Your AI account was hacked: how to tell, and what to do first

Conversations you never had, a charge you did not make, a sign-in code you did not ask for. Here is how to read the signs in ChatGPT, Claude, Gemini, Copilot and Perplexity — and the order of steps that actually gets a stranger out, rather than just changing a password they never needed.

ByNikita Lushpanov· Chief Product Officer ·LinkedIn
Quick answer

The giveaway is conversations in your history that are not yours. If you see them, the cause is almost never a breach at the AI company — it is password-stealing malware on the device you sign in from, and that changes the fix. Scan the device first, then reset the password, then sign out of all devices to kill the session the attacker is already holding, then turn on two-factor authentication and secure the email address behind the account. Afterwards, read your history to work out what you once pasted into it, and revoke every API key and connected app. Changing only the password puts you back here next month.

Where to look, service by service

Every one of these has a page listing the devices currently signed in, and a way to end all of those sessions at once. That is the control that matters most; a password reset on its own leaves an existing session alive.

ServiceWhere the sessions liveWhat else to revoke
ChatGPT (OpenAI)Settings → Security → Log out of all devices, which also lists where the account is currently signed in.API keys on the developer platform, connected apps, and the Plus or Pro subscription on your saved card.
Claude (Anthropic)Settings → Account, where you can sign out of other sessions; sign-in is by emailed code for most people, so your inbox is the real lock.API keys and workspaces on the Console, plus any connectors or integrations you attached to the chat.
Google GeminiThere is no separate Gemini login. Use Google’s Security Checkup — it lists every signed-in device and recent security event on the account.Gmail forwarding rules and filters, third-party app access, and any exports queued through Google Takeout.
PerplexitySettings → Account; sign-in is usually a magic link or a Google login, so check that upstream account too.Your Pro subscription, your search and thread history, and any files you uploaded to a Space.
Microsoft CopilotLike Gemini, it rides on the account behind it: check Microsoft account → Security → Sign-in activity.Outlook forwarding rules, linked devices, and anything Copilot can reach across your Microsoft 365 files.
Character.AIAccount settings; the account is often tied to a Google or Apple sign-in rather than its own password.Your character library and chat history, which is the part people most want back and most want private.
MidjourneyThrough Discord, where the account actually lives — check Discord’s Devices and Authorised Apps lists.The subscription on your card, your image gallery, and the Discord account itself, which is the bigger loss.

Find out what else your email is attached to

One address usually unlocks a long tail of accounts. PersProtect shows which known breaches hold yours, and where your address and phone number are published across 499 broker and people-search sites — then files the removals for you.

Check my exposure — free →

1. The signs worth acting on

Conversations in your history that you did not have — a different language, a subject you have no interest in, a coding question from someone who does not code. A charge or a plan change you did not make. A sign-in code emailed to you while you were doing something else entirely. A session listed on a device or in a country that is not yours. A model usage or rate limit you hit without using it. Any one of these on its own is enough to go and check the device list; none of them is worth waiting to confirm with a second sign, because the account is doing whatever it is doing in the meantime.

2. It was probably your device, not the AI company

The dominant way these accounts change hands has nothing to do with a break-in at OpenAI, Anthropic or Google. It is information-stealing malware, picked up from a cracked download, a fake installer or a malicious browser extension, which reads every password stored in the browser and copies the session cookies sitting beside them, then packages the lot for sale. Chat logins have become a routine line item in those bundles because the accounts carry paid subscriptions. The practical consequence is the whole reason the order below matters: a stolen session cookie lets somebody stay signed in as you regardless of how good your new password is.

3. Do it in this order

Scan the computer or phone you use for the service and remove anything it finds, before touching a password — otherwise the new one is captured as you type it. Then reset the password, using something you have not used anywhere else. Then sign out of all devices, which is the step that kills the attacker’s existing session and the one most people skip. Then turn on two-factor authentication, and save the recovery codes offline. Finally secure the email address behind the account, because on most of these services a password reset is just an email away and the inbox is the real key. Reversing any two of those steps means starting again in a week.

