Cofense Uncovers 48-Hour ChatGPT Phishing Scam Stealing Credentials and Card Data
Updated
Updated · Fox News · Sep 27
Cofense Uncovers 48-Hour ChatGPT Phishing Scam Stealing Credentials and Card Data
2 articles · Updated · Fox News · Sep 27
Summary
Cofense found a phishing campaign sending fake ChatGPT billing emails that claim a payment failed and give users 48 hours to update subscription details.
The emails impersonate OpenAI with ChatGPT branding, but Cofense traced one sender to support@9527db6e1a[.]nxcli[.]io rather than an official OpenAI domain.
Clicking the payment button routes victims through a Google API redirect to a counterfeit ChatGPT login page on an unrelated domain, where attackers capture passwords and payment information.
OpenAI did not comment before deadline; Cofense urged users to check billing only through ChatGPT directly, verify sender and website domains, and enable 2FA.
The campaign shows how attackers are exploiting ChatGPT's mainstream use and trusted branding to target both personal and workplace accounts.