In partnership with

AI Spotlight — Someone Else Might Be Reading Your ChatGPT History
AI SPOTLIGHT

Someone Else Might Be Reading Your ChatGPT History

Over 100,000 stolen AI chatbot logins are already circulating on dark web marketplaces. Here's exactly where to check yours.

📖 4 minute read
Padlock icon overlaid on a laptop screen representing account security

Welcome Back,

Just like any other online service, hackers can target and break into your accounts on popular AI platforms such as ChatGPT, Claude, and Perplexity, according to TechCrunch's Lorenzo Franceschi-Bicchierai. It's an obvious point once you hear it, and an easy one to overlook, most of us think about account security for banking and email, far less for the AI chatbot we've been pasting years of personal and professional context into.

That risk isn't hypothetical. A separate report cited by Technology Org found 101,134 infected devices holding saved chatbot logins circulating on dark web marketplaces, with volume peaking at 26,802 in a single month. Criminals have clearly worked out the value of these accounts.

Today we look at the exact, step-by-step way to check for suspicious logins on ChatGPT, Claude, and Perplexity, why Claude's login system works completely differently from the other two, and why the email inbox behind all of these accounts might be the single most important thing to secure first.

📌 In Today's AI Spotlight

  • The exact click path to check active sessions on ChatGPT and Claude.
  • Why Claude has no password, and what that means for you.
  • How to handle Perplexity, the one platform that shows you nothing.
  • Why your email inbox matters more than any single AI account.
  • Our AI Spotlight take on why this check takes five minutes and is worth doing today.

🔍 ChatGPT: Check Your Active Sessions First

To find out if someone has broken into your ChatGPT account, open it on your computer's browser, click on your username in the bottom left corner, go to "Settings," then "Security and Login," and finally click on "Active Sessions." You'll see every device currently logged into your account, if anything looks unfamiliar, you can log out of that single device, or click "Log out all" to clear everything at once.

If you want to change your password after that, you'll need to log out of your account first. On ChatGPT's website, click "Log in" in the bottom-left corner, enter your email address, click "Forgot password," then "Continue." ChatGPT will send you an email containing a six-digit code, enter that code on the login page, click "Continue," and then set a new password.

"ChatGPT and Perplexity offer MFA. Claude doesn't, because instead of asking for a password, Anthropic's AI chatbot sends a login link to your email address."

— Lorenzo Franceschi-Bicchierai, TechCrunch

That MFA distinction matters, ChatGPT and Perplexity support multi-factor authentication, meaning even a stolen password alone isn't enough to get in if you've turned that extra layer on. Take a moment to check your ChatGPT security settings for that option if you haven't already enabled it.

Security settings and login screen on a computer

ChatGPT's "Active Sessions" page shows every device currently signed into your account.

🔑 Claude: The Platform With No Password to Steal

Claude's approach is genuinely different from ChatGPT's. To check it, open Claude in your computer's browser, click your username in the bottom-left corner, then "Settings," and click "Account." That's where you'll find your "Active sessions." If you don't recognize one of them, hover over it, click the three vertical dots that appear on the right, and click "Log out" or "Terminate." You can also click "Log out of all devices" to clear everything at once.

💡 AI Spotlight Take

Claude doesn't allow you to use passwords at all, so there's nothing to reset. Once you log back in using your email address, you'll receive a link to sign in directly. That design genuinely removes one entire category of risk, a stolen or reused password simply can't be used against your Claude account, because there's no password in the first place.

That doesn't make Claude immune to compromise, though, it just shifts the attack surface entirely onto your email inbox. If someone can access the email address tied to your Claude account, they can request that same login link themselves. Which brings us to the part of this story that matters more than any single platform's settings menu.

Stop letting busywork get in the way of selling

Researching accounts. Building lists. Writing sequences.

There's a better use of your team's time.

Apollo is the AI revenue engine that handles the busywork, so you can stay focused on selling.

Plus, everything you need is in one place:

  • 230M+ verified contacts

  • AI-powered outreach

  • Data enrichment

  • Inbound lead capture

  • Meeting scheduler

  • And more

Stop doing busywork and start building pipeline, faster.

With Apollo — the AI revenue engine powering 4M+ users.

AI Spotlight — Someone Else Might Be Reading Your ChatGPT History Part 2

🕵️ Perplexity: The Platform That Shows You Nothing

Perplexity handles this differently than either of the other two, and honestly, less transparently. The AI-powered search engine does not show you where you are logged in, there's no list of active devices to review at all.

