
Fake ChatGPT Billing Emails Steal Card Details
Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…
Researchers and the FBI warn that criminals are luring World Cup fans to convincing fake FIFA ticket websites, often via social media ads and shared links. The scam steals payment details in real time during checkout, including card data and one-time passcodes (OTPs), while victims believe they are buying legitimate tickets.
Criminals built cloned versions of FIFA's official ticketing site, copying tournament news, match schedules, stadium information, and the ticket purchasing flow to make the pages look authentic. Fans arrived at these pages mainly through Facebook and Instagram ads and shared links rather than by navigating directly to an official source. Once a victim reached checkout, the fraudulent site captured card numbers, expiration dates, CVV codes, and one-time passwords (OTPs) in real time, giving attackers everything needed to complete unauthorized transactions.
Researchers observed this was not a single opportunistic site but an organized operation, with multiple operators using shared infrastructure. The FBI reported dozens of fraudulent domains impersonating FIFA, many relying on typosquatting: subtle misspellings or different domain extensions designed to pass a quick glance as the real thing.
Several factors made this scam effective:
Organizations with staff who travel, manage events, or handle expense purchases should reinforce a few habits. Buy tickets only through official sources or authorized partners, and avoid third-party sellers that cannot be verified. Encourage people to type the official website address directly rather than clicking links shared on social platforms. Train finance teams and cardholders to treat OTP requests on unfamiliar checkout pages as a signal to stop and verify the site's legitimacy before entering any payment information.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
The phishing infrastructure captured payment card details, including card numbers, expiration dates, CVV codes, and one-time passwords (OTPs) during the checkout process on cloned FIFA ticketing pages.
Much of the malicious traffic originated from Facebook and Instagram, where advertisements and shared links directed fans to fraudulent ticketing websites.
Attackers created look alike websites with subtle misspellings or different domain extensions to trick fans into believing they were visiting the official FIFA website.
Purchase tickets directly from official platforms or authorized partners, avoid links shared on social media or in unsolicited messages, and treat unusually cheap tickets or urgent sales pitches as red flags.
You see a Facebook ad for World Cup tickets that looks totally official, FIFA logo, stadium pics, the works. You click through to a site that’s cloned FIFA’s real page, news, match schedules, stadium info, and a slick ticket checkout that asks for your card and an OTP texted to your phone. Here’s the trap: the FBI found dozens of fake FIFA domains with tiny misspellings and odd extensions. If you reached the checkout from a social media ad, and the URL isn’t exactly fifa.com or an official partner, that OTP box is a giant red flag. If you want tickets, don’t touch links in ads or posts. Type the official site address yourself and only buy through FIFA or verified partners.

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…

Scammers are posing as FBI staff who supposedly handle IC3 (Internet Crime Complaint Center) reports to trick people who have already been scammed once. The…

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment…

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into…

The “Pink” data extortion group is running a real-world voice phishing campaign targeting employees in Microsoft 365 / Entra ID environments. Callers…

The FBI warns scammers are impersonating FBI/IC3 staff and re-targeting people who already lost money to fraud. The scammers use emails, phone calls, social…