Drooid Logo
Back to story perspectives

Full Breakdown

Phishing Emails Mimic ChatGPT Billing Notices

By Drooid · · How we work

Phishing Campaign Overview

Security researchers at Cofense identified a phishing campaign that impersonates OpenAI and the ChatGPT service. The fraudulent messages appear to be routine subscription alerts, using the official ChatGPT logo and a “Subscription Payment Required” headline. Recipients are told they have 48 hours to update their payment information, prompting quick action. The sender address is masked as a familiar name but actually originates from the domain support@9527db6e1a.nxcli.io, which is unrelated to OpenAI’s listed domains such as @openai.com, @mail.openai.com, and @email.openai.com.

How the Scam Operates

Cofense reports that the email’s “Update Payment Information” button first redirects through a Google API link before sending users to a malicious site. The intermediate Google redirect can make the URL appear trustworthy, but the final destination uses a look-alike domain that does not match the legitimate ChatGPT login URL. The phishing page replicates the authentic login interface, complete with logos and icons, to capture entered credentials. After submission, victims are shown an error screen that mimics a temporary login problem, while the attacker already records the login data.

Official Response and Expert Commentary

OpenAI’s public guidance advises users to verify billing issues directly on ChatGPT.com or through the official app, checking Settings -> Billing (or Settings -> Account -> Payment -> Manage for some accounts). OpenAI also supports two-factor authentication (2FA) via authenticator apps, push notifications, text messages, or passkeys, though enabling 2FA does not automatically terminate existing sessions. Cofense reached out to OpenAI for comment but did not receive a response before the article’s deadline. Cyber-security commentator Kurt “CyberGuy” Knutsson emphasizes that the email’s polished appearance and urgent language are designed to lower recipients’ guard.

Recommended Protective Actions

Cofense and security experts suggest several safeguards:

1. Verify the sender address by expanding the email header and confirming the domain against OpenAI’s official list.

2. Check the browser address bar before entering any credentials; unfamiliar domains should be closed immediately.

3. Use a unique password and a password manager to avoid credential reuse across services.

4. Enable multi-factor authentication in ChatGPT’s Security settings.

5. Maintain up-to-date antivirus software to detect malicious links.

6. If credentials or payment details are entered, change the password promptly, review active sessions, and contact the card issuer for potential fraud.

7. Report workplace-related incidents to IT or security teams when corporate accounts are involved.

Following these steps can reduce the risk of credential theft and financial loss from the fake ChatGPT billing email campaign.