The signs your ChatGPT account is hacked are rarely dramatic. There is no ransom note and no locked screen, just a conversation sitting in your history that you know you never had. Scroll through the AI subreddits and the same post appears every week: someone finds chats written in a language they do not speak, someone else discovers a paid plan they never bought, and one person only noticed after logging in for the first time in six months.
The reflex is to assume OpenAI got breached. Usually it did not. In most of these cases the account was fine and the device was not.
I opened my own before writing this section. Three sessions, all mine, all from the same city, so nothing alarming. What did surprise me was the third row: a browser session from May 29, still signed in nearly three months later. Not a break-in, just a door I had left open and forgotten about, which is the more common version of this problem.
The signs your ChatGPT account is hacked, and the false alarms
Account takeover on an AI tool looks nothing like a bank alert. It is quiet, and plenty of the posts describing one turn out to have an explanation that is not a takeover. The catch is that you cannot tell which from the symptom, so the table below gives you the candidates and the check that separates them rather than a verdict.
| What you notice | Candidate explanations | What settles it |
|---|---|---|
| Chats in a language you do not speak | Someone else using the account, or a shared device, or a session you forgot you left signed in | Active sessions, looking for a device or location you do not recognise |
| A paid plan you never bought | A takeover being monetised, or a shared payment method, a family plan, an app-store subscription | Your billing history and which payment method was charged |
| A sudden ban for “suspicious activity” | Someone else’s abuse on your account, an automated false positive, or something you did trip | Active sessions first, because an appeal will not hold if the attacker is still in |
| A password reset email you did not request | Your address is on a list and someone is probing, not necessarily inside yet | Whether anything else changed; a probe on its own leaves no other trace |
| The model seems to remember a different person | Usually memory or context behaving oddly | Check sessions anyway before settling on the bug explanation |
| Chats you deleted still showing up | Usually sync or display lag | Same check, since someone holding a live session can also be creating chats |
The last two are the ones people panic about most and the ones most often explained by the product rather than an intruder. Do the session check anyway. It costs thirty seconds and it is the only step that distinguishes a bug from company.
How attackers get in without your password or 2FA
Here is the part that surprises people who did everything right. You can have a strong, unique password and two-factor authentication switched on, and still lose the account without either one being defeated.
When you log in, the service checks your password, checks your second factor, and then hands your browser a session cookie: a long random string that means “this browser already proved who it is.” Requests after that ride on the cookie rather than on your credentials. A service can still force a fresh check, when the session expires or when something about the request looks wrong, but in the ordinary case your password and your authenticator app are not consulted again.
Infostealer malware goes straight for that cookie. Families like Lumma, RedLine, Raccoon, and Vidar are built to sweep a browser’s saved credentials and session state, package them into a log file, and ship it out within minutes of infection. This used to be trivial, because the browser would decrypt a stored cookie for any process running as you. Chrome closed that route in version 127 with App-Bound Encryption, which ties decryption to a service running at system privilege. Then the stealers adapted: within months, working bypasses were shipping in Lumma, Vidar, StealC and several others. Read the protection as raising the cost rather than removing the risk, and note that it is Chrome on Windows specifically, so how much it helps depends on your browser and platform.

Stolen cookies do not defeat two-factor authentication. They skip past the login step where two-factor would have been checked.
That is why “I changed my password and it happened again” is such a common follow-up post. The reset is not the useless step it gets described as: OpenAI’s own security guidance is that to block someone already in your account you should “reset your password first, and then enable MFA.” What a reset does not touch is the malware still sitting on the device, waiting to take the new password as soon as you set it. The order of the steps below is doing more work than any single step in it.
Where stolen ChatGPT accounts get sold
They end up in the same commodity marketplaces as everything else, and the volume is no longer small.
When Group-IB first reported on this in June 2023, it had identified 101,134 stealer-infected devices holding saved ChatGPT credentials, found in logs traded over the previous twelve months. Most of those logs came from a single stealer family, Raccoon. The 2026 X-Force Threat Intelligence Index, published in February 2026, reports that during 2025 more than 300,000 ChatGPT credential sets were advertised on the dark web, driven largely by infostealer operators who had added AI services to their target lists.
Note the two units before you compare them: Group-IB counted infected devices, IBM counted credential sets on sale. The direction is the useful part, not the arithmetic. IBM’s own conclusion is about what happens next rather than the volume, and it is that password reuse across personal and enterprise accounts opens indirect attack paths, where a low-value consumer login is used to reach high-value enterprise access.
