OpenAI
Disclosed Mar 24, 20233 years agoConfirmed
ChatGPT Redis bug exposed chat titles and Plus subscriber payment details
A bug in the open-source redis-py client let some ChatGPT users see other users' chat history titles, and exposed name, email, payment address and partial card details of about 1.2% of ChatGPT Plus subscribers active during a nine-hour window.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Mar 24, 2023 |
| Discovered | Mar 20, 2023 |
| Attack | Exposed data |
| Data exposed | Names, Emails, Addresses, Payment cards, Prompts and chats |
| Sector | AI · US |
| Status | Confirmed |
| Lawsuit or fine | EUR 15M Italian Garante fine (Dec 2024) that cited failure to notify this breach among other findings; decision overturned by the Court of Rome (March 2026) |
Sources
| Source | |
|---|---|
| OpenAI: ChatGPT payment data leak caused by open-source bugbleepingcomputer.com · News | News |
| ChatGPT, il Garante privacy chiude l'istruttoria (EUR 15M fine)garanteprivacy.it · Regulator | Regulator |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Mar 24, 2023 |
Other breaches at OpenAI
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.