As the world grapples with artificial intelligence (AI) systems becoming more powerful, highlighted by the rapid adoption and popularity of OpenAI’s ChatGPT in just eight weeks, experts say the platform could be used by criminals to breach or attack organisations and individuals at an accelerated pace.
ChatGPT is a chatbot launched by AI non-profit OpenAI in November 2022. It is capable of generating human-like text and has a range of applications including translation.
The platform has proven to be popular in its relatively short lifespan, reaching 1-million users much faster than Pinterest, Instagram, Facebook and other social media sites.
Alongside climate change, education and employment, the chatbot and its technology were a main topic of discussion at the World Economic Forum in Davos, Switzerland, last week.
“On the surface this might sound like an amazing invention that can be used to explain complex concepts in simple terms, brainstorm creative ideas, or even automate certain actions like customer support, writing memos or keeping minutes of meetings,” says Stephen Osler, co-founder and business development director at Nclose, a local cybersecurity firm. “But it also poses a serious threat to cybersecurity”.
The platform appears to have already gone mainstream in the business world.
Almost 30% of the nearly 4,500 professionals surveyed this month by Fishbowl, a social platform owned by employer review site Glassdoor, said that they had already used ChatGPT or another AI program in their work. Respondents include employees at Amazon, Bank of America, JPMorgan, Google, Twitter and Facebook parent Meta.
Anna Collard, senior vice-president for content strategy at KnowBe4 Africa, a cybersecurity training company, says the threats are likely to become more prevalent as OpenAI continues to train its model.
“ChatGPT’s powerful language model can be used to generate realistic and convincing phishing messages, making it easier for attackers to trick victims into providing sensitive information or downloading malware.”
Tied to this, Collard says the platform can be used to create a convincing digital copy of an individual’s writing style, allowing attackers to impersonate their target through text, such as in an email or text message.
It appears that the platform could also help to increase efficiency for cybercriminals in their work.
“The generation of text through ChatGPT’s language models allows attackers to create fake ads, listings and many other forms of scamming material,” she says, adding it “can also be used to automate the creation of malicious messages and phishing emails making it possible for attackers to launch large-scale attacks more efficiently”.
ChatGPT has, unsurprisingly, attracted much attention from technology giants and financiers, meaning its scale and influence are set to grow even further.
Microsoft is in talks with OpenAI about investing as much as $10bn in the project. The software giant is also looking to integrate GPT, the language model that underlies ChatGPT, into its widely used Teams and Office software. If that happens, AI tech may well be brought into the mainstream.
Steve Povolny, principal engineer and director at Trellix, a US-based cybersecurity firm, says criminals are already finding ways to use ChatGPT for nefarious purposes.
“While ChatGPT attempts to limit malicious input and output, the reality is that cybercriminals are already looking at unique ways to leverage the tool for nefarious purposes. It isn’t hard to create hyper realistic phishing emails or exploit code, for example, simply by changing the user input or slightly adapting the output generated,” he said.
Beyond text, Povolny says the evolution of AI and data science-based tools is likely to lead to other mediums, including audio and video as channels through which attacks are done.
Still, the computer engineer is positive that the cybersecurity industry can harness the power of the platform for innovation and collaboration, for good.
“While cybersecurity concerns have manifested, it’s important to remember that this tool has even greater potential to be used for good. It can be effective at spotting critical coding errors, describing complex technical concepts in simplistic language, and even developing script and resilient code, among other examples.” /With Bloomberg










Would you like to comment on this article?
Sign up (it's quick and free) or sign in now.
Please read our Comment Policy before commenting.