OpenAI introduced two new ChatGPT account security features: Lockdown Mode, designed to reduce prompt-injection-driven data exfiltration, and Active Sessions, which lets users review and terminate account sign-ins. Lockdown Mode restricts ChatGPT’s access to the web and external services so that even if hidden malicious instructions reach the model, the outbound exfiltration step is harder to complete. OpenAI first made the feature available to enterprise customers in February before expanding rollout to personal and self-serve business accounts in early June.
The company said Lockdown Mode is intended for users and organizations handling sensitive data, but it comes with functional tradeoffs. When enabled, it disables live connector access, write actions, certain tools such as Finances and shopping agents, and it cannot be used with Developer Mode. Active Sessions adds visibility into logged-in devices, approximate locations, sign-in times, app usage, and trusted or current session status, while allowing users to revoke individual sessions or sign out everywhere; however, it does not support SSO-based accounts and does not track third-party app sessions or Codex CLI logins.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
In early June, OpenAI began rolling out Lockdown Mode to personal accounts and self-serve business accounts. OpenAI also introduced Active Sessions, a security setting that lets users review and terminate ChatGPT account sign-ins.
OpenAI first made ChatGPT Lockdown Mode available to enterprise plans. The feature is designed to reduce prompt-injection-driven data exfiltration by limiting access to the web and external services.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.