4. Read the history before you delete it

Assume every conversation was read. The job now is to turn that into a list: any password, API key, account number, address, client name or document you ever pasted into a chat needs rotating or watching, and the list is longer than anybody expects because a chat window does not feel like a place where you are typing secrets. Work through it before you clear the history, because once the threads are gone so is your record of what was in them. Then delete what you would not want quoted back at you, and consider turning off training on your conversations while you are in settings.

5. API keys and billing are the expensive part

For anyone who has ever opened the developer side of these platforms, this is where a hijacked account stops being an inconvenience. An API key is a bearer credential: whoever holds it can spend against your account until you revoke it, and usage-based billing means the damage keeps growing quietly rather than showing up as a single charge. Revoke and regenerate every key rather than only the ones you think were exposed, set a spending limit, and check the usage graph for a period that does not match your own work. Do the same for the consumer side — look at the subscription, the payment method on file and any plan upgrade you did not buy.

6. Check what the account is connected to

Modern AI accounts reach outwards: connectors and integrations to your files, your calendar, your repositories, your mail. Those connections outlive a password change and are the quietest way to keep reading someone’s data after being locked out of the front door. Go through the connected-apps or integrations list and remove anything you do not actively use, then do the same on the Google, Microsoft or Discord account behind the service. While you are in the mail settings, look specifically at forwarding rules and filters — the same quiet persistence trick shows up after every kind of account takeover.

Common questions

Hacked AI accounts, answered

How can I tell whether my ChatGPT or Claude account has been hacked?

Look for conversations you did not have. That is the clearest signal and the one people miss, because a stranger using your account leaves threads behind in a language, a subject or a tone that is not yours. After that: a subscription charge you did not make, a plan that changed, a login notification from a country you have never visited, an emailed sign-in code arriving when you were not signing in, or a session listed on a device you do not own. Any one of them is enough to act on. Waiting for a second sign is how a session that could have been killed in a minute lasts a month.

Was the AI company breached, or was it me?

Overwhelmingly the second, and that is not a defence of the companies — it is what determines whether your fix works. Chat accounts are stolen in bulk by information-stealing malware that sits on somebody’s own computer, scrapes every password saved in the browser and the session cookies alongside them, and sells the lot. The credentials then turn up in bundles that get resold for the price of a coffee. It matters because a stolen cookie ignores your new password. If you reset without dealing with the machine, you have handed the thief a fresh one.

What can someone actually do with my AI account?

Read it, mostly, and that is the underrated part. People paste things into a chat window they would never put in an email: contracts, salary numbers, medical symptoms, a rough draft of a resignation, source code, sometimes an API key or a password by accident. The account also carries a subscription on your card, and on the developer side it can carry API keys that bill by usage — a stolen key with no spending limit is the version of this that gets expensive rather than merely embarrassing.

I changed my password and it happened again. Why?

Because the password was never the way in. Two things survive a reset: malware still running on your device, which will take the new password as soon as you type it, and an active session token the attacker already holds, which stays valid until you explicitly sign out every device. Do those in the right order — clean the machine, then reset, then revoke all sessions, then turn on two-factor — and the loop closes. Do them out of order and you repeat it.

Should I delete my chat history?

Read it first, then delete what you would not want quoted. The point of reading it is to build the list of things to rotate: every credential, key, account number or address you ever pasted into a conversation should be treated as known to somebody else, and deleting the thread does not make that untrue. Once you have that list, clearing the history is a reasonable habit going forward, and most of these services also let you turn off training on your conversations in settings.

My AI account signs in with Google or Apple. What do I secure?

The Google or Apple account, first and with priority. Where sign-in is delegated, the AI service has no password of its own to steal — whoever controls the upstream account controls the chat, and everything else that account signs into. Secure it there: sign out unknown sessions, check for mail-forwarding rules and filters somebody may have added quietly, review which third-party apps have access, and make sure two-factor is on with recovery codes saved somewhere offline.

Do these accounts show up in breach checks?

Your email address may well appear in known breach data from any number of services, and that is worth checking. But credentials harvested by malware from your own device usually are not in those datasets at all, because there was no breach of a company to index — the theft happened on your laptop. So a clean result is genuinely good news about breaches and says nothing about stealer malware. Treat the two as separate questions with separate answers.

Locked them out? Now shrink what they could find next time.

See which sites publish your address, phone number and relatives right now — free, in about a minute.

Run a free exposure scan →