Breaking
February 12, 2025

Hackers offer 20 million OpenAI credentials for sale, but it says there’s no evidence of a breach | usagoldmines.com


  • A hacker has allegedly listed 20 million OpenAI logins for sale
  • However the origins of these credentials are disputed
  • OpenAI says its investigation has found no evidence of a compromise

A hacker claims to be selling the login credentials of 20 million OpenAI users accounts – but the company says its own investigation has found no evidence of a hack.

A report from Malwarebytes Labs discovered a cybercriminal who goes by the name ‘emirking’ had listed a dataset for sale on a cybercrime forum claiming to contain, ‘20 million access codes to OpenAI accounts’.

OpenAI responded, stating, “We take these claims seriously. We have not seen any evidence that this is connected to a compromise of OpenAI systems to date.” Breaches like these can have catastrophic consequences for both the company and the users, but there are a few red flags that point to this incident being less than genuine, here’s what we know.

An unlikely story?

In Malwarebytes Lab’s initial report, there was some doubt cast over the origins of the information, with the report outlining

“It seems unlikely that such a large amount of credentials could be harvested in phishing operations against users, so if the claim is true, emirking may have found a way to compromise the auth0.openai.com subdomain by exploiting a vulnerability or by obtaining administrator credentials.”

The report also pointed out that the cybercriminal allegedly responsible for the leak was a relatively new user of the forums – which wouldn’t mean much on its own, but KELA cybersecurity also assessed the available data, and concluded the credentials were obtained via infostealer malware.

The analyzed sample by KELA showed the compromised logins related to OpenAI services, and contained authentication details to ‘auth0.openai.com’.

The security researchers then cross-referenced these details with its own data lake of “compromised accounts obtained from infostealer malware, which contains more than a billion records, including over 4 million bots collected in 2024.”

“All credentials from the sample shared by the actor ‘emirking’ were found to originate in these compromised accounts, likely hinting at the source of the full 20 million OpenAI accounts that the actor intends to sell,” the security company confirmed.

Ultimately, the investigation concluded, “the majority of compromised credentials of OpenAI services offered for sale on BreachForums by emirking are not related to a breach of OpenaAI systems.”

The credentials were deemed to be a part of a larger dataset “scraped from a mix of private and public sources that sell and share infostealer logs” – not from an unreported compromise.

Staying safe

No matter how the leaked credentials were acquired, anyone who has had their details leaked is at risk. The primary danger with this incident is social engineering attacks and identity theft.

Because many users of AI chatbots will (sometimes unwittingly) hand over personal information, anyone with access to their accounts could use the compromised email address to engineer personal and specific phishing attacks designed to steal even more information.

Just asking a chatbot for restaurant recommendations in your city, advice on budgeting, or work-specific questions or summaries can give attackers all the information they need to craft a convincing way to reach out pretending to be a colleague, trusted company, friend, or family member.

Being vigilant is the most effective way to combat this. Don’t give out any information to an unknown person or unexpected contact that you haven’t thoroughly vetted first, and make sure not to click any links you don’t 100% trust.

Make sure to also create a strong and secure password, and it’s important that you do not reuse passwords from one site to another – this helps by quarantining any account that has been breached.

It’s a similar process when mitigating the risk of identity theft. Keeping an eye on your accounts, statements, and bills to make sure there’s nothing you don’t recognize, and let your bank know immediately if there is anything suspicious.

We’ve also listed some software which can essentially do the work for you, monitoring your credit files, warning about suspicious activity, and alerting you if any personal information is used (such as new bank accounts being opened in your name). Some even offer identity recovery and insurance policies up to $1 million, so check out our picks for best identity theft protection for families if you’re concerned about your information.

You might also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Apple Now Lets You Move Digital Purchases From One Apple Account to Another Juli Clover | usagoldmin...

Use This App Instead of Excel to Directly Edit CSV Files Justin Pot | usagoldmines.com

Apple's Powerbeats Pro 2 Have a Built-In Heart Rate Monitor Jake Peterson | usagoldmines.com

ColorWare Launches New 'Blended' Custom AirPods Colors Juli Clover | usagoldmines.com

Tariffs will “blow a hole” in the US auto industry, says Ford CEO Jonathan M. Gitlin | usagoldmines....

When software updates actually improve—instead of ruin—our favorite devices Scharon Harding | usagol...

My Favorite Deals on Tech and Appliances From Best Buy's Presidents Day Sale Daniel Oropeza | usagol...

Google just set the date for I/O 2025, and get ready for the next big version of Gemini jacob.krol@f...

