Fake OpenAI Billing Emails Target ChatGPT Users in Credential Phishing Scam

Fake OpenAI Billing Emails Target ChatGPT Users in Credential Phishing Scam

Cofense researchers identified phishing emails impersonating OpenAI billing notices to steal ChatGPT credentials and payment information.

Listen to this article

0:00

Press play to start listening

A credential harvesting campaign is targeting ChatGPT users with fake OpenAI subscription notices designed to steal account credentials and payment information. According to technical analysis by Josh Varden of the Cofense Phishing Defense Center (PDC), the emails impersonate OpenAI and warn recipients about an apparent problem with their ChatGPT subscription payment.

How the Fake Email Looks

The scam email looks like a regular ChatGPT subscription notice, especially due to the inclusion of the genuine ChatGPT logo. The words “Subscription Payment Required” are prominently displayed, and the message claims a $23.80 charge, giving recipients 48 hours to update their payment information to create a sense of urgency.

However, several details within the email expose the scam. The email originates from [email protected] rather than an official OpenAI domain.

The “Update Payment Information” button uses a Google API wrapper URL (notifications.googleapis.com/email/redirect?...) that redirects the victim to the phishing infrastructure. The final pages are hosted at e83cedb076.nxcli.io/fertaq/app/login.php and key.php.

Lure email content (Source: Cofense)

Fake ChatGPT Login Page

After clicking the button, the Google API redirect sends the victim to a page designed to closely resemble the ChatGPT sign-in portal. It uses familiar logos, styling, and icons to appear legitimate.

The browser address bar provides one obvious warning sign. Instead of an authentic OpenAI domain, the page uses an unrelated nxcli.io address. Entering credentials on the fake page allows the attackers to capture the information before the victim is redirected to an error page.

Cofense’s blog post states its PDC has identified other credential-stealing phishing emails impersonating major services, most commonly Microsoft, Google, and Adobe. The ChatGPT campaign uses the same familiar billing theme, with a fake payment notice leading recipients to a credential-harvesting page.

Using ChatGPT’s name in phishing emails is another recurring theme. Most recently, in May 2026, Microsoft detected a separate ChatGPT-themed campaign involving 4,500 emails, 97% of which targeted users in South Africa.

The fake login/phishing page (Source: Cofense)

Related activity sent as many as 100,000 emails in a single day to targets in Switzerland, Austria, and South Africa. The emails used fake payment-update messages to direct users to phishing pages that collected personal and credit-card information.

(Photo by Jonathan Kemper on Unsplash)

Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience…
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts