OpenAI discloses ChatGPT outage exposing user payment and chat data
OpenAI said the bug let some Plus subscribers' names, email and billing addresses and partial card numbers become visible to other active users for roughly nine hours.
- Security & misuse
- Minor
OpenAI disclosed that a bug had briefly exposed some ChatGPT users’ data to other active users on 20 March 2023, prompting the company to take the service offline while it fixed the issue. The company traced the fault to the open-source Redis client library redis-py: a change OpenAI had made to its server caused a spike in cancelled Redis requests, which created a small chance that a connection would return data belonging to a different user rather than the one who made the request.
Two categories of data were affected. Some users briefly saw the titles of another active user’s chat history, and in some cases the first message of a newly started conversation if two users happened to be active at the same moment. Separately, and more seriously, the same bug could expose billing-related information: OpenAI said this affected 1.2% of ChatGPT Plus subscribers active during a specific nine-hour window, who could have had their first and last name, email address, payment address, card type and expiration date, and the last four digits of a card number visible to another user. Full card numbers were never exposed.
OpenAI said it patched the bug after identifying it and contacted affected Plus subscribers directly. The disclosure came days before Italy’s Garante ordered ChatGPT taken offline in the country, citing this incident alongside broader complaints about the absence of a legal basis for processing users’ data and the lack of age verification — making the outage a direct trigger for the first national-level regulatory block of a major generative AI product.