OpenAI March 20 ChatGPT Outage and Data Exposure Analysis

TL;DR

OpenAI took ChatGPT offline on March 20, 2023, following the discovery of a bug in an open-source library that allowed some users to see chat titles and the first messages of new conversations from other active users. Additionally, the bug exposed payment-related information for approximately 1.2% of active ChatGPT Plus subscribers during a specific nine-hour window.

The Root Cause: Open-Source Library Bug

ChatGPT was taken offline to address a bug in an open-source library. This bug caused a data leak where active users could see titles from another active user's chat history. In some cases, the first message of a newly created conversation was also visible to other active users if both parties were active at the same time.

OpenAI has since patched the bug and restored the service, including the chat history feature, though a few hours of history were lost.

Exposure of ChatGPT Plus Payment Information

An investigation revealed that the same library bug caused the unintentional visibility of payment-related information for 1.2% of ChatGPT Plus subscribers who were active during a nine-hour window on Monday, March 20, between 1 a.m. and 10 a.m. Pacific time.

Data Points Exposed

For affected users, the following information may have been visible to other active users:

  • First and last name
  • Email address
  • Payment address
  • Credit card type
  • Last four digits of the credit card number
  • Credit card expiration date

OpenAI explicitly stated that full credit card numbers were not exposed at any time.

Access Vectors

There were two primary ways this payment information could have been exposed:

  1. Subscription Confirmation Emails: Some confirmation emails generated between 1 a.m. and 10 a.m. Pacific time on March 20 were sent to the wrong users. These emails contained the credit card type and last four digits of another user's card.
  2. Account Management Interface: Between 1 a.m. and 10 am. Pacific time on March 20, users clicking on "My account" then "Manage my subscription" may have seen the payment details of another active ChatGPT Plus subscriber.

Mitigation and User Notification

OpenAI has reached out to notify all affected users whose payment information may have been exposed. The company has stated they are confident that there is no ongoing risk to users' data following the patch.

"Everyone at OpenAI is committed to protecting our users’ privacy and keeping our data safe. It’s a responsibility we take incredibly seriously. Unfortunately, this week we fell short of that commitment, and of our users’ expectations."

OpenAI has apologized to the users and the community to rebuild trust.

Sources