{"id":7139,"date":"2023-08-02T10:26:51","date_gmt":"2023-08-02T10:26:51","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/02\/post_id-3254\/"},"modified":"2026-07-04T10:23:13","modified_gmt":"2026-07-04T10:23:13","slug":"dangers-for-companies-how-cybercriminals-exploit-chatgpt","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2023\/08\/02\/dangers-for-companies-how-cybercriminals-exploit-chatgpt\/","title":{"rendered":"Dangers for Companies &#8211; How Cybercriminals Exploit ChatGPT"},"content":{"rendered":"<h2 style=\"font-weight: 400;\"><b>Dangers for Companies &#8211; How Cybercriminals Exploit ChatGPT<\/b><\/h2>\n<p><strong>AI applications are used by many Germans. Companies also deploy them to quickly generate codes using ChatGPT, for example. However, cybercriminals exploit the program&#8217;s susceptibility to errors. What companies need to consider when dealing with ChatGPT and similar tools.<\/strong><\/p>\n<p style=\"font-weight: 400;\">Applications based on artificial intelligence have become mainstream. According to the &#8220;Opinion Monitor on Artificial Intelligence,&#8221; around half of Germans have a positive attitude towards AI programs like ChatGPT. Approximately one-fifth of Germans have already used the text generation software, according to Bitkom. However, 44 percent also fear AI and its impacts. Indeed, while AI applications can be very useful, they also increase the cybersecurity risks for companies.<\/p>\n<p style=\"font-weight: 400;\"><strong>Cybercriminals place malicious code in ChatGPT<\/strong><\/p>\n<p style=\"font-weight: 400;\">ChatGPT is not only capable of writing a birthday speech or summarizing a scientific article but can also be used to create codes. The problem: ChatGPT still tends to respond to requests with made-up answers, citations, and directories. Cybercriminals exploit this flaw to place malicious code at these invented locations by ChatGPT.<\/p>\n<p style=\"font-weight: 400;\">If companies access these sources and download the corresponding codes, they significantly endanger the security of their systems. The rule of thumb is therefore: never download and execute unchecked codes from ChatGPT! Every generated line of code must be tested in a secure environment, and regular, protected backups of the original system codes are essential.<\/p>\n<h3 style=\"font-weight: 400;\"><strong>Using AI in Companies &#8211; What to Consider <\/strong><\/h3>\n<p style=\"font-weight: 400;\">To avoid creating additional risks when working with AI programs, companies should keep some fundamental rules in mind. These include:<\/p>\n<ul>\n<li><strong>Risk awareness<\/strong>: Careless handling of ChatGPT and similar tools can quickly become dangerous. It is important to raise awareness of the negative impacts that AI can have.<\/li>\n<li><strong>Data sensitivity<\/strong>: Employees should not feed AI programs with sensitive data such as passwords or personal information.<\/li>\n<li><strong>Proven security practices<\/strong>: What applies to all areas also applies especially to handling AI: employees must apply proven security practices, change their passwords regularly, and protect sensitive information.<\/li>\n<li><strong>Know the limits<\/strong>: Companies must be aware that ChatGPT is still not a mature program and therefore regularly reaches its limits. Its understanding is still very limited, so all outputs of the program must be thoroughly checked.<\/li>\n<\/ul>\n<h3 style=\"font-weight: 400;\"><strong>AI as a Security Assistant <\/strong><\/h3>\n<p style=\"font-weight: 400;\">At the same time, AI applications like ChatGPT can be more than useful helpers in defending against cyber threats. For example, the program can be used to check software for security vulnerabilities. The AI only needs to be trained with a few data points and relieves human employees, who can thus perform security checks without understanding the basic mechanisms of the software being checked. Additionally, ChatGPT can be used as a spam filter. The AI is much more efficient and accurate than a conventional spam program.<\/p>\n<p style=\"font-weight: 400;\">ChatGPT can thus primarily relieve its human colleagues, who are reaching their limits due to the increase in cybersecurity incidents and the flood of security-relevant messages that need to be processed daily. The AI performs an initial evaluation and can carry out basic checks, while humans focus on the truly important events. Company decision-makers can thus benefit from the advantages of AI applications like ChatGPT and simultaneously minimize the risks to the security of their own systems.<\/p>\n<h2>TL;DR<\/h2>\n<ul>\n<li>Cybercriminals place malicious code at sources and directories invented by ChatGPT<\/li>\n<li>Companies must never execute AI-generated code without checking  &#8211;  testing in a secure environment is mandatory<\/li>\n<li>ChatGPT can also be used as a security assistant: for code audits, spam filtering, and incident analysis<\/li>\n<\/ul>\n<h2>Key Facts<\/h2>\n<p><strong>AI Usage in Germany:<\/strong> Around one-fifth of Germans have already used ChatGPT (Bitkom)<\/p>\n<p><strong>Main Risk:<\/strong> ChatGPT invents citations and directories  &#8211;  attackers place malicious code there<\/p>\n<p><strong>Security Rule No. 1:<\/strong> Never download and execute unchecked codes from ChatGPT<\/p>\n<p><strong>AI as Defender:<\/strong> ChatGPT can be used as a spam filter and for automated security checks<\/p>\n<p><strong>Fact:<\/strong> Deepfake-based social engineering attacks increased by 550 percent in 2024, according to Europol.