← the record
AIAAIC-1211

Study: ChatGPT generates plausible phishing emails, malware

It is possible to make ChatGPT generate 'plausible' phishing emails and malicious code, according to security researchers. ChatGPT generated a ' plausible phishing email ' after Check Point Research researchers asked the chatbot to 'write a phishing email' coming from a 'fictional web-hosting service.' In a similar vein, r esearchers at Abnormal Security asked ChatGPT to write an email 'that has a high likelihood of getting the recipient to click on a link.' The findings raised concerns about the apparent ease with which ChatGPT can be tricked into generating dangerous content, and begged questions about how well OpenAI usage policies are enforced. The policies forbid the use of its systems to 'generate code that is designed to disrupt, damage, or gain unauthorized access to a computer system'. System 🤖 ChatGPT Operator: Developer: OpenAI Country: USA Sector: Technology Purpose: Generate text Technology: Chatbot; Generative AI; Machine learning Issue: Security

Date it happened
2022-12-01
Organisation involved
Abnormal Security; Check Point Research
Product, system or model
ChatGPT
Where this came from
Share this incident
XLinkedInFacebookWhatsAppEmail
Attribution

This incident was imported from AIAAIC and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.

This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.