ChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts
Cofense identified a phishing campaign impersonating ChatGPT billing notices to steal OpenAI credentials and payment data via fake login pages hosted on nxcli.io.
Cofense's Phishing Defense Center observed emails posing as OpenAI subscription payment notices with a 48-hour deadline, sent from support@9527db6e1a[.]nxcli[.]io. Links route through notifications[.]googleapis[.]com redirect wrappers to credential-harvesting pages on e83cedb076[.]nxcli[.]io that closely mimic the ChatGPT login interface. After credentials are submitted, victims see an error page while attackers capture data that can expose account history, API usage, payment details, and sensitive prompts.