
Fake ChatGPT Billing Emails Use Urgency to Steal Logins
Published by AINave Editorial • Reviewed by Ramit
A fake ChatGPT billing email can turn a routine subscription worry into a credential-stealing attempt. In a campaign identified by security researchers at Cofense, a message impersonating OpenAI claims a payment was declined and urges recipients to update their details within 48 hours. The email uses ChatGPT branding and a prominent payment button to make acting quickly feel like the sensible choice. Cofense’s findings, as reported by Fox News, show how a familiar account workflow can be repurposed as phishing bait.
The familiar branding is only the first step
The reported email labels itself “Subscription Payment Required,” warns of a 48-hour deadline and signs off as “The OpenAI Team.” But its sender address, support@9527db6e1a[.]nxcli[.]io, uses an nxcli.io domain rather than an OpenAI domain. That mismatch is more useful than the display name, which can be made to look reassuring. Cofense identified the sender address as one signal that the message was not a genuine OpenAI billing notice.
The button’s route adds a twist: it first passes through a Google API redirect, then forwards to an attacker-controlled site. Seeing a familiar service in an intermediate link does not tell you where the link ultimately leads. The destination copies the ChatGPT login experience, but sits on an unrelated domain. Anyone who enters login details there gives them to the attacker; Cofense says the campaign also targets payment information. The redirect and copied sign-in page exploit the gap between a page’s appearance and the domain actually serving it.
Check the account, not the email
If a message claims your payment failed, open ChatGPT yourself or use its official app rather than following the email button. For a web subscription, check Settings → Billing; some accounts may instead show Settings → Account → Payment → Manage. If Apple or Google Play manages the subscription, check it through that store. These are the independent billing routes described in the report.
That approach avoids having to judge whether a polished email or a redirect is convincing. It also works whether the warning is genuine or not: the account’s own billing page is the place to verify the claim.
If you already entered your password on a suspicious page, change it promptly and review active sessions under ChatGPT’s Security settings. You can sign out of all sessions there, though the report says that process can take up to 30 minutes. If the page received payment details, contact the card issuer using the number on the card and check recent transactions. The report also advises notifying workplace IT or security if work credentials or a company-managed account were involved.
The key detail is not whether a message looks like ChatGPT. It is whether the account shows the same billing issue when you reach it independently.






















