ChatGPT, Claude, and Perplexity: How to Detect a Breach of Your Account on AI Platforms and End Suspicious Sessions?
Listen to this article
Read by Anchor
User accounts on generative AI platforms such as ChatGPT, Claude, and Perplexity, face the risk of being hacked and digitally targeted, just like any other service or social network on the internet. As the reliance on these tools increases, the importance of continuously verifying connected devices and closing suspicious sessions becomes apparent, in addition to following basic measures such as using unique passwords through password management programs and enabling multi-factor authentication to prevent unauthorized access, even in the event of a password leak.
The three platforms differ in their security structure and identity verification methods available to users. ChatGPT, owned by OpenAI, and Perplexity allow users to enable multi-factor authentication to protect their accounts from takeover attempts, while Anthropic, the company behind Claude, uses a different model that does not use passwords at all, as the platform sends a direct login link to the user's email, eliminating the need for a password or password reset procedures.
Checking ChatGPT sessionsRequires opening the account via a computer browser, clicking on the user's name in the bottom corner, entering the settings, then the security and login tab, and finally accessing active sessions. This list allows users to see all connected devices, with the option to log out of a specific unknown device or choose to log out of all devices. If a user wants to change their password, they must first log out of the account, then click on log in, enter their email, and press the forgot password option, to receive a six-digit code via email that is entered on the site to set a new password, or use the reset link attached to the message.
Managing connections on the Claude platformIs done by opening the site in the browser, clicking on the user's name in the bottom corner, then going to settings and choosing account to access the list of active sessions. If a unfamiliar session is detected, users can hover over it, click on the three vertical dots on the right, and choose to log out or end the session, or press the option to log out of all devices at once. This allows users to log in again later by requesting a new login link that is sent directly to their email.
Dealing with Perplexity sessionsDiffers from the two previous services, as the search engine does not display a detailed list of devices or locations from which the user has logged in. If users are concerned about their account being hacked, they can log in via the browser, click on the user's name in the bottom corner, open all settings, and press log out of all sessions to confirm the process and expel any unknown access. When logging in again by entering their email, the platform sends a message containing a unique six-digit code to be entered on the site, or a direct link that allows login by clicking on the login button within the message.