ZeroHour
Help Net Securitypublished ()ingested Anamarija Pogorelec

A fake ChatGPT billing email is after your OpenAI password

mediumPhishing & fraud exploited in the wildimportance 45
AI summary · glm-5.3-flash

Cofense reports a fake ChatGPT billing email harvesting OpenAI credentials via a Google redirect to a spoofed login page.

Cofense's Phishing Defense Center traced a fake ChatGPT billing email, sent from support@9527db6e1a[.]nxcli[.]io, claiming a $23.80 overdue balance and a 48-hour deadline before account suspension. The 'Update Payment Information' button routes through a notifications[.]googleapis[.]com redirect to a spoofed OpenAI login page that captures credentials and sends victims to an error page. Cofense published indicators including the Google redirect link plus login.php and key.php paths on the nxcli[.]io host.

  • Email spoofs ChatGPT billing with $23.80 balance and 48-hour suspension deadline
  • Button uses notifications[.]googleapis[.]com redirect, so hover checks reveal a Google URL
  • Fake 'Welcome back' page captures credentials, then sends victims to an error page
  • Indicators include login.php and key.php paths on the nxcli[.]io host
ProductsChatGPT

Indicators of compromiseAll →

TypeIndicatorContext
domain9527db6e1a.nxcli.iohe From line is where it falls apart. It comes from support@9527db6e1a[.]nxcli[.]io, which is not an OpenAI address. The link runs through
domainnotifications.googleapis.coms not link to the phishing site directly. Its URL starts at notifications[.]googleapis[.]com, a Google API redirect that forwards the browser to the
domainnxcli.ioicators: the Google redirect link and two paths on the same nxcli[.]io host, login.php and key.php. Mail teams can search their
Full article369 words · extracted from helpnetsecurity.com · click to collapse

A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing Defense Center traced the email’s payment button through a Google redirect to the attacker’s page.

The lure targets ChatGPT users on work and personal accounts alike, and it copies the kind of bill a subscriber already expects. Credentials entered on the fake page go to the attacker, and the victim is sent on to an error page.

ChatGPT phishing email

ChatGPT phishing email (Source: Cofense)

The bill looks right

The email arrives from a sender named ChatGPT with the subject line “Urgent: Update Your Payment Method to Avoid Service Interruption.” It carries the ChatGPT logo, a final-notice tag and an outstanding balance of $23.80. It warns that the account may be suspended if billing isn’t fixed within 48 hours, then offers a large green “Update Payment Information” button and signs off as “The OpenAI Team.” The deadline and the bold type push the reader to click before looking closely.

The From line is where it falls apart. It comes from support@9527db6e1a[.]nxcli[.]io, which is not an OpenAI address.

The link runs through Google

The button does not link to the phishing site directly. Its URL starts at notifications[.]googleapis[.]com, a Google API redirect that forwards the browser to the payload. That complicates the usual advice to hover before clicking. Hovering shows a Google address where a reader would expect an OpenAI one, and Varden counts that mismatch as a giveaway. Catching it means knowing that a Google link has no business on an OpenAI invoice.

The fake landing page shows the ChatGPT logo and a “Welcome back” greeting above username and password boxes. The real sign-in page lives at auth.openai.com, and the browser’s address bar shows the difference to anyone who looks.

What to block and check

Cofense listed three indicators: the Google redirect link and two paths on the same nxcli[.]io host, login.php and key.php. Mail teams can search their logs for all three. If you use ChatGPT, the check that matters takes two seconds: read the address bar and confirm it says auth.openai.com before you type a password.

Download: 2026 Credential Risk Report

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/09/17/chatgpt-phishing-email-openai-password/