Back to Technically U

Podcast Episode

The AI Data Disaster: What ChatGPT, Claude, and Gemini Really Do With Your Secrets

Technically U··31 August 2026·22 min

About this episode

143,000 ChatGPT, Claude, and Copilot conversations are publicly accessible right now. Here's what was exposed—and why your AI isn't as private as you think.🚨 THE HEADLINE:143,000 user conversations with ChatGPT, Claude, Copilot, and other AI tools are publicly accessible on Archive.org. Anyone with internet access can read them.WHAT'S IN THEM:- Medical histories and diagnoses- Financial accounts and credit card numbers- Source code from major companies- Internal company documents- Social Security numbers- Passwords and API keys- Legal contracts and NDAs---💀 REAL INCIDENTS (2024-2026):CASE 1: Samsung's Proprietary Chip Design Leaked- Samsung engineer pasted confidential code into ChatGPT- Wanted optimization help- Code was for a secret chip design project- Code ended up in OpenAI's training data- Samsung immediately banned ChatGPT company-wideCASE 2: 143,000 Conversations Made Public (2025-2026)- Security researcher found shareable conversation links- Many linked from forums, Reddit, social media- Archive.org captured 143,000+ conversations- Indexed and searchable- Included medical data, financial info, source code- Most users had no idea conversations were publicCASE 3: Mexican Government Breach (Dec 2025 - Feb 2026)- Single attacker used Claude Code and ChatGPT- Breached 9 government agencies- Stole data on 195 MILLION Mexican citizens- Claude Code executed 75% of all attack commands- 1,088 prompts = 5,317 AI-executed commands- Built tools to forge tax certificates in real-timeCASE 4: ChatGPT Data Leakage Vulnerability (Feb 2026)- Researchers discovered vulnerability in ChatGPT- Allowed silent data exfiltration via DNS queries- Data leaked without user knowledge or consent- Attackers could command model to extract specific data- Could enable remote command execution- Fixed by OpenAI, but proven the attack surface existsCASE 5: API Keys and Secrets Exposed- 23.8 million "secrets" (passwords, keys) leaked via AI tools in 2024- 25% increase year-over-year- A single screenshot with exposed API key → data in ChatGPT logs- If OpenAI logs are breached, attackers get production access---🔴 WHAT YOU SHOULD NEVER SHARE:CATEGORY 1: Passwords, API Keys, Credentials❌ Pasting code with API keys visible❌ Database connection strings❌ SSH keys❌ AWS access tokens❌ Private encryption keysWhy: 23.8M secrets leaked via AI in 2024. If logs are breached, attackers have direct infrastructure access.CATEGORY 2: Health Information (PHI)❌ Medical diagnoses❌ Medications and dosages❌ Lab results❌ Mental health concerns❌ Sexual health questionsWhy: HIPAA doesn't protect consumer AI. Data in training datasets. Breaches expose health records. Insurance companies could deny coverage.CATEGORY 3: Financial Information❌ Bank account numbers❌ Credit card numbers❌ Social Security numbers❌ Tax returns❌ Investment account details❌ Mortgage documentsWhy: Complete identity theft package if exposed. Perfect for fraud.CATEGORY 4: Proprietary Source Code❌ Company software❌ Technical architecture❌ Algorithms❌ Frameworks specific to your business❌ Configuration files with secretsWhy: 11% of ChatGPT inputs from workers contained confidential code. May be in training data. Rivals could see it.CATEGORY 5: Personal Identifying Information (PII)❌ Full names with context❌ Addresses❌ Phone numbers❌ Email addresses (specific to you)❌ Driver's license numbersWhy: Combined with other data = phishing/identity theft profile.CATEGORY 6: Legal Documents & NDAs❌ Contracts❌ Non-Disclosure Agreements❌ Partnership agreements❌ Internal legal opinions❌ Litigation recordsWhy: Pasting an NDA-covered document into a third party may violate the NDA itself. Sensitive terms exposed to competitors.CATEGORY 7: Regulated Data (HIPAA, PCI, GDPR, FERPA, SOX)❌ Healthcare records❌ Credit card data❌ EU resident personal data❌ Student education records❌ Financial reporting data