“ChatGPT data leak” is a frequent search, often prompted by a headline. But the phrase covers very different situations: a bug at the vendor, an employee pasting a confidential document, credentials stolen from an infected computer, a sharing option that was misunderstood. Here are the documented cases, with sources, and what they teach an organisation.
ChatGPT data leaks: what are we talking about?
The GDPR defines a personal data breach as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data (Article 4).7 Applied to generative AI, this definition covers three families of situations:
- An incident at the vendor, such as a technical bug;
- Uncontrolled internal use: data sent to a service that should not have received it;
- A compromised account: a third party gains access to a user’s history.
The known cases, from 2023 to 2025
The timeline below only includes events documented by the vendor itself or by recognised media outlets.
- 20 March 2023A bug exposes conversation titlesA bug in an open-source library allows some users to see the titles of other active users’ conversations. OpenAI states that payment information of 1.2% of ChatGPT Plus subscribers who were active during a nine-hour window may have been exposed, without full card numbers.1
- April 2023Samsung: code and a meeting pasted into ChatGPTAccording to press reports, three employees entered source code to be checked, code to be optimised and a meeting recording to produce minutes.2
- May 2023Samsung restricts generative AI toolsThe company temporarily limits their use on the devices it provides.3
- 20 June 2023ChatGPT credentials found in malware logsGroup-IB identifies 101,134 devices infected with information-stealing malware on which ChatGPT credentials were saved, between June 2022 and May 2023.4
- 30 July 2025Shared conversations appear in GoogleFast Company reveals that nearly 4,500 shared ChatGPT conversations show up in Google search results.5
- 31 July 2025OpenAI removes the “make discoverable” optionIts head of security describes a short-lived experiment that created too many opportunities to share information unintentionally, and announces the removal of the indexed content.6
The bug of 20 March 2023
OpenAI published a detailed account: a bug in an open-source library allowed some users to see titles from another active user’s chat history. Payment-related information of 1.2% of ChatGPT Plus subscribers who were active during a nine-hour window may have been visible; the vendor states that full card numbers were never exposed.1 It is the only case on this list that stems from a technical failure of the service.
Samsung, April and May 2023
The most frequently cited case. According to press reports, one employee asked ChatGPT to check database source code, another requested code optimisation, and a third submitted a meeting recording to obtain minutes.2 Samsung then temporarily restricted the use of generative AI tools on company devices.3 No hacking here: employees used a convenient tool, with no framework for data.
Stolen credentials, June 2023
Group-IB identified 101,134 devices infected with information-stealing malware on which ChatGPT credentials were saved, between June 2022 and May 2023.4 The service itself is not at fault: it was users’ computers that were compromised. But the consequence is real, since anyone who logs in with these credentials can access the conversation history, and therefore everything that was pasted into it.
Shared conversations indexed, July 2025
ChatGPT allowed users to create a public share link to a conversation, with an option to make it discoverable by search engines. Fast Company showed that nearly 4,500 conversations appeared in Google.5 The very next day, OpenAI removed the option, judging that it created too many opportunities to share information unintentionally, and announced that it was working to remove the indexed content.6
The published figures
What these cases have in common
Of the cases listed, only one stems from a failure of the service. The others come down to usage: confidential documents pasted without thinking, a public sharing option that was misunderstood, credentials stored on infected computers. The common thread: the data should not have been there.
Business plans reduce part of the risk: OpenAI states, for example, that ChatGPT Business and Enterprise data is not used for training by default and is encrypted at rest and in transit.9 But no contract prevents an employee from pasting a customer file into the wrong tool, or from sharing a public link. That is why France’s national cybersecurity agency (ANSSI) recommends adopting a cautious approach when deploying generative AI.11
After an incident: the organisation’s obligations
If personal data has been sent to an unauthorised service, the organisation must assess the situation. Where a breach presents a risk to the rights and freedoms of individuals, the GDPR requires it to be notified to the competent supervisory authority (the CNIL in France) without undue delay and, where feasible, no later than 72 hours after becoming aware of it (Article 33).7 If the risk is high, the people concerned must also be informed (Article 34).7 Every breach must also be documented in an internal register (Article 33(5)).7
When the organisation uses a business plan, the vendor in principle acts as a processor. The GDPR then requires the processor to notify the controller of any breach without undue delay after becoming aware of it (Article 33(2)).7 With a personal account used by an employee, this contractual link does not exist: the organisation will not be informed by the vendor, and will often only discover the incident by chance.
