Your AI accounts are getting picked off — check them now
Hackers are targeting AI services — ChatGPT, Claude, Gemini, and others — and they're doing it the way they do everything these days: steal your login, then use your account to generate phishing emails, spam, or scams. The accounts themselves are just a tool to them. The real damage is what they build with them.
Franceschi-Bicchierai put together a guide for spotting the telltale signs: strange activity in your usage history, messages you didn't write, API keys you don't recognize, or sudden spikes in tokens. The fix is straightforward — change your password, turn on 2FA if you haven't, revoke any API keys you've forgotten about. If you're running a small business or a side hustle that depends on AI tools, this isn't theoretical. One compromised account can burn through your credits, leak your data, or send spam from your name.
Why this matters for us: the auntie sending mass messages on behalf of her cousin's business is exactly the kind of collateral damage — and the accounts of our own side hustles are the ones being targeted.
“The accounts themselves are just a tool to them. The real damage is what they build with them.”