Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Change the exposed password now, then end other ChatGPT sessions and check for activity you did not recognize. If you reused that password elsewhere, replace it on those accounts too. Start from a known official ChatGPT or OpenAI Help Center address—not a link from the fake site or a suspicious message.

1. Change the password—or secure the sign-in provider

OpenAI advises changing a password right away if it may have been exposed. Use a new, unique password; a password manager can help generate and store one. OpenAI’s steps are in its password-change guide.

If you sign in with an OpenAI email and password

  1. Go to the official ChatGPT site by typing its address yourself or using a bookmark you trust.
  2. If you are signed in, open Settings → Account and update the password.
  3. If you cannot access the account, open a private browser window, choose Log in, enter your account email or phone, then select Forgot password? and follow the reset email.

A password change applies across your OpenAI account, including the API Platform.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you use Google, Microsoft, or Apple to sign in

Continue signing in through the same provider. If you entered that provider’s password on the fake site, change it through that provider’s official account recovery process and secure that account. A ChatGPT password reset may not be available for an account created through social sign-in; OpenAI’s password guidance explains this distinction.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

2. Change reused passwords on other accounts

If the exposed password was also used elsewhere, change it on every account where it appeared. Prioritize your email account and any other account that can be used to reset passwords. The FTC recommends changing reused passwords and using unique passwords for accounts (FTC guidance on protecting personal information).

3. Log out other sessions and inspect security history

  1. In ChatGPT, go to Settings → Security and login → Log out of all devices.
  2. Review Security history for sign-ins or security changes you did not make.

OpenAI says a password change and a manual all-device logout can each take up to 30 minutes to complete. Security-history location and device details may be approximate or unavailable, so use them as clues rather than definitive proof that an event was—or was not—you. See OpenAI’s compromised-account guidance.

Rank #2
Sale
Password Safe
  • Requires 3 "AAA" batteries (included)
  • Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs

4. Turn on multifactor authentication

After changing the password and logging out other sessions, enable a second sign-in factor in Settings → Security. Depending on your device, country, account tier, and sign-in method, OpenAI may offer an authenticator app, push prompt, text or WhatsApp code, or passkey; available choices can vary. MFA adds a barrier to later sign-ins, but enabling it does not end sessions that are already active. OpenAI describes the available options in its MFA guide. CISA also explains why MFA helps protect accounts when passwords are compromised (CISA guidance).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

5. Get help if you see unauthorized activity or cannot get back in

If you find unfamiliar activity, account details have changed, or you cannot regain access, contact OpenAI Support through a new chat in the official Help Center or use OpenAI’s unauthorized-activity guidance. Do not use contact links supplied by the suspicious site.

If you use the OpenAI API

If you also suspect an API key was exposed, delete that key in the API key dashboard, review API usage for activity you do not recognize, and contact Support if needed. This is a separate precaution for API users; entering a ChatGPT password alone does not establish that an API key was exposed.

Rank #4
Yubico - YubiKey Bio C (FIDO Edition) - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C, Biometric, FIDO Certified - Protect Your Online Accounts
  • FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
  • SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
  • DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
  • DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
  • Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)

6. Take additional steps only if you shared more than a password

  • You entered payment details: Contact the card issuer using the number on the card or its official app. The FTC recommends contacting the issuer if you gave payment information to a suspected scam site (FTC guidance for people who were scammed).
  • You downloaded a file or app, or suspect malware: Avoid opening it again and run a scan with legitimate, updated security software. Password entry by itself does not show that your device is infected; the FTC’s phishing guidance covers suspicious links and attachments.
  • You received a phishing email or text: You can report an email to reportphishing@apwg.org, forward a phishing text to SPAM (7726), or report it to the FTC at ReportFraud.ftc.gov. Secure your account first.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.