Hence the value of a simple rule in the policy: any employee who has entered sensitive data by mistake reports it immediately, without fear, so that the organisation can act within the deadlines.
How to protect yourself from a data leak
- Use business accounts under contract, rather than personal accounts.
- Write a policy listing the data that must never be entered, as recommended by France’s data protection authority, the CNIL.8
- Govern sharing. Remind users that a share link makes the conversation accessible to anyone who gets hold of it.
- Protect accounts: strong authentication, up-to-date computers and antivirus software, to limit credential theft.
- Set retention. On an individual account, temporary chats are not used for training and are kept for no more than 30 days, according to OpenAI.10
- Anonymise before sending. It is the only measure that also protects against human error.
name, email, phone, amount
Emma Clarke[NAME_1], e.clarke@example.com[EMAIL_1], 07700 900456[PHONE_1], £1,240
Oliver Bennett[NAME_2], o.bennett@example.com[EMAIL_2], 07700 900789[PHONE_2], £860
For anonymisation, tools installed on the computer can detect sensitive data in messages and files before they are sent. Tacite-IA is one of them: analysis runs locally, with no AI, in Chrome, Edge and coding assistants. Desktop apps, such as the ChatGPT desktop app, remain outside its scope: the policy and training keep their full role there.
Frequently asked questions
Does a hacked ChatGPT account expose my conversations?
Yes: anyone who logs in with stolen credentials can access the account history. Group-IB identified more than 100,000 infected devices on which ChatGPT credentials were saved between June 2022 and May 2023. Strong authentication and well-protected computers limit this risk.
Have there already been data leaks involving ChatGPT?
Yes, several cases are documented: a bug in March 2023 that exposed conversation titles and payment information of some Plus subscribers, internal data entered by Samsung employees in April 2023, and Google indexing publicly shared conversations in July 2025.
What happened at Samsung with ChatGPT?
According to press reports, three employees entered source code and a meeting recording into ChatGPT. Samsung then temporarily restricted the use of generative AI tools on company devices, in May 2023.
Are my shared ChatGPT conversations visible on Google?
On 31 July 2025, OpenAI removed the option that allowed a shared conversation to be made discoverable by search engines, and announced that it was working to remove the indexed content. A share link nevertheless remains accessible to anyone who obtains it.
What should you do if an employee has pasted customer data into ChatGPT?
Assess the situation quickly: which data, how many people, which account. If the breach presents a risk to individuals, the GDPR requires it to be notified to the supervisory authority (the CNIL in France) within 72 hours of becoming aware of it, and recorded in the breach register.
Sources
- March 20 ChatGPT outage: Here’s what happened. OpenAI. Accessed on 5 October 2026.
- Three Samsung employees reportedly leaked sensitive data to ChatGPT. Engadget, 7 April 2023. Accessed on 5 October 2026.
- Samsung bans use of generative AI tools like ChatGPT after April internal data leak. TechCrunch, 2 May 2023. Accessed on 5 October 2026.
- Group-IB discovers 100K+ compromised ChatGPT accounts on dark web marketplaces. Group-IB, 20 June 2023. Accessed on 5 October 2026.
- Exclusive: Google is indexing ChatGPT conversations…. Fast Company, 30 July 2025. Accessed on 5 October 2026.
- OpenAI kills “short-lived experiment” where ChatGPT chats could be found on Google. Malwarebytes, 1 August 2025 (quoting the statement by OpenAI’s head of security of 31 July 2025). Accessed on 5 October 2026.
- Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation). EUR-Lex. Accessed on 5 October 2026.
- Les questions-réponses de la CNIL sur l’utilisation d’un système d’IA générative. CNIL (French data protection authority), 18 July 2024. In French. Accessed on 5 October 2026.
- Enterprise privacy at OpenAI. OpenAI, page updated on 8 January 2026. Accessed on 5 October 2026.
- Data controls in ChatGPT. OpenAI Help Center. Accessed on 5 October 2026.
- Recommandations de sécurité pour un système d’IA générative. ANSSI (France’s national cybersecurity agency), 29 April 2024. In French. Accessed on 5 October 2026.
ChatGPT is a trademark of OpenAI, Copilot of Microsoft, Claude of Anthropic, Gemini of Google. Tacite-IA is not affiliated with any of these vendors. This article is for information only and does not constitute legal advice.