Fake ChatGPT billing email targets OpenAI passwords
Cofense found a phishing email posing as ChatGPT demanding a payment method update and citing a $23.80 debt. The button leads through a Google redirect to a fake OpenAI login page that sends entered credentials to attackers.
- Email comes from support@9527db6e1a[.]nxcli[.]io, not OpenAI
- Payment button goes through a notifications[.]googleapis[.]com redirect
- Fake page mimics auth.openai.com and collects credentials
- Cofense advises checking the address bar before entering a password
Read next
Security