express gazette logo
The Express Gazette
Sunday, September 27, 2026

Scammers Use Fake ChatGPT Billing Emails to Steal Logins, Payment Info

A new phishing campaign impersonates OpenAI, creating convincing emails that lead to fake login pages.

US Politics • 3 hours ago
Scammers Use Fake ChatGPT Billing Emails to Steal Logins, Payment Info

Cybercriminals are employing a sophisticated phishing campaign that impersonates OpenAI and ChatGPT, aiming to steal user login credentials and payment information. Security researchers at Cofense have identified fake emails that appear to be routine subscription notices, designed to prompt users into updating their payment details.

How the Scam Works

The phishing emails are crafted to look legitimate, often using the official ChatGPT logo and language that creates a sense of urgency. According to Cofense, the emails claim that a subscription payment has failed and that the user has a limited time, typically 48 hours, to resolve the issue. A prominent "Update Payment Information" button is included, which, when clicked, leads to a convincing replica of the ChatGPT login page.

The sender's email address is a key indicator of the scam. Cofense reported that the malicious emails originated from addresses like support@9527db6e1a[.]nxcli[.]io, a domain unrelated to OpenAI's official domains, which include @openai.com, @mail.openai.com, and @email.openai.com.

Clicking the "Update Payment Information" button can initiate a Google API redirect, further obscuring the malicious nature of the link before forwarding the user to the attacker's site. This tactic leverages the trust associated with Google's services to make the link appear more legitimate.

Once on the fake login page, which closely mimics the authentic ChatGPT interface with familiar logos and text, users are prompted to enter their credentials. If successful, the phishing page captures this information and sends it to the attackers. The page then typically redirects the victim to an error screen, making the deception harder to detect.

A ChatGPT login screen

Protecting Yourself

To avoid falling victim to such scams, security experts recommend several precautions:

  • Verify Billing Directly: If an email indicates a billing issue, do not click any links. Instead, navigate directly to the official ChatGPT website or open the app and check your account settings and billing information there.
  • Inspect Sender Addresses: Always examine the full sender's email address, not just the display name. Compare it against official domains provided by the service.
  • Check URLs Before Signing In: Before entering any credentials, verify the domain in the browser's address bar. If it seems unfamiliar or suspicious, close the page and access the service directly.
  • Use Strong Security Practices: Employ unique passwords for each online account, utilize a password manager, and enable two-factor authentication (2FA) whenever possible. OpenAI supports 2FA for enhanced account security.
  • Maintain Antivirus Protection: Keep robust antivirus software updated on all devices to help detect and block malicious links and websites.
  • Respond to Compromises Swiftly: If you suspect you have entered your password on a phishing site, change your password immediately and review your active login sessions. If you have shared payment details, contact your card issuer promptly to report the potential compromise.
  • Report Work Account Incidents: If a work account was involved, notify your IT or security department.

Sources