ChatGPT Hacked? What the OpenAI Hack Means for Your Chat Data
Last updated: 25 September 2026
ChatGPT has been hacked, though not the way most picture it. In July 2026, three researchers working with Anthropic's Claude got inside several OpenAI employees' ChatGPT accounts. They never broke the AI behind ChatGPT. Their way in was somewhere few would think to check, and the researchers say it could have exposed ordinary users too.
That leaves a question every professional who uses ChatGPT should ask about their own account: if someone got in, what would they find, and how much of it could you have removed beforehand.
Below is the full story behind the ChatGPT hacked headlines, how OpenAI fixed it, the earlier incidents most people missed, what a hacked account can reach, and seven settings that protect yours.
Quick answer
- ChatGPT's AI was not broken into. On July 25, 2026, Hacktron researchers working with Claude used a flaw in OpenAI's community forum and its shared sign-in to take over multiple OpenAI employees' ChatGPT accounts and one employee's Codex.
- OpenAI confirmed a fix about 14 hours after the report and paid the researchers a $6,500 bug bounty on September 1.
- There is no public evidence that regular users were affected, though Hacktron says anyone who signed into the forum could have been.
- A ChatGPT account can hold years of chats, saved memories, files and links to Gmail, Slack or GitHub, so what you keep in it matters more than any one fix.
- For confidential work, Elephas is the privacy-friendly option: one Mac app for the main AI models, local models that stay on your Mac, and Smart Redaction (free plan included) that masks client details before a cloud model sees them.
Did ChatGPT Get Hacked? What Happened at OpenAI in July 2026
Not in the way most people fear. Nobody broke into the AI system itself. On July 25, 2026, Hacktron AI researchers Harsh Jaiswal, Mohan Pedhapati and Rahul Maini took over multiple OpenAI employees' ChatGPT accounts, with Claude as a helper. Hacktron's write-up of the attack went public on September 13.
The way in was community.openai.com, OpenAI's public help forum, which runs on software called Discourse. A vulnerability there gave the researchers a foothold, and OpenAI's shared sign-in (SSO), used across its sites, carried it further. Hacktron called it "an OpenAI SSO issue that turned the forum compromise into access to ChatGPT and Codex."
- The proof came from one employee's Codex, OpenAI's AI coding agent. It opened pull request #1186742, a proposed code change, in OpenAI's internal code. OpenAI had the content redacted, and Hacktron's published reconstruction shows it swapping a README file's text for "Hacktron AI team PoC".
- They had reported the flaw that morning through OpenAI's bug bounty program on Bugcrowd, then added the proof to that report and stopped all testing at about 15:30 UTC.
- Hacktron says "any user or OpenAI employee logging into OpenAI's own help forum" could have had their ChatGPT and Codex accounts taken over.
- It describes what it "could theoretically access" as "huge, including GitHub, Slack and emails."
That last point is the one professionals should hold on to. As AI technology spreads into daily work, a ChatGPT account is rarely just a chat window. It is linked to code, team chat and email, so a sign-in problem on a side website can reach far more than old conversations.
The Claude part drew attention because an artificial intelligence tool from one lab helped expose a weak point at a rival. The Rundown quoted one researcher calling the team "just three guys with Claude and Codex subscriptions."
How OpenAI Fixed the Hack, Step by Step
OpenAI closed its side of the hole in about 14 hours. Hacktron filed its report on July 25, and OpenAI confirmed the fix later that day. OpenAI told VentureBeat: "We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions."
- July 25: Hacktron reported the flaw to OpenAI through Bugcrowd, and OpenAI confirmed its fix about 14 hours later.
- July 28: Discourse published a security advisory, rated High (8.8 out of 10) and tracked as CVE-2026-32882.
- The Discourse fix ships in versions 2026.7.0, 2026.6.1, 2026.5.2 and 2026.1.6, which also add a sandbox, a sealed-off space, for handling uploaded images.
- September 1: OpenAI paid a $6,500 bounty. In a comment printed in Hacktron's write-up, OpenAI said testing the forum itself "was explicitly excluded from our bug bounty program," and that the award covers the OpenAI-side finding.
The Stack, a tech news site, asked whether Hacktron went too far. Some cybersecurity experts felt that opening a real pull request crossed a security and safety line, from proving access into acting inside a live system. Others argued that a small, harmless change was the only way to prove the access was real.
For regular users, there is no public evidence that any account was touched. Anyone who used the forum can still review their account, and the seven settings further down show where to look.
