International Edition
Latest News
Technology

Fake ChatGPT Billing Emails Target Subscribers in New Phishing Campaign

A sophisticated phishing campaign targeting ChatGPT subscribers uses forged OpenAI billing notices, urgent 48-hour warnings, and Google API redirects to steal user login credentials and payment information. Security researchers at Cofense uncovered the operation, highlighting a growing threat…

Fake ChatGPT Billing Emails Target Subscribers in New Phishing Campaign

A sophisticated phishing campaign targeting ChatGPT subscribers uses forged OpenAI billing notices, urgent 48-hour warnings, and Google API redirects to steal user login credentials and payment information. Security researchers at Cofense uncovered the operation, highlighting a growing threat vector where attackers exploit trusted SaaS subscription management flows to compromise accounts and harvest financial data.

Mechanics of the ChatGPT Billing Phishing Campaign

The fraudulent operation relies on polished emails designed to mimic routine administrative notifications from OpenAI. According to the Cofense Phishing Defense Center, the messages display the official ChatGPT logo and feature prominent warnings stating that a subscription payment has failed or expired. Victims are given a strict 48-hour deadline to resolve the issue before losing account access. The email signs off as “The OpenAI Team” to establish false credibility.

The core deception centers on a prominent “Update Payment Information” button. When recipients click the link, they are routed through a Google API redirect before landing on a rogue login portal hosted on an unrelated domain. Cofense identified the initial sender address as support@9527db6e1a[.]nxcli[.]io, a domain with no affiliation to OpenAI. Official customer communications from OpenAI originate from verified domains such as @openai.com, @mail.openai.com, and @email.openai.com.

Security Risks for Subscription-Based SaaS Platforms

The campaign highlights a vulnerability in how subscription-based software companies handle customer billing communications. Attackers increasingly target the email-to-payment pipeline because compromised accounts yield direct financial gain, login credentials, and downstream customer churn. Historically, enterprise security budgets focused heavily on data-center protection and API security, often leaving routine billing notifications exposed to brand impersonation.

The use of trusted third-party redirects, such as Google API paths, complicates standard user verification methods. While hovering over a link can sometimes expose a destination URL, automated redirects frequently obscure the final landing page. Cybersecurity analysts recommend that users bypass email links entirely when receiving account alerts, going directly to the official platform instead.

Mitigation Strategies for SaaS Operators and Users

Security experts advise SaaS operators to tighten email authentication protocols, adopt domain-specific messaging standards, and educate users on official communication channels. Integrating secure, contextual payment alerts directly into product user interfaces rather than relying solely on email prompts helps mitigate the risk of credential harvesting.

ChatGPT phishing email targets subscribers with fake billing page
Photo: foxnews.com

For individual subscribers, verifying sender addresses beyond the display name remains a primary defense. Checking the exact domain in the sender header helps identify fraudulent messages before interacting with payment links or entering credentials into unfamiliar portals.

Phishing Campaigns Impersonate ChatGPT Billing to Steal Payment Details
About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”