ChatGPT targeted in server-side data theft attack
Researchers at web security company Radware recently discovered what they described as a service-side data theft attack method involving ChatGPT.
The attack, dubbed ShadowLeak, targeted ChatGPT’s Deep Research capability, which is designed to conduct multi-step research for complex tasks. OpenAI neutralized ShadowLeak after it was notified by Radware.
The ShadowLeak attack did not require any user interaction. The attacker simply needed to send a specially crafted email that when processed by the Deep Research agent would instruct it to silently collect valuable data and send it back to the attacker.
Read more at Security Week