Premium chatbot accounts for services like ChatGPT and Claude can be costly, prompting some users to share passwords to split subscription fees. However, this practice carries substantial risks, as highlighted by various security incidents.

For example, a password-sharing scenario turned disastrous for a Disney worker, Matthew Van Andel. He downloaded what he thought was an AI tool from GitHub, which was actually malware, compromising his personal device. This malware subsequently exposed his 1Password account credentials and session cookies, leading to a hacker gaining access to his entire digital life, including financial information and even Ring cameras. The incident resulted in the leak of 44 million Disney messages and personal data, ultimately costing Van Andel his job, about $200,000 in bonuses, and his health insurance, prompting him to seek an eight-figure settlement.

Another instance involves Paradox.ai, a company providing AI hiring chatbots to Fortune 500 firms. Security researchers uncovered a major vulnerability where an administrator account for McDonald's at Paradox.ai was protected by the weak password "123456," exposing 64 million job applicants' records, including names, email addresses, and phone numbers. The broader implications of weak password hygiene were further revealed when a Paradox.ai developer's personal device was compromised by malware in June 2025, leading to the theft of credentials for secure services like their Okta SSO platform and Atlassian. This compromise exposed hundreds of passwords, many of which were reused for various Fortune 500 client accounts, demonstrating the cascading risks of poor password practices.

These incidents underscore that while sharing or reusing passwords might seem convenient or economical, the potential for data breaches, financial losses, and personal upheaval is significant. Companies and individuals alike face ongoing threats from opportunistic hackers, and securing multi-factor authentication, strong unique passwords, and being cautious about third-party software are critical to mitigating these risks.