For a few months, it has been discovered that Chatgpt has risks to cyber security. In addition, there has been an increase in the sale of premium accounts of the solution stolen in the Dark Web, which is a serious risk to privacy, both of individual and companies.
A problem that adds to the recent controversy about Chatgpt’s privacy, with its prohibition of use in Italy, and the threat of a block within Germany and other countries of the European Union.
To deepen this, from Check Point they have discovered that cybercriminals are stealing the credentials of the Premium chatgpt accounts to overcome geofencing restrictions imposed by OpenAi and obtain unlimited access to the functions of this artificial intelligence tool.
“AI is a powerful tool. In Check Point Software we use it in our Threatcloud to detect and block cyber attacks in real time. Unfortunately, cybercriminals are also the first to adopt it,” explains Sergey Shykevich, Threat Intelligence Group Manager of Check Point Research.
Chatgpt’s stolen account trade
Frequently, hackers take advantage of the use of their passwords on several platforms, which allows them to use emails and password collections distributed in the Dark Web until they find combinations of coincidental credentials to access the accounts.
Check Point Research warns of an increase in cases of theft and trade of accounts Chatgpt Premium by cybercrime
Most of these stolen accounts are being sold, but some of the attackers also share the premium subscriptions of chatgpt for free to announce their own services or new tools for the theft of other accounts.
Thanks to this, analyzing the way in which the accounts and their structure were shared, the researchers have concluded that the robberies have been made by using an accounts, finally taking them to Silverbullet, a non -malicious suite destined to perform web tests.
This software can be used for data extraction and analysis, perform automated Penteting tests, or unit tests through Selenium, among other functions. However, it is also frequently used by cybercriminals to carry out credentials against different websites and, therefore, the theft of accounts.
