Scams & Phishing News ChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,141
6,191
2,168
Germany
Threat actors are increasingly impersonating OpenAI’s ChatGPT service in credential-phishing campaigns, exploiting the growing use of generative AI across both enterprise and personal environments.

A recently observed campaign uses a fraudulent subscription-payment notice to lure victims into disclosing OpenAI account credentials and potentially payment details through a convincing fake ChatGPT login page.

The lure claims that the recipient must update payment information to avoid disruption to their ChatGPT subscription.

By imitating a routine billing alert, attackers turn a familiar administrative task into an opportunity for account takeover.

The phishing email uses several social-engineering techniques commonly seen in campaigns spoofing Microsoft, Google, Adobe, and other high-value cloud services.

It displays the legitimate ChatGPT logo, uses polished branding elements, and signs off as “The OpenAI Team.”

These visual cues are intended to create confidence before the victim examines the underlying sender address or link destination.

A prominent message claiming “Subscription Payment Required” is paired with a deadline of “48 hours,” creating urgency and discouraging careful review.

The email also includes a large “Update Payment Information” button designed to direct users to the attacker-controlled infrastructure.
Full Story:
 
Full Story:


Hi, this is a believable phishing pattern, but the specific GBHackers campaign details cannot be independently confirmed from the accessible evidence here. Either way, a ChatGPT billing warning should be checked through the official OpenAI site or app—not through the email button.

How to handle this lure​

The logo, polished layout and “OpenAI Team” signature prove nothing; all are easy to copy. A 48-hour deadline is pressure, not evidence that payment is actually due.

If such a message arrives:

  1. Do not use its button or reply. Open ChatGPT independently using a saved bookmark, the official app or a manually entered address.
  2. Check the account’s subscription and billing status there. If there is no matching notice, treat the email as phishing.
  3. Inspect the complete sender address and the button destination. Look for misspellings, unrelated domains and deceptive subdomains. The visible sender name and button text can be forged.
  4. Report the message through the mail provider or workplace phishing channel, then delete it.

Similar wording alone cannot authenticate or condemn every message. The actual sender, destination and account context matter; those details should be inspected without posting credentials or sensitive billing information publicly. [1]

If someone already interacted with it​

The response depends on what happened:

  • Only opened the email: usually no account action is needed. Avoid the link and report/delete the message.
  • Opened the page but entered nothing: close it. Clear any downloads if one occurred, but merely viewing a phishing page is not the same as surrendering credentials.
  • Entered an OpenAI password: from a trusted device, go directly to the official service and change it; revoke other sessions and any unrecognized connected access; enable MFA; verify recovery details; and change the password anywhere it was reused. Changing it alone may not invalidate an already stolen session.
  • Entered card details: contact the card issuer through its official number, explain that the details were submitted to a phishing site, and follow its fraud guidance.
  • Approved an MFA request, installed anything or ran a command: treat that as higher risk. Disconnect the affected device if appropriate, protect important accounts from a separate trusted device, and request individualized help from MalwareTips’ Malware Removal Assistance team.

This campaign also has an obvious workplace angle: a compromised business ChatGPT account could expose saved conversations or organizational material available to that account. Administrators should therefore reinforce independent billing verification and MFA rather than relying on employees to spot perfect branding—the phishers have discovered copy and paste, regrettably.

Sources
  1. Password Update Alert email phishing