ChatGPT data leak exposed some users' credit card details — are you affected?

ChatGPT
(Image credit: Getty Images/SOPA Images)

In case you missed it, Open AI published a blog on Friday revealing the reason ChatGPT suffered an outage on March 20. As it turned out, the AI chatbot was temporarily taken down due to a bug that allowed users to see others' conversations.

It doesn't stop there. Open AI also discovered that there was a moment in time in which that same security flaw exposed some users' credit card details. However, Open AI chatbot claims that the number of users affected by this vulnerability is "extremely low."

Who was affected by the ChatGPT credit card leak?

Open AI revealed that 1.2% of ChatGPT Plus subscribers, members who pay $20 a month for faster response times, access to the chatbot during peak times, and exclusive access to new improvements and features, were affected by the credit-card leak. 

Users who were active during a nine-hour window potentially had the last four digitals of their credit card numbers leaked as well as the expiration date. "Full credit card numbers were not exposed at any time," Open AI said. Other details that were exposed include first and last names, and payment addresses.

Open AI explained two ways in which ChatGPT subscribers could have seen others' sensitive information.

1. Opening a subscription confirmation email sent on March 20 between 1 a.m. and 10 a.m. PT. Some of these emails were sent to the wrong users and exposed the last four digits of others credit card details.

2. Navigating to My Account > Manage my subscription in ChatGPT between 1.a.m. and 10 a.m. PT on March 20. Other users' sensitive information, including credit card details, may have been visible during this window.

Open AI repeatedly mentioned that full credit card numbers did not appear during the data leak. Fortunately, the bug is now patched, allowing Open AI to bring ChatGPT back online.

Open AI concluded its blog post stating that it made a promise to protecting users' privacy, but unfortunately, it fell short of that commitment. "We apologize again to our users and the entire ChatGPT community," Open AI said, adding that it will work untiringly to rebuild users' trust.

Kimberly Gedeon

Kimberly Gedeon, holding a Master's degree in International Journalism, launched her career as a journalist for MadameNoire's business beat in 2013. She loved translating stuffy stories about the economy, personal finance and investing into digestible, easy-to-understand, entertaining stories for young women of color. During her time on the business beat, she discovered her passion for tech as she dove into articles about tech entrepreneurship, the Consumer Electronics Show (CES) and the latest tablets. After eight years of freelancing, dabbling in a myriad of beats, she's finally found a home at Laptop Mag that accepts her as the crypto-addicted, virtual reality-loving, investing-focused, tech-fascinated nerd she is. Woot!

Read more
DeepSeek whale logo in the style of the TikTok logo.
The DeepSeek mania proves it's finally — finally! — time to talk about AI privacy
DeepSeek whale logo on a geometric background.
DeepSeek: The best ChatGPT alternative or a hotbed of dubious claims?
DeepSeek AI chatbot on a phone
DeepSeek jailbreakers are tricking the chatbot into bad-mouthing the Chinese government
chatgpt vs deepseek on mobile phones
DeepSeek vs. ChatGPT: Here's what critics are saying
DeepSeek whale logo in the style of the TikTok logo.
DeepSeek's success has painted a huge TikTok-shaped target on its back
Jensen Huang, co-founder and chief executive officer of Nvidia Corp., during the Nvidia GPU Technology Conference (GTC) in San Jose, California, US, on Tuesday, March 19, 2024. Dubbed the Woodstock festival of AI by Bank of America analysts, GTC this year is set to draw 300,000 in-person and virtual attendees for the debut of Nvidia Corp.'s B100. Photographer: David Paul Morris/Bloomberg via Getty Images
Nvidia's Jensen Huang has some strong words for DeepSeek — and they're probably not what you think
Latest in Antivirus & Cyber-security
TP-Link routers targeted by Chinese state-sponsored cyber attacks
TP-Link routers may face nationwide ban after 'significantly alarming' link to US cyberattacks
What is a VPN kill switch — and why you should use one
You need a VPN for school, here are 3 services we recommend
The AMD Ryzen and NVIDIA RTX stickers on the Acer Nitro 17
'You basically have to throw your computer away': Researchers explain AMD 'Sinkclose' vulnerability, but do you need to worry?
Google Search
This malware is posing as Google Authenticator using Google ads — here's how to protect yourself
Windows 10 BSOD saying "It's not you, it's me."
Microsoft reveals CrowdStrike outage could have a surprising long-term impact on everyday users
MANILA, PHILIPPINES - JULY 19: Long queues of passengers form at the check-in counters at Ninoy Aquino International Airport, amid a global IT disruption caused by a Microsoft outage and a Crowdstrike IT problem, on July 19, 2024 in Manila, Philippines. A significant global outage affecting Microsoft services, particularly Microsoft 365, has caused widespread disruptions across various sectors, including airlines, banks, and health systems. The outage was attributed to a glitch in CrowdStrike's "Falcon Sensor" software, which impacted Windows systems, leading to thousands of flight cancellations and operational chaos in multiple industries. Microsoft has reported that the underlying cause of the outage has been fixed, but residual effects continue to impact some users as the company works on full recovery. (Photo by Ezra Acayan/Getty Images)
The CrowdStrike outage spotlights major vulnerabilities in the global information ecosystem
Latest in News
Nintendo switch 2 virtual game card
Nintendo's Virtual Game Card feature might be more revolutionary than the Switch 2
A close-up of a light-colored computer keyboard shows the keys T, Y, G, and H replaced by the logos of OpenAI, DeepSeek, Grok, and Gemini, the leading competitors in the artificial intelligence market. This serves as a visual metaphor for the intense rivalry and innovation in the AI industry. (Photo by Matteo Della Torre/NurPhoto via Getty Images)
Is generative AI inadvertently reducing the voices of many to the banality of one?
Asus ROG Ally Z1 on a brown table with the game Unpacking played on screen.
Handheld gaming PCs have a Windows problem — but maybe not for long
WWDC 2025 could mark the beginning of the end for certain iPhone users
Error when installing Google Chrome on the Asus Vivobook 16 Flip, on a white desk against a blue background.
"This app can't run on your PC": Google's Chrome Installer broke on Windows, but there's a fix
Nintendo Switch 2 handheld gaming console
Nintendo Switch 2 preorder date: It might be a lot closer than you think, say tipsters