Compromised AI Accounts, By the Numbers

101,134

infected devices found holding saved chatbot logins on dark web markets

 

26,802

peak volume of stolen logins found circulating in a single month

 

3

major AI platforms covered in TechCrunch's security guide

So if you're worried someone may have broken into your account, go to Perplexity in your browser and click your username in the bottom-left corner, then "All settings." Finally, click on "Sign out of all sessions," and then "Confirm." At that point, you can log back in by entering your email address, you'll then receive an email with a unique six-digit code. Enter the code on the website to log in, or click the "Sign in" button in the email to log in directly.

Person reviewing account settings and security options on a laptop

Perplexity's blanket sign-out is a blunt tool, since it can't show you which specific devices are logged in beforehand.

📧 Your Inbox Is the Real Front Door

Every one of these recovery flows, ChatGPT's six-digit code, Claude's login link, Perplexity's six-digit code, lands in the same place, your email inbox. That makes the mailbox attached to these accounts the single most valuable target in the entire chain.

Securing a chatbot account while the associated inbox stays weak achieves very little.

That's a genuinely important reframe. It's tempting to think of "checking if my ChatGPT account was hacked" as an isolated task specific to that one app. In practice, it's downstream of a much more fundamental question, is my email account itself secure, since anyone who controls that inbox can reset or log into essentially every AI platform tied to it.

The baseline advice holds regardless of platform, use a different, unique password for every service, store them in a password manager, and turn on multi-factor authentication wherever it's offered. The industry is gradually moving toward passwordless sign-in built on device-bound credentials, which removes the reusable secret entirely, but most AI platforms, and most of the internet generally, haven't fully arrived there yet.

✅ The Five-Minute Checklist

Pulling this together into something you can actually act on right now, before you finish reading this newsletter.

Do This Today

⚠️  Check ChatGPT's Active Sessions under Settings → Security and Login
⚠️  Check Claude's Active Sessions under Settings → Account
⚠️  If unsure about Perplexity, just sign out of all sessions from All Settings
⚠️  Enable multi-factor authentication on your email account first, since it protects everything downstream

None of these steps require technical expertise, and none take more than a couple of minutes per platform. That's genuinely the whole point, this isn't a task that needs to be scary or complicated, it's a habit worth building the same way you'd periodically check your bank statement.

Two-factor authentication code entry on a smartphone

Multi-factor authentication on your email account is the single highest-leverage step, since it protects every downstream recovery flow.

🧠 AI Spotlight Analysis

The most useful thing about this story is how ordinary it treats AI accounts, exactly like any other online service, subject to the exact same hygiene practices as your bank or your email. That framing is a genuinely healthy corrective to how casually a lot of people, understandably, treat AI chatbots as low-stakes tools rather than accounts holding years of personal conversations, work drafts, and sensitive context.

Claude's no-password design is a small but genuinely interesting glimpse of where account security is generally headed, removing the reusable secret that gets phished, leaked, or reused across sites. It's not a complete solution on its own, since it just relocates the trust to your email, but it does eliminate one specific, very common attack vector entirely.

💬 Quote of the Week

"Just like any other online service, hackers can target and break into your accounts on popular AI platforms."

— Lorenzo Franceschi-Bicchierai, TechCrunch

That plainly stated fact is really the whole story. AI platforms have quietly become another category of account worth genuinely protecting, right alongside email and banking, and the good news is the actual defensive steps are quick, specific, and already sitting inside settings menus you've probably never opened.

💡 Final Thoughts

With over 100,000 stolen chatbot logins already circulating on dark web marketplaces, this isn't a theoretical worry, it's an active, ongoing market. The good news is that checking your exposure across ChatGPT, Claude, and Perplexity takes a matter of minutes, and each platform gives you a clear, if imperfect, way to see or clear suspicious access.

The bigger lesson underneath the specific click-paths is that your email inbox is the actual perimeter here, not any individual AI account. Strengthen that first, unique password, multi-factor authentication turned on, and every AI platform downstream of it gets meaningfully safer as a result.

Have you ever checked your ChatGPT or Claude account for logins you didn't recognize? Hit reply, we read every response.

🔗 Sources and Further Reading

TechCrunch: How to tell if your AI platforms' accounts have been hacked
Technology Org: How to Tell If Your AI Account Was Hacked

❤️ Enjoying AI Spotlight?

If today's edition helped you lock down an account you'd never thought to check, consider sharing it with a colleague, founder, or friend interested in technology.

Share AI Spotlight →

Thanks for reading AI Spotlight.

Our mission is simple: deliver clear, trustworthy, and actionable AI insights that help professionals stay ahead without the hype.