Konga Wordkraft
Menu Close

Cyber Alert: ChatGPT flaw allows attackers to secretly steal Gmail data –Report

*Researchers have demonstrated the cyberattack by making a victim’s ChatGPT session retrieve e-mail data from Gmail, and send it back to an attacker, warning that with great AI power also comes ‘great data responsibility’

Isola Moses | ConsumerConnect

Following recent study, researchers found a way to get ChatGPT to access a victim’s Gmail, chat history, and files by exploiting a hidden communication channel that connects separate user accounts.

ChatGPT has reportedly introduced key cybersecurity threats, privacy risks, and operational vulnerabilities for individual consumers  and organisations.

Lagos, Access Bank, Delta, Ekiti, Imo, Shell, NASENI support GOCOP conference as partners

ConsumerConnect gathered Check Point Research recently, however, discovered that ChatGPT sessions belonging to different consumers could secretly communicate with each other through an internal service, according to Cybernews.

It is also noted that a cyberattacker could use that channel to send a hidden instruction to a victim’s ChatGPT session, which would then carry out the task, using the access already available to the victim.

The study revealed the attack could reach data from connected services such as Gmail, Google Drive, Microsoft Teams, and GitHub, depending on what the victim had connected to ChatGPT.

It could also access files and conversation history available to the affected session.

Report further indicated the researchers as well demonstrated the cyberattack by making a victim’s ChatGPT session retrieve e-mail data from Gmail, and send it back to an attacker.

The worrying part was that the victim did not see the attacker’s request, according to report.

Leave a Reply

Your email address will not be published. Required fields are marked *