- Content source
- https://gbhackers.com/chatgpt-phishing-campaign/
Full Story:Threat actors are increasingly impersonating OpenAI’s ChatGPT service in credential-phishing campaigns, exploiting the growing use of generative AI across both enterprise and personal environments.
A recently observed campaign uses a fraudulent subscription-payment notice to lure victims into disclosing OpenAI account credentials and potentially payment details through a convincing fake ChatGPT login page.
The lure claims that the recipient must update payment information to avoid disruption to their ChatGPT subscription.
By imitating a routine billing alert, attackers turn a familiar administrative task into an opportunity for account takeover.
The phishing email uses several social-engineering techniques commonly seen in campaigns spoofing Microsoft, Google, Adobe, and other high-value cloud services.
It displays the legitimate ChatGPT logo, uses polished branding elements, and signs off as “The OpenAI Team.”
These visual cues are intended to create confidence before the victim examines the underlying sender address or link destination.
A prominent message claiming “Subscription Payment Required” is paired with a deadline of “48 hours,” creating urgency and discouraging careful review.
The email also includes a large “Update Payment Information” button designed to direct users to the attacker-controlled infrastructure.
ChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts
Threat actors are increasingly impersonating OpenAI’s ChatGPT service in credential-phishing campaigns, exploiting the growing use of generative AI.
gbhackers.com