Over 100,000 ChatGPT accounts being sold on the dark web — what you need to know

A graphic showing off OpenAI's new GPT-4 AI language model
(Image credit: OpenAI)

Over 100,000 ChatGPT accounts have been compromised by malware and put up for sale on the dark web, according to a new report. This means both the account credentials and the contents of chat histories can be accessed by bad actors willing to pay top dollar on illegal marketplaces. Given the explosion of popularity of OpenAI’s tool over the last few months, this news should serve as warning for most of the chatbot's casual users. 

On Tuesday, Singapore-based cybersecurity company Group-IB announced that it had discovered the compromised ChatGPT credentials inside logs coming from an info stealing malware called Raccoon traded on the dark web. The company identified 101,134 stealer-infected devices with saved ChatGPT credentials. 

What does this mean for average users? Well, if hackers enter the compromised accounts they’ll gain access to any chats users stored online. Therefore, any personal information or company trade secrets users may have entered in their prompts to OpenAI’s chatbot could end up in the wrong hands. 

Group-IB found the Raccoon info stealer breached the majority of the logs containing the ChatGPT accounts. Raccoon is one of the more prominent info stealers available and requires little coding experience to procure and operate. Like other trojans, info stealers are a type of malware that indiscriminately collects credentials from instant messengers, emails, and browsers. It then sends all this data to the malware operator. 

The cybersecurity firm said the sheer amount of compromised ChatGPT accounts it is finding shows just how popular ChatGPT has become around the world.

The company started identifying stealer logs with compromised data as early as June 2022. It found 74 of them. Back then, ChatGPT3 was already in existence but it wasn’t widely released to the public. By May 2023, six months after the famous November launch, that figure had exploded to 26,802.

Within this study period, the Asia-Pacific region saw the largest number of ChatGPT account credentials stolen by info stealers. Broken down by country, India, Pakistan, and Brazil topped the list with the U.S. coming in sixth.

OpenAI was quick to point out in a statement shared with The Hacker News the accounts were compromised due to malware on people’s devices and not because of an OpenAI breach. Nonetheless, it said it’s investigating the exposed accounts.

How to stay safe using ChatGPT

man sat at darkened desk working on laptop and desktop

(Image credit: Shutterstock)

OpenAI’s users will naturally be asking themselves what they can do to prevent their accounts from being leaked. The usual security practices apply. 

Set a strong password and change it every so often, especially if you have reason to believe you may have been targeted by an info stealer or other types of malware.

Group-IB also recommends enabling Two Factor Authentication (2FA) which means that an additional security code is sent to people that want to log in to their account. Unfortunately, a note on OpenAI’s website says that new 2FA and multifactor authentication enrollments are temporarily paused.

Using one of the best VPNs which encrypts your online identity also makes it harder for someone to break in and steal your data.

It's best to avoid inserting any sensitive information in your ChatGPT prompts in the first place. But if you’ve already made that error, consider clearing your chat history and going forward you may want to turn the feature that saves your chats off.  As always, you should also ensure you have the best antivirus software installed on your PC or one of the best android antivirus apps on your Android smartphone to protect both your devices and your data.

More from Tom's Guide

Christoph Schwaiger

Christoph Schwaiger is a journalist who mainly covers technology, science, and current affairs. His stories have appeared in Tom's Guide, New Scientist, Live Science, and other established publications. Always up for joining a good discussion, Christoph enjoys speaking at events or to other journalists and has appeared on LBC and Times Radio among other outlets. He believes in giving back to the community and has served on different consultative councils. He was also a National President for Junior Chamber International (JCI), a global organization founded in the USA. You can follow him on Twitter @cschwaigermt.

Read more
ChatGPT logo on a smart phone resting on a laptop keyboard, lit with a dark purple light
OpenAI has been actively banning users if they’re suspected of malicious activities
ChatGPT on iPhone
ChatGPT was down — updates on quick outage
ChatGPT on iPhone
ChatGPT went down — full timeline as major outage hit users worldwide
DeepSeek logo on mobile phone
Is DeepSeek safe to use?
DeepSeek logo on phone
Is DeepSeek a national security threat? I asked ChatGPT, Gemini, Perplexity and DeepSeek itself
An image of a CAPTCHA
Hackers are using reCAPTCHA to trick users into infecting their own PCs with malware — how to stay safe
Latest in ChatGPT
ChatGPT on iPhone
ChatGPT was down — updates on quick outage
ChatGPT app on iPhone
I just tested ChatGPT-4.5 with 5 prompts — the good, the bad and the weird
ChatGPT app icon on mobile device
ChatGPT 4.5 — 5 big upgrades you need to know
OpenAI logo
OpenAI ChatGPT-4.5 is here and it's the most human-like chatbot yet — here's how to try it
ChatGPT app icon on mobile device
ChatGPT Plus just got a huge deep research upgrade — here's how to try it now
A person logging into LinkedIn on their phone and laptop
Looking for a job? — 7 prompts to use ChatGPT o3-mini as a job search assistant
Latest in News
Bill Gates in 2019
Bill Gates just predicted the death of every job thanks to AI — except for these three
NYTimes Connections
NYT Connections today hints and answers — Wednesday, March 26 (#654)
Gemini screenshot image
Google unveils Gemini 2.5 — claims AI breakthrough with enhanced reasoning and multimodal power
Samsung Galaxy Z Flip 6 review.
Samsung Galaxy Z Flip 7 design just teased in new cases leak — and the outer display is huge
Google Chrome
Chrome failed to install on Windows PCs, but Google has issued a fix — here's what happened
nyc spring day AI image
OpenAI just unveiled enhanced image generator within ChatGPT-4o — here's what you can do now