Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Artificial Intelligence - Users Share Personal, Emotional, Confidential Info with ChatGPT
Artificial Intelligence Emerging Threats Latest News News & Analysis Study & Research Threats and Vulnerabilities

Users Share Personal, Emotional, Confidential Info with ChatGPT

Josh Breaker RolfeBy Josh Breaker RolfeSeptember 5, 20252 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Personal Info with ChatGPT
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

ChatGPT users are routinely sharing personally identifiable information (PII), sensitive emotional disclosures, and confidential material with the AI platform, analysis from SafetyDetectives has revealed.  

The cybersecurity reviewer’s deep dive into 1000s of ChatGPT conversations, leaked in August 2025, confirms what many already suspected: many internet users aren’t fully aware of how the AI model handles and distributes their data, and they have a startling level of trust in a still-emerging technology.  

A UX Flaw That Turned into a Data Leak 

The leak originally stemmed from a now-removed “Make Chat Discoverable” feature that allowed search engines to index conversations and make them accessible to anyone online. While the option did warn that chats would appear in web searches, SafetyDetectives suggests many users failed to grasp the full implications.  

Users are Using ChatGPT as Therapists and Lawyers 

The analysis, covering over 43 million words across the exposed conversations, found that people are treating ChatGPT as everything from a therapist to a legal consultant.  

Nearly 60% of flagged conversations fell under “professional consultations,” with users asking the chatbot for advice on sensitive matters, including:  

  • Legal disputes 
  • Workplace conflicts 
  • Family planning 

In many cases, users disclosed suicidal ideation, addiction struggles, and emotional trauma. Others uploaded full resumes, complete with names, addresses, phone numbers, and employment history. This is all information cybercriminals could use to blackmail victims or for fraud and identity theft.  

Some Users Participate in Marathon Sessions 

The dataset also revealed unusual and concerning patterns in user behavior. While most chats were short, coming in at under 500 words, some were startlingly lengthy. Just 100 chats made up more than 43 million words analyzed, and the longest single conversation ran to 116,024 words, roughly the length of a full novel.  

Calls for Stronger Warnings and Redactions 

SafetyDetectives argues that the incident highlights the need for stronger protections and clearer dislosures. Their report recommends:  

  • Prominent, unambiguous warnings against sharing personal or confidential data 
  • Automatic redaction of PII when conversations are shared 
  • Simplified and safer defaults for privacy settings, so users do not inadvertently expose sensitive material 

Without stronger safeguards, the researchers caution, oversharing with AI assistants will continue to present a growing cybersecurity and public safety issue.  

Josh Breaker Rolfe

Josh is a Content writer at Bora. He graduated with a degree in Journalism in 2021 and has a background in cybersecurity PR. He's written on a wide range of topics, from AI to Zero Trust, and is particularly interested in the impacts of cybersecurity on the wider economy.

  • Josh Breaker Rolfe
    Thales Data Threat Report: AI and Cloud Complexity Fuel New Data Security Risks
  • Josh Breaker Rolfe
    50+ Organizations Breached Due to Missing MFA
  • Josh Breaker Rolfe
    What Happens after a Phishing Email Lands in Your Inbox?
  • Josh Breaker Rolfe
    Red Hat OpenShift AI Vulnerability Allows Attackers to Seize Infrastructure Control

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The next phase of endpoint security starts with simplicity

June 24, 20266 Mins Read

Klue supply chain breach exposes Salesforce data at several security firms

June 24, 20266 Mins Read

What Are AI SOC Agents? Use Cases, Architecture, and the Leading Vendors

June 19, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}