Aller au contenu

Data leak at an AI service: what should you do?

It happens, and it could affect you. The right things to do within the hour, and what you should never entrust to an assistant.

Advertisement

One morning, an email arrives. The subject line begins with "Important information about the security of your account".

You open it, and one question immediately crosses your mind: what have I told that assistant over the past few months?

This scenario is anything but imaginary. OpenAI is currently trying to gauge the scale of a user data leak, revealed at the same time as its security incidents. It will be neither the first nor the last company to have to send this kind of message. Better to know what to do.

Why it is more sensitive than elsewhere

A leak at an online retail site exposes your address and your orders. Unpleasant, but limited.

An assistant, on the other hand, receives your questions. And people ask it a lot of them, often very personal: a health concern, a letter of complaint, a money problem, a conflict at work, a work document pasted in for it to summarise. Put end to end, these exchanges sometimes say more about you than a diary.

The five reflexes, in order

1. Check that the message is genuine. A fake leak alert is one of the most classic scams there is. Do not click on any link. Go to the site or the app yourself, and look for the information in your account or in official announcements.

2. Read exactly what leaked. An email address, conversations, payment methods? What follows depends entirely on the answer.

3. Change your password. And everywhere you used the same one, because it is a hacker's first reflex: to try the password they have recovered elsewhere.

4. Turn on two-factor verification. The code received on your phone in addition to the password. Even if someone knows your password, they will not be able to get in.

5. Be wary of messages that are too well informed. In the weeks that follow, an email or an SMS mentioning precise details about you may seem legitimate. That is precisely what stolen data makes possible. Be doubly cautious.

If you had put work documents into it

This is the case most often forgotten. If you have pasted documents from your employer, client data or confidential information into an assistant, tell your manager or the IT department. It is not pleasant, but it is far worse if they find out another way.

Your rights

In Europe, the law is on your side. A company that suffers a personal data leak must report it to the data protection authority within 72 hours. If the leak presents a high risk to you, it must also notify you directly.

In France, you can file a complaint with the CNIL if you consider that your data has not been properly protected, or that you were not informed as you should have been.

What you should never paste into an assistant 🚫
A bank card number. A password, even "just so it can check it". A national insurance number or a photo of an ID document. Your employer's confidential documents. And a relative's medical information, when they never agreed to it being passed around. For everything else, go into the settings: most services let you delete your history and refuse to let your conversations be used to improve their models.

What we take away

An assistant is a very handy confidant. But it is a confidant that keeps a record of everything you tell it.

Write to it as if that record could, one day, fall into other hands. Most of the time, it won't. And if it does, you'll be glad you didn't leave what really matters in it. To sort all this out right now, our article on why ChatGPT is free explains where to find the right settings.

Advertisement