10 Sources
[1]
OpenAI announces new advanced security for ChatGPT accounts, including a partnership with Yubico | TechCrunch
OpenAI is getting serious about account security. The company on Thursday launched Advanced Account Security, a set of opt-in protections for ChatGPT users designed for high-value individuals -- but available to anyone who wants them. As part of that new program, digital security provider Yubico
[2]
OpenAI Rolls Out 'Advanced' Security Mode for At-Risk Accounts
For anyone who fears their ChatGPT and Codex accounts might be targeted by attackers, OpenAI announced on Thursday that it is adding an optional new level of account protection that adds an extra layer of security. Dubbed Advanced Account Security, the feature enforces strict access controls that
[3]
Your ChatGPT account just got more secure, but you have to opt in - here's how
Whether you use ChatGPT personally or professionally, you may share certain sensitive information and files in your conversations. And you certainly don't want that data falling into the wrong hands. But what can you do beyond creating a strong password and using two-factor authentication? Plenty,
[4]
OpenAI's Advanced Account Protection Dumps Passwords for Security Keys
To stop the most determined hackers, OpenAI is introducing a new security mode for ChatGPT and Codex accounts that ditches traditional passwords for more secure alternatives. The opt-in setting is called "Advanced Account Security," and features hardware security keys and software-based passkeys
[5]
OpenAI launches hardware security keys for ChatGPT with Yubico partnership and disables password login for high-risk users
OpenAI has released a security feature for ChatGPT accounts that treats them the way banks treat online banking: hardware keys, no passwords, no email recovery, and no help from customer support if you lose access. The feature, called Advanced Account Security, is an opt-in setting that requires
[6]
You can now protect your ChatGPT account with a special USB-key
If you've ever worried about someone getting into your ChatGPT account, ChatGPT account, OpenAI has finally introduced something worth paying attention to. The company has rolled out a new opt-in feature called Advanced Account Security, and it is exactly what it sounds like. You can now lock down
[7]
OpenAI Rolls Out Advanced Account Security for ChatGPT Users - Decrypt
Enrolled accounts are excluded from model training by default. OpenAI on Thursday introduced Advanced Account Security, a new opt-in setting for ChatGPT designed for users who want stronger protection or face higher risks of digital attacks. The company said the new feature was created in
[8]
ChatGPT accounts can now be shielded by a special USB
TL;DR: OpenAI's Advanced Account Security now lets ChatGPT users secure accounts with physical hardware keys, enhancing protection against phishing by replacing passwords with encrypted device-based authentication. This upgrade targets high-risk users but removes standard recovery options,
[9]
OpenAI Launches Advanced Security for ChatGPT Accounts
Partnership with Yubico: The AI company has partnered with Yubico to support hardware-based authentication through security keys. They will offer a customised bundle of YubiKeys at preferred pricing. While the partnership launches alongside Advanced Account Security, the hardware bundle will be
[10]
OpenAI Tightens ChatGPT Security with Advanced Protection for High-Risk Users
OpenAI is rolling out advanced security protections for ChatGPT users, targeting high-risk accounts. The update introduces stronger safeguards against hacking, data leaks, and identity-based attacks. OpenAI has implemented an additional security measure for high-risk ChatGPT users. The Sam
Share
Copy Link
OpenAI introduced Advanced Account Security for ChatGPT and Codex accounts, replacing passwords with hardware security keys and passkeys. Through a Yubico partnership, users can purchase co-branded YubiKeys for $68. The opt-in security feature targets journalists, dissidents, and researchers but remains available to all users seeking enhanced protection against phishing attacks.
OpenAI launched Advanced Account Security on Thursday, marking a shift in how the company approaches account protection for ChatGPT and Codex users
1
. The opt-in security feature eliminates traditional password-based login entirely, requiring users to authenticate with hardware security keys or passkeys instead2
. While designed for journalists, political dissidents, elected officials, and researchers who handle sensitive information, the feature is accessible to any ChatGPT user seeking enhanced account protection3
.
Source: TweakTown
The company emphasizes that ChatGPT accounts increasingly hold deeply personal and professional context, sitting at the center of connected tools and workflows
2
. For high-risk users, the stakes are particularly elevated, as conversations may include confidential work projects, medical symptoms, legal exposure, and business strategies5
.As part of the security rollout, OpenAI partnered with Yubico to offer co-branded YubiKeys at a significant discount
1
. Users can purchase a bundle containing the YubiKey C NFC and YubiKey C Nano for $68, almost half off the usual retail price of $1263
. The partnership aims to drastically reduce the threat of unauthorized access to sensitive data in OpenAI accounts worldwide, according to Yubico CEO Jerrod Chong1
.
Source: TechCrunch
Hardware security keys are physical USB devices containing unique cryptographic identifiers that allow only the person possessing them to log into connected accounts
1
. The YubiKey C Nano is designed to stay plugged into a laptop for simple, low-friction daily authentication4
. While Yubico's products are featured, other FIDO2-compliant hardware tokens are also supported5
.
Source: PC Magazine
Advanced Account Security replaces every conventional login mechanism with cryptographic authentication
5
. Users must register two separate credentials, choosing from passkeys stored on their device, hardware security keys, or a combination of both2
. Each credential generates a unique cryptographic key pair that never leaves the device, meaning there's no password to steal, no one-time code to intercept, and no recovery email that attackers can compromise through social engineering5
.The feature disables email and SMS authentication routes for account recovery, forcing users to rely on backup passkeys, security keys, or recovery keys instead
2
. During enrollment, OpenAI automatically generates recovery keys that users must copy or download and store in a safe place3
. This design makes accounts resistant to phishing messages, password guessing, and SIM swap attacks4
.However, the security comes with significant trade-offs. OpenAI's support team cannot restore access to accounts protected by Advanced Account Security if users lose both credentials and their recovery keys
2
. The company has made this design choice explicit: if all authentication methods are lost, the account becomes permanently unrecoverable5
.Related Stories
The feature includes several secondary safeguards beyond passwordless authentication. Sign-in sessions are shortened to reduce the window of exposure if a device or active session is compromised
4
. Users receive alerts for every new login and can review and manage all active ChatGPT and Codex sessions from their account dashboard2
.Advanced Account Security automatically opts users out of AI model training by default, meaning conversations won't be used to improve future versions of ChatGPT
3
. This links the highest level of account protection to the highest level of data privacy, creating a tier of users whose interactions are both cryptographically secured and contractually excluded from OpenAI's training pipeline5
.The security upgrade addresses growing threats in the AI space. In 2024, cybersecurity firm Group-IB identified more than 100,000 stolen ChatGPT credentials circulating on dark web marketplaces, harvested from devices compromised by information-stealing malware
5
. Industry research suggests that 46 percent of all successful cyberattacks on small and medium businesses in 2026 will originate from credential reuse5
. The architecture borrows from zero-trust principles that protect classified government systems and cryptocurrency wallets, now applied to a consumer chatbot5
.Members of OpenAI's Trusted Access for Cyber program will be required to enable Advanced Account Security beginning June 1 or submit an alternative attestation implementing phishing-resistant authentication through enterprise single sign-on
2
. OpenAI expects to extend the feature to additional audiences, including enterprise environments, where stronger account security matters just as much3
.Summarized by
Navi
[1]
06 Jun 2026•Technology

26 Aug 2026•Technology

28 May 2025•Technology

1
Policy and Regulation

2
Technology

3
Policy and Regulation
