Signs Your ChatGPT Account Is Hacked (and How It Happens)

The signs your ChatGPT account is hacked are usually quiet: chats you never wrote, a plan you never bought. Here is how infostealers take AI logins, why MFA misses it, and what to check first.

Published: Aug 20, 2026

9-13 mins

By Grace

The signs your ChatGPT account is hacked are rarely dramatic. There is no ransom note and no locked screen, just a conversation sitting in your history that you know you never had. Scroll through the AI subreddits and the same post appears every week: someone finds chats written in a language they do not speak, someone else discovers a paid plan they never bought, and one person only noticed after logging in for the first time in six months.

The reflex is to assume OpenAI got breached. Usually it did not. In most of these cases the account was fine and the device was not.

I opened my own before writing this section. Three sessions, all mine, all from the same city, so nothing alarming. What did surprise me was the third row: a browser session from May 29, still signed in nearly three months later. Not a break-in, just a door I had left open and forgotten about, which is the more common version of this problem.


The signs your ChatGPT account is hacked, and the false alarms

Account takeover on an AI tool looks nothing like a bank alert. It is quiet, and plenty of the posts describing one turn out to have an explanation that is not a takeover. The catch is that you cannot tell which from the symptom, so the table below gives you the candidates and the check that separates them rather than a verdict.

What you notice Candidate explanations What settles it
Chats in a language you do not speak Someone else using the account, or a shared device, or a session you forgot you left signed in Active sessions, looking for a device or location you do not recognise
A paid plan you never bought A takeover being monetised, or a shared payment method, a family plan, an app-store subscription Your billing history and which payment method was charged
A sudden ban for “suspicious activity” Someone else’s abuse on your account, an automated false positive, or something you did trip Active sessions first, because an appeal will not hold if the attacker is still in
A password reset email you did not request Your address is on a list and someone is probing, not necessarily inside yet Whether anything else changed; a probe on its own leaves no other trace
The model seems to remember a different person Usually memory or context behaving oddly Check sessions anyway before settling on the bug explanation
Chats you deleted still showing up Usually sync or display lag Same check, since someone holding a live session can also be creating chats

The last two are the ones people panic about most and the ones most often explained by the product rather than an intruder. Do the session check anyway. It costs thirty seconds and it is the only step that distinguishes a bug from company.


How attackers get in without your password or 2FA

Here is the part that surprises people who did everything right. You can have a strong, unique password and two-factor authentication switched on, and still lose the account without either one being defeated.

When you log in, the service checks your password, checks your second factor, and then hands your browser a session cookie: a long random string that means “this browser already proved who it is.” Requests after that ride on the cookie rather than on your credentials. A service can still force a fresh check, when the session expires or when something about the request looks wrong, but in the ordinary case your password and your authenticator app are not consulted again.

Infostealer malware goes straight for that cookie. Families like Lumma, RedLine, Raccoon, and Vidar are built to sweep a browser’s saved credentials and session state, package them into a log file, and ship it out within minutes of infection. This used to be trivial, because the browser would decrypt a stored cookie for any process running as you. Chrome closed that route in version 127 with App-Bound Encryption, which ties decryption to a service running at system privilege. Then the stealers adapted: within months, working bypasses were shipping in Lumma, Vidar, StealC and several others. Read the protection as raising the cost rather than removing the risk, and note that it is Chrome on Windows specifically, so how much it helps depends on your browser and platform.

How infostealers bypass login: the user signs in with a password and a two-factor code, the browser receives a session cookie, malware copies that cookie, and the attacker replays it to skip the login entirely

Stolen cookies do not defeat two-factor authentication. They skip past the login step where two-factor would have been checked.

That is why “I changed my password and it happened again” is such a common follow-up post. The reset is not the useless step it gets described as: OpenAI’s own security guidance is that to block someone already in your account you should “reset your password first, and then enable MFA.” What a reset does not touch is the malware still sitting on the device, waiting to take the new password as soon as you set it. The order of the steps below is doing more work than any single step in it.


Where stolen ChatGPT accounts get sold

They end up in the same commodity marketplaces as everything else, and the volume is no longer small.

When Group-IB first reported on this in June 2023, it had identified 101,134 stealer-infected devices holding saved ChatGPT credentials, found in logs traded over the previous twelve months. Most of those logs came from a single stealer family, Raccoon. The 2026 X-Force Threat Intelligence Index, published in February 2026, reports that during 2025 more than 300,000 ChatGPT credential sets were advertised on the dark web, driven largely by infostealer operators who had added AI services to their target lists.

Note the two units before you compare them: Group-IB counted infected devices, IBM counted credential sets on sale. The direction is the useful part, not the arithmetic. IBM’s own conclusion is about what happens next rather than the volume, and it is that password reuse across personal and enterprise accounts opens indirect attack paths, where a low-value consumer login is used to reach high-value enterprise access.

Which raises a fair question. Why would anyone want your AI login? Some buyers just want free access to a paid tier. The more interesting motive is the history. An AI account is a searchable archive of whatever its owner has pasted into it, and people paste things into chatbots they would never put in an email: contracts, client lists, incident details, half-finished code with keys still in it. The account is not the prize. The transcript is.


