Fake ChatGPT payment emails: criminals impersonate OpenAI. How can you avoid the scam?

Do you use a paid ChatGPT plan? Be careful with messages asking you to update your payment method urgently. In a new phishing campaign, criminals are impersonating OpenAI and directing recipients to a fake login page. Learn how to recognise the scam and avoid becoming a victim.

How does the scam work?

The campaign was reported by researchers at the Cofense Phishing Defense Center and covered in Poland by outlets including Sekurak. The criminals send messages claiming that there is a problem with the recipient’s ChatGPT payment. The recipient is supposedly given 48 hours to update their details or the account will be blocked.

The message resembles a typical subscription notification. It includes the ChatGPT logo, OpenAI branding, a ‘The OpenAI Team’ signature and a prominent button for updating payment details. The time pressure is designed to make the recipient react before checking the sender and the link.

Clicking the button opens a page that closely resembles the real ChatGPT login screen. The email address and password entered there do not go to OpenAI but to the criminals. An error then appears on the screen, while the attackers already have the details they need to attempt to take over the account.

Why can the link look trustworthy?

The criminals paid attention to more than the appearance of the message. The button used a redirect service within Google’s infrastructure. The link preview could therefore show the familiar googleapis.com domain, even though the browser eventually displayed a fake login page hosted at a completely different address.

This mechanism was intended to mislead more than the recipient. Simpler antivirus products and email gateways that primarily checked the beginning of the link could see a Google domain and fail to recognise the criminals’ address hidden further along the redirect chain. This gave the scam a better chance of bypassing those safeguards.

You should therefore never judge a link only by its beginning or by the presence of a familiar company name. After opening a page, check the address shown in the browser bar. If the screen looks like a ChatGPT login page but the domain does not belong to OpenAI, do not enter any information.

How can you protect yourself from this type of phishing attempt?

Two details exposed the scam in this campaign. Even before clicking the button, the recipient could see that the message had been sent from an address with no connection to OpenAI. If the link was opened, the address displayed in the browser bar was another warning sign. The page looked like the ChatGPT login screen but operated under an unrelated domain.

Similar messages may refer not only to OpenAI services but also to banking, online purchases or streaming subscriptions. How can you protect yourself? First of all, do not act hastily. Follow a few simple rules:

  • Check the sender’s full email address rather than relying only on the displayed name.

  • Do not use a button in the message to make a payment or sign in. Open the service yourself using a saved address or the official app, then check whether there is actually a problem.

  • If you have already opened the page, check its address before entering any information. A logo and login screen can be copied, but the domain shows where you really are.

  • Do not give in to time pressure. A threat that your account will be blocked quickly is meant to make you react without checking the details.

  • Use a password manager. If it does not suggest saved credentials on a page that looks like a familiar login screen, treat that as a warning and never enter the password manually.

You should also remember to use a different password for every account. That way, even if one account is compromised, the criminals will not gain access to your other services.

What about two-factor authentication? Sekurak notes that one-time codes from an authentication app or SMS can be intercepted in real time during similar attacks. They may therefore fail to provide sufficient protection in this situation. Hardware security keys and passkeys provide greater resistance to phishing because they check whether the user is on the correct website before confirming the login.

What should you do after entering your password on a fake page?

If you do enter your login details on a fake page, go directly to the legitimate website and change your password immediately. If you used the same password for other services, change it there as well and make each new password unique. Check active sessions and sign out any devices you do not recognise.

If the incident involves a work account, report it immediately to the person responsible for security. Conversation history and uploaded files may contain important information about projects, clients or company procedures. Prompt reporting makes it possible to block access sooner and check whether anyone has used the stolen information for further activity.

Do not rely on vigilance alone

When you receive a message like this, the most important steps are to check the sender and the website address carefully and to open the service directly rather than through a button in the email. In an ideal world, this would always be enough.

In everyday life, however, things are rarely ideal. A busy moment or a brief lapse in attention can be enough to cause a problem. That is why good habits should be supported with additional safeguards.

A password manager, such as Bitdefender SecurePass mentioned earlier, helps create and store unique, complex passwords and automatically fills them on the websites associated with them. If it does not suggest saved credentials on a fake login page, that may be a sign that something is wrong.

It is also worth using antivirus software with anti-phishing protection.​ Such software can warn you about suspicious websites or block known malicious addresses. These features are available both in selected Bitdefender packages for home users (available from our Allegro store) and in solutions designed for businesses (find out more here). They may not always be 100% effective, but they often help prevent problems.

Protect yourself and do not let online scammers catch you off guard!

Frequently Asked Questions

Have a project in mind?

Message us

Let's talk about how we can help bring your ideas to life.

Zanek

Can't keep up with changes in AI world?

Let us do the heavy lifting. Every week we distill the most important AI developments into a focused 5-minute briefing - so you stay ahead without the noise.

Find out more
Weekly AIonline