Home / Technology / Fake ChatGPT Email Steals Account Details
Fake ChatGPT Email Steals Account Details
27 Sep
Summary
- Phishing emails mimic ChatGPT subscription warnings.
- Fake login pages steal credentials and payment info.
- Check sender address and domain before clicking links.

Cybercriminals are launching a sophisticated phishing campaign that impersonates ChatGPT's subscription billing notifications. These deceptive emails, featuring the official ChatGPT logo and urgent language like 'Subscription Payment Required,' aim to trick users into believing their payment details need updating. The emails pressure recipients to act within 48 hours, providing a prominent button to 'Update Payment Information.'
Upon clicking this button, users are redirected through a Google API before landing on a malicious site. This site is a near-perfect replica of the legitimate ChatGPT login page, designed to capture entered usernames and passwords. Security researchers caution that while the sender's email address is a key red flag (e.g., using domains like ".nxcli.io" instead of official OpenAI domains), the deceptive nature of the fake login page makes it harder to spot.
To protect yourself, always verify the sender's full email address against official OpenAI domains (@openai.com, @mail.openai.com, etc.). Before entering any login or payment information, meticulously check the browser's address bar for the correct domain. If unsure, bypass the email link entirely and navigate directly to the official ChatGPT website or app to manage your account settings.