Logo
FrontierNews.ai

Fake ChatGPT Billing Emails Are Stealing Passwords at Scale: Here's How to Spot Them

Cybercriminals are running a sophisticated phishing campaign that impersonates OpenAI and ChatGPT, using fake billing emails to trick users into surrendering their login credentials and payment information. Security researchers at Cofense discovered the scam, which exploits the routine nature of subscription payment problems to lower users' guard and push them toward clicking malicious links.

How Does This ChatGPT Phishing Scam Actually Work?

The attack starts with an email that looks polished and official. It uses the real ChatGPT logo and claims your subscription payment needs attention. The message prominently displays "Subscription Payment Required" and warns that you have 48 hours to act, creating artificial urgency. A large "Update Payment Information" button gives you an obvious way to supposedly fix the problem, and the message signs off as "The OpenAI Team." According to Cofense, the attackers combine familiar images, bold wording, and urgency to push people into acting quickly without thinking.

The sender's email address is one of the biggest red flags. Cofense found that the phishing message came from support@9527db6e1a[.]nxcli[.]io, a domain that has nothing to do with OpenAI. OpenAI currently lists several domains it uses for legitimate customer emails, including @openai.com, @mail.openai.com, and @email.openai.com. That makes the full sender address worth checking carefully.

Once someone clicks the "Update Payment Information" button, the deception deepens. Cofense found that clicking the button first sent users through a Google API redirect, which then forwarded them to the attacker's malicious site. That can make a suspicious link look more convincing at first glance because Google appears along the way. Seeing Google somewhere in a link does not tell you where you will eventually land.

The phishing page closely copies the ChatGPT login experience, complete with familiar logos, text, and icons. However, the domain in the browser does not match the legitimate ChatGPT login domain. If a victim enters login information, the fake site captures it and sends it to the attacker. The page then sends the victim to an error screen, which could easily look like a temporary login problem. By then, the attacker may already have the credentials.

What Red Flags Should You Watch For in Billing Emails?

The most important defense is learning to spot the warning signs before you click anything. Cofense says the phishing campaign targeted people using ChatGPT through personal and work accounts, making this a widespread threat. The scam works because the email looks like something you might actually expect to receive, and a payment problem feels routine enough to make people lower their guard.

  • Sender Email Address: Expand the sender information and look at the actual email address, not just the display name. In this campaign, the sender used an nxcli.io domain. OpenAI publishes the domains it uses for legitimate communications, which gives you something concrete to compare against.
  • Browser Address Bar: Check the domain in the browser address bar before entering a password or payment information. If the domain looks unfamiliar, close the page immediately. Then open the service yourself through its official app or website.
  • Urgency and Pressure Tactics: Be skeptical of emails that create artificial time pressure, such as warnings that you have 48 hours to act or that your account will be suspended. Legitimate billing notifications from OpenAI rarely use aggressive urgency language.
  • Suspicious Links and Redirects: Do not rely on hovering over buttons to check the destination, as redirects can make that check less useful. The safer option is to skip the email link entirely and go directly to ChatGPT.com or open the official app.

Steps to Protect Your ChatGPT Account Right Now

  • Skip the Email Link: If an email says there is a payment problem, do not click the button. Go directly to ChatGPT.com or open the official app and sign in yourself. For web subscriptions, OpenAI says to check Settings, then Billing. Some accounts may show Settings, then Account, then Payment, then Manage instead.
  • Use a Unique Password: Never reuse your ChatGPT password on other accounts. Use a unique password and consider using a password manager to generate and store it. That way, one stolen password cannot easily unlock several of your accounts.
  • Enable Two-Factor Authentication: OpenAI supports two-factor authentication (2FA), which adds another hurdle if someone gets your password. You can enable it from the Security section of your ChatGPT settings. Available verification methods may include an authenticator app, push notification, text message, or passkey.
  • Review Active Sessions: If you entered your password on a suspicious site, change it immediately. Then open ChatGPT and go to Settings, then Security, then Active sessions. Review the listed devices and sessions. If you see something you do not recognize, log it out.
  • Log Out Everywhere: OpenAI lets you go to Settings, then Security, then Active sessions and choose Log out of all sessions. The company says signing out across every device can take up to 30 minutes.
  • Secure Your Sign-In Methods: If you use Google, Microsoft, or Apple to sign in to ChatGPT, secure that account as well. Compromising your ChatGPT account could give attackers access to your other linked accounts.
  • Contact Your Card Issuer: If you gave a suspicious site your card information, call the number on the back of your card immediately. Tell the issuer that your payment information may have been compromised. Then review recent transactions for anything you do not recognize.

Cofense says the phishing campaign targeted people using ChatGPT through personal and work accounts. If you entered work credentials or used a company-managed account, contact your IT or security team. They can review account activity and take additional steps if necessary.

The broader lesson here is that scammers exploit routine situations to lower your guard. A payment problem feels normal, and that can make people skip their usual security checks. By taking a few extra seconds to verify the sender's email address and the browser domain before entering sensitive information, you can avoid becoming a victim of this widespread phishing campaign.