<\/p>\n<p><strong>Fact:<\/strong> AI-powered cyberattacks increased by 135 percent in 2024, according to Darktrace.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>How do cybercriminals use ChatGPT for attacks?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">ChatGPT tends to invent non-existent sources and package directories. Attackers register these invented sources and place malware there. If developers download the code recommended by ChatGPT, they infect their systems.<\/p>\n<\/details>\n<details>\n<summary><strong>What rules should companies establish for AI use?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Companies need clear guidelines: do not feed the AI with sensitive data, do not execute generated code without checking, change passwords regularly, and have a general awareness of the technology&#8217;s susceptibility to errors.<\/p>\n<\/details>\n<details>\n<summary><strong>Can ChatGPT also improve cybersecurity?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Yes. ChatGPT can check software for security vulnerabilities, act as an intelligent spam filter, and perform an initial evaluation of security-relevant messages. This relieves IT security teams in their daily incident analysis.<\/p>\n<\/details>\n<details>\n<summary><strong>Should employees enter sensitive company data into ChatGPT?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">No. Employees should not enter passwords, personal information, or confidential business data into AI systems. The entered data could be used for training or become accessible through security vulnerabilities.<\/p>\n<\/details>\n<details>\n<summary><strong>How can AI-generated code be used safely?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Every line of code generated by ChatGPT must be tested in an isolated sandbox environment. Additionally, regular, protected backups of the original system codes should be created to enable quick restoration in case of damage.<\/p>\n<\/details>\n<h2>Further Reading in the Network<\/h2>\n<p><a href=\"https:\/\/www.cloudmagazin.com\">AI Security in Cloud Environments on cloudmagazin.com<\/a><\/p>\n<p><a href=\"https:\/\/www.mybusinessfuture.com\">AI Use in Daily Business Operations on mybusinessfuture.com<\/a><\/p>\n<p><a href=\"https:\/\/www.digital-chiefs.de\">Responsible AI Use as a Leadership Task on digital-chiefs.de<\/a><\/p>\n<p style=\"font-weight: 400;\">Bild: Matheus Bertelli\/pexels.com <a href=\"https:\/\/www.pexels.com\/de-de\/foto\/frau-laptop-arbeiten-internet-16094040\/\">https:\/\/www.pexels.com\/de-de\/foto\/frau-laptop-arbeiten-internet-16094040\/<\/a><\/p>\n<p style=\"text-align: right;\">\n<h2>Related Articles<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/06\/cybersecurity-trends-2026-seven-key-developments\/\">Cybersecurity Trends 2026: The 7 Developments Security Decision-Makers Need to Know<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/01\/hybrid-warfare-and-disinformation-the-underestimated-cyber-threat-to-businesses\/\">Hybrid Warfare and Disinformation: The Underestimated Cyber Threat to Companies<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/02\/25\/post_id-3835\/\">Palantir and the Future of Cyber Defense: AI as a Strategic Weapon<\/a><\/li>\n<\/ul>\n<p><em>Header Image Source: Pexels<\/em><\/p><\/p>\n","protected":false},"excerpt":{"rendered":"Dangers for Companies &#8211; How Cybercriminals Exploit ChatGPT AI applications are used by many Germans. Companies also deploy them to quickly generate codes using ChatGPT, for example. However, cybercriminals exploit the program&#8217;s susceptibility to errors. What companies need to consider when dealing with ChatGPT and similar tools. Applications based on artificial intelligence have become mainstream. [&hellip;]","protected":false},"author":55,"featured_media":3256,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"chatgpt","_yoast_wpseo_title":"Dangers for Companies - How Cybercriminals Exploit ChatGPT","_yoast_wpseo_metadesc":"ChatGPT dangers for companies: Learn how cybercriminals exploit AI to create malware and phishing\u2014protect your business now.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["post_id-3254"],"footnotes":""},"categories":[259],"tags":[248],"class_list":["post-7139","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-strategie-governance-en","tag-ki"],"evm_reading_time_minutes":6,"wpml_language":"en","wpml_translation_of":3254,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7139","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=7139"}],"version-history":[{"count":4,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7139\/revisions"}],"predecessor-version":[{"id":18678,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7139\/revisions\/18678"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/3256"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=7139"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=7139"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=7139"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}