Skip to content
A fake ChatGPT billing email is after your OpenAI password

A fake ChatGPT billing email is after your OpenAI password

Helpnetsecurity September 17, 2026

A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing Defense Center traced the email’s payment button through a Google redirect to the attacker’s page.

ChatGPT phishing email (Source: Cofense)

The email arrives from a sender named ChatGPT with the subject line “Urgent: Update Your Payment Method to Avoid Service Interruption.” It carries the ChatGPT logo, a final-notice tag and an outstanding balance of $23.80. It warns that the account may be suspended if billing isn’t fixed within 48 hours, then offers a large green “Update Payment Information” button and signs off as “The OpenAI Team.” The deadline and the bold type push the reader to click before looking closely.

The From line is where it falls apart. It comes from support@9527db6e1a[.]nxcli[.]io, which is not an OpenAI address.

The link runs through Google

The button does not link to the phishing site directly. Its URL starts at notifications[.]googleapis[.]com, a Google API redirect that forwards the browser to the payload. That complicates the usual advice to hover before clicking. Hovering shows a Google address where a reader would expect an OpenAI one, and Varden counts that mismatch as a giveaway. Catching it means knowing that a Google link has no business on an OpenAI invoice.

The fake landing page shows the ChatGPT logo and a “Welcome back” greeting above username and password boxes. The real sign-in page lives at auth.openai.com, and the browser’s address bar shows the difference to anyone who looks.

What to block and check

Cofense listed three indicators: the Google redirect link and two paths on the same nxcli[.]io host, login.php and key.php. Mail teams can their logs for all three. If you use ChatGPT, the check that matters takes two seconds: read the address bar and confirm it says auth.openai.com before you type a password.

Download: 2026 Credential Risk Report

The AI security question leaders should be asking instead

AI is adding to the review load on open-source projects, many of them thinly funded

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)

Download: The High-Performance Team Playbook

Simplify security management with CIS SecureSuite Platform

Download: The IT and security field guide to AI adoption

Fake AI trading agent steals crypto wallet passwords

The AI security question leaders should be asking instead

A flat cybersecurity budget doesn’t have to mean weaker coverage

AI is adding to the review load on open-source projects, many of them thinly funded

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)