Fake ChatGPT Billing Email Steals OpenAI Logins

Help Net Security · Medium sophistication
Last updated September 18, 2026

A phishing email posing as a ChatGPT billing notice pressures users to “update payment information” to avoid service interruption. The button routes through a Google redirect and lands on a fake OpenAI login page that captures usernames and passwords before sending victims to an error page.

How the Attack Worked

This phishing campaign impersonated ChatGPT's billing team with an email warning that the account would be suspended unless payment information was updated within 48 hours. The message included a button labeled to update payment information. Clicking it did not go directly to OpenAI. Instead, the link routed through a Google API redirect at notifications.googleapis.com, which then forwarded the victim's browser to a fake OpenAI login page. That page collected usernames and passwords before sending victims to an error page, a common tactic to reduce suspicion after the credentials were already stolen.

Why It Succeeded

The attack combined a believable pretext with technical camouflage. Billing and payment interruption warnings create urgency, and the 48 hour deadline was designed to push recipients into acting before they closely examined the message. The use of a legitimate Google redirect domain added a layer of false credibility, since a link starting with a recognizable Google address can appear safer than it actually is. The final login page also closely mimicked OpenAI's real sign-in experience, which can fool users who are not carefully checking the browser address bar.

What to Watch For

  • Urgent billing or payment emails that threaten account suspension within a short deadline
  • Sender addresses that do not match the impersonated company's actual domain, such as a nxcli.io address instead of an OpenAI one
  • Links that redirect through third-party services like Google APIs before reaching the final destination
  • Login pages that do not match the expected domain, such as anything other than auth.openai.com for OpenAI sign-ins

How to Build Resistance

Organizations and individuals using ChatGPT or other OpenAI services for work should train users to slow down when billing emails create urgency. Verifying account or payment issues through a known, trusted channel rather than clicking embedded links reduces risk significantly. Users should also be encouraged to check sender domains carefully, since display names can be spoofed even when the underlying address is not associated with the real company. Finally, before entering any credentials, users should confirm that the browser's address bar shows the legitimate auth.openai.com domain. Building this habit into regular awareness training, particularly for finance and helpdesk teams that regularly interact with billing communications, can meaningfully reduce the chance that a similar campaign succeeds.

Key findings

  • Email impersonates ChatGPT/OpenAI billing and uses urgency (“within 48 hours”) to push clicks.
  • The payment button uses a Google API redirect (notifications[.]googleapis[.]com) to forward users to the attacker’s site.
  • Victims are sent to a spoofed OpenAI login page that collects usernames and passwords, then redirects to an error page.
  • Sender address is not an OpenAI domain (support@9527db6e1a[.]nxcli[.]io).
  • Cofense highlighted IOCs including the Google redirect and nxcli[.]io paths login.php and key.php.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance/Accounts Payable, Teams using ChatGPT/OpenAI accounts, IT/Helpdesk, Security awareness trainees.
  • Affected industries: Any industry using ChatGPT (work accounts), Consumers/personal accounts.
  • Attack channels: email, website.
  • Impersonated: ChatGPT / OpenAI billing team.

Red flags to watch for

  • Sender email domain is not OpenAI (nxcli[.]io).
  • Link routes through a Google redirect (notifications[.]googleapis[.]com) instead of an OpenAI domain.
  • Login page is not at auth.openai.com (address bar doesn’t match).
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the fake ChatGPT billing email trick victims?

The email impersonated ChatGPT's billing team and warned that the account would be suspended if payment wasn't updated within 48 hours, pressuring recipients to click a payment button without checking the details.

What made the phishing link appear trustworthy?

The payment button routed through a Google API redirect at notifications.googleapis.com before forwarding victims to the attacker's fake OpenAI login page, making the link look safer than it was.

What are the key red flags in this attack?

The sender address used a nxcli.io domain instead of an OpenAI address, and the login page did not appear at auth.openai.com, both signs the request was fraudulent.

Who is at risk from this type of phishing email?

Anyone using ChatGPT or OpenAI accounts, including employees across departments, finance teams, and IT/helpdesk staff who might be asked to verify or update payment details.

Read the video transcript

You get an email from “ChatGPT” saying: “Urgent: Update Your Payment Method to Avoid Service Interruption.” Sounds legit, right? Here’s the trick: the big green button sends you to a Google redirect at notifications.googleapis.com, then drops you on a fake OpenAI login page that quietly steals your username and password. The aha: everything looks like OpenAI, but the clues are in the tiny text, sender is support@9527db6e1a.nxcli.io, the link starts with notifications.googleapis.com, and the real sign-in should be at auth.openai.com. If you get an urgent ChatGPT billing email, don’t click the button, open your browser, type auth.openai.com yourself, and sign in there to check your account.

Categories

Similar attacks

Fake ChatGPT Invoice Steals Login Credentials

Fake ChatGPT Invoice Steals Login Credentials

Cofense observed a real phishing email that impersonates OpenAI/ChatGPT billing to trick users into “updating” payment details. The email uses the real ChatGPT logo, urgency (“48 hours”), and a prominent button to drive clicks to a lookalike ChatGPT login page. Any credentials entered are harvested…

September 17, 2026
Hidden ChatGPT Tasks Leak Data Across Accounts

Hidden ChatGPT Tasks Leak Data Across Accounts

Check Point researchers demonstrated a real proof-of-concept where a victim’s ChatGPT session could be tricked into running hidden, attacker-controlled tasks in parallel with the user’s normal request. In the demo, the attacker used a covert cross-account channel to make ChatGPT access the victim’s…

September 8, 2026
Zero-Click Prompts Hijack AI Browsers via Email/X

Zero-Click Prompts Hijack AI Browsers via Email/X

Zenity demonstrated real-world attack chains where hidden instructions in emails or content on X can hijack AI “agentic browsers” (ChatGPT Atlas and the Claude Chrome extension). In the demos, the AI agent can be steered to perform actions in the user’s already logged-in sessions, sending phishing…

August 6, 2026
AI Browser Tricked into Spamming WhatsApp, Shopping

AI Browser Tricked into Spamming WhatsApp, Shopping

Researchers showed how a malicious web page could trick OpenAI’s Atlas AI-enabled browser into taking actions a user didn’t intend, like spamming WhatsApp contacts or modifying an Amazon account. The attacks used prompt-injection style instructions hidden in a seemingly legitimate “newsletter…

August 6, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment failed” billing email to drive victims to a credit-card theft page. The report also notes other brand-impersonation scams using cloned stores…

July 24, 2026