Apple contemplates SMB, enterprise as its next major revenue stream as it launches a new partner pro...

New hack uses prompt injection to corrupt Gemini’s long-term memory Dan Goodin | usagoldmines.com

Google I/O 2025 is Happening May 20-21 Kellen | usagoldmines.com

Where to Find Accurate Medical Info Recently Removed From the CDC's Site Beth Skwarecki | usagoldmin...

'Finch' Motivates Me to Complete My To-do List Without Shaming Me Lindsey Ellefson | usagoldmines.co...

This BBC Study Shows How Inaccurate AI News Summaries Actually Are Michelle Ehrhardt | usagoldmines....

New Powerbeats Pro 2 Will Have Day One Firmware Update Juli Clover | usagoldmines.com

Apple Adopting 'Gulf of America' Naming for Apple Maps Juli Clover | usagoldmines.com

NYT Strands hints and answers for Wednesday, February 12 (game #346) | usagoldmines.com

NYT Connections hints and answers for Wednesday, February 12 (game #612) | usagoldmines.com

Quordle hints and answers for Wednesday, February 12 (game #1115) | usagoldmines.com

Biggest Google Pixel 9a leak so far reveals colors and seems to confirm the death of the camera bar ...

Judge orders Trump admin. to restore CDC and FDA webpages by midnight Beth Mole | usagoldmines.com

Grab this 27-inch Acer OLED gaming monitor for 50% off today | usagoldmines.com

What to Say to Get Out of Jury Duty Meredith Dietz | usagoldmines.com

This tiny 2TB portable SSD has a unique feature that makes it the perfect storage companion for your...

Jura's new coffee machine brews hot or cold and can even add your choice of syrup | usagoldmines.co...

Fastest VPN 2025: We identify the speediest performers | usagoldmines.com

5 sneaky ways hackers use generative AI to scam you | usagoldmines.com

A beginner’s guide to using a Chromebook | usagoldmines.com

Best VPN for streaming Netflix 2025: Watch from wherever you are | usagoldmines.com

The winner of Newegg’s PC building race finished in under 5 minutes | usagoldmines.com

Best smart speakers & displays for state-of-the-art smart homes | usagoldmines.com

Notepad has spell check. Here’s how to turn it on or off | usagoldmines.com

Galaxy S25 Ultra Review: Same Price, But Some Nice Upgrades Tim | usagoldmines.com

How to Get Free Car Maintenance and Repair Work Jeff Somers | usagoldmines.com

Samsung HBM roadmap shows Google could become Nvidia's fiercest competitor in AI by 2026, but I wond...

Sony’s next flagship wireless headphones just edged closer to launch – here’s when they might land h...

Google's stronghold on search is loosening ever so lightly, report finds, but don't expect it to cru...

Google Chrome may soon use “AI” to replace compromised passwords Kevin Purdy | usagoldmines.com

Verizon beats lawsuit from utility worker who said lead cables made him sick Jon Brodkin | usagoldmi...

Bow down to YouTube, the lord of the living room | usagoldmines.com

Apple Just Released a New Security Patch Jake Peterson | usagoldmines.com

My Favorite Amazon Deal of the Day: This Blink Video Doorbell Daniel Oropeza | usagoldmines.com

Apple Suppliers Preparing for New iPad Air, MacBook Air, and iPad 11 Joe Rossignol | usagoldmines.co...

Apple Completes Pixelmator Acquisition Juli Clover | usagoldmines.com

Get Apple's 13-Inch M2 MacBook Air for Just $749 During Best Buy's Presidents' Day Sale Mitchel Brou...

Sony will release an Astro Bot PS5 bundle in March according to new leak | usagoldmines.com

Feel like the battery on your wireless earbuds degrades faster than other tech? You might not be wro...

Supermarket Simulator Pro is no more as a number of 'spam' games are removed from the PS Store | us...

Microsoft warns hackers have a new and devious way of distributing malware | usagoldmines.com

Keen to buy a new gaming laptop with an RTX 5000 GPU? Save the date: Nvidia’s announced pre-orders o...

Samsung Galaxy S26 could get a major battery upgrade that makes it worth waiting for | usagoldmines...

Microsoft will now pay you even more to find security bugs in Copilot | usagoldmines.com

Perfecting Honda’s 2026 F1 powertrain is “not so easy,” says racing boss Jonathan M. Gitlin | usagol...

