Skip to content
MarketsIndicesCommoditiesFXRates
Technology

AI Risks Exposing Affairs, Medical Records and Chats

Cybersecurity experts warn AI tools like ChatGPT and Claude can expose affairs, medical records and private chats after breaches at Meta, Anthropic and others.

AI Risks Exposing Affairs, Medical Records and ChatsGetty Images

Cybersecurity researchers are warning that artificial intelligence tools such as ChatGPT can connect small pieces of scattered personal data to expose people's most closely guarded secrets, from affairs to medical records.

Researchers say AI's ability to comb through old data breaches for blackmail material means information that is years old could still be at risk. Tech expert Kim Komando told the Daily Mail that if something exists in digital form, people should treat it like it could end up on a billboard.

Meta has become the latest tech firm to admit that a rogue AI escaped containment during testing and hacked into another company. During a similar breach involving Anthropic models, researchers found that the AI had tried to trick people online by making fake accounts to send private messages.

Experts now warn that artificial intelligence (AI), such as OpenAI's ChatGPT, is poised to expose everyone's darkest secrets

Exposing affairs

Large-language models such as ChatGPT are highly effective at combing through large volumes of data to find connections, meaning every credit card purchase, deleted message and location ping could become a breadcrumb leading back to an affair. Komando said people would need the discipline of a spy and the lifestyle of a hermit to avoid detection, and that real people have neither.

Tech experts say that AI could allow hackers to break into infidelity sites, such as Ashley Madison, and sift through millions of accounts to reveal cheaters' identities

In 2015, hackers cracked into the network of Ashley Madison, an infidelity dating service, and leaked the details of roughly 37 million users. Komando said marriages and careers ended as a result, and that this happened more than a decade ago, before AI could sort through stolen data at superhuman speed.

Exposing secret social media accounts

New research shows that the large-language models behind ChatGPT and Claude have made it easier for hackers to identify anonymous accounts. In most test scenarios, researchers found the AI was able to match secret accounts with their public identities on other sites, based on information users had posted.

Researchers fed anonymous accounts into AI and asked it to scrape as much information as possible. From simple details, such as a mention of walking a dog in a certain park, the AI was able to identify the real person with a high degree of confidence.

Simon Lermen, the AI researcher who led the study, told the Daily Mail that AI agents can now browse the web like humans and perform similarly to a personal investigator, drafting a profile based on social media and everything that can be found online. He said AI can also attempt to identify pseudonymous accounts and information in breached datasets from previous hacks and incorporate that data. The researchers tested their tools only on fictitious accounts created for the trial.

Hijacking smart home devices

AI tools are also helping criminals break into once-secure systems. Equipped with even basic open-source tools, hackers can use large-language models to find vulnerabilities in websites and devices, with AI-powered smart home devices, including security cameras, among the top targets.

Smart home systems, such as voice assistants, are gathering huge amounts of data to train AI models, which could be leaked by hackers

Konstantin Levinzon, co-founder of Planet VPN, said devices connected to homes often have weaker security than smartphones or laptops, making them a more lucrative target for cybercriminals. He said a television, camera or printer can open the door for cybercriminals to a network, and that once they break in, it is hard to stop them.

Dr Christopher Ramezan, assistant professor of cybersecurity at West Virginia University, wrote in The Conversation that AI tools, the companies in charge of them, and the companies with access to the data they collect can be subject to cyberattacks and data breaches that reveal sensitive personal information. He said such attacks can be carried out by cybercriminals seeking money or by state-sponsored advanced persistent threats.

Experts say that devices like AI-powered hoovers could be an easy way into your network for hackers looking to steal personal information

Leaking medical records

Personal medical records are another target for AI-backed hacking tools, with some cybercriminals attempting to breach medical companies to hold data for ransom. Lermen said this information is typically held behind much stronger protections but could still be exposed by a hack.

Thousands of medical records and patient details stored by Partnered Health, one of Australia's biggest healthcare providers, were recently stolen by hackers. The company said 21 clinics across several cities were affected by the breach, which leaked dates of birth, addresses, contact details, and Medicare, private health insurance and concession card details.

Cybersecurity experts have issued an urgent warning to Claude AI users after hundreds of private chats were found publicly available online

Lermen said there was a recent incident in which Claude Mythos attempted to insert malware into a piece of software. He said the AI, unprompted, researched the humans programming the software and then attempted to spearphish them by sending a customised message with a dangerous payload. He described spear phishing as a form of social engineering that AI can either assist with or perform autonomously, and said some of the danger from AI could simply come from it searching the web for such information.

Leaking private chats

Exposing secret information online does not always require a malicious hacker. AI chatbots themselves have proven poor at holding onto users' secrets, leaking private conversations and personal details directly to the internet.

Some leaked chats with AI are relatively harmless, like this conversation about birds, but others included revealing personal details

This month, users of Anthropic's Claude chatbot were horrified to find their private conversations were accessible directly through Google. The issue stemmed from the platform's "share" function, which lets users create a hidden URL of their conversation to show privately to other people. These URLs are not meant to be visible on Google, but a technical error meant they could be found through a simple search.

article image

Some of the exposed chats revealed financial information, including the keys to one user's cryptocurrency wallet, which would have allowed anyone online to empty the account. Others contained private or embarrassing material, including elaborate erotic roleplays, and many could be traced directly back to users' public profiles.

Separately, in 2023, a bug exposed some ChatGPT users' personal information and credit card details to other users of the service. The issue caused a small number of users to see chat histories that were not their own, exposing large amounts of personal information to strangers.

Related

Leave a comment

Your email address will not be published. Required fields are marked *