HomeIntelligenceBrief
BREACH BRIEF🟢 Low Advisory

OpenAI Introduces Passkey‑Only Authentication for ChatGPT and Codex, Eliminating Passwords

OpenAI has rolled out an opt‑in Advanced Account Security setting that removes passwords from ChatGPT and Codex sign‑ins, requiring FIDO2 passkeys or hardware security keys. The change curtails phishing vectors and automatically excludes secured‑account conversations from model training, a key consideration for third‑party risk managers.

LiveThreat™ Intelligence · 📅 May 04, 2026· 📰 helpnetsecurity.com
🟢
Severity
Low
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

OpenAI Introduces Passkey‑Only Authentication for ChatGPT and Codex, Eliminating Passwords

What Happened — OpenAI launched “Advanced Account Security,” an opt‑in setting that removes password‑based sign‑in for ChatGPT and Codex accounts and replaces it with FIDO2‑compatible passkeys or hardware security keys. Email and SMS recovery flows are disabled; recovery relies solely on backup passkeys or security keys held by the user.

Why It Matters for TPRM

  • Reduces phishing‑related credential compromise risk for organizations that embed OpenAI models in critical workflows.
  • Limits exposure of sensitive prompts and data by preventing password‑based attacks and by automatically excluding secured‑account conversations from model training.
  • Shifts recovery responsibility to end‑users, requiring vendors to verify that their staff maintain secure backup credentials.

Who Is Affected — SaaS providers, research institutions, media outlets, NGOs, and any enterprise that uses ChatGPT or Codex, especially those with “Trusted Access for Cyber” privileges.

Recommended Actions

  • Review your organization’s OpenAI usage and confirm whether Advanced Account Security is enabled for all privileged accounts.
  • Update internal IAM policies to require passkey or hardware‑key authentication for any third‑party AI services.
  • Ensure backup passkeys are stored securely and that recovery procedures are documented.

Technical Notes — The feature leverages FIDO2 and WebAuthn standards; OpenAI partners with Yubico to offer discounted YubiKey bundles. Mandatory enrollment begins 1 June 2026 for Trusted Access for Cyber members; other organizations may attest to equivalent phishing‑resistant SSO. Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/05/04/openai-chatgpt-advanced-account-security/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.