Desk live·
ForensicPost
AI/AI/File 23-0324

OpenAI Says a Redis Client Bug Showed Users Other People’s Chat Titles

For nine hours some ChatGPT users could see titles from strangers’ conversation histories, and a fraction of paying subscribers had partial billing details exposed to other users. Nobody attacked anything — a caching library returned the wrong data under load.

Constructed geometry · not a chart of case data
TargetOpenAI
ActorUnattributed
D. Kennedy9 min readConfidence: high2 sources reviewed

OpenAI took ChatGPT offline on 20 March 2023 and published an account on 24 March. The cause was a bug in the redis-py open source client library, surfaced by a change OpenAI had made that caused a spike in request cancellations.

The effect was that connections could return data belonging to another user. Titles from active users’ chat histories became visible to others, and OpenAI stated the bug may have exposed payment-related information for 1.2% of ChatGPT Plus subscribers active during a nine-hour window — first and last name, email address, payment address, card expiry and the last four digits of a card number. Full card numbers were not exposed.

The Failure Was In A Dependency

Nothing here was malicious and nothing was misconfigured in the sense the corpus usually means. A library behaved incorrectly under a load pattern the deploying organisation had just changed.

The corpus records dependency failure as its own category at 25-0717 and 25-0711, but both of those were deliberate compromises. This is the accidental version, and it is the more common one: most software fails because something underneath it did, not because somebody attacked it.

Chat Titles Are Content

A conversation title is generated from what the conversation is about. Seeing a stranger’s titles is not metadata leakage in any comforting sense — it is a list of the things that person asked a machine in private.

This is the earliest file in this database concerning a consumer AI service, and it sets the pattern the corpus returns to at 26-0303, where an assistant disclosed internal pricing, and at 26-0509 on instruction and data sharing a channel. The novel data type arrived before anyone had a category for it.

Published Quickly, In Detail

OpenAI took the service down, published a technical account naming the library and the change that triggered it, and quantified the exposure to a percentage and a time window.

The corpus notes at 25-0924 and 23-1220 that the files it can write well are the ones where somebody published specifics. This is a small incident with an unusually good record, and the second half is why it is worth a file at all.

How we reported this

Built on OpenAI’s own published account of the 20 March 2023 outage and on contemporaneous reporting of it. The redis-py bug, the cancellation spike, the nine-hour window, the 1.2% figure and the enumerated payment fields are OpenAI’s own. No count of affected individuals is asserted: OpenAI published a percentage of active subscribers in a window rather than a number, and this desk does not convert one into the other. No claim is made that any data was retained or misused by anyone who saw it. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. March 20 ChatGPT outage: Here’s what happenedOpenAI
  2. OpenAI Reveals Redis Bug Behind ChatGPT User Data Exposure IncidentThe Hacker News
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary