Fake ChatGPT billing emails can steal your login
Cybercriminals are impersonating OpenAI in fake ChatGPT subscription emails designed to steal login credentials and payment details. The messages create urgency by claiming a payment problem and giving recipients 48 hours to update their information, directing them towards a convincing imitation of the ChatGPT login page.
Cofense researchers identified a suspicious sender address unrelated to OpenAI and found that the payment button used a Google API redirect before forwarding victims to a malicious website. The fraudulent page copies familiar ChatGPT branding, but its domain does not match the legitimate service; entering details sends them to attackers. Users should inspect sender addresses and avoid email links, instead accessing ChatGPT directly through a trusted bookmark or official website.
- Fake billing emails imitate OpenAI and ChatGPT.
- Links lead to credential-stealing login pages.
- Check domains and access ChatGPT directly.