Which raises a fair question. Why would anyone want your AI login? Some buyers just want free access to a paid tier. The more interesting motive is the history. An AI account is a searchable archive of whatever its owner has pasted into it, and people paste things into chatbots they would never put in an email: contracts, client lists, incident details, half-finished code with keys still in it. The account is not the prize. The transcript is.
What to do if your ChatGPT account is hacked, in order
Most recovery advice fails because people run the steps in the wrong sequence. If malware is still resident on the machine, resetting the password just hands the attacker a fresh one.
- Clean the device first. Run a real anti-malware scan on the machine you use ChatGPT from. Until that is done, everything below is temporary.
- Invalidate the sessions, not just the password. In ChatGPT, open Settings, then Security and login, then Active sessions, and choose “Log out of all sessions.” OpenAI’s help article names that middle menu simply “Security,” so if you are following their steps and cannot find it, look for “Security and login” instead. OpenAI rolled this panel out on June 2, 2026, and it shows each first-party session with the device, approximate location and sign-in time, so you can see what is connected before you clear it. The confirmation button reads “Log out of all devices,” it signs out your current session too, and OpenAI says the process may take up to 30 minutes. Two limits to know. The panel covers first-party OpenAI sessions only, so third-party apps, connected apps and Codex CLI sessions are not listed. And it is not available at all on accounts linked to an organization’s SSO sign-in.
- Then change the password, and confirm it is not reused anywhere else.
- Re-enroll two-factor authentication rather than assuming the existing enrollment is still clean.
- Check the email account behind it. If the way in was your inbox, fixing ChatGPT alone changes nothing.
- Read your own chat history and write down what a stranger would have learned from it. Everyone skips this step, and it is the one that actually tells you how bad the incident was.

The Active Sessions panel is the fastest way to see whether anyone else is currently holding a valid session on your account.
When a hacked personal account holds work data
For most people this is an annoying afternoon. If you are also the person who signs off on security, it is something else, because the exposure is not the subscription. It is everything anyone at your company has typed into a personal AI account that nobody is monitoring.
A compromised personal ChatGPT login is a data incident wearing a consumer disguise. There is no admin console showing you it happened, no alert, and no log to pull. If your team is using personal AI accounts for work, one infostealer on one laptop can export months of that work to a stranger without anything reaching you. Someone might still catch it, through a charge they did not make or a session they do not recognise, but the catching is left entirely to the individual, and they have to think to look. That is the practical cost of shadow AI at work: you cannot respond to a breach inside a system you did not know was holding your data.
My own rule is narrow: chat history stays off. It costs me the convenience of scrolling back to find something I wrote last week, and I think that is a fair trade. Turning history off protects nothing about the conversation I am having right now, and it does nothing about malware that has already taken the cookie. What it does is limit how much a stranger inherits if that day ever comes.
FAQ
QDoes changing my ChatGPT password log out whoever is in my account?
Does changing my ChatGPT password log out whoever is in my account?
QCan my ChatGPT account be hacked if I sign in with Google?
Can my ChatGPT account be hacked if I sign in with Google?
QWhy did OpenAI ban my account for suspicious activity I did not do?
Why did OpenAI ban my account for suspicious activity I did not do?
QWas my account affected by the OpenAI data breach?
Was my account affected by the OpenAI data breach?
QShould I delete my ChatGPT chat history to be safe?
Should I delete my ChatGPT chat history to be safe?
Sources
- IBM: 2026 X-Force Threat Intelligence Index
- Group-IB: 101,134 stealer-infected devices with saved ChatGPT credentials
- OpenAI: What to know about a recent Mixpanel security incident
- OpenAI Help Center: Managing active sessions in ChatGPT
- OpenAI Help Center: How can I keep my OpenAI accounts secure? (reset the password before enabling MFA)
- BleepingComputer: infostealers bypassing Chrome’s App-Bound Encryption
- OpenAI: ChatGPT release notes, June 2, 2026
- The Hacker News: Session cookie theft, and why MFA does not stop it
The two volume figures count different things and are not a like-for-like series: Group-IB counted stealer-infected devices holding ChatGPT credentials over June 2022 to May 2023, while IBM counted credential sets advertised on the dark web during 2025. Product behaviour described here reflects OpenAI’s documentation as of August 2026 and can change.