ChatGPT Shows Users Each Other's Credit Cards
A redis-py library update was deployed to improve ChatGPT's session handling. A cache race condition exposed other users' names, billing addresses, and card details for a nine-hour window; OpenAI described the affected population as 'extremely low.' Extremely low was 1.2% of all ChatGPT Plus subscribers.
Severity: Unrated · Category: Data Exfiltration
Impact: 1.2% of ChatGPT Plus subscribers exposed
Source: OpenAI Post-Mortem, Mar 24 2023
How Fencio prevents this
Sensitive data and an outbound channel ended up in the same context. The agent did not need to be malicious. It only needed to be convinced that sending the data somewhere was part of the job.
Fencio tracks sensitive data as it moves through an agent session and checks every outbound path, from links and images to emails and API calls. When classified data is about to leave, or a series of answers adds up to something the requester is not entitled to see, the response is blocked or redacted.