Hackers Impersonate ChatGPT Subscription Alerts to Steal OpenAI Account Credentials
Cofense reports a phishing campaign using fake ChatGPT subscription payment notices to lure users to credential-harvesting pages and steal OpenAI account logins.
Cofense identified phishing emails impersonating ChatGPT subscription invoices, using the genuine logo, 'Subscription Payment Required' wording, and a 48-hour urgency deadline. Links route through a Google notifications API redirect wrapper to attacker-controlled nxcli[.]io infrastructure hosting a fake ChatGPT login page that forwards submitted credentials to the attackers before showing an error. Cofense published IOCs including sender support@9527db6e1a[.]nxcli[.]io and two stage-2 payload URLs; the operators behind the campaign were not named.
- Emails impersonate 'The OpenAI Team' with real ChatGPT branding and an 'Update Payment Information' button.
- Links use a Google API redirect wrapper to reach attacker-controlled nxcli[.]io infrastructure.
- Fake login page captures OpenAI credentials, then displays an error to victims.
- Cofense published IOCs; MFA, unique passwords, and direct site navigation are recommended defenses.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | 9527db6e1a.nxcli.io | e (IoCs):- Type Indicator Description Email address support@9527db6e1a[.]nxcli[.]io Sender address used in the observed phishing email URL |
| domain | e83cedb076.nxcli.io | 5nZyb_erqo Stage 1 observed email infection URL URL hXXps://e83cedb076[.]nxcli[.]io/fertaq/app/key[.]php Stage 2 observed payload URL URL h |
| domain | key.php | nfection URL URL hXXps://e83cedb076[.]nxcli[.]io/fertaq/app/key[.]php Stage 2 observed payload URL URL hXXps://e83cedb076[.]nxc |
| domain | login.php | payload URL URL hXXps://e83cedb076[.]nxcli[.]io/fertaq/app/login[.]php Stage 2 observed payload URL Note: IP addresses and domai |
| domain | notifications.googleapis.com | der address used in the observed phishing email URL hXXps://notifications[.]googleapis[.]com/email/redirect?t=AFG8qyW_Su5pVpWF_Tm7YFcNgju_01zhPKtjCp |
| url | https://e83cedb076[ | T5E4LWD15nZyb_erqo Stage 1 observed email infection URL URL hXXps://e83cedb076[.]nxcli[.]io/fertaq/app/key[.]php Stage 2 observed payload U |
| url | https://notifications[ | .]io Sender address used in the observed phishing email URL hXXps://notifications[.]googleapis[.]com/email/redirect?t=AFG8qyW_Su5pVpWF_Tm7YFcN |
Full article796 words · extracted from cybersecuritynews.com · click to collapse
ChatGPT subscription notices have become the latest cover for credential-stealing emails. The campaign uses a familiar billing problem to push recipients toward a fake sign-in page, where attackers can collect OpenAI account details.
A successful theft can expose saved conversations and give criminals another identity to abuse in follow-on scams. The messages target people using ChatGPT for work or personal activities.
They claim a subscription payment must be updated, placing pressure on the recipient to act within 48 hours. For workers, the risk can extend beyond a single personal account when the same inbox or password habits overlap with business systems.
Analysts at Cofense identified the fraudulent subscription-invoice email and said it was designed to capture OpenAI account credentials. A trusted logo, payment language, and a convincing login screen can make the phishing email feel legitimate.
Cofense said in a report shared with Cyber Security News (CSN) that it also highlights an expanding social-engineering risk around tools that many users now access every day.
Recent ChatGPT subscription phishing coverage likewise illustrates why subscription notices remain an effective way to seek both credentials and financial details. The report did not name the operators behind the activity.
Hackers Impersonate ChatGPT Subscription Alerts
The email presents itself as a normal invoice, using the real ChatGPT logo and prominent wording such as “Subscription Payment Required.” A large “Update Payment Information” button supplies the next step. It closes as though it came from “The OpenAI Team,” combining several small signals that can lower a reader’s suspicion.
.webp)
The sender address tells a different story. It does not belong to OpenAI, even though the display and message wording suggest otherwise. Recipients who place a pointer over the button can also spot an unexpected destination.
The link first uses a Google API wrapper, then redirects to attacker-controlled infrastructure rather than an official account page.
After a click, the victim reaches a page made to resemble the ChatGPT login experience, including legitimate-looking branding, text, and icons. The site does not use the legitimate OpenAI authentication address.
Submitted credentials are sent to the attacker, after which the page redirects the victim to an error message instead of completing a sign-in.
This approach does not require attackers to compromise the AI service itself. It exploits trust in its name and the normal expectation that paid services sometimes need billing changes. A related report on trusted redirects in phishing shows how redirect chains can also make malicious destinations harder to identify.
How Users Can Spot the Lure
The safest response to an unexpected billing message is not to use its button or embedded link. Open a browser independently, visit the service through a known bookmark or typed address, and review account status there. This avoids the attacker-controlled route to the sign-in screen.
Users should examine the full sender address, not just its display name, and hover over links before opening them. An unrelated domain is a clear warning. The official login address should be checked carefully, especially when a page closely copies a familiar design or asks for payment details immediately.
.webp)
Organizations can reduce exposure by teaching staff to report suspicious invoices, reviewing email controls, and ensuring suspicious links are investigated before employees act.
Personal users should change their password promptly through the legitimate site if they entered it on a questionable page, then review account activity and payment settings.
Multi-factor authentication can add an important barrier, but it is not a reason to trust a suspicious page. Some phishing operations aim to capture sign-in sessions as well as passwords, as coverage of phishing kits bypassing MFA has shown.
Unique passwords, careful link checks, and direct access through known sites remain essential. AI-themed scams are likely to keep evolving.
Users should treat claims of expiring access, failed payments, or urgent security changes with the same caution applied to banking and workplace accounts. Verifying a notice before the first click can prevent account compromise.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Email address | support@9527db6e1a[.]nxcli[.]io | Sender address used in the observed phishing email |
| URL | hXXps://notifications[.]googleapis[.]com/email/redirect?t=AFG8qyW_Su5pVpWF_Tm7YFcNgju_01zhPKtjCpIcIfTVDTsqk_NT5E4LWD15nZyb_erqo | Stage 1 observed email infection URL |
| URL | hXXps://e83cedb076[.]nxcli[.]io/fertaq/app/key[.]php | Stage 2 observed payload URL |
| URL | hXXps://e83cedb076[.]nxcli[.]io/fertaq/app/login[.]php | Stage 2 observed payload URL |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/chatgpt-subscription/