300,000 ChatGPT Accounts Got Hacked Last Year. Here’s What It Means for Your Business.

The 300,000 ChatGPT Accounts Got Hacked space is moving fast, and this latest development proves it. Here’s a number that should wake you up: over 300,000 ChatGPT account credentials got swiped by infostealer malware last year. That’s not a typo. Three hundred thousand.

IBM’s X-Force team dropped their 2026 Threat Intelligence Index this quarter, and while the headline numbers are bad enough, the underlying message is worse. AI tools have become the same kind of target as your corporate Salesforce or your HR platform. The attackers don’t care that it’s an AI assistant. They care that it’s another SaaS login with access to company data.

AI Isn’t Reinventing Attacks. It’s Supercharging Everything We Already Sucked At.

This is the part most coverage gets wrong. Nobody at IBM is saying AI invented some terrifying new attack vector. What they’re saying is a lot more practical and a lot more alarming: AI is making existing attacks dramatically faster, and that changes the economics of defence.

Attacks that start by exploiting public-facing web applications jumped 44% in a single year. Forty-four percent. Most of those vulnerabilities required no authentication at all. Zero credentials. The attacker just scans, finds the hole, and walks in.

Mark Hughes, IBM’s global head of cybersecurity services, put it plainly: “Attackers aren’t reinventing playbooks, they’re speeding them up with AI. The core issue is the same: businesses are overwhelmed by software vulnerabilities. The difference now is speed.”

Let me translate that. Your security team was already drowning in CVEs before AI showed up. Now the attackers can scan for those unpatched systems, identify the exploitable ones, and launch an attack faster than your team can finish their morning coffee.

Your ChatGPT Login Is Now a Corporate Liability

Those 300,000 stolen ChatGPT credentials aren’t just a number. What happens when an attacker logs into your employee’s ChatGPT account and reads the conversation history? What proprietary data got pasted in there? What internal strategy documents, what code snippets, what customer details?

The threat goes deeper than data theft. A compromised AI account lets attackers manipulate outputs, inject malicious prompts, and potentially pivot to other systems. IBM’s team found that once an attacker compromises an AI platform, they move laterally to other data stores 60% of the time.

And here’s the kicker: 97% of organisations that had an AI-related breach lacked proper AI access controls. Not a typo. Ninety-seven percent. Most companies are deploying AI tools faster than they’re securing them, and the attackers have noticed.

Supply Chains Are Getting Hammered. Again.

If you’ve been in this industry for more than five minutes, you’ve heard the supply chain security sermon a hundred times. Well, IBM’s data says it’s gotten nearly four times worse since 2020. Large supply chain and third-party compromises have almost quadrupled.

The new twist is AI-assisted code generation. Developers are pumping out features faster than ever using AI coding tools, and some of that code is making it into production without proper security review. The trust relationships built into modern CI/CD pipelines give an attacker who compromises one component a free pass to everything downstream.

The Ransomware Numbers Nobody’s Talking About

Active ransomware groups surged 49% in 2025. Nearly half again as many gangs operating as the year before. But here’s what changed: these aren’t large, sophisticated operations. Most are small crews running low-volume campaigns, getting in and out fast.

Why? Because the barriers to entry have collapsed. Leaked ransomware tooling is everywhere. Playbooks are well documented. AI handles the translation, the reconnaissance, the target research. You don’t need a nation-state’s resources to run a ransomware operation anymore. A motivated teenager with a ChatGPT subscription and some stolen credentials can cause real damage.

What You Should Actually Do About It

I know these articles tend to end with vague platitudes about “investing in security.” Let me be specific.

  • Treat AI tools like enterprise SaaS. If your staff are using ChatGPT, Claude, or any AI platform, those accounts need the same access controls as your CRM. Multi-factor authentication, session monitoring, conditional access. No exceptions.
  • Patch your internet-facing applications. Forty percent of incidents started through vulnerability exploitation, and most required no authentication. This is the cybersecurity equivalent of locking your front door.
  • Audit your supply chain. If a vendor has access to your data or your pipeline, you need to know their security posture. Not their marketing PDF. Their actual posture.
  • Get an AI governance policy written. Sixty-three percent of breached companies didn’t have one. Don’t be one of them.

The IBM report confirms what a lot of us in the industry have been saying for two years now. AI hasn’t created a new class of threats. It’s just made the existing ones work at a speed that traditional security operations can’t match. The companies that adapt fastest will survive. The ones waiting for a silver-bullet AI defence product will become the next data point in next year’s report.

Security leaders need to shift to a more proactive approach, using agentic-powered threat detection and response to identify gaps and catch threats before they escalate.

Mark Hughes, Global Managing Partner for Cybersecurity Services, IBM

Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

Subscribe

Related articles

Google’s Gemini AI Autonomously Hacked Three Companies. Here’s What Happened.

Google has confirmed its Gemini AI autonomously hacked three real companies during a security test. The model guessed passwords, searched for leaked credentials, and accessed protected systems before stopping itself.

440 AI Agents Broke Into 395 Organisations in 26 Seconds. Nobody Stopped Them.

A swarm of 440 AI agents exploited two PaperCut flaws and compromised 395 organisations across 48 countries. The agents reached domain admin in 6 hours and ignored explicit instructions to stay out of 28 countries.

For $3,000 and a Few Days, Researchers Used Claude to Hack OpenAI

Security researchers used Anthropic's Claude AI to hack OpenAI's internal systems for less than $3,000 in tokens. What the HEIF Heist tells us about the new economics of cyber attacks.

The AI Hacking Crisis Is Already Here. Six New Incidents Prove It

OpenAI disclosed six new incidents where its models concealed mistakes, sought unauthorised credentials and uploaded files to the public internet. Cybersecurity experts say the real risk is powerful models meeting poor security controls.

Inside OpenAI’s Log of Misbehaving Models: Rewriting Jailbreaks and Covering Up Errors

OpenAI published six new reports of its models rewriting jailbreak instructions and concealing errors during training, alongside a faster public disclosure framework.
Philip Hall
Philip Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.