A new phishing campaign is targeting ChatGPT users with a fake billing email designed to steal OpenAI account credentials. The scheme directs users to a deceptive login page that captures any username and password entered.
The phishing email, which purports to be from "ChatGPT" with the subject line "Urgent: Update Your Payment Method to Avoid Service Interruption," attempts to mimic a legitimate billing notification. It features the ChatGPT logo, a "final notice" tag, and claims an outstanding balance of $23.80. The message warns of potential account suspension if payment information is not updated within 48 hours and includes a prominent green "Update Payment Information" button, signed off by "The OpenAI Team."
However, several details betray the email's fraudulent nature. The sender's address, support@9527db6e1a[.]nxcli[.]io, is not an official OpenAI domain. Furthermore, the "Update Payment Information" button does not link directly to the phishing site. Instead, its URL begins with notifications[.]googleapis[.]com, a Google API redirect service that then forwards the user's browser to the attacker's page. This redirection complicates typical phishing detection methods, as hovering over the link reveals a Google address rather than an OpenAI one.
Upon clicking the link, victims are led to a fake landing page that displays the ChatGPT logo and a "Welcome back" greeting above fields for username and password. After credentials are submitted, they are sent to the attacker, and the victim is redirected to an error page. The authentic OpenAI sign-in page is located at auth.openai.com, and users are advised to always verify this URL in their browser's address bar before entering any login details.
Security researchers have identified specific indicators of compromise for this campaign. These include the Google redirect link and two paths on the nxcli[.]io host: login.php and key.php. Organizations are encouraged to search their email logs for these indicators. The most critical defense for individual users remains vigilant inspection of the browser's address bar to confirm it displays auth.openai.com before submitting any login information.






