Story perspectives
Cofense Warns of OpenAI Phishing Stealing ChatGPT Credentials
By Drooid · · How we work
1 of 1
Story summary
- Cofense uncovered a phishing campaign that impersonates OpenAI and ChatGPT.
- The fraudulent email claims a subscription payment problem, shows the real ChatGPT logo, and warns of a 48-hour deadline.
- The sender address support@9527db6e1a.nxcli.io does not match any OpenAI domain.
- Clicking the link routes through a Google API before reaching a fake ChatGPT login page capturing credentials and payment data.
- Cofense advises users to avoid email links, verify the address bar, and confirm billing on ChatGPT.com.
