Helpnetsecurity Phishing Attack Targets OpenAI Users via Fake ChatGPT Email
Article Content
- •Phishing email impersonates OpenAI to steal user credentials.
- •Urgent language and fake billing claims pressure users to act quickly.
- •Users must verify URLs to avoid falling for the scam.
A phishing campaign is targeting OpenAI users with a fake ChatGPT billing email that attempts to steal login credentials. The email, appearing to be from ChatGPT, claims an outstanding balance of $23.80 and urges users to update their payment information within 48 hours to avoid service interruption. The email directs users to a fraudulent login page mimicking OpenAI's official site, using a Google redirect to obscure the true destination. Security experts from Cofense identified the phishing indicators, including the suspicious sender address and the misleading Google link. Users are advised to verify the URL before entering any credentials. This attack exploits social engineering tactics to create a sense of urgency. No specific CVEs are mentioned in relation to this phishing attempt. The current status indicates ongoing risk for users who may fall victim to this scam.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track OpenAI and CVE-2026-90894 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Cybercriminals Use Fake AI Agents to Steal Crypto Wallets Cybercriminals are exploiting interest in Agentic AI by creating fake AI trading agents to lure crypto users into downloading malware. This malware, known as Needle Stealer, replaces legitimate browser wallet extensions like MetaMask and Coinbase with malicious versions that capture user credentials. The attacks were…
FBI Seizes NightmareStresser DDoS-for-Hire Domains in Major Crackdown On September 15, 2026, the FBI seized the domains of NightmareStresser, a notorious DDoS-for-hire service linked to hundreds of thousands of attacks since 2022. This operation, part of the ongoing Operation PowerOFF, targeted infrastructure enabling users to launch distributed denial-of-service attacks against various…