In late January 2025, a threat actor using the name "Gloomer" claimed on BreachForums to have breached OmniGPT, an AI aggregator that gives users access to models such as ChatGPT, Claude and Gemini through one subscription. The alleged dump, first flagged by the threat intelligence team KrakenLabs, was offered for US$100 and was said to contain about 30,000 user email addresses, some phone numbers, 34 million messages between users and AI models, and links to thousands of uploaded files. According to the actor and to reporters who reviewed samples, some of those messages and files contained API keys, login credentials and billing information that users had shared with the chatbots. OmniGPT has not publicly confirmed or denied the breach, so the intrusion itself remains a claim. What it illustrates is certain: secrets pasted into AI tools are stored by those tools, and they leak with them.
Key takeaways
- A threat actor called Gloomer claimed to have breached OmniGPT and offered 34 million chat messages, about 30,000 user emails and file links for sale.
- The alleged data included API keys and credentials that users had pasted into conversations or uploaded files, according to the actor and press reports.
- OmniGPT had not made a public statement at the time of reporting; the breach is unconfirmed.
- A leaked excerpt reportedly showed API request headers and payloads referencing OmniGPT's application endpoint, SecureWorld said.
- The identity lesson: any API key shared with an AI assistant should be treated as exposed to that provider, and rotated if the provider is breached.
At a glance
| Organisation | OmniGPT, an AI aggregator platform |
|---|---|
| When | Claim flagged by KrakenLabs on 27 January 2025; CyberInsider reports the data was posted on 9 February 2025 |
| Attacker | A threat actor using the name "Gloomer" (claimed) |
| Entry point | Not disclosed |
| Identities abused | API keys, login credentials and other secrets shared by users in chats and uploaded files; possibly authentication payloads in API request data |
| Impact | 34 million AI chat messages, about 30,000 email addresses and thousands of file links allegedly leaked; unconfirmed by OmniGPT |
| Category | NHI, LLM and AI platform. Incident class: claimed breach (AI chat logs containing user API keys and credentials; unconfirmed) |
What happened
On 27 January 2025, KrakenLabs posted a breach alert: "Threat actor "Gloomer" claims to have breached" OmniGPT, selling the data for US$100: 30,000 user emails (20% with phone numbers), 34 million AI chat messages and more than 6,000 file links, "some containing sensitive data like credentials." CyberInsider, which reported the claim on 13 February 2025, said the data was posted on 9 February and that the actor claimed to have "successfully infiltrated OmniGPT's systems." Forcepoint later described the claim as made in early February after KrakenLabs' initial report in late January.
According to SecureWorld, the forum post claimed the leak contained all chat messages between users and AI models, links to files users had uploaded, the email addresses and phone numbers of about 30,000 users, and "API request details and authentication payloads." A leaked excerpt "shows API request headers and payloads, specifically referencing OmniGPT's application endpoint," SecureWorld reported, adding that if verified this could indicate flaws in how the platform manages authentication. CyberInsider said the dataset was "said to include links to user-uploaded files, some containing sensitive data such as API keys, credentials, and billing information," and that forum users showed particular interest "in extracting valuable credentials from chatbot conversations."
CyberInsider asked OmniGPT for comment and reported that the platform had not made any public statements. SecureWorld likewise said OmniGPT "has not publicly acknowledged the breach or issued an official statement." We found no later confirmation. Forcepoint's analysis was framed as applying "regardless of whether the alleged OmniGPT breach occurred."
Timeline
| Date | Event |
|---|---|
| 27 January 2025 | KrakenLabs flags Gloomer's claim to have breached OmniGPT. |
| 9 February 2025 | The data is posted on BreachForums, according to CyberInsider. |
| 13 February 2025 | CyberInsider and SecureWorld report the claim; OmniGPT has made no public statement. |
| 5 March 2025 | Forcepoint publishes an analysis of the alleged breach as a lesson in generative AI data risk. |
How it happened: the identity attack path
- Users share secrets with AI. Users pasted API keys and credentials into chats or uploaded files containing them, according to the claim.
- The platform stores everything. Conversations and uploaded files were retained on OmniGPT's systems.
- Alleged intrusion. The actor claims to have accessed those systems; how is not disclosed.
- Data offered for sale. Messages, contact details and file links were offered on BreachForums.
- Credential harvesting. Forum users showed interest in extracting credentials from the conversations.
Impact
- Claimed: 34 million chat messages, about 30,000 email addresses (some with phone numbers) and more than 6,000 file links.
- Secrets at risk: API keys, login credentials and billing information that users shared with the chatbots, if the data is genuine.
- Confirmation: none from OmniGPT at the time of reporting.
What this means for NHI governance
People paste API keys into AI assistants all the time: to debug a failing request, to review a configuration file, to ask why an integration returns an error. Each time, the key is copied into a third party's storage, alongside the conversation, and usually stays there. An AI aggregator adds another layer, holding conversations that may also be sent to several model providers. If any of those stores is breached, every key ever pasted into it is exposed at once.
For organisations, the lesson is to treat AI tools as a place secrets can leak to, just like a public repository or a ticketing system. That means scanning and blocking secrets before they reach AI tools, approving which AI services employees may use, and rotating any key that has been shared with a service that is later breached. See our Shadow AI Discovery Guide, Secrets Management Guide and API Key Management Guide.
Recommendations
- Do not paste secrets into AI tools. Redact API keys and credentials before sharing code or logs, and use secret scanning or data loss prevention on AI traffic. See our Secrets Management Guide.
- Rotate keys shared with a breached service. If you used OmniGPT or a similar tool and shared keys, revoke and reissue them. See the Leaked Credential Response Playbook.
- Know which AI tools are in use. Discover unapproved AI services and steer users to approved ones. See the Shadow AI Discovery Guide.
- Scope and expire API keys. Short-lived, narrowly scoped keys limit the damage when one leaks. See the API Key Management Guide.
- Assess AI vendors before use. Check data retention, encryption and breach disclosure practices. See the AI Security Platform Buyer's Guide.
Frequently asked questions
Was OmniGPT breached?
A threat actor called Gloomer claimed in January and February 2025 to have breached OmniGPT and offered its data for sale. OmniGPT had not publicly confirmed or denied the breach at the time of reporting, so it remains a claim.
What data was in the alleged OmniGPT leak?
According to the actor and press reports, 34 million user chat messages, about 30,000 email addresses, some phone numbers and more than 6,000 links to uploaded files, some containing API keys, credentials and billing information.
Why are API keys in chat logs a risk?
Keys pasted into AI tools are stored with the conversation. If the provider is breached, those keys are exposed and can be used to access the services they unlock until they are rotated.
Related NHI Mgmt Group resources
DeepSeek Database Exposure 2025 · Azure OpenAI Abuse 2025 · Shadow AI Discovery Guide · Secrets Management Guide · API Key Management Guide
How NHI Mgmt Group can help
Secrets now leak through AI tools as well as code and tickets. We help teams find which AI services hold their credentials, stop secrets reaching them and respond when a provider is breached. See our NHI and AI agent security training.