概要: OpenAIのChatGPTプレミアムサブスクリプションサービスを装ったフィッシング攻撃が報告されています。AI生成メールを使用して、ユーザーの認証情報や財務データを盗み取ろうとしています。サイバー犯罪者は、被害者に支払い情報の更新を促す偽の更新リクエストを送信し、偽装されたOpenAIログインページに誘導しているとされています。
Alleged: FraudGPT と OpenAI developed an AI system deployed by Cybercriminals , Phishing scammers , FraudGPT operators , Dark Web threat actors と Unknown scammers, which harmed OpenAI users と ChatGPT Premium subscribers.
インシデントのステータス
Risk Subdomain
A further 23 subdomains create an accessible and understandable classification of hazards and harms associated with AI
4.3. Fraud, scams, and targeted manipulation
Risk Domain
The Domain Taxonomy of AI Risks classifies risks into seven AI risk domains: (1) Discrimination & toxicity, (2) Privacy & security, (3) Misinformation, (4) Malicious actors & misuse, (5) Human-computer interaction, (6) Socioeconomic & environmental harms, and (7) AI system safety, failures & limitations.
- Malicious Actors & Misuse
Entity
Which, if any, entity is presented as the main cause of the risk
Human
Timing
The stage in the AI lifecycle at which the risk is presented as occurring
Post-deployment
Intent
Whether the risk is presented as occurring as an expected or unexpected outcome from pursuing a goal
Intentional