Most reports come from credentials reused from an unrelated breach, or from signing in with a different method and seeing an empty history. Change your password, turn on two factor authentication, sign out of other sessions, and export your history so a lockout cannot cost you the transcripts.
Short answer
Most reports come from credentials reused from an unrelated breach, or from signing in with a different method and seeing an empty history. Change your password, turn on two factor authentication, sign out of other sessions, and export your history so a lockout cannot cost you the transcripts.
Step by step
Look at the conversations you do not recognise: Chats in another language or about unfamiliar topics point at someone else using your login. An empty sidebar usually points at a different sign in method instead, which is not a compromise at all.
Change the password and make it unique: If the same password protects anything else, change it there too. Credential stuffing from old breaches is how nearly all of these happen.
Turn on two factor authentication: Settings, then Security. This is the single change that ends the problem permanently.
End every other session: Signing out of all devices in Settings kicks out anyone still holding a session, which a password change alone does not always do.
Export your history now: Settings, then Data Controls, then Export Data. If you later lose access, or need to delete the account and start clean, that ZIP is the only copy of your conversations.
Check billing: A stolen account is often used for the paid features. Review your subscription and card statement, and contact OpenAI support for charges you did not make.
Before assuming a breach, rule out the three things that look identical from the outside.
The three common explanations
| What you see | Most likely cause | Fix |
|---|---|---|
| Chats you never wrote, often another language | Your password was reused and leaked elsewhere | New password, two factor, sign out all sessions |
| Sidebar suddenly empty | You signed in with Google where you previously used a password, or the reverse | Sign out, use the other method |
| Chats missing but others present | Archived, or deleted from a shared device | Settings, General, Archived Chats |
The second one is extremely common and is not a security incident. Google sign in creates a separate account from an email and password sign in on the same address, so the history simply belongs to the other one.
If someone really did get in
Work in this order: change the password, turn on two factor authentication, sign out of all sessions, then review billing. Only the second step actually keeps them out. Do not skip it and hope a new password is enough, because if the password came from a breach list the next list will have the new one too.
Then read through what they could see. Your chat history may contain drafts, addresses, business details, code and anything else you pasted. Treat it the way you would treat a compromised inbox and assume it was read.
The recovery problem nobody plans for
If you have to delete the account and start fresh, or support locks it during an investigation, your conversations go with it. There is no export from outside the account and no way to recover history afterwards.
So do the export while you still have access. Settings, then Data Controls, then Export Data gives you a ZIP built around conversations.json, which is unreadable on its own. Dropping that ZIP into ChatExports converts it into per conversation PDF, Word, Markdown or CSV files inside your browser tab, with nothing uploaded. That copy survives a lockout, a deleted account and a future password reset.
Reducing what a future break in reaches
Turn off model training in Data Controls, use Temporary Chat for anything sensitive, clear saved memories you do not want persisted, and keep your own archive so the platform is not the only place your history exists. An account with two factor authentication and no secrets in it is a boring target.
Frequently asked questions
Has OpenAI been hacked?
There have been incidents involving a third party vendor and large lists of stolen ChatGPT logins traded online, but those logins came from malware and reused passwords on users' own devices, not from a break in to OpenAI's chat storage.
Why are there chats in my sidebar I did not write?
Someone else is signing in with your credentials. Change the password, turn on two factor authentication, and sign out of all sessions.
My ChatGPT history vanished, was I hacked?
Usually not. Check whether you signed in with a different method, and check Settings, General, Archived Chats before assuming anything was removed.
Can I recover conversations after an account is compromised?
Only from an export you requested earlier. There is no way to retrieve history from outside the account.