Home · Technology · Sep 27 archive
Fake ChatGPT Billing Emails Steal Login Info
Confirmed
In Short: According to the Cofense Phishing Defense Center, the fake email claims a subscription payment was declined and urges the recipient to update payment information. The email uses the real ChatGPT logo and a button that leads to a convincing copy of the ChatGPT login page.

Security researchers at Cofense uncovered a phishing campaign that impersonates OpenAI and ChatGPT, tricking users into revealing login information. The scam starts with an email that looks polished enough to make recipients pause.
The fake email is headed “Urgent: Update Your Payment Method to Avoid Service Interruption” and arrives from a fake sender address at 9527db6e1a.nxcli.io, not an OpenAI domain. It demands a $23.80 balance within 48 hours.
Josh Varden of the Cofense Phishing Defense Center said, “With AI growing in popularity over the past few years, it is no surprise that threat actors are beginning to spoof ChatGPT.”
Researchers found two endpoints, login.php and key.php, on the same nxcli.io host, as tells. The same billing-urgency instinct works against OpenAI’s growing workforce and its expanding subscriber base, giving attackers more plausible billing contacts to imitate.
The phishing campaign has sent 4,500 emails to targets in South Africa, impersonating AI brands including ChatGPT, Microsoft Copilot, DeepSeek, and Anthropic’s Claude.
Halimah Delaine Prado, Google General Counsel, revealed the rise of AI-powered phishing scams originating from China's 'outsider enterprise.' These criminals use artificial intelligence to create highly convincing fake websites, impersonating trusted brands like T-Mobile to defraud hundreds of thousands of Americans, causing millions in losses.
The sites impersonate legitimate businesses and can steal payment details at checkout, including one-time bank verification codes. In some cases, researchers found fake stores loading assets directly from the legitimate company's servers.
Posts from this topic will be added to your daily email digest and your homepage feed.
What this adds
The fake email campaign was identified on September 18, 2026, by Cofense’s Phishing Defense Center.
The phishing campaign has sent 4,500 emails to targets in South Africa.
The New Mexico Supreme Court fined attorney Stephen Aarons $5,000 and held him in contempt for filing an appeal that included fabricated witness testimony and police statements generated by ChatGPT.
Background
A fake ChatGPT billing email is tricking users into revealing login information.
What's confirmed
- According to the Cofense Phishing Defense Center, it uses the real ChatGPT logo and claims your subscription payment needs attention.
- If you are checking email between meetings or quickly scrolling on your phone, all of that can feel believable.
- However, the domain in the browser does not match the legitimate ChatGPT login domain identified by Cofense.
- If you pay for ChatGPT, an email saying there is a problem with your subscription could easily get your attention.
- Either way, you probably want to fix it before anything happens to your account.
- Security researchers at Cofense uncovered a phishing campaign that impersonates OpenAI and ChatGPT.
- The fake email looks like a routine subscription notice.
- However, the button inside can lead to a convincing copy of the ChatGPT login page.
What's still developing
- Many lawyers have been caught citing fake cases in briefs or inaccurately describing real cases.
- While Aarons didn’t cite fake cases, he inaccurately described real ones and cited fake testimony.
- Aarons told the state Supreme Court at a hearing on August 21 that he fed a computer-generated transcript of the murder trial and other documents related to the case into ChatGPT, which outputted the fake quotes.
- Aarons added that the cases he cited in his brief were not fake, although his brief described them inaccurately.
- Bacon responded that there’s no “material distinction” between inaccurately describing a real case and citing a fake one, as the rules about candor to the court apply “with equal force” either way.
- The New Mexico Supreme Court held a ChatGPT-using lawyer in direct contempt of court for submitting a brief with “false testimony from wholly fabricated witnesses,” including fake police testimony and other mistakes.
- A little over a year ago, in August 2025, Aarons submitted the brief containing fake testimony and other errors.
- The New Mexico Supreme Court fined attorney Stephen Aarons $5,000 and held him in contempt for filing an appeal that included fabricated witness testimony and police statements generated by ChatGPT.
- Aarons admitted he used ChatGPT to summarize trial proceedings for the appeal of Oscar Renee Sandoval, convicted for the murder of the mother of his children, but failed to verify the output’s accuracy.
- A defense lawyer appealing his client’s murder conviction submitted a brief containing made-up police testimony and witnesses fabricated by OpenAI’s ChatGPT, New Mexico’s highest court has said.
- Aarons, in a statement to the Reuters news agency, said he had used ChatGPT to summarise the trial proceedings when he agreed to take up the defendant’s appeal last year, and did not understand the degree to which AI could “hallucinate” facts.
- Aarons told the court at an August 21 hearing that he fed a computer-generated transcript and other case materials to ChatGPT, presuming it would generate “a bulletproof summary”.
