Press play to start listening
A credential harvesting campaign is targeting ChatGPT users with fake OpenAI subscription notices designed to steal account credentials and payment information. According to technical analysis by Josh Varden of the Cofense Phishing Defense Center (PDC), the emails impersonate OpenAI and warn recipients about an apparent problem with their ChatGPT subscription payment.
How the Fake Email Looks
The scam email looks like a regular ChatGPT subscription notice, especially due to the inclusion of the genuine ChatGPT logo. The words “Subscription Payment Required” are prominently displayed, and the message claims a $23.80 charge, giving recipients 48 hours to update their payment information to create a sense of urgency.
However, several details within the email expose the scam. The email originates from [email protected] rather than an official OpenAI domain.
The “Update Payment Information” button uses a Google API wrapper URL (notifications.googleapis.com/email/redirect?...) that redirects the victim to the phishing infrastructure. The final pages are hosted at e83cedb076.nxcli.io/fertaq/app/login.php and key.php.
Fake ChatGPT Login Page
After clicking the button, the Google API redirect sends the victim to a page designed to closely resemble the ChatGPT sign-in portal. It uses familiar logos, styling, and icons to appear legitimate.
The browser address bar provides one obvious warning sign. Instead of an authentic OpenAI domain, the page uses an unrelated nxcli.io address. Entering credentials on the fake page allows the attackers to capture the information before the victim is redirected to an error page.
Cofense’s blog post states its PDC has identified other credential-stealing phishing emails impersonating major services, most commonly Microsoft, Google, and Adobe. The ChatGPT campaign uses the same familiar billing theme, with a fake payment notice leading recipients to a credential-harvesting page.
Using ChatGPT’s name in phishing emails is another recurring theme. Most recently, in May 2026, Microsoft detected a separate ChatGPT-themed campaign involving 4,500 emails, 97% of which targeted users in South Africa.
Related activity sent as many as 100,000 emails in a single day to targets in Switzerland, Austria, and South Africa. The emails used fake payment-update messages to direct users to phishing pages that collected personal and credit-card information.
(Photo by Jonathan Kemper on Unsplash)