What to do if your ChatGPT account is hacked, in order

Most recovery advice fails because people run the steps in the wrong sequence. If malware is still resident on the machine, resetting the password just hands the attacker a fresh one.

  1. Clean the device first. Run a real anti-malware scan on the machine you use ChatGPT from. Until that is done, everything below is temporary.
  2. Invalidate the sessions, not just the password. In ChatGPT, open Settings, then Security and login, then Active sessions, and choose “Log out of all sessions.” OpenAI’s help article names that middle menu simply “Security,” so if you are following their steps and cannot find it, look for “Security and login” instead. OpenAI rolled this panel out on June 2, 2026, and it shows each first-party session with the device, approximate location and sign-in time, so you can see what is connected before you clear it. The confirmation button reads “Log out of all devices,” it signs out your current session too, and OpenAI says the process may take up to 30 minutes. Two limits to know. The panel covers first-party OpenAI sessions only, so third-party apps, connected apps and Codex CLI sessions are not listed. And it is not available at all on accounts linked to an organization’s SSO sign-in.
  3. Then change the password, and confirm it is not reused anywhere else.
  4. Re-enroll two-factor authentication rather than assuming the existing enrollment is still clean.
  5. Check the email account behind it. If the way in was your inbox, fixing ChatGPT alone changes nothing.
  6. Read your own chat history and write down what a stranger would have learned from it. Everyone skips this step, and it is the one that actually tells you how bad the incident was.
The ChatGPT Settings Security Active sessions panel listing signed-in devices with the log out of all sessions control

The Active Sessions panel is the fastest way to see whether anyone else is currently holding a valid session on your account.


When a hacked personal account holds work data

For most people this is an annoying afternoon. If you are also the person who signs off on security, it is something else, because the exposure is not the subscription. It is everything anyone at your company has typed into a personal AI account that nobody is monitoring.

A compromised personal ChatGPT login is a data incident wearing a consumer disguise. There is no admin console showing you it happened, no alert, and no log to pull. If your team is using personal AI accounts for work, one infostealer on one laptop can export months of that work to a stranger without anything reaching you. Someone might still catch it, through a charge they did not make or a session they do not recognise, but the catching is left entirely to the individual, and they have to think to look. That is the practical cost of shadow AI at work: you cannot respond to a breach inside a system you did not know was holding your data.

My own rule is narrow: chat history stays off. It costs me the convenience of scrolling back to find something I wrote last week, and I think that is a fair trade. Turning history off protects nothing about the conversation I am having right now, and it does nothing about malware that has already taken the cookie. What it does is limit how much a stranger inherits if that day ever comes.


FAQ

Q

Does changing my ChatGPT password log out whoever is in my account?

It should, and this gets misreported often enough to be worth stating plainly: OpenAI’s guidance for blocking someone already in your account is to reset the password first, then enable MFA. Do not lean on it alone, though. OpenAI documents “Log out of all sessions” as the explicit control for ending every signed-in device, and says that can take up to 30 minutes to propagate. Run both, and clean the machine before either, because if the malware is still resident the new password goes the same way the old one did.
Q

Can my ChatGPT account be hacked if I sign in with Google?

Yes, in two different ways. If your Google account is compromised then everything you signed into with it goes too, which makes that account a single point of failure. Separately, session cookie theft works the same regardless of how you originally authenticated, because the stolen cookie is issued after login and does not care which provider verified you.
Q

Why did OpenAI ban my account for suspicious activity I did not do?

This is a common outcome of an undetected takeover: someone else used your account in ways that broke the usage policies, and the enforcement landed on you. Before filing an appeal, check active sessions and scan the device, because an appeal will not hold if the attacker still has access. Say plainly in the support request that you believe the account was compromised.
Q

Was my account affected by the OpenAI data breach?

The November 2025 incident was a breach of Mixpanel, a third-party analytics vendor OpenAI used on its API platform, not of OpenAI’s own systems. It exposed contact metadata such as names, email addresses, approximate city-level location, and browser and operating system details. It reached API platform users, and, per a clarification OpenAI added in December 2025, a limited number of ChatGPT users who had filed help center tickets or signed in to platform.openai.com. OpenAI stated that no chats, passwords, credentials, API keys or payment details were exposed, and confirmed separately that session and authentication tokens were not affected, which is the part that matters if you are reading this page about stolen cookies. OpenAI has since terminated its use of Mixpanel.
Q

Should I delete my ChatGPT chat history to be safe?

Deleting history reduces what a future intruder can read, so it helps going forward, but it does not undo an exposure that already happened. If you suspect a compromise, review the history before deleting it so you know what was at risk. For work use, the more durable fix is not pasting sensitive material into a personal account in the first place.

Sources

The two volume figures count different things and are not a like-for-like series: Group-IB counted stealer-infected devices holding ChatGPT credentials over June 2022 to May 2023, while IBM counted credential sets advertised on the dark web during 2025. Product behaviour described here reflects OpenAI’s documentation as of August 2026 and can change.

Written by Grace

I test AI tools and agents in my own workflow, and write down what I find, including the settings that surprised me. About Grace and how posts are verified

Leave a Comment