Hackers Impersonate ChatGPT Subscription Alerts to Steal OpenAI Account Credentials
Cofense reports a phishing campaign using fake ChatGPT subscription payment notices to lure users to credential-harvesting pages and steal OpenAI account logins.
Cofense identified phishing emails impersonating ChatGPT subscription invoices, using the genuine logo, 'Subscription Payment Required' wording, and a 48-hour urgency deadline. Links route through a Google notifications API redirect wrapper to attacker-controlled nxcli[.]io infrastructure hosting a fake ChatGPT login page that forwards submitted credentials to the attackers before showing an error. Cofense published IOCs including sender support@9527db6e1a[.]nxcli[.]io and two stage-2 payload URLs; the operators behind the campaign were not named.