Yubico has expanded availability of its OpenAI-branded YubiKey bundle to Singapore, Malaysia, Australia, Japan, South Korea and Taiwan, among other markets, as OpenAI introduces stronger account-security requirements for members of its Trusted Access for Cyber program.
The cybersecurity company said the two-key bundle is now available in 10 additional countries: Australia, Egypt, Japan, Malaysia, Mexico, Saudi Arabia, Singapore, South Korea, Taiwan and the United Arab Emirates. The expansion follows OpenAI’s September 1 launch of Advanced Account Security, which Yubico said requires hardware-backed passkeys for Trusted Access for Cyber members.
Two security-key form factors
The bundle includes a YubiKey C NFC designed for use across mobile devices and tablets, and a low-profile YubiKey C Nano intended to remain in a laptop’s USB-C port. Both are hardware security keys that support passkeys and FIDO-compatible authentication.
OpenAI’s own Advanced Account Security page says the service makes security keys and passkeys the default phishing-resistant sign-in methods and adds stricter recovery safeguards. It also says users may purchase two security keys through its partnership with Yubico at preferred pricing.
That distinction matters because a physical key is not the only way to use the service. OpenAI says users can use compatible FIDO security keys or passkeys, and that the Yubico bundle is one eligible option. Its bundle guidance also says availability can vary by country, account eligibility, inventory and other restrictions.
Regional availability needs account-level confirmation
Yubico’s September 3 announcement identifies Singapore and the other nine new markets as places where the custom bundle is being introduced. However, users must sign in to an OpenAI account to see whether they are eligible and to access the purchase flow. The online checkout is completed through Yubico, according to OpenAI.
The country rollout gives users in several Asia-Pacific markets a branded hardware-key option as companies and researchers assess stronger protections for AI accounts, including accounts that may contain proprietary code, sensitive conversations or access to advanced tools. In Singapore, Malaysia, Japan, South Korea and Taiwan, the launch ties a global account-security initiative to a specific hardware product that can be used with ChatGPT and Codex.
Reducing exposure to phishing attacks
Hardware-backed authentication is designed to reduce the risk that a password, one-time code or push-notification approval can be captured through phishing. Rather than treating the physical keys as the sole security solution, OpenAI’s guidance presents them as part of a configuration that requires at least two secure sign-in methods, including one that works across devices.
Yubico said enrolling security keys under OpenAI’s program disables weaker, phishable authentication methods for participants. That account-level policy is relevant to the Trusted Access for Cyber program, which is aimed at security researchers and defenders. OpenAI’s public account-security page broadly describes stronger sign-in, recovery, session and login-alert controls, but readers should not assume that all Trusted Access for Cyber requirements apply to every ChatGPT or Codex account.
The expansion builds on an April partnership announcement between the companies. For users in the newly listed markets, the practical next step is to check the signed-in OpenAI purchase experience and Yubico checkout page for the current eligibility, pricing, tax and delivery terms.
Yubico announced the market expansion on September 3.

