How to tell if your AI platform account has been hacked

AI chat apps have become an ordinary part of daily life, with users sharing everything from work emails to personal health questions, financial planning and private journal entries with these tools. That makes accounts an increasingly valuable target for attackers.
Unlike a compromised email or social media account, a hijacked AI account often poses a threat that's harder to notice right away. Rather than immediately posting or messaging something, an attacker can quietly comb through past conversations, harvesting password hints, financial information or personal details.
Specialists say the first place to check is the account's 'login history' or 'active devices' section. Most major AI platforms list recent devices, browsers and approximate locations used to sign in from the account settings menu; an unfamiliar device or an unexpected geographic location can be an early sign of compromise.
A second warning sign is finding conversations, searches or generated content in the account's activity log that you didn't create yourself. Several platforms offer a detailed activity history letting users review their own past usage, and checking it regularly can help catch unusual behaviour early.
Third, unexpected password reset emails or 'sign-in attempt' notifications arriving at the email address linked to the account are also worth investigating. Attackers often try resetting a password before taking over an account, and even failed attempts can leave a trace in your inbox.
Linked payment methods are another area worth checking. Unfamiliar charges or unexpected plan upgrades on credit card statements tied to an AI subscription can indicate the account is being used without your knowledge.
If you suspect your account has been compromised, specialists recommend changing the password immediately as a first step, and enabling two-factor authentication if it isn't already active. Two-factor authentication blocks most unauthorized access attempts that rely on password knowledge alone.
After changing the password, logging out of all other active sessions and devices tied to the account is also an important step. Most platforms offer a 'log out of all devices' option in their settings menu, cutting off an attacker's access immediately.
Specialists also advise against reusing the same password across multiple platforms, recommending unique, strong passwords especially for email and AI accounts. A password manager can make that practice easier to maintain.
Finally, if a compromise is confirmed, it's advisable to report it to the platform's support team and to change any sensitive information — passwords, financial details, private documents — that was shared elsewhere too, since information disclosed in an AI conversation can end up in an attacker's hands and be used to target other accounts as well.
Read next

What is MCP, and why does it matter that 21,000 servers were exposed
The Model Context Protocol, an open standard that lets AI assistants connect to outside tools and data, has hit a security inflection point after researchers found more than 21,000 unprotected servers exposed on the open internet. Here's what MCP is, why developers adopted it so fast, and why that exposure matters.

Judge gives Google one week to fix 'anticompetitive' download flow in Google Play
A federal judge has ruled that Google made it unnecessarily difficult for Android users to download alternative app stores, giving the company one week to fix the flow. The order will make third-party app stores more visible and accessible from within Google Play itself.

The world's largest all-electric aircraft flew its first test using just $5 of electricity
A venture backed by commercial airlines has completed the first test flight of what it calls the largest all-electric aircraft to fly, using roughly $5 worth of electricity for the flight. The company's longer-term goal is to develop a hybrid-electric, and eventually fully electric, commercial passenger aircraft.

Every fusion energy startup that has raised over $100 million
Fusion energy startups have collectively raised $7.1 billion to date, with the majority of that money concentrated in a handful of companies. Here's a look at the best-funded fusion startups and how their technical approaches differ.

You can now turn off Google Gemini's visible AI watermarks. Here is what that actually changes
Google now lets users toggle off the visible watermark that normally appears on images, videos and music generated with Gemini and its Nano Banana and Omni models. The invisible SynthID watermark and embedded metadata remain in place regardless, meaning the content stays technically traceable as AI-generated even when it no longer looks that way.