convincing phishing emails tailored to specific targets. Cybercriminals have even developed a malicious alternative called WormGPT, trained on malware-focused data, which shows potential for sophisticated phishing and business email compromise (BEC) attacks. The use of generative AI in BEC attacks allows for more persuasive and strategically cunning messages, posing a significant threat to organizations. Defending against this emerging threat requires training employees to verify urgent messages and improving email verification processes.