
Fake ChatGPT Billing Emails Steal Card Details
Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…
This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to pressure users into taking an immediate action (pay, verify, or share an authentication code).
Two separate incidents in this roundup share the same underlying playbook: impersonate a trusted brand and pressure the target into an immediate action. In the first, phishing emails impersonated ChatGPT Plus billing, telling recipients an urgent payment update was needed and directing them to an embedded link to enter payment card details. In the second, a convicted attacker posed as Snapchat support over the phone, asking victims to read back the one-time authentication code they had just received in order to "verify" or "secure" their account.
Both scenarios relied on borrowed trust and urgency rather than technical exploitation. ChatGPT has entered the top 10 most-impersonated brands, meaning recipients are increasingly likely to encounter a message that looks plausible simply because the brand is popular and widely used. Microsoft remains a heavily impersonated brand as well, showing that attackers gravitate toward services people already trust and use daily. In the Snapchat case, the attacker leaned on the appearance of legitimate support outreach, which lowered the target's guard long enough to extract the authentication code before it expired.
Defenders across finance, executive, and IT/helpdesk roles are common targets for billing-themed phishing, while all employees remain potential targets for support impersonation calls. Practical steps include:
The common thread across both cases is impersonation of a trusted name paired with a call to act quickly, whether that means paying, verifying, or sharing a code. Recognizing that pattern, rather than trying to spot every individual brand being spoofed, is the more durable defense.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It is a phishing campaign that sends fake ChatGPT Plus billing notices urging recipients to click an embedded payment link and enter payment card details, part of a broader trend of AI brands entering the top 10 most-impersonated brands.
An attacker impersonated Snap representatives and used social engineering to convince victims to read out authentication codes they had just received, which allowed account takeovers and theft of private content.
Verify billing messages independently instead of clicking embedded payment links, and never share one-time passcodes with anyone, even someone claiming to be official support.
Widely trusted brands like Microsoft and popular AI tools create a false sense of legitimacy, and urgency around billing or account security pressures people into acting before they verify the request.
You might trust a text that says, “Hi, this is Snapchat Support,” or an email about your ChatGPT Plus billing… and that’s the problem. Real campaigns send fake ChatGPT Plus billing emails to steal your card, while others call pretending to be Snapchat support just to grab the authentication code that hits your phone. Here’s the aha: no real support, Snapchat, Microsoft, ChatGPT, anyone, will ever need the one-time code that was sent to you. The moment you read that code out, you’ve handed them your account. If you get a billing email or a support call, stop and do this: hang up, close the email, and go straight to the official app or website yourself to check your account.

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…

A real phishing campaign targeted Call of Duty Mobile players by promising free in-game currency. Victims were tricked into entering their email and password,…

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment…

A voicemail-themed phishing campaign (“Kali365 Ringer”) targeted financial and insurance organizations using a missed-call notification and a Google Sites page…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…