OpenAI: Hackers Impersonate ChatGPT Subscription Alerts to Steal OpenAI Account Credentials

OpenAI: Hackers Impersonate ChatGPT Subscription Alerts to Steal OpenAI Account Credentials

ChatGPT Subscription Phishing Campaign Steals Credentials via Fake Billing Alerts

A new phishing campaign is exploiting ChatGPT subscription notices to steal user credentials, targeting individuals who use the AI service for work or personal purposes. The attack, identified by cybersecurity firm Cofense, impersonates OpenAI billing alerts, urging recipients to update payment details within 48 hours.

The fraudulent emails mimic legitimate OpenAI communications, featuring the company’s logo, official-sounding language, and a prominent "Update Payment Information" button. However, the sender address support@9527db6e1a[.]nxcli[.]io does not belong to OpenAI, and the embedded link redirects victims through a Google API wrapper before landing on attacker-controlled infrastructure.

Once clicked, the link directs users to a convincing but fake ChatGPT login page, where submitted credentials are harvested. Victims are then redirected to an error message, masking the theft. A successful breach could expose saved conversations and enable follow-on scams, particularly if users reuse passwords across personal and business accounts.

The campaign highlights the growing risk of social engineering targeting widely used subscription services. Attackers leverage trust in familiar brands and billing notifications to bypass skepticism, making these tactics particularly effective. Cofense’s report underscores how redirect chains and cloned login pages can obscure malicious intent, complicating detection.

While the operators behind the campaign remain unidentified, indicators of compromise (IoCs) include the sender domain nxcli[.]io and two malicious URLs used in the attack chain. The incident reflects broader trends in AI-themed phishing, where attackers exploit urgency and familiarity to compromise accounts.

Source: https://cybersecuritynews.com/chatgpt-subscription/

OpenAI TPRM report: https://www.rankiteo.com/company/openai

"id": "ope1789736218",
"linkid": "openai",
"type": "Cyber Attack",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Individuals using ChatGPT for '
                                              'work or personal purposes',
                        'industry': 'Artificial Intelligence',
                        'name': 'OpenAI (Impersonated)',
                        'type': 'Technology Company'}],
 'attack_vector': 'Email',
 'data_breach': {'data_exfiltration': 'Credentials harvested via fake login '
                                      'page',
                 'personally_identifiable_information': 'Potential (if '
                                                        'credentials are '
                                                        'reused for other '
                                                        'services)',
                 'sensitivity_of_data': 'High (Personally Identifiable '
                                        'Information if credentials are '
                                        'reused)',
                 'type_of_data_compromised': 'Credentials, Saved '
                                             'Conversations'},
 'description': 'A new phishing campaign is exploiting ChatGPT subscription '
                'notices to steal user credentials, targeting individuals who '
                'use the AI service for work or personal purposes. The attack '
                'impersonates OpenAI billing alerts, urging recipients to '
                'update payment details within 48 hours. The fraudulent emails '
                'mimic legitimate OpenAI communications but redirect victims '
                'to a fake ChatGPT login page where credentials are harvested.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage to '
                                       'OpenAI due to impersonation',
            'data_compromised': 'User credentials (potentially reused across '
                                'accounts), saved ChatGPT conversations',
            'identity_theft_risk': 'High (if credentials are reused for other '
                                   'services)'},
 'initial_access_broker': {'entry_point': 'Phishing Email'},
 'lessons_learned': 'Attackers leverage trust in familiar brands and billing '
                    'notifications to bypass skepticism. Redirect chains and '
                    'cloned login pages can obscure malicious intent, '
                    'complicating detection.',
 'motivation': 'Credential Theft',
 'post_incident_analysis': {'root_causes': 'Exploitation of trust in OpenAI '
                                           'brand, urgency tactics (48-hour '
                                           'deadline), and use of redirect '
                                           'chains to obscure malicious '
                                           'intent'},
 'recommendations': 'Users should verify sender addresses, avoid clicking on '
                    'embedded links in unsolicited emails, and enable '
                    'multi-factor authentication (MFA) to mitigate credential '
                    'theft risks.',
 'references': [{'source': 'Cofense'}],
 'response': {'third_party_assistance': 'Cofense (Cybersecurity Firm)'},
 'title': 'ChatGPT Subscription Phishing Campaign Steals Credentials via Fake '
          'Billing Alerts',
 'type': 'Phishing',
 'vulnerability_exploited': 'Social Engineering (Trust in Brand, Urgency)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.