Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

AI hackers stole 300,000 ChatGPT credentials in 2025: IBM

IBM reported that infostealer malware exposed more than 300,000 ChatGPT credentials in 2025 and urged organisations to improve credential hygiene and secure configurations.

This was highlighted in IBM’s 2026 X-Force Threat Intelligence Index, which found that AI-driven attacks were rising as basic security gaps allowed attackers to find weaknesses faster.

IBM X-Force found that attacks exploiting public-facing applications rose 44% globally.

Active ransomware and extortion groups rose 49% year-on-year, while publicly disclosed victim counts increased about 12%.

Vulnerability exploitation accounted for 40% of incidents in 2025, IBM X-Force said.

Large supply-chain and third-party compromises nearly quadrupled since 2020, with AI-powered tooling and leaked tooling lowering barriers for ransomware operators.

Asia Pacific made up 27% of cases and was the second most-attacked region.

Manufacturing was the top sector at 27.7% of incidents, and Asia Pacific accounted for 68% of all manufacturing cases observed by IBM X-Force.

🔗 Source: IBM

🧠 Food for thought

Implications, context, and why it matters.

Attackers are reusing old flaws, not creating new ones

  • More attacks hit public-facing applications because basic security work gets missed, not because tactics have changed.
  • IBM tracked nearly 40,000 software vulnerabilities in 2025. 56% needed no authentication, so attackers could enter systems without a click or a login 1.
  • Vulnerability exploitation drove 40% of incidents in 2025. Stolen or misused credentials made up 32% 1.
  • AI works as a “force multiplier” that speeds up finding known weaknesses and makes phishing feel more real. It is not producing new categories of hacks 1.

An AI security race is changing identity protection

  • Leaked AI credentials bring direct financial exposure. In 2025, infostealer malware (a type of malicious software that steals usernames and passwords) exposed over 300,000 ChatGPT credentials.
  • Organizations with unsanctioned “shadow AI” tools (employee-used AI tools that aren’t approved or governed by the company) paid an average of USD 670,000 more per breach than peers with little or no shadow AI use 2.
  • Identity-focused abuse is likely to grow. One forecast expects that by 2027, 80% of organizations will face phishing from criminals using synthetic identities (AI-generated or fabricated personas designed to appear real) 3.
  • Security teams are moving away from static playbooks. They are adopting automated defenses that respond faster.
  • By 2030, 45% of organizations will centrally manage the orchestration (coordination and control) of AI agents to improve collaboration, scale operations, and support ethical governance of AI deployments 3.

Recent IBM developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.