what sign up
nixm nixm

← learn

ChatGPT data leaks — what actually happened, and what it means for you

October 1, 2026

ChatGPT has had a few real leaks, none of them a mass dump of conversations. In March 2023 a bug let some users see other people's chat titles and exposed limited payment details for about 1.2% of active Plus subscribers. In mid-2025, shared chats that users had marked "discoverable" showed up in Google search. In November 2025, a breach at an analytics vendor exposed names and emails tied to some OpenAI accounts, but no chats. The most common leak, though, is people pasting things they should not.

The short answer

There is no known incident where attackers walked off with ChatGPT conversations in bulk. There have been three real exposures, and each one teaches something different. Here they are in order, with what each means for you today.

March 2023: the bug that showed other people's chat titles

On March 20, 2023, a bug in an open-source library ChatGPT used caused some users to see conversation titles from other users' chat histories in their sidebar. OpenAI took ChatGPT offline to fix it. Its investigation then found that during a roughly nine-hour window the same bug could expose limited payment details of about 1.2% of ChatGPT Plus subscribers who were active at the time: name, email address, payment address, card type, the last four digits of the card and its expiry date. Full card numbers were not exposed.

What it means: no attacker was needed. An ordinary software bug was enough to show one person's data to another. Anything stored can be exposed by a mistake, which is the strongest argument for keeping sensitive material out of stored chats.

2023: the leak that comes from users

The same spring, Samsung engineers pasted confidential source code and internal meeting notes into ChatGPT while asking for help, and the company restricted its use soon after. Nothing was hacked. The information left the company the moment it was typed, into a service that stored it and, at the time, could train on it.

What it means: this is still the most common way ChatGPT "leaks" data. Your employer's rules on AI exist for this reason, and a work account is visible to your company's admins, as can your employer see your ChatGPT explains.

July 2025: shared chats in Google search

ChatGPT's share feature briefly offered a "Make this chat discoverable" option. Shared chats with it switched on could be indexed by search engines, and at the end of July 2025 researchers found thousands of them in Google, some containing personal details their authors clearly never meant to publish. OpenAI removed the option.

What it means: a share link is a public copy. Review and revoke old links under Settings, then Data controls, then Shared links. The same thing happened at a larger scale with Grok, covered in is Grok private.

November 2025: the analytics vendor breach

An attacker broke into Mixpanel, an analytics provider OpenAI used, mainly on its developer platform. The stolen data included names, email addresses and approximate locations tied to some OpenAI accounts. OpenAI said no chats, passwords, API keys or payment details were involved, and it stopped using Mixpanel.

What it means: your exposure includes the companies a service relies on, not just the service itself. The practical risk from leaked names and emails is phishing, so treat any message asking for your OpenAI login with suspicion.

What has not happened, and what still could

None of these was a bulk theft of conversations. But two things are worth keeping in mind.

  • Stored chats can be compelled. A 2025 court order in the New York Times case required OpenAI to preserve chats it would otherwise have deleted, as the NYT v. OpenAI explainer covers.
  • Your own account is the weakest link. Security researchers regularly find ChatGPT logins in data stolen by password-stealing malware. Anyone with your login can read your whole history.

How to limit what a leak could expose

  1. Keep it out in the first place: no passwords, card or ID numbers, client data or other people's private details.
  2. Delete what you do not need. The steps are in how to delete your ChatGPT history.
  3. Use temporary chat for anything sensitive.
  4. Revoke shared links you no longer need.
  5. Turn on two-factor authentication for your account.

Every relevant setting is in ChatGPT's privacy settings, explained, and the wider picture is in AI privacy concerns.

Where nixm fits

The less a service keeps, the less any leak can expose. nixm doesn't keep a transcript. A distilled log of the session stays with the signal for seven days, then dissolves, along with any images you uploaded. No account is needed to start.

frequently asked

Has ChatGPT ever had a data leak?

Yes. In March 2023 a bug let some users see other people's chat titles and exposed limited payment details for about 1.2% of active Plus subscribers. In 2025, discoverable shared chats appeared in Google, and a vendor breach exposed some account names and emails.

Were ChatGPT conversations leaked?

There is no known bulk theft of conversations. The 2023 bug exposed chat titles, the 2025 indexing exposed chats users had shared publicly, and the 2025 vendor breach involved no chats, per OpenAI.

What was the Mixpanel breach?

In November 2025 an attacker breached Mixpanel, an analytics vendor OpenAI used, exposing names, emails and approximate locations tied to some accounts. OpenAI said no chats, passwords, API keys or payment details were involved.

Can my shared ChatGPT links show up on Google?

Shared chats marked discoverable did in 2025, and OpenAI then removed that option. A share link is still a public copy, so review and revoke old ones under Data controls.

What is the biggest ChatGPT data leak risk?

What you paste in. Confidential work material, passwords and other people's details become part of a stored record the moment you type them.

How do I protect my ChatGPT data?

Keep sensitive details out, delete chats you do not need, use temporary chat, revoke old share links and turn on two-factor authentication.

Can I try nixm without an account?

Yes. Open nixm.ai and seed a signal, with no sign-up and no transcript kept.

try it now — no account, no transcript kept. even the signal dissolves in seven days.

seed a signal →

Enter your email and receive a link to sign in. No passwords, just a secure signal to connect.

why connect

  • 20 free credits to start
  • your signals, remembered
  • buy more credits anytime
  • image & video generation features
or
+