
Fake ChatGPT Billing Emails Steal Card Details
Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment…
Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit card numbers.
In a documented case from June, scammers sent a fake ChatGPT Plus payment failure email designed to mimic an official OpenAI billing notice. The email pushed recipients to act quickly on a supposed billing problem. Clicking through led victims to a fraudulent page built to harvest full credit card numbers, disguised to look like a legitimate payment resolution flow.
This was not an isolated case. Check Point's reporting places ChatGPT in its top 10 most impersonated brands in phishing attacks for the first time in Q2 2026, a sign of how widely used the service has become and how attractive that popularity is to scammers. Other impersonation examples from the same period included a cloned Michael Kors storefront that replicated an entire checkout flow, a fake UNIQLO site, and a Microsoft support page pushing a bogus Office security update that actually installed malware.
Across nearly all of these cases, the trigger was urgency. Payment failures, security alerts, and required updates all push recipients to act before they stop to think, which is exactly the intended effect. A believable billing notice tied to a widely used service like ChatGPT Plus creates a plausible, low-friction reason to click immediately, especially for employees who manage their own subscriptions or expense payments.
Defenders and employees can reduce risk from this style of attack with a few consistent habits:
Because this campaign relied on a spoofed link and a fraudulent payment page rather than a technical exploit, awareness and verification habits are the most direct defense. Employees who manage AI subscriptions, expense payments, or IT support requests are worth prioritizing in training, since they are the roles most likely to encounter a believable version of this pretext.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
A fake ChatGPT Plus payment failure email mimicked an official OpenAI billing notice and led victims to a fraudulent page built to harvest full credit card numbers.
Check Point reported ChatGPT entered its list of the top 10 most impersonated brands in phishing attacks for the first time in Q2 2026, reflecting how mainstream the service has become.
The same reporting period included a cloned Michael Kors checkout flow, a fake UNIQLO site, and a fake Microsoft support page pushing a bogus Office security update that installed malware.
Verify the billing issue by navigating directly to the vendor's official site rather than clicking links in the email, and check for small inconsistencies like distorted logos or slightly wrong domains.
ChatGPT just hit Check Point’s top 10 most impersonated brands. So yes, fake ChatGPT billing emails are now a thing. One June case: a “ChatGPT Plus payment failure” email that looked like an OpenAI notice. Click the button, and you land on a perfect-looking ChatGPT billing page built just to harvest your full credit card number. Same playbook shows up as a cloned Michael Kors checkout or a fake Microsoft support page pushing an urgent Office update. Different brands, same trick: scare you with payment failures or security alerts so you type before you think. If you get a ChatGPT Plus or billing scare email, don’t touch the link. Open your browser, go to chatgpt.com or openai.com yourself, and check your account there.

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment…

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…