{"id":485395,"date":"2023-03-27T12:18:06","date_gmt":"2023-03-27T10:18:06","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=485395"},"modified":"2023-03-27T12:24:24","modified_gmt":"2023-03-27T10:24:24","slug":"chatgpt-leaked-payment-details-to-wrong-users","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/485395-chatgpt-leaked-payment-details-to-wrong-users.html","title":{"rendered":"ChatGPT leaked payment details to wrong users"},"content":{"rendered":"<p>OpenAI has explained how a bug in ChatGPT&#8217;s Redis open-source client library exposed some ChatGPT Plus subscribers&#8217; payment details to other users.<\/p>\n<p>The company took ChatGPT offline last week after it became aware of a flaw that allowed some users to see the titles and first messages from other active users&#8217; chat histories.<\/p>\n<p>It patched the bug and restored ChatGPT services and chat histories shortly thereafter.<\/p>\n<p>However, following further investigation, OpenAI discovered the same bug had also caused unintentional visibility of payment-related information.<\/p>\n<p>It said this affected about 1.2% of the ChatGPT Plus subscribers who were active during a specific nine-hour window.<\/p>\n<p>&#8220;In the hours before we took ChatGPT offline on Monday, it was possible for some users to see another active user&#8217;s first and last name, email address, payment address, the last four digits (only) of a credit card number, and credit card expiration date,&#8221; OpenAI said.<\/p>\n<p>Fortunately, full credit card numbers were not exposed at any time.<\/p>\n<p>OpenAI said there were two possible scenarios in which the wrong ChatGPT Plus subscriber might have seen another user&#8217;s payment details.<\/p>\n<p>Firstly, they might have been sent the wrong subscription confirmation email on 20 March 2023 between 10:00 and 19:00 South African time.<\/p>\n<p>&#8220;Due to the bug, some subscription confirmation emails generated during that window were sent to the wrong users,&#8221; OpenAI said.<\/p>\n<p>&#8220;These emails contained the last four digits of another user&#8217;s credit card number, but full credit card numbers did not appear.<\/p>\n<p>It added that it was possible a &#8220;small number&#8221; of subscription confirmation emails might have been incorrectly addressed before 20 March, but it was yet to confirm any such instances.<\/p>\n<p>The second scenario in which a user&#8217;s information might have been exposed could occur if another active user opened the &#8220;Managed my subscription&#8221; in the My Account section of ChatGPT during the same time.<\/p>\n<p>&#8220;During this window, another active ChatGPT Plus user&#8217;s first and last name, email address, payment address, the last four digits (only) of a credit card number, and credit card expiration date might have been visible,&#8221; OpenAI said.<\/p>\n<p>&#8220;It&#8217;s possible that this also could have occurred prior to 20 March, although we have not confirmed any instances of this.&#8221;<\/p>\n<p>OpenAI said it contacted affected users to notify them that their payment information might have been exposed.<\/p>\n<p>It added it was confident that there was no ongoing risk to users&#8217; data.<\/p>\n<p>The company also provided in-depth technical details about the bug and how it was fixed in a <a href=\"https:\/\/openai.com\/blog\/march-20-chatgpt-outage\" target=\"_blank\" rel=\"noopener\"><strong>blog post last week<\/strong><\/a>.<\/p>\n<hr \/>\n<h2 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/software\/485127-openais-chatgpt-gets-access-to-the-web-for-the-first-time.html\" rel=\"bookmark\">OpenAI&#8217;s ChatGPT gets access to the web for the first time<\/a><\/h2>\n","protected":false},"excerpt":{"rendered":"<p>The same bug that exposed certain users&#8217; chat histories also potentially leaked payment details and other personal information.<\/p>\n","protected":false},"author":341042,"featured_media":479605,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[83065,84047,50043,45266,437],"class_list":["post-485395","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-chatgpt","tag-chatgpt-plus","tag-data-leak","tag-openai","tag-privacy"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/485395"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341042"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=485395"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/485395\/revisions"}],"predecessor-version":[{"id":485409,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/485395\/revisions\/485409"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/479605"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=485395"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=485395"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=485395"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}