AI chatbots have become a daily utility for millions of users, holding everything from work documents to personal queries. But like any online service, accounts on platforms such as ChatGPT, Claude, and Perplexity are vulnerable to hackers who steal passwords or exploit session tokens. In August 2026, with AI platforms increasingly integrated into workplace workflows, a compromised account can expose far more than a chat history.
TechCrunch’s cybersecurity desk has put together a practical guide to identifying unauthorized access on the three most popular AI platforms. The core advice remains consistent across all services: use unique passwords stored in a password manager and enable multi-factor authentication (MFA) wherever possible. However, each platform handles security differently, and knowing the specifics can save you from a prolonged breach.
Also read: Amazon is buying and destroying rare books to train its AI models
ChatGPT: Reviewing Active Sessions and Resetting Your Password
OpenAI’s ChatGPT offers a straightforward way to audit your account. On a desktop browser, click your username in the bottom-left corner, address to Settings, then Security and Login, and finally select Active Sessions. This screen displays every device currently logged into your account, along with location and browser details.
If you spot a device you don’t recognize, you can terminate that single session directly from the list. For a more thorough cleanup, the Log out all button ends every session at once, forcing all devices to re-authenticate.
Also read: Groq Raises $350M to Accelerate Neocloud Pivot After Nvidia Licensing Deal
Changing your password requires a full logout first. On the ChatGPT login page, enter your email, click Forgot password, and then Continue. OpenAI will send a six-digit code to your inbox. Enter that code on the login page, and you’ll be prompted to set a new password. The email also contains a direct reset your password link with official instructions.
Claude: No Passwords, but Session Controls Exist
Anthropic’s Claude takes a different approach to authentication. Instead of passwords, the platform relies on email-based magic links for every login. This means there is no password to steal, but it also means your email account becomes the single point of failure.
To check for suspicious activity in Claude, open the platform in your browser, click your username in the bottom-left corner, go to Settings, and then Account. The Active sessions section lists all currently logged-in devices. Hover over any unfamiliar session, click the three vertical dots on the right, and choose Log out or Terminate. A global Log out of all devices option is also available for complete resets.
Because Claude doesn’t use passwords, securing the account means securing the associated email address. Enabling MFA on your email provider is the most effective way to prevent an attacker from receiving those login links in the first place.
Perplexity: A Blunter Security Approach
Perplexity, the AI-powered search engine, does not offer a session management interface. Users cannot see where they are logged in, which makes detecting a breach more difficult. The platform’s recommended response is a forced global logout.
In your browser, click your username in the bottom-left corner, then All settings, and select Sign out of all sessions. Confirm the action, and every device will be disconnected. To regain access, enter your email address on the login page, and Perplexity will send a unique six-digit code. Enter that code on the site, or click the Sign in button in the email to authenticate directly.
This blunt approach is effective but inconvenient, especially if you use Perplexity across multiple devices. Users who frequently switch between work and personal devices may want to log back in only on trusted machines after a forced reset.
What to Do After Securing Your Account
Once you’ve regained control of your account, take steps to prevent a repeat breach. Beyond enabling MFA where available, review any connected third-party apps or API keys. On ChatGPT, for instance, check whether any external services still have access tokens that may have been compromised during the intrusion.
It’s also worth examining your chat history for signs of tampering. Attackers who gain access to an AI account often use it to mine sensitive information from past conversations, including proprietary code, financial details, or personal data. If you find evidence of exfiltration, consider notifying your organization’s security team if the account was used for work purposes.
For users concerned about long-term security hygiene, the Federal Trade Commission’s guidance on identity theft recovery applies equally to AI accounts: document the breach, change credentials, and monitor for unusual activity in the weeks that follow. As AI platforms continue to expand their features — from file uploads to voice interactions — the attack surface will only grow, making routine security audits a necessary habit.

Be the first to comment