Phishing Campaign Impersonated OpenAI for Credentials

A new phishing scheme uses fraudulent billing alerts to harvest ChatGPT account credentials and payment data.

Updated on Sept. 27, 2026 in Artificial Intelligence

Isometric editorial illustration of a complex data lattice and fiber optic network, representing cybersecurity infrastructure threats.
Security researchers have identified a phishing campaign targeting ChatGPT users by impersonating OpenAI billing notifications to harvest account credentials and payment information. AI Illustration. Upload story photo >

Live Poll

Do you feel confident in your ability to spot a sophisticated phishing email?

Security researchers have identified a phishing campaign impersonating OpenAI to steal user account and payment information. The attack lures victims through emails claiming that a ChatGPT subscription payment requires immediate attention.

Why it matters

The campaign exploits the ubiquity of routine billing notifications to pressure users into surrendering sensitive data. By mimicking legitimate administrative communication, the attackers target both personal and work account credentials.

The attackers utilize a Google API redirect to mask the ultimate destination of phishing links before reaching a malicious site. These landing pages visually replicate the logos, icons, and official text found on the legitimate ChatGPT login page.

The players

Cofense

A cybersecurity firm specializing in phish detection and incident response services for enterprise security teams.

OpenAI

An artificial intelligence research and deployment company that develops the ChatGPT product suite.

The details

The mechanism relies on social engineering designed to instill urgency, specifically warning users that a payment update is required within 48 hours to maintain service. The phishing emails originate from the domain support@9527db6e1a.nxcli.io. By routing traffic through a Google API, the attackers attempt to obscure the malicious nature of the destination URL from security filters.

Timeline

  1. September 27, 2026: The phishing campaign was identified and reported by security researchers.

The Tech Race

This campaign mirrors an increasing industry trend where attackers focus on AI-as-a-service platforms as high-value targets for credential harvesting. Security research organizations are now prioritizing the identification of these specific impersonation tactics to counter the rise of AI-brand spoofing.

Users should verify that payment update notifications originate only from the official ChatGPT.com domain rather than external links. Those who suspect they have interacted with these emails should immediately log out of all active devices to terminate potentially compromised sessions.

The takeaway

The campaign demonstrates that even widely used productivity tools are now primary vectors for credential theft. Users should watch for any billing notifications that use non-official domains and always navigate directly to the service provider for account changes.

Further reading

For broader trends in platform security, visit the Artificial Intelligence section.

Live Poll

Do you feel confident in your ability to spot a sophisticated phishing email?