
Are you sharing your secrets with ChatGPT?
Why prompts can expose sensitive information, how imitation AI services create phishing risks, and why users and companies need clear rules for sharing data with AI tools.
One aspect of new technology is the general public's lack of awareness of its potential nefarious uses; here, ChatGPT is the perfect storm. It's new; there is huge hype around it to the point of being viral. Currently, there are very few actual incidents related to its use, which may create a strong bias toward information leakage from users' side.
ALERT: Even people conscious about sharing private or sensitive information do so via ChatGPT prompts. Prompts are archived!
What will unfold is very easy to predict (and is already happening). With ChatGPT, a new phishing channel is born. We will start seeing replicas of ChatGPT or other similar prompt-based websites. This will be further fueled by the fact that ChatGPT is (at least for now) limiting use due to capacity constraints or requiring a paid subscription. As a result, we will see new unlimited ChatGPT and free ChatGPT lures in our emails, chat messages, and on the web.
Cybercriminals who can eavesdrop on or collect your prompts sound like the beginning of a juicy ransomware incident. But even without phishing - forcing my way into your existing genuine ChatGPT account to get access to all your historical prompts will follow the same pattern. Tools already let users store ChatGPT prompts and results in GitHub, so this is another flavor of the same. The last one - do you know how OpenAI is using the prompts we submit to ChatGPT?

@Users: Don't share proprietary, sensitive, or intellectual property information you don't want to become common knowledge. Treat every ChatGPT prompt as publicly available information, or don't type it in.
@Companies: ensure employees understand what information (e.g., source code, accounting details, technical blueprints, audit results, etc.) shouldn't be typed into prompts, and share clear guidelines.