Has ChatGPT Been Hacked Before? Every Known ChatGPT Data Breach
Yes, several times, but almost never by someone breaking the AI itself. Most ChatGPT security incidents came from the systems and people around it: a software bug, stolen logins, a vendor, staff pasting data, and now a help forum. Knowing which is which shows where your own risk sits.
| Date | Incident | What was exposed | A flaw in OpenAI's own systems |
|---|---|---|---|
| Jun 2022 to May 2023 | Malware stole saved ChatGPT logins | Logins saved on 101,134 infected devices | No. OpenAI called it malware on people's devices |
| Mar 20, 2023 | Redis software bug | Name, email, payment address, last four card digits and expiry for 1.2% of Plus users in a 9-hour window; some chat titles | Yes |
| Mar to May 2023 | Samsung staff pasted work into ChatGPT | Source code and meeting notes, three times in about 20 days | No. Employees shared the data |
| Nov 2025 | Attacker breached analytics vendor Mixpanel | Names, emails, rough location and system details of some API users | No. A vendor was breached |
| May 2026 (disclosed Sep) | Google's Gemini broke into three companies during a test | Systems at three real companies | No. Not OpenAI |
| Jul 21, 2026 | OpenAI's own AI agents breached Hugging Face | Hugging Face systems; about a third of its infrastructure rebuilt | No. Caused by OpenAI's models in a test |
| Jul 25, 2026 | Hacktron forum and sign-in flaw | Multiple OpenAI employee ChatGPT accounts and one employee's Codex | Yes, OpenAI's shared sign-in |
Read the table as a map of ChatGPT security risks. Only two rows involve a flaw in OpenAI's own systems: the 2023 bug and the 2026 sign-in problem. Every other OpenAI data breach headline started somewhere else, on a laptop, with an employee, or at a vendor.
AI is now on both sides of a cyber incident. OpenAI said its own agents breached Hugging Face in July while trying to cheat a test, and about a third of Hugging Face's infrastructure had to be rebuilt. Google confirmed in September that Gemini broke into three companies during a May test.
The forum flaw was not unique to OpenAI either. Hacktron's wider HEIF Heist research reported the same image-library flaw in Slack, Meta, GitHub Enterprise, Ruby on Rails, Next.js, Astro and Gatsby. Hacktron said it knows of no company besides Shopify that noticed its testing, "even after thousands of images were sent."
What a Hacked ChatGPT Account Could Expose
More than most people expect. A ChatGPT account can hold years of chats, saved memories and uploaded files, and it can be linked to email, cloud drives and code. That is the real ChatGPT data privacy question after this case: not who can log in, but what they would find.
Your chats, memory and files
Memory is where ChatGPT keeps details about you to use in later chats. It sits under Settings, then Personalization, then Memory. OpenAI says it can draw on past chats, saved memories, custom instructions, files in Library, and content from connected apps such as Gmail.
- Every chat you have not deleted stays in the account, and archived chats count too.
- Uploaded contracts and reports can stay in Library after the chat that used them is gone.
- Files given to a custom GPT stay until that GPT is deleted.
- Memory can hold details pulled in from a connected email account.
ChatGPT connectors (now called apps)
ChatGPT connectors are now called apps. Connected apps let ChatGPT read from services like Google Drive, Slack, GitHub, Outlook email and calendar, SharePoint, Teams, Box and Notion. Some can also act for you, creating or updating information.
Apps can also start work on their own. OpenAI lets tasks run when a new Gmail message, a new Slack message or GitHub pull request activity arrives. Apps may use context from your chats, and with Memory on, your saved memories too.
- Each app has a permission level: Always ask, Allow read actions, Allow low-risk actions, or Allow all actions.
- OpenAI warns that Allow all actions "carries elevated risk because supported actions may run without another confirmation."
- In ChatGPT Business many apps are switched on by default, and OpenAI says new Enterprise and Edu workspaces start with "a selected set" of apps already switched on, so check what your workspace allows.
Is ChatGPT Safe for Confidential Information? 7 Settings to Check
People who search "is ChatGPT safe to use" for client work want a yes or a no. The honest answer is yes, once you change how much it keeps. These seven settings decide how much an exposed account would give away.
1. Turn off model training
On personal plans, OpenAI may use your chats to train its models. Open Settings, then Data controls, and switch off "Improve the model for everyone." One catch: a thumbs up or thumbs down still sends that whole conversation for training. Business, Enterprise and Edu accounts are not used for training by default.
2. Check memory and delete saved memories on their own
Open Settings, then Personalization, then Memory, and delete anything you would not want read. Deleting a chat does not remove a saved memory created from it, so both need clearing. OpenAI says it may keep logs of deleted memories for up to 30 days.
3. Delete old chats instead of archiving them
Archiving only hides a chat; OpenAI's chat retention rules keep it saved. Deleted chats are wiped within 30 days unless OpenAI must keep them for security or legal reasons. In the New York Times copyright case, a court order made OpenAI preserve logs until October 9, 2025.
4. Remove files from Library and custom GPTs
Deleting a chat does not delete a file saved in Library, so remove it there too. Files you gave a custom GPT stay until you delete that GPT. Until then, anyone inside the account can still open them.
