Fake ChatGPT Billing Emails Target Users to Steal Login Credentials

Feature and Cover OpenAI Provides ChatGPT to Federal Agencies for $1 Yearly

A phishing campaign impersonating OpenAI is using fake ChatGPT billing emails to steal user credentials and payment information.

A recent phishing campaign has emerged, targeting users of OpenAI’s ChatGPT by sending fraudulent billing emails that appear to be legitimate. These emails are designed to deceive recipients into providing their login credentials and payment details.

For those who pay for ChatGPT, an email claiming there is an issue with your subscription can easily grab your attention. Whether it’s a notification about an expired card or a failed payment, the urgency to resolve the issue can lead users to act quickly. Cybercriminals are exploiting this sense of urgency.

Security researchers at Cofense have uncovered this phishing scheme, which mimics OpenAI and ChatGPT. The emails are crafted to look like standard subscription notices, but they contain a link that directs users to a fraudulent login page that closely resembles the real ChatGPT interface. According to Cofense, the primary goal of this campaign is to capture account credentials and payment information.

The phishing email is designed to look polished and professional, featuring the authentic ChatGPT logo and a message that claims immediate action is required regarding your subscription payment. The email prominently states “Subscription Payment Required” and insists that you have only 48 hours to respond. A conspicuous “Update Payment Information” button is included, which is intended to lure users into clicking it. The email concludes with a signature from “The OpenAI Team,” further enhancing its credibility.

However, the sender’s email address is a significant red flag. Cofense identified that the phishing email originated from support@9527db6e1a[.]nxcli[.]io, a domain that is not associated with OpenAI. Legitimate OpenAI communications come from domains such as @openai.com, @mail.openai.com, and @email.openai.com. Therefore, it is crucial to verify the full sender address rather than relying solely on the display name in your inbox, as scammers can easily manipulate this to appear trustworthy.

Another layer of deception is embedded in the phishing email’s button. When users click “Update Payment Information,” they are first redirected through a Google API link before being sent to the attacker’s malicious site. This tactic can make the link appear more legitimate at first glance, as it includes a trusted service. Cybercriminals have previously exploited trusted platforms in similar phishing attacks, making it essential to remain cautious even when a link appears to be associated with a reputable service.

Once users click through, the phishing attempt becomes increasingly difficult to detect. The fraudulent page closely mimics the ChatGPT login experience, complete with familiar logos and text. However, the domain in the browser will not match the legitimate ChatGPT login page. If a victim enters their login information, the fake site captures the credentials and sends them to the attacker. Afterward, the victim is redirected to an error screen, which could easily be mistaken for a temporary login issue. By this point, the attacker may have already obtained the user’s credentials.

To protect yourself from such scams, it is advisable to avoid clicking links in emails that claim there is a payment problem. Instead, navigate directly to ChatGPT.com or use the official app to log in. For web subscriptions, OpenAI recommends checking the billing section under Settings. If you subscribed through Apple or Google Play, manage your subscription through those platforms.

Additionally, always examine the sender information to verify the actual email address. In this case, the sender used an nxcli.io domain, which is not associated with OpenAI. Familiarize yourself with the legitimate domains used by OpenAI to ensure you can spot fraudulent communications.

Before entering any password or payment information, check the browser address bar for the correct domain. If the domain appears unfamiliar, close the page and access the service through its official app or website. This practice can also safeguard you against fake banking sites, as criminals have been known to create lookalike bank login pages.

It is crucial to avoid reusing your ChatGPT password across multiple accounts. Using a unique password for each account is recommended, and employing a password manager can help generate and store these securely. This approach minimizes the risk of a single stolen password compromising multiple accounts.

OpenAI supports two-factor authentication (2FA), which can be enabled from the Security section of your ChatGPT settings. Depending on your account, available verification methods may include an authenticator app, push notifications, text messages, or passkeys. While enabling 2FA adds an extra layer of security, it does not automatically log out existing sessions.

Strong antivirus software can also provide warnings about malicious links and phishing websites, helping to block other threats that may arrive through scam emails. Ensure that your antivirus protection is updated on all devices where you check email or access important accounts.

If you suspect that you have entered your password on a suspicious site, change it immediately. Then, log into ChatGPT and review your active sessions under the Security settings. If you notice any unfamiliar devices or sessions, log them out. OpenAI also allows users to log out of all sessions, although this process may take up to 30 minutes.

If you provided payment information to a suspicious site, contact your card issuer right away. Inform them that your payment information may have been compromised and review recent transactions for any unauthorized activity. Your card issuer may recommend replacing your card to prevent further issues.

Cofense reports that this phishing campaign targets individuals using ChatGPT through both personal and work accounts. If you entered work credentials or used a company-managed account, it is advisable to contact your IT or security team for further assistance.

This scam is effective because the email mimics something users might expect to receive, making it easier for people to lower their guard. If you receive a billing warning from ChatGPT, do not click on any links in the email. Instead, go directly to the ChatGPT website to check your account. If you have already entered your password on a suspicious page, change it immediately and review your active sessions. If you shared payment information, contact your card issuer promptly.

For more information on cybersecurity and to stay updated on potential threats, visit CyberGuy.com.

Leave a Reply

Your email address will not be published. Required fields are marked *

More Related Stories

-+=