
Fake ChatGPT Billing Emails Steal Card Details
Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…
Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment failed” billing email to drive victims to a credit-card theft page. The report also notes other brand-impersonation scams using cloned stores and fake login pages to steal credentials or payments.
According to Check Point, ChatGPT entered the top 10 most impersonated brands in Q2 2026. One documented example involved a fake email claiming a ChatGPT Plus subscription payment had failed. The message was dressed up to look exactly like an OpenAI billing notice, using the opening line "ChatGPT Plus payment failed" to create a sense of urgency. Victims who clicked through were directed to a page built purely to steal full credit card details.
This type of scheme fits a broader pattern Check Point calls brand phishing, where a scammer impersonates a trusted, well-known company by email and/or fake websites in order to steal login credentials, payment details or personal information. The report also references other cases, including cloned storefronts and a fake PayPal login page, showing that this approach is used across multiple well-known brands, not just one.
The email's effectiveness relied on close visual mimicry of a legitimate OpenAI billing notice combined with a plausible, low-friction pretext: a routine payment failure. Because subscription billing issues are common and often require quick action to avoid service interruption, recipients may feel pressured to resolve the problem immediately rather than pausing to verify the source. The target audience for this kind of lure is broad, spanning all employees as well as finance, procurement, and accounts payable staff who regularly handle payment information.
Organizations can reduce risk from this style of attack with a few practical habits:
This technique aligns with tactics such as Spearphishing Link and Malicious Link user execution, both commonly used in brand-impersonation campaigns designed to harvest payment or credential data at scale.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It was designed to look exactly like an OpenAI billing notice, claiming a ChatGPT Plus payment had failed and needed to be fixed.
The link led to a page built purely to steal full credit card details from the victim.
No. Microsoft remained the most impersonated brand in the report, accounting for 23% of observed phishing attempts, though ChatGPT entered the top 10 in Q2 2026.
Verify the request through a trusted path, such as typing the official site address directly or using a known bookmark, rather than clicking the link in the message.
You might trust a ChatGPT email, right? Phishers are counting on that. Check Point caught a fake 'ChatGPT Plus payment failed' email, dressed up exactly like an OpenAI billing notice, pushing you to 'update payment' on a cloned page that only wants your full card details. Here’s the trap: the logo, colors, and wording all look right, but the link takes you to some random domain, and the page pressures you to re-enter every card detail from scratch for an 'urgent' failed payment. If you ever see 'ChatGPT Plus payment failed', ignore the link. Instead, open chat.openai.com yourself or use your bookmark and check billing only from there.

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…

Cofense observed a real phishing campaign impersonating Google Ads Sync Accounts (MMC) with a fake “maintenance/system upgrade” notice. The email pressures…