ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

Fake ChatGPT billing emails harvest OpenAI credentials via Google redirect to spoofed login pages

mediumPhishing & fraudexploited in the wildimportance 52
What's new: First merged summary for this story. The Help Net Security report contributed the $23.80 overdue balance figure and the login.php/key.php indicators; the GBHackers report added the specific phishing host e83cedb076[.]nxcli[.]io, confirmed targeting of both work and personal OpenAI accounts, and detailed the data at risk (API keys, prompts, files, account history, payment data). The two reports…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Cofense's Phishing Defense Center is tracking a phishing campaign impersonating ChatGPT billing notices, sent from support@9527db6e1a[.]nxcli[.]io, that uses a notifications[.]googleapis[.]com redirect to fake OpenAI login pages on nxcli[.]io to steal…

Cofense's Phishing Defense Center identified a phishing campaign impersonating ChatGPT/OpenAI subscription billing notices, claiming a $23.80 overdue balance and warning of account suspension within 48 hours. The 'Update Payment Information' button routes through a notifications[.]googleapis[.]com redirect wrapper — so hover checks reveal only a legitimate-looking Google URL — to credential-harvesting pages on e83cedb076[.]nxcli[.]io that closely mimic the ChatGPT login interface. After victims submit credentials, they are sent to an error page while the attackers capture the data. GBHackers reports the campaign targets both work and personal OpenAI accounts, and that stolen credentials can expose account history, API keys and usage, sensitive prompts, files, and payment details. Cofense published indicators including the Google redirect link and login.php and key.php paths on the nxcli[.]io host.

  • Phishing emails pose as ChatGPT/OpenAI billing notices claiming a $23.80 overdue balance with a 48-hour deadline before account suspension
  • Sender address support@9527db6e1a[.]nxcli[.]io is not an OpenAI domain
  • Links route through a notifications[.]googleapis[.]com redirect wrapper, so hover checks display a Google URL
  • Credential-harvesting pages are hosted on e83cedb076[.]nxcli[.]io and mimic the ChatGPT login interface
  • Victims are sent to an error page after submitting credentials
  • The campaign targets both work and personal OpenAI accounts (per GBHackers)
  • Stolen credentials can expose account history, API keys and usage, sensitive prompts, files, and payment data
  • Published indicators include the Google redirect link and login.php and key.php paths on the nxcli[.]io host

Coverage timeline

  1. · 1d ago
    Help Net Security· 45
    A fake ChatGPT billing email is after your OpenAI password

    Cofense reports a fake ChatGPT billing email harvesting OpenAI credentials via a Google redirect to a spoofed login page.

  2. · 4h ago
    GBHackers· 52
    ChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts

    Cofense identified a phishing campaign impersonating ChatGPT billing notices to steal OpenAI credentials and payment data via fake login pages hosted on nxcli.io.