Skip to content
Phishing Attack Targets OpenAI Users via Fake ChatGPT Email

Phishing Attack Targets OpenAI Users via Fake ChatGPT Email

First seen 17 Sep 2026, 17:28 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 17, 2026 at 19:54 UTC
  • Phishing email impersonates OpenAI to steal user credentials.
  • Urgent language and fake billing claims pressure users to act quickly.
  • Users must verify URLs to avoid falling for the scam.

A phishing campaign is targeting OpenAI users with a fake ChatGPT billing email that attempts to steal login credentials. The email, appearing to be from ChatGPT, claims an outstanding balance of $23.80 and urges users to update their payment information within 48 hours to avoid service interruption. The email directs users to a fraudulent login page mimicking OpenAI's official site, using a Google redirect to obscure the true destination. Security experts from Cofense identified the phishing indicators, including the suspicious sender address and the misleading Google link. Users are advised to verify the URL before entering any credentials. This attack exploits social engineering tactics to create a sense of urgency. No specific CVEs are mentioned in relation to this phishing attempt. The current status indicates ongoing risk for users who may fall victim to this scam.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-14
CVE-2026-90894 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-17
Phishing email campaign identified
Cofense reported a phishing email targeting OpenAI users, urging them to update payment information.
Helpnetsecurity

More articles in this cluster (2)

Following this threat?

Track OpenAI and CVE-2026-90894 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed