Home · Technology · Sep 27 archive

Fake ChatGPT Billing Emails Steal Login Info

Confirmed

Technology Desk

In Short: According to the Cofense Phishing Defense Center, the fake email claims a subscription payment was declined and urges the recipient to update payment information. The email uses the real ChatGPT logo and a button that leads to a convincing copy of the ChatGPT login page.

ChatGPT Built Me a Phishing Campaign to Hack Emails
YouTube — cwade12c

Security researchers at Cofense uncovered a phishing campaign that impersonates OpenAI and ChatGPT, tricking users into revealing login information. The scam starts with an email that looks polished enough to make recipients pause.

The fake email is headed “Urgent: Update Your Payment Method to Avoid Service Interruption” and arrives from a fake sender address at 9527db6e1a.nxcli.io, not an OpenAI domain. It demands a $23.80 balance within 48 hours.

YouTube — cwade12c YouTube

Josh Varden of the Cofense Phishing Defense Center said, “With AI growing in popularity over the past few years, it is no surprise that threat actors are beginning to spoof ChatGPT.”

Researchers found two endpoints, login.php and key.php, on the same nxcli.io host, as tells. The same billing-urgency instinct works against OpenAI’s growing workforce and its expanding subscriber base, giving attackers more plausible billing contacts to imitate.

The phishing campaign has sent 4,500 emails to targets in South Africa, impersonating AI brands including ChatGPT, Microsoft Copilot, DeepSeek, and Anthropic’s Claude.

Halimah Delaine Prado, Google General Counsel, revealed the rise of AI-powered phishing scams originating from China's 'outsider enterprise.' These criminals use artificial intelligence to create highly convincing fake websites, impersonating trusted brands like T-Mobile to defraud hundreds of thousands of Americans, causing millions in losses.

The sites impersonate legitimate businesses and can steal payment details at checkout, including one-time bank verification codes. In some cases, researchers found fake stores loading assets directly from the legitimate company's servers.

Posts from this topic will be added to your daily email digest and your homepage feed.

What this adds

The fake email campaign was identified on September 18, 2026, by Cofense’s Phishing Defense Center.

The phishing campaign has sent 4,500 emails to targets in South Africa.

The New Mexico Supreme Court fined attorney Stephen Aarons $5,000 and held him in contempt for filing an appeal that included fabricated witness testimony and police statements generated by ChatGPT.

Background

A fake ChatGPT billing email is tricking users into revealing login information.

What's confirmed

What's still developing

Sources