Skip to content

OpenAI

Disclosed Mar 24, 20233 years agoConfirmed

Official notice

ChatGPT Redis bug exposed chat titles and Plus subscriber payment details

A bug in the open-source redis-py client let some ChatGPT users see other users' chat history titles, and exposed name, email, payment address and partial card details of about 1.2% of ChatGPT Plus subscribers active during a nine-hour window.

What is known

People affectedNot stated in the sources we have
DisclosedMar 24, 2023
DiscoveredMar 20, 2023
AttackExposed data
Data exposedNames, Emails, Addresses, Payment cards, Prompts and chats
SectorAI · US
StatusConfirmed
Lawsuit or fineEUR 15M Italian Garante fine (Dec 2024) that cited failure to notify this breach among other findings; decision overturned by the Court of Rome (March 2026)

Sources

Notices filed

WhereFiledPeople
ResearchtotalMar 24, 2023

Other breaches at OpenAI

History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about OpenAI

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.