Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Artificial Intelligence

OpenAI Rolling Out ChatGPT Account Security Controls

The Active Sessions and Lockdown Mode features are being made more broadly available by the AI giant.

OpenAI

OpenAI told SecurityWeek that it’s making two ChatGPT security controls more widely available, giving users additional tools to protect their accounts and data. 

One of the features is Lockdown Mode, which enables owners of ChatGPT accounts, including personal and self-serve Business accounts, to reduce the risk of data exfiltration from prompt injection attacks.

“Lockdown Mode is designed to help prevent the final stage of data exfiltration from a prompt injection attack by limiting outbound network requests that could transfer sensitive data to an attacker,” OpenAI explains. “Lockdown Mode does not prevent prompt injections from appearing in the content ChatGPT processes.”

Enabling Lockdown Mode disables or limits capabilities such as live web browsing, image support, deep research, agent mode, canvas networking, and file downloads.

The AI giant noted that the feature is not intended for all users and organizations, only those that handle highly sensitive data and require extra protection against potential data exfiltration conducted through prompt injection. 

Lockdown Mode can be enabled in Settings> Security> Advanced Security.

Advertisement. Scroll to continue reading.

The second feature is Active Sessions, which enables ChatGPT users to review where their account is signed in. Users can see the sessions and devices they are logged into, and log out of sessions they don’t recognize. 

The feature is available for all ChatGPT accounts and workspace types, except accounts linked to an organization’s SSO setup.

Active Sessions is available in Settings> Security.

The announcement comes after OpenAI unveiled a new account security feature for ChatGPT users at increased risk of targeted hacking.

The opt-in feature, Advanced Account Security, is designed to strengthen sign-in protection by disabling password-based login and requiring physical security keys or passkeys. It also covers account recovery, replacing email- and SMS-based recovery with backup passkeys, recovery keys, and security keys.

Advanced Account Security also shortens sign-in sessions to reduce the risk of account takeover in the event of a device or session compromise.

Related: OpenAI Widens Access to Cybersecurity Model After Anthropic’s Mythos Reveal

Related: 1Password Teams With OpenAI to Stop AI Coding Agents From Leaking Credentials

Related: OpenAI Hit by TanStack Supply Chain Attack

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.