Last week a colleague messaged me in a panic. Someone had logged into her ChatGPT from a city she had never been to, and she had no idea how long they had been there — or what they had read in the meantime. Her first instinct was to delete the account entirely. I talked her down, walked her through the session log, and within ten minutes we had the intruder kicked out and her password rotated.

U.S. Air Force poster about keeping a single device full of personal and work information secure
Image: U.S. Air Force via Wikimedia Commons (Public Domain)

That experience stuck with me, because most people do not know their AI accounts even have a session log. ChatGPT, Claude, and Perplexity have all quietly shipped device-management screens, and the steps to review them are short. TechCrunch published a solid roundup of exactly this on August 15, and I want to give you the same walkthrough — plus what to do after you spot something wrong.

Why your AI account is worth checking

An AI account is not just a chat history. Your ChatGPT workspace can hold uploaded files, custom instructions, and a payment method if you are on a paid plan. Claude carries your conversations and any projects you have built. Perplexity holds your search history and bookmarks. All three are prime targets for credential stuffing and session hijacking, because most people reuse passwords and never look at their logged-in devices.

There is also the less obvious angle: an attacker who gets into your AI account can run up your usage quota, mine your private conversations for context, or quietly exfiltrate anything you have pasted into the chat — the same class of risk as the AI agents that hacked real companies this month — API keys, internal notes, draft documents. That is why the check matters even if nothing has been billed yet.

Before you start: the two habits that make this easier

Use a unique password per platform, stored in a password manager. I know it sounds like boilerplate, but it is the single biggest reason account takeovers spread — one leaked password works everywhere. And turn on multi-factor authentication (MFA) where it exists: both ChatGPT and Perplexity offer it, and it stops most stolen-password logins cold.

Claude is a special case. Anthropic’s chatbot does not use a password at all — it sends a login link to your email instead. That means there is no password for an attacker to steal, but it also means your email inbox is effectively your second factor, so securing that email account matters even more.

Step 1: ChatGPT — review and kill active sessions

Open ChatGPT in your browser and click your username in the bottom-left corner. Go to Settings, then Security and Login, and click Active Sessions. You will see a list of every device and browser currently logged into your account, usually with location and last-active details.

Scan the list for anything you do not recognize — a laptop model you never owned, a city you have never visited, a session that went active at 3 a.m. If you find one, you can log out of that single device right from the list. You can also click Log out all to nuke every session including your own, which is the move I recommend when you are not sure how many devices are compromised.

Once you are logged out everywhere, reset your password. On the ChatGPT login page, click Log in, enter your email, then choose Forgot password and continue. ChatGPT sends a six-digit code to your inbox — enter it, then set a new password. The flow is identical on mobile, so you can do this from your phone while standing in a parking lot, which is honestly how most people end up doing it.

While you are in Settings, open the Security section and enable multi-factor authentication if you have not already. It takes two minutes with any authenticator app, and it turns a stolen password from a disaster into a minor inconvenience.

Step 2: Claude — check active sessions

Claude’s session manager lives under Settings > Account. Open Claude in your browser, click your username in the bottom-left corner, go to Settings, then Account, and scroll to the Active sessions section.

Each session shows the device and browser, an approximate location, and when it was last used. If you see a session you do not recognize, hover over it, click the three-dot menu on the right, and choose Log out or Terminate. Claude’s official documentation confirms the exact same flow, and notes that a terminated session will need to log in again with your email link.

If you are worried about multiple devices, use Log out of all devices instead — it signs out everything and you log back in with your email link. Because Claude is passwordless, there is no password to rotate here; your protection is the email account that receives those magic links, so make sure that inbox is locked down with its own strong login and MFA.

Step 3: Perplexity — no session list, so sign out of everything

Perplexity is the odd one out: it does not show you where you are logged in. You cannot review a session list, so the only way to clear a possible intruder is to sign out of all sessions at once. The official help center describes the option plainly: sign out of every device and browser you are signed in on — useful if a device is lost.

Here is the exact flow: click your username in the bottom-left corner, open All settings, then click Sign out of all sessions and confirm. You will be logged out everywhere, including the device in your hand. Log back in with your email address, and Perplexity sends a unique six-digit code — enter it on the site (or use the sign-in link in the email) and you are back in with a clean slate.

Perplexity also supports SMS-based phone verification on some accounts, which adds an extra layer. If you have never verified a phone number there, it is worth doing now, because it gives you a second signal when someone tries to take over the account.

After you kick the intruder out

Clearing sessions is step one, but a determined attacker leaves fingerprints elsewhere. Do these four things within the hour:

  • Rotate passwords on connected services. If you logged into an AI platform with Google or Apple, change those passwords too — they are the master keys.
  • Revoke API keys. If you ever generated an API key on the platform, delete and regenerate it. Old keys are a favorite backdoor for attackers who get in once.
  • Review payment and usage history. Check for charges you did not make and usage spikes you did not cause. A suddenly active account is a red flag even after you sign everyone out.
  • Scan for unknown connected apps. Some platforms let third-party apps connect to your account. Revoke anything you do not recognize.

Then check your email for suspicious login notifications and password reset attempts. Platforms send these for a reason — if you ignored them before, that is probably when the intruder got in.

Make it a monthly habit

Session checks take about five minutes total across all three platforms, and they belong in the same maintenance routine as clearing browser extensions you no longer trust. I wrote a similar walkthrough for checking malicious Chrome VPN extensions a few days ago, and the principle is identical: your accounts accumulate devices silently, and the ones you do not remember are the ones you should worry about.

If you are already deep into AI-assisted workflows — the kind where an agent can read your prompts and files — which is exactly the Claude Code auto mode question — a stolen account is a bigger deal than a lost chat history. I have been preaching the same habit for auditing MCP servers: anything that can see your secrets deserves a regular audit. Your AI login is the front door to that whole setup, so start there.

Five minutes now beats a week of explaining to your boss how a stranger read your private documents. Check your sessions tonight, set up MFA while you are in there, and you will probably sleep a little better — the same way my colleague did after we found that session and killed it.

Filed under Tech & Gadgets
Last Update: August 16, 2026 by Felix AlterEgo
0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted