ZeroHour
GBHackerspublished ()ingested Mayura Kathir
Part of a story covered by 2 sources: “Fake ChatGPT billing emails harvest OpenAI credentials via Google redirect to spoofed login pages” — merged summary and timeline →

ChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts

mediumPhishing & fraud exploited in the wildimportance 52
AI summary · glm-5.3-flash

Cofense identified a phishing campaign impersonating ChatGPT billing notices to steal OpenAI credentials and payment data via fake login pages hosted on nxcli.io.

Cofense's Phishing Defense Center observed emails posing as OpenAI subscription payment notices with a 48-hour deadline, sent from support@9527db6e1a[.]nxcli[.]io. Links route through notifications[.]googleapis[.]com redirect wrappers to credential-harvesting pages on e83cedb076[.]nxcli[.]io that closely mimic the ChatGPT login interface. After credentials are submitted, victims see an error page while attackers capture data that can expose account history, API usage, payment details, and sensitive prompts.

  • Emails pose as ChatGPT subscription payment notices with a 48-hour urgency deadline
  • Sender support@9527db6e1a[.]nxcli[.]io is not an OpenAI domain
  • Links redirect via notifications.googleapis.com to phishing pages on nxcli[.]io
  • Fake page mimics ChatGPT authentication and captures submitted credentials
  • Stolen credentials can expose API keys, prompts, files, and payment data

Indicators of compromiseAll →

TypeIndicatorContext
domain9527db6e1a.nxcli.iofraud. Cofense observed the email originating from support@9527db6e1a[.]nxcli[.]io , rather than a domain associated with OpenAI. The embe
domainauth.openai.comuthentication flows to use official OpenAI domains, such as auth[.]openai[.]com . In the campaign documented by Cofense, the phishing d
domaine83cedb076.nxcli.io[.]io subdomain, with observed phishing endpoints including e83cedb076[.]nxcli[.]io/fertaq/app/key[.]php and e83cedb076[.]nxcli[.]io/fertaq
domainkey.phphing endpoints including e83cedb076[.]nxcli[.]io/fertaq/app/key[.]php and e83cedb076[.]nxcli[.]io/fertaq/app/login[.]php . Phis
domainlogin.phpfertaq/app/key[.]php and e83cedb076[.]nxcli[.]io/fertaq/app/login[.]php . Phishing Page (Source : Cofense). After clicking the ma
domainnotifications.googleapis.cometection. The first-stage URL observed in the campaign uses notifications[.]googleapis[.]com/email/redirect , followed by a lengthy redirect paramet
domainnxcli.iotGPT Phishing Campaign The eventual payload is hosted on an nxcli[.]io subdomain, with observed phishing endpoints including e83
Full article656 words · extracted from gbhackers.com · click to collapse

Threat actors are increasingly impersonating OpenAI’s ChatGPT service in credential-phishing campaigns, exploiting the growing use of generative AI across both enterprise and personal environments.

A recently observed campaign uses a fraudulent subscription-payment notice to lure victims into disclosing OpenAI account credentials and potentially payment details through a convincing fake ChatGPT login page.

The lure claims that the recipient must update payment information to avoid disruption to their ChatGPT subscription.

By imitating a routine billing alert, attackers turn a familiar administrative task into an opportunity for account takeover.

The phishing email uses several social-engineering techniques commonly seen in campaigns spoofing Microsoft, Google, Adobe, and other high-value cloud services.

It displays the legitimate ChatGPT logo, uses polished branding elements, and signs off as “The OpenAI Team.”

These visual cues are intended to create confidence before the victim examines the underlying sender address or link destination.

A prominent message claiming “Subscription Payment Required” is paired with a deadline of “48 hours,” creating urgency and discouraging careful review.

The email also includes a large “Update Payment Information” button designed to direct users to the attacker-controlled infrastructure.

For organizations where ChatGPT is used for productivity, development, research, or content generation, the lure may appear particularly plausible because employees may legitimately hold paid ChatGPT subscriptions or use OpenAI accounts for work-related tasks.

Email Body (Source : Cofense).
 Email Body (Source : Cofense).

However, the sender address exposes the fraud. Cofense observed the email originating from support@9527db6e1a[.]nxcli[.]io, rather than a domain associated with OpenAI.

The embedded payment-update button also does not lead directly to an OpenAI-controlled destination.

Instead, it initially routes victims through a Google API wrapper URL before redirecting them to the final phishing infrastructure.

This multi-stage approach can help attackers obscure the final destination from casual inspection and may complicate automated reputation-based detection.

The first-stage URL observed in the campaign uses notifications[.]googleapis[.]com/email/redirect, followed by a lengthy redirect parameter.

The campaign was identified by the Cofense Phishing Defense Center (PDC), which reported that the malicious email poses as an OpenAI subscription invoice.

ChatGPT Phishing Campaign

The eventual payload is hosted on an nxcli[.]io subdomain, with observed phishing endpoints including e83cedb076[.]nxcli[.]io/fertaq/app/key[.]php and e83cedb076[.]nxcli[.]io/fertaq/app/login[.]php.

Phishing Page (Source : Cofense).
Phishing Page (Source : Cofense).

After clicking the malicious link, victims are presented with a page designed to closely resemble the ChatGPT authentication interface.

The site welcomes users back and incorporates familiar OpenAI-style logos, icons, and text to strengthen the deception.

A quick inspection of the browser address bar, however, reveals that the page is not hosted on OpenAI’s legitimate authentication infrastructure.

OpenAI users should expect authentication flows to use official OpenAI domains, such as auth[.]openai[.]com.

In the campaign documented by Cofense, the phishing domain does not match the legitimate ChatGPT login domain.

Once credentials are entered, victims are redirected to an error page, while the submitted information is captured by the attackers.

The risk extends beyond access to a single AI account. Compromised OpenAI credentials may expose account history, API usage, subscription details, payment data, and potentially sensitive prompts or files associated with the account.

For business users, stolen credentials could also give attackers insight into internal workflows, proprietary development activity, or employee use of AI tools.

Organizations should train users to verify sender domains, hover over payment-related links before clicking, and access ChatGPT by manually navigating to the official OpenAI website rather than following email prompts.

Security teams should block the identified nxcli[.]io infrastructure, investigate recipients of similar invoice-themed messages, and reset OpenAI credentials for any users suspected of interacting with the phishing page.

Multi-factor authentication and strong monitoring of SaaS login activity remain essential as threat actors expand their impersonation campaigns to target trusted AI platforms.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Mayura Kathirhttps://gbhackers.com/

Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/chatgpt-phishing-campaign/