Fake ChatGPT Billing Emails Steal Card Details

TechRepublic Security · Medium sophistication
Last updated July 30, 2026

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit card numbers.

How the attack worked

In a documented case from June, scammers sent a fake ChatGPT Plus payment failure email designed to mimic an official OpenAI billing notice. The email pushed recipients to act quickly on a supposed billing problem. Clicking through led victims to a fraudulent page built to harvest full credit card numbers, disguised to look like a legitimate payment resolution flow.

This was not an isolated case. Check Point's reporting places ChatGPT in its top 10 most impersonated brands in phishing attacks for the first time in Q2 2026, a sign of how widely used the service has become and how attractive that popularity is to scammers. Other impersonation examples from the same period included a cloned Michael Kors storefront that replicated an entire checkout flow, a fake UNIQLO site, and a Microsoft support page pushing a bogus Office security update that actually installed malware.

Why it succeeded

Across nearly all of these cases, the trigger was urgency. Payment failures, security alerts, and required updates all push recipients to act before they stop to think, which is exactly the intended effect. A believable billing notice tied to a widely used service like ChatGPT Plus creates a plausible, low-friction reason to click immediately, especially for employees who manage their own subscriptions or expense payments.

What to watch for

  • Billing or payment failure emails that create pressure to act immediately
  • Security alerts or required update notices arriving unexpectedly
  • Links in emails that lead to a payment or login page instead of the official site
  • Small visual inconsistencies: a distorted logo, a login button that does not work, or a domain that is almost but not quite right
  • Requests to re-enter full credit card numbers to resolve a billing issue

Building resistance

Defenders and employees can reduce risk from this style of attack with a few consistent habits:

  • Treat subscription and billing problem emails as high-risk, and verify by typing the company's web address directly into a browser rather than clicking through the message
  • Slow down deliberately whenever a message frames the situation as urgent, whether it is a payment failure, a security alert, or a required update
  • Hover over links and buttons before clicking, and check the destination domain closely for subtle differences from the real one
  • Enable multifactor authentication wherever it is offered, so a captured password or card entry alone is less likely to lead to full account compromise

Because this campaign relied on a spoofed link and a fraudulent payment page rather than a technical exploit, awareness and verification habits are the most direct defense. Employees who manage AI subscriptions, expense payments, or IT support requests are worth prioritizing in training, since they are the roles most likely to encounter a believable version of this pretext.

Key findings

  • ChatGPT entered Check Point’s “top 10 most impersonated brands in phishing attacks” for the first time (Q2 2026).
  • A documented June case used a fake “ChatGPT Plus payment failure” email that led to a fraudulent page “built to harvest full credit card numbers.”
  • Other impersonation examples mentioned include a cloned Michael Kors checkout flow, a fake UNIQLO site, and a fake Microsoft support page pushing a bogus Office security update that installed malware.
  • Urgency is a common driver: “Payment failures, security alerts, and required updates all push you to act before you stop to think.”

Who’s being targeted

  • Commonly targeted roles: All employees, Finance/AP, IT/Helpdesk, Employees who manage subscriptions or expense payments, Executives (high click-risk brand impersonation).
  • Affected industries: Technology companies, Social media platforms, Banks, Retail (e-commerce).
  • Attack channels: email, website.
  • Impersonated: OpenAI billing / ChatGPT Plus, Michael Kors (cloned storefront), Microsoft Support / Office security update.

Red flags to watch for

  • Creates urgency around billing/payment failure
  • Link leads to a lookalike page rather than using the official site directly
  • Request for “full credit card numbers” via a page reached from an email link
  • Full checkout flow exists but is hosted on a non-official domain
  • Brand impersonation designed to look legitimate end-to-end
  • Pressure to complete purchase quickly (urgency trigger referenced broadly)
  • Support/update page is not reached via trusted internal update mechanisms
  • High-pressure language about “security alerts” or “required updates”
  • Update installs malware rather than a legitimate patch
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the fake ChatGPT billing scam work?

A fake ChatGPT Plus payment failure email mimicked an official OpenAI billing notice and led victims to a fraudulent page built to harvest full credit card numbers.

Why did ChatGPT become a phishing target?

Check Point reported ChatGPT entered its list of the top 10 most impersonated brands in phishing attacks for the first time in Q2 2026, reflecting how mainstream the service has become.

What other brands were impersonated in similar scams?

The same reporting period included a cloned Michael Kors checkout flow, a fake UNIQLO site, and a fake Microsoft support page pushing a bogus Office security update that installed malware.

What is the best way to verify a billing email is legitimate?

Verify the billing issue by navigating directly to the vendor's official site rather than clicking links in the email, and check for small inconsistencies like distorted logos or slightly wrong domains.

Read the video transcript

ChatGPT just hit Check Point’s top 10 most impersonated brands. So yes, fake ChatGPT billing emails are now a thing. One June case: a “ChatGPT Plus payment failure” email that looked like an OpenAI notice. Click the button, and you land on a perfect-looking ChatGPT billing page built just to harvest your full credit card number. Same playbook shows up as a cloned Michael Kors checkout or a fake Microsoft support page pushing an urgent Office update. Different brands, same trick: scare you with payment failures or security alerts so you type before you think. If you get a ChatGPT Plus or billing scare email, don’t touch the link. Open your browser, go to chatgpt.com or openai.com yourself, and check your account there.

Similar attacks