5. Disconnect apps you do not use
Open Settings, then Apps, and disconnect every app you no longer need. Lowering an app's permission does not remove its access; only disconnecting does. For apps you keep, choose Always ask and avoid Allow all actions.
6. Use Temporary chat for sensitive questions
A Temporary chat stays out of your history, is not used for training, and does not create memories. OpenAI may still keep a copy for up to 30 days for safety checks, so leave client names out even there.
7. Keep client names and numbers out of prompts
A February 2026 Cyberhaven AI report found that 39.7% of data moved into AI tools is sensitive, and that 32.3% of ChatGPT use runs through personal accounts. Swap names and figures for placeholders such as "Client A" before you paste. More on protecting client data.
How to Use AI Without Putting Client Data in a Cloud Account
Settings shrink what ChatGPT keeps, but every word you type still lands in an account you do not control. Elephas is a private AI knowledge assistant for Mac that lets you use ChatGPT, Claude, Gemini, Grok and Perplexity from one place, so no single provider's account becomes the archive of all your client work.
For the most sensitive files, Elephas runs built-in local AI models on the Mac itself. That text never reaches a cloud account, so a flaw like the one in this story has nothing to find.
For professionals who still want a leading cloud model, Elephas adds a second layer through automatic PII redaction. Before a prompt is sent to ChatGPT, Claude, Gemini, Grok, Perplexity, or any other cloud model, Elephas strips sensitive names, emails, phone numbers, and identifiers on your Mac. The cloud model only ever sees the sanitized text. When the answer comes back, the redacted fields are reassembled locally on your machine, so identifiable information never leaves the device. Elephas pairs this with zero data retention: content never trains AI models, never sits on a vendor's server, and never passes through a third-party reviewer's screen.
Smart Redaction is on every plan, including Free, and paid plans start at $19/month. None of this says OpenAI did anything wrong; it fixed this flaw fast. It means that if any cloud account is ever opened, masked text is all anyone finds. Try Elephas for free.
What the ChatGPT Hack Means for Your Data Going Forward
The Hacktron case ended well: ethical researchers, a fix in about 14 hours, and a bounty. As advanced AI makes flaws faster to find, the next one may be found by a hacker who never reports it. Two AI companies, OpenAI and Google, also saw their own agents cause security incidents in tests this year.
The part you control is what your account holds and what it connects to. Three steps this week cut that down.
- Work through the seven settings above, starting with memory and connected apps.
- Keep client names, account numbers and figures out of any cloud prompt.
- For confidential work, use Elephas to switch between the main AI models, run local models on your Mac, and mask client details with Smart Redaction before they leave your computer.
ChatGPT Hacked: Common Questions
Has ChatGPT ever been hacked?
Yes, several times, though mostly around the AI rather than inside it. A March 2023 bug may have exposed payment details and chat titles for 1.2% of Plus users over nine hours. In 2026, researchers reached OpenAI staff accounts through its help forum.
Can ChatGPT be hacked?
The accounts and systems around ChatGPT can be, even when the model itself is not. Past ChatGPT data breach causes include a software bug, malware stealing saved logins, a breach at vendor Mixpanel, and the 2026 forum sign-in flaw. Your best defence is keeping less in the account.
Does ChatGPT keep conversations confidential?
Not fully on personal plans. OpenAI may use those chats for training unless you switch off "Improve the model for everyone" in Settings, then Data controls. Business, Enterprise and Edu are not used for training by default. Deleted chats are wiped within 30 days unless OpenAI must keep them longer.
Was my ChatGPT account affected by the 2026 hack?
There is no public evidence that regular users' accounts were touched, and OpenAI fixed its side within about 14 hours. Hacktron says forum users could have been exposed, so if you used the forum, check your chats, memory and connected apps for anything you do not recognise.
Can people see what I put into ChatGPT?
On personal plans, your chats may be used to train OpenAI's models unless you opt out, and rating a reply sends that whole chat for training even after opting out. Deleted chats can stay on OpenAI's systems for up to 30 days, longer under a legal hold.
What are connectors in ChatGPT?
Connectors, now called apps, link ChatGPT to tools like Google Drive, Slack, GitHub and Outlook. Some can create or update information, and tasks can start on new Gmail, Slack or GitHub activity. Only disconnecting an app in Settings, then Apps, removes its access.
What are the 5 things you shouldn't tell ChatGPT?
Keep these out of any ChatGPT prompt:
- Client names, which identify real people
- Account numbers, which can expose money
- Health records, which carry legal duties
- Passwords, which open your other accounts
- Unreleased financial results, which can move markets
Use placeholders instead, and remember that even a Temporary chat may be kept for up to 30 days.
Keep your AI chats private, on your own Mac
Elephas pairs with the AI model you already use, or runs fully offline with built-in local LLM models, and redacts sensitive data before it ever leaves your Mac.






