ZeroHour
Vendor

Cofense

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

ChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts

Cofense identified a phishing campaign impersonating ChatGPT billing notices to steal OpenAI credentials and payment data via fake login pages hosted on nxcli.io.

Cofense's Phishing Defense Center observed emails posing as OpenAI subscription payment notices with a 48-hour deadline, sent from support@9527db6e1a[.]nxcli[.]io. Links route through notifications[.]googleapis[.]com redirect wrappers to credential-harvesting pages on e83cedb076[.]nxcli[.]io that closely mimic the ChatGPT login interface. After credentials are submitted, victims see an error page while attackers capture data that can expose account history, API usage, payment details, and sensitive prompts.

GBHackers · 5h agoPhishing & fraud in the wild 2 sources

A fake ChatGPT billing email is after your OpenAI password

Cofense reports a fake ChatGPT billing email harvesting OpenAI credentials via a Google redirect to a spoofed login page.

Cofense's Phishing Defense Center traced a fake ChatGPT billing email, sent from support@9527db6e1a[.]nxcli[.]io, claiming a $23.80 overdue balance and a 48-hour deadline before account suspension. The 'Update Payment Information' button routes through a notifications[.]googleapis[.]com redirect to a spoofed OpenAI login page that captures credentials and sends victims to an error page. Cofense published indicators including the Google redirect link plus login.php and key.php paths on the nxcli[.]io host.

Help Net Securityupdated · 5h agofirst · 1d agoPhishing & fraud in the wild 2 sources

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.