Customize Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorized as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

No cookies to display.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

No cookies to display.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

No cookies to display.

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

No cookies to display.

Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.

No cookies to display.

URL has been copied successfully!
Microsoft sues overseas threat actor group over abuse of OpenAI service
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Microsoft has filed suit against 10 unnamed people (“Does”), who are apparently operating overseas, for misuse of its Azure OpenAI platform, asking the Eastern District of Virginia federal court for damages and injunctive relief.The suit was filed in late December but was not made public until last Friday, when the initial sealed filings were revealed. The complaint makes numerous claims, of which the most prominent are violations of the Computer Fraud and Abuse Act, as well as the Racketeering and Organized Corruption Act.Microsoft, according to its main complaint, is accusing the 10 “Does” of illicitly accessing its Azure OpenAI service and using it to provide a “hacking-as-a-service” offering to other unnamed bad actors. The nameless defendants, who, according to Microsoft, make up a foreign-based consortium, used the OpenAI access to provide generative AI services to criminals, while simultaneously circumventing the “guard rails” that Microsoft has put in place in order to prevent its AI from being used for nefarious purposes.Microsoft’s guard rails, as detailed in the complaint, are designed to bar generative AI from performing certain harmful tasks, including intentionally misleading people, creating harassing content, and much more, causing the system to reject such prompts. The unnamed hackers in this case are alleged to have devised workarounds for this behavior, allowing the AI to be used maliciously by the group’s customers.”As alleged in our court filings unsealed today, Microsoft has observed a foreign-based threatactor group develop sophisticated software that exploited exposed customer credentials scraped from public websites,” wrote Steven Masada, assistant general counsel at Microsoft’s digital crimes unit, in a blog post published on Friday. “Cybercriminals then used these services and resold access to other malicious actors with detailed instructions on how to use these custom tools to generate harmful and illicit content.”Masada noted that the company has since blocked this access to its services, and “enhanced its safeguards” against similar attacks.The lawsuit, at least in part, is an investigative tool, according to Microsoft, which said that it had seized a website linked to the criminal enterprise and gained further insight into the operation as a consequence. While the practice of suing anonymous overseas criminals in US courts isn’t exactly common, it’s a known method of pursuing this type of cybercrime, according to George Washington University law professor Paul Schiff Berman.The idea is to expedite investigation, said Berman. By pursuing legal action in federal court, Microsoft can use legal tools to discover more information about websites and companies that are potentially involved in the illicit activity.”I suspect that Microsoft is hoping that, in the discovery process, they’ll be able to use the subpoena power of the court to discover information that will tell them something more about who these people are,” he said.It’s likely to be a long process, but more information about the alleged hackers could open access to further legal avenues against them. For one thing, Berman said, even if the perpetrators aren’t subject to the jurisdiction of a US court, they could be residents of a country with which the US has what’s called a mutual legal assistance treaty, which offers a channel for requesting assistance from the court system of a foreign country to provide further information or documents.Domain registrars and web services firms in the US can be another source of information, according to Berman something which Microsoft’s legal team apparently understands quite well, highlighting in the complaint the attacker’s misuse of services from US-based companies like Verisign and the Public Internet Registry.Nevertheless, there are numerous obstacles that Microsoft must overcome to gather information on the alleged cybercriminals, Berman noted. Mutual legal assistance treaties are not ubiquitous, which means that countries hostile to US interests are unlikely to have such an arrangement in place, for one thing.”I don’t think [Microsoft is] filing this suit thinking they’re going to be successful at all these things,” Berman said. “I think they’re filing the suit partially to show Americans that they’re trying “¦ but also, to the extent they can get information, they can alert the US government.”

First seen on csoonline.com

Jump to article: www.csoonline.com/article/3801927/microsoft-sues-overseas-threat-actor-group-over-abuse-of-openai-service.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link