technology

Your late-night confession to chatgpt is already weaponized

María Aperador keeps a folder labeled “digital body-bags.” Inside: screenshots of Spaniards who told Gemini their antidepressant dose, then watched the same dosage appear in a phishing email two weeks later. The European Union’s cybersecurity agency ENISA confirms the vector: four out of five phishing lures that land in European inboxes this year are now written by generative models trained on exactly those casual, midnight overshares.

Lo que nadie cuenta es that every whispered secret—bank codes, passport numbers, the ultrasound JPEG you dropped into Copilot—isn’t ephemeral. It’s a frozen asset. OpenAI’s own former researchers warned of the largest intimacy archive ever assembled: billions of conversational snapshots, time-stamped, geolocated, cross-indexed. Once inside, the data is copied across cloud regions faster than you can delete the chat. Aperador’s rule of thumb: if you wouldn’t tattoo it on your forearm, don’t type it.

Sam altman’s blunt prophecy and the 32.7% who ignored it

“The intellectual middle class disappears,” Altman told a closed-door summit in Athens. Translation: either you prompt-engineer the machine, or the machine prompt-engineers you. Eurostat’s freshest numbers show nearly a third of EU citizens already feed daily prompts to large language models; among Greek and Estonian teens the share rockets past 80%. The apps feel like friends, so users treat them like priests. Result: a parallel economy of raw psychological material—panic attacks, bankruptcy fears, revenge fantasies—stockpiled where GDPR can’t reach.

Attackers cash in with two tricks. First, prompt injection: a hidden line of text buried in a shared Notion page forces the bot to vomit previous conversations when the next user asks politely. Second, commodity malware that screenshots your desktop every 30 seconds, shipping the images to a Telegram channel where teenagers bid for dossiers. A Madrid travel influencer learned the fusion last month: her ChatGPT thread about solo itineraries in Morocco became the blueprint for a fake hostel scam that drained €7,400 from her followers.

The five data types that sign your own ransom note

The five data types that sign your own ransom note

Aperador’s blacklist is merciless: mental-health transcripts, banking credentials, government IDs, geotagged plans, personal photos. Each category feeds a different criminal pipeline. Clinical details train deepfake voices for vishing calls; a single IBAN screenshot can be cloned into 200 synthetic checks; passport numbers are minted into NFT bundles on dark markets that clear in under six minutes. Even the viral Ghibli-style selfie you uploaded is reversed, geolocated, and packaged into blackmail letters demanding Bitcoin in exchange for not sending your cartoon face to your employer.

She is unmoved by the argument that “nobody would bother with my boring life.” The average European’s chat history sells for €38. Scrape a million histories and you have a €38 million revenue stream with zero shipping costs. The only winning move is not to play: keep therapy between you and your therapist, banking between you and your bank, and let the bots hallucinate fiction instead of harvesting your facts.

Next time the cursor blinks at 2 a.m., remember the EU’s newest entry in the threat taxonomy: “user-as-vulnerability.” The patch is prehistoric—silence. Close the tab, drink water, talk to a human. Otherwise, your secrets are already in transit, priced per kilobyte and heading east.