Fake ChatGPT Invoice Email Steals Logins

IT Pro Security · Medium sophistication
Last updated September 18, 2026

Attackers are sending fake ChatGPT billing emails that pressure people to “update payment” within 48 hours to avoid service interruption. The message links to a convincing look‑alike ChatGPT login page via a Google redirect, aiming to steal OpenAI credentials.

Key findings

  • A fake ChatGPT subscription invoice email is being used to steal OpenAI account credentials.
  • The lure uses urgency: victims are told to pay an outstanding balance of $23.80 within 48 hours to avoid service interruption.
  • The sender address is not an OpenAI domain (support@9527db6e1a.nxcli.io).
  • The “Update Payment Information” button uses a Google redirect that ultimately sends victims to a malicious page resembling the real ChatGPT sign-in portal.
  • Indicators of compromise included the Google redirect and two nxcli[.]io paths: login.php and key.php.
  • The article notes broader AI-brand impersonation campaigns affecting South Africa, Switzerland, and Austria, including large-scale email volumes.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance/Accounts Payable, Executives, IT/Helpdesk.
  • Affected industries: Technology, Professional Services, Any business using AI SaaS tools, Consumers / personal email users.
  • Attack channels: email, website.
  • Impersonated: ChatGPT / OpenAI Billing Support.

Awareness takeaways

  • Treat “urgent payment update” messages as high-risk and verify through the official site/app, not the email button.
  • Check sender domains carefully, brand names and logos don’t prove legitimacy.
  • Hover/check links and confirm you are on the real login domain before entering credentials (e.g., auth.openai.com).
  • Assume attackers will imitate popular AI tools (and other big brands) and build training around these look-alike login pages.

Red flags to watch for

  • Sender domain is not an official OpenAI domain (nxcli.io).
  • Link uses a Google redirect/wrapper before landing on a login page.
  • URL does not match the legitimate login host (users should see auth.openai.com).
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: "Urgent: Update Your Payment Method to Avoid Service Interruption" for a $23.80 ChatGPT invoice. It looks legit, but the sender is support@9527db6e1a.nxcli.io, and the "Update Payment Information" button hides a Google redirect that lands on a fake ChatGPT login page. Here’s the trick: the page looks like ChatGPT, but the URL is nxcli.io with paths like login.php and key.php. If it’s real, you should see auth.openai.com in the address bar. If you get an urgent ChatGPT payment email, don’t click the button, open your browser, type auth.openai.com yourself, and sign in from there.

Similar attacks

Fake ChatGPT Invoice Steals Login Credentials

Fake ChatGPT Invoice Steals Login Credentials

Cofense observed a real phishing email that impersonates OpenAI/ChatGPT billing to trick users into “updating” payment details. The email uses the real ChatGPT logo, urgency (“48 hours”), and a prominent button to drive clicks to a lookalike ChatGPT login page. Any credentials entered are harvested…

September 17, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
AI Browser Tricked into Spamming WhatsApp, Shopping

AI Browser Tricked into Spamming WhatsApp, Shopping

Researchers showed how a malicious web page could trick OpenAI’s Atlas AI-enabled browser into taking actions a user didn’t intend, like spamming WhatsApp contacts or modifying an Amazon account. The attacks used prompt-injection style instructions hidden in a seemingly legitimate “newsletter…

August 6, 2026
Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
Fake Google Ads “Sync” Alert Steals Credentials

Fake Google Ads “Sync” Alert Steals Credentials

Cofense observed a real phishing campaign impersonating Google Ads Sync Accounts (MMC) with a fake “maintenance/system upgrade” notice. The email pressures recipients to click “Complete Sync Account,” sending them through lookalike sites and a fake Google sign-in pop-up that captures credentials.…

July 21, 2026