Fake ChatGPT Billing Emails Steal Card Details

Infosecurity Magazine · Medium sophistication
Last updated July 30, 2026

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment failed” billing email to drive victims to a credit-card theft page. The report also notes other brand-impersonation scams using cloned stores and fake login pages to steal credentials or payments.

How the Attack Worked

According to Check Point, ChatGPT entered the top 10 most impersonated brands in Q2 2026. One documented example involved a fake email claiming a ChatGPT Plus subscription payment had failed. The message was dressed up to look exactly like an OpenAI billing notice, using the opening line "ChatGPT Plus payment failed" to create a sense of urgency. Victims who clicked through were directed to a page built purely to steal full credit card details.

This type of scheme fits a broader pattern Check Point calls brand phishing, where a scammer impersonates a trusted, well-known company by email and/or fake websites in order to steal login credentials, payment details or personal information. The report also references other cases, including cloned storefronts and a fake PayPal login page, showing that this approach is used across multiple well-known brands, not just one.

Why It Succeeded

The email's effectiveness relied on close visual mimicry of a legitimate OpenAI billing notice combined with a plausible, low-friction pretext: a routine payment failure. Because subscription billing issues are common and often require quick action to avoid service interruption, recipients may feel pressured to resolve the problem immediately rather than pausing to verify the source. The target audience for this kind of lure is broad, spanning all employees as well as finance, procurement, and accounts payable staff who regularly handle payment information.

What to Watch For

  • An unexpected billing failure notice that pressures immediate action
  • A link leading to a payment page requesting full credit card details
  • Emails that closely replicate a well-known brand's look and formatting but request unusual or sensitive information
  • Any request to re-enter payment credentials outside of a normal account login flow

Building Resistance

Organizations can reduce risk from this style of attack with a few practical habits:

  • Treat unexpected subscription or payment failure emails as suspicious, and verify by logging in through a typed URL or saved bookmark instead of clicking email links.
  • Train staff to focus on what information a message is requesting and where its links actually lead, rather than relying on logos or formatting to judge legitimacy.
  • Reinforce that brand phishing targets both credentials and payment data, so employees should never enter card details from a link in an unsolicited message.
  • Encourage reporting of suspicious billing or subscription emails to IT or helpdesk teams so patterns can be tracked across the organization.

This technique aligns with tactics such as Spearphishing Link and Malicious Link user execution, both commonly used in brand-impersonation campaigns designed to harvest payment or credential data at scale.

Key findings

  • ChatGPT entered the top 10 most impersonated brands in Q2 2026, per Check Point.
  • Check Point observed a fake “ChatGPT Plus payment failed” email that mimicked an OpenAI billing notice and led to a credit-card theft page.
  • Microsoft remained the most impersonated brand in the report, accounting for 23% of observed phishing attempts.
  • The report describes brand phishing as impersonation via email and/or fake websites to steal “login credentials, payment details or personal information.”
  • Other real-world cases mentioned include cloned storefronts and a fake PayPal login page.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, Procurement, Accounts Payable, IT / Helpdesk.
  • Affected industries: Technology, Social networks, Banking, Retail / eCommerce (apparel).
  • Attack channels: email, website.
  • Impersonated: OpenAI / ChatGPT Billing.

Red flags to watch for

  • Unexpected billing failure notice that pressures you to take action
  • Link leads to a lookalike payment page designed to collect card details
  • Email is “dressed up to look exactly like an OpenAI billing notice” (brand impersonation)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What did the fake ChatGPT email look like?

It was designed to look exactly like an OpenAI billing notice, claiming a ChatGPT Plus payment had failed and needed to be fixed.

What happened if someone clicked the link?

The link led to a page built purely to steal full credit card details from the victim.

Is ChatGPT the most impersonated brand?

No. Microsoft remained the most impersonated brand in the report, accounting for 23% of observed phishing attempts, though ChatGPT entered the top 10 in Q2 2026.

What should employees do with unexpected billing emails?

Verify the request through a trusted path, such as typing the official site address directly or using a known bookmark, rather than clicking the link in the message.

Read the video transcript

You might trust a ChatGPT email, right? Phishers are counting on that. Check Point caught a fake 'ChatGPT Plus payment failed' email, dressed up exactly like an OpenAI billing notice, pushing you to 'update payment' on a cloned page that only wants your full card details. Here’s the trap: the logo, colors, and wording all look right, but the link takes you to some random domain, and the page pressures you to re-enter every card detail from scratch for an 'urgent' failed payment. If you ever see 'ChatGPT Plus payment failed', ignore the link. Instead, open chat.openai.com yourself or use your bookmark and check billing only from there.

Similar attacks