Fake ChatGPT billing emails harvest OpenAI credentials via Google redirect to spoofed login pages
Cofense's Phishing Defense Center is tracking a phishing campaign impersonating ChatGPT billing notices, sent from support@9527db6e1a[.]nxcli[.]io, that uses a notifications[.]googleapis[.]com redirect to fake OpenAI login pages on nxcli[.]io to steal…
Cofense's Phishing Defense Center identified a phishing campaign impersonating ChatGPT/OpenAI subscription billing notices, claiming a $23.80 overdue balance and warning of account suspension within 48 hours. The 'Update Payment Information' button routes through a notifications[.]googleapis[.]com redirect wrapper — so hover checks reveal only a legitimate-looking Google URL — to credential-harvesting pages on e83cedb076[.]nxcli[.]io that closely mimic the ChatGPT login interface. After victims submit credentials, they are sent to an error page while the attackers capture the data. GBHackers reports the campaign targets both work and personal OpenAI accounts, and that stolen credentials can expose account history, API keys and usage, sensitive prompts, files, and payment details. Cofense published indicators including the Google redirect link and login.php and key.php paths on the nxcli[.]io host.
- Phishing emails pose as ChatGPT/OpenAI billing notices claiming a $23.80 overdue balance with a 48-hour deadline before account suspension
- Sender address support@9527db6e1a[.]nxcli[.]io is not an OpenAI domain
- Links route through a notifications[.]googleapis[.]com redirect wrapper, so hover checks display a Google URL
- Credential-harvesting pages are hosted on e83cedb076[.]nxcli[.]io and mimic the ChatGPT login interface
- Victims are sent to an error page after submitting credentials
- The campaign targets both work and personal OpenAI accounts (per GBHackers)
- Stolen credentials can expose account history, API keys and usage, sensitive prompts, files, and payment data
- Published indicators include the Google redirect link and login.php and key.php paths on the nxcli[.]io host
Coverage timelineoldest first · each row is one article
- · 1d agoA fake ChatGPT billing email is after your OpenAI password
Help Net Security· 45
Cofense reports a fake ChatGPT billing email harvesting OpenAI credentials via a Google redirect to a spoofed login page.
- · 4h agoChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts
GBHackers· 52
Cofense identified a phishing campaign impersonating ChatGPT billing notices to steal OpenAI credentials and payment data via fake login pages hosted on nxcli.io.