Bird flu strain that just jumped to cows infects dairy worker in Nevada Beth Mole | usagoldmines.com

Best DVR for cord-cutters: Tablo vs Zapperbox vs Channels vs the rest | usagoldmines.com

Monitor makers are stockpiling panels to lessen impact of US tariffs | usagoldmines.com

Finally! New Framework laptop designs are coming soon | usagoldmines.com

This Anker Thunderbolt 4 dock with quad 4K support is $100 off | usagoldmines.com

Here’s the Pixel 9a in a Bunch of Colors Kellen | usagoldmines.com

US Decides to Change the “Gulf of Mexico” to the “Gulf of America” and Google Maps Will Reflect That...

You Should Double Check Which Apps Can See Your iPhone Photos Khamosh Pathak | usagoldmines.com

New AirPods With Powerbeats Pro 2's Heart Rate Monitoring Feature Still 'Months Away' Joe Rossignol ...

Sam Altman: OpenAI is not for sale, even for Elon Musk’s $97 billion offer Benj Edwards | usagoldmin...

Ugreen CM642 SSD enclosure review: Fast, roll-your-own USB4 storage | usagoldmines.com

One retailer hints that RTX 5070 Ti cards are coming next week | usagoldmines.com

Despite assurances, Nvidia’s RTX 5090 is melting power plugs after all | usagoldmines.com

You Can Quietly Mute People on Discord Now Khamosh Pathak | usagoldmines.com

Here's How to Access Your Router's Hidden Parental Controls Jason Keil | usagoldmines.com

Here's Where 'Tap to Pay on iPhone' is Available Joe Rossignol | usagoldmines.com

Apple Arcade Adding Two New Games in March Joe Rossignol | usagoldmines.com

Got $50,000? You Can Bid on This Business Card Signed by Steve Jobs Joe Rossignol | usagoldmines.com

The Nvidia vs AMD GPU fight could be about to get really interesting with ‘aggressive’ Radeon RX 900...

Google system abused by hackers to hijack ecommerce stores | usagoldmines.com

Sony's next State of Play arrives tomorrow and will feature 'news and updates on great games coming ...

Oracle Red Bull Racing signs up 1Password to boost its Formula 1 security | usagoldmines.com

Apple could make buying the wrong size Apple Watch a thing of the past with this futuristic inventio...

8base ransomware site taken down in global police operation | usagoldmines.com

ULA’s Vulcan rocket still doesn’t have the Space Force’s seal of approval Stephen Clark | usagoldmin...

How fast can your USB cable move data? Use this formula to find out | usagoldmines.com

This Ryzen 7 mini PC with 16GB RAM has never been cheaper: $249 | usagoldmines.com

Samsung’s 27-inch 240Hz OLED monitor just dropped to its best price | usagoldmines.com

This Samsung Galaxy S22 Is Over $500 Off Right Now Pradershika Sharma | usagoldmines.com

Apple Reportedly 'Passed Over' DeepSeek as Apple Intelligence Partner Joe Rossignol | usagoldmines.c...

Powerbeats Pro 2 Debut With Heart Rate Monitoring, H2 Chip, Active Noise Cancellation, and More Eric...

Newspaper printing across US hit after Lee Enterprises says “cybersecurity event” disrupted operatio...

Ever wish you had a tube amp with you everywhere for your headphones? Now you can with this switchab...

Google One AI Premium now includes one of my favourite AI tools for no extra cost, and it’s 50% off ...

Google Maps and Apple Maps can't agree on the name of the Gulf of America, and I am so confused lanc...

"Privacy isn’t just a buzzword" – independent audit confirms NordVPN doesn't store your data chiara....

Did you turn off Apple Intelligence? Updating to iOS 18.3.1 or macOS 15.3.1 might’ve turned it on ag...

The Fantastic Four: First Steps: release date, trailer, confirmed cast, plot synopsis, and more news...

‘Labor of love’: Powerbeats Pro 2 are officially here with heart-rate tracking, and Apple’s Hardware...

Network complexity: a hidden tax on business | usagoldmines.com

Transforming meetings: how technology is bridging the engagement gap | usagoldmines.com

US and UK refuse to sign AI safety declaration at summit Leila Abboud and Melissa Heikkilä, Financia...

iOS 18.3.1 update fixes security flaw used in “extremely sophisticated attack” Andrew Cunningham | u...

Use this formula to calculate your USB cable’s data transfer speed | usagoldmines.com

Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com

Why (and How) to Wear Your Apple Watch on Your Ankle Beth Skwarecki | usagoldmines.com

Some Apple Watch Series 10 Users Experiencing Speaker Volume Issue Joe Rossignol | usagoldmines.com

Leave a Reply