Cyber Security News

Malicious ChatGPT Agents May Steal Chat Messages and Users Personal Data

In November 2023, OpenAI released GPTs publicly for everyone to create their customized version of GPT models. Several new customized GPTs were created for different purposes. However, on the other hand, threat actors can also utilize this public GPT model to create their versions of GPTs to perform various malicious activities.

Researchers have developed a new GPT to demonstrate the ease with which cybercriminals can steal user information, such as chat messages and passwords, or create malicious code through certain chat requests.

Thief GPT

This new malicious ChatGPT agent was created to forward users’ chat messages to a third-party server and ask for sensitive information such as username and password. 

Thief GPT (Source: Embracethered)

This was possible as ChatGPT loads images from any website, which requires data to be sent to a third-party server. Moreover, a GPT can also contain instructions to ask the user for information and can send it anywhere, depending upon the configuration of the GPT.

The new demo GPT was named Thief GPT and was capable of asking questions to the user to send it to a third-party server secretly. However, when publishing it to users, there were specific guidelines that denied the request.

According to the documentation, ChatGPT allows three types of publishing for creators—only me (default), Anyone with a link, and Public. Nevertheless, since the researchers had the words “Steal” and “malicious”, it violated the “brand and usage” guidelines and was eventually rejected.

Rejected Guidelines (Source: Embracethered)

Later, it was quickly fixed and was accepted by the GPT store. This led to the conclusion that there are chances for malicious actors to utilize this publicly available GPT code for malicious purposes.

Furthermore, a complete report has been published, which provides details about the method, usage, and other information.

Eswar

Eswar is a Cyber security reporter with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is reporting data breach, Privacy and APT Threats.

Recent Posts

New Chaosbot Leveraging CiscoVPN and Active Directory Passwords to Execute Network Commands

ChaosBot surfaced in late September 2025 as a sophisticated Rust-based backdoor targeting enterprise networks. Initial…

14 hours ago

Threat Actors Exploiting SonicWall SSL VPN Devices in Wild to Deploy Akira Ransomware

Threat actors have reemerged in mid-2025 leveraging previously disclosed vulnerabilities in SonicWall SSL VPN appliances…

15 hours ago

Nanoprecise partners with AccuKnox to strengthen its Zero Trust Cloud Security and Compliance Posture

Menlo Park, USA, October 10th, 2025, CyberNewsWire AccuKnox, a leader in Zero Trust Cloud Native…

15 hours ago

175 Malicious npm Packages With 26,000 Downloads Attacking Technology, and Energy Companies Worldwide

Socket's Threat Research Team has uncovered a sophisticated phishing campaign involving 175 malicious npm packages…

16 hours ago

RondoDox Botnet Exploits 50+ Vulnerabilities to Attack Routers, CCTV Systems and Web Servers

Since its emergence in early 2025, RondoDox has rapidly become one of the most pervasive…

17 hours ago

Microsoft Defender Incorrectly Flags SQL Server Software as End-of-life

Microsoft Defender for Endpoint is incorrectly flagging specific versions of SQL Server as having reached…

18 hours ago