top of page

🚨 Fake ChatGPT Billing Emails Use a Google Redirect to Steal Logins

Writer: AigiShield
AigiShield
1 day ago
3 min read

VERIFIED EMERGING SCAM ALERT

Report date: September 20, 2026

Scam type: ChatGPT/OpenAI billing impersonation phishing / credential theft / payment-information theft

What happened

Cofense's Phishing Defense Center documented a phishing campaign impersonating ChatGPT and OpenAI billing communications. The fraudulent email claims that a subscription payment needs attention and pressures the recipient to act quickly to avoid service interruption. One documented version claims an outstanding balance of $23.80 and gives the recipient 48 hours to update payment information. The message copies familiar ChatGPT branding, but it is not an OpenAI billing notice.

The campaign is especially notable because the malicious button can first route through a legitimate Google API redirect before sending the victim to an attacker-controlled page. That means a quick hover over the button may initially show a Google-owned domain rather than the final phishing destination. Independent cybersecurity reporting from Help Net Security and ITPro corroborates Cofense's findings.

How the scam works

The victim receives an email that appears to be a routine ChatGPT subscription or billing warning. It uses urgency, a plausible small balance, official-looking branding, and a prominent payment-update button. Clicking the button can route the browser through a Google redirect service and then to a counterfeit ChatGPT sign-in page hosted on an unrelated domain. Credentials entered on the fake page are captured by the attacker. Other versions of the broader billing lure have also sought payment-card information.

Who is targeted

The campaign can target both personal ChatGPT users and people who use ChatGPT at work. Anyone with a paid AI subscription may be more likely to believe a routine-looking billing notice because subscription renewals and payment updates are expected parts of using online services.

Warning signs

Watch for unexpected billing warnings that create a short deadline, threaten account suspension, use a sender address outside OpenAI's official domains, or send you through a link that does not ultimately lead to an official OpenAI site. A copied logo, polished formatting, or even an intermediate Google-owned redirect does not prove the destination is legitimate.

What consumers should do

Do not use an unexpected email's payment or login button to investigate a claimed ChatGPT billing problem. Open ChatGPT independently and check your account from the service itself. OpenAI advises users to double-check email addresses and URLs before entering account details, use strong unique credentials, enable multi-factor authentication, and act quickly if an account may have been compromised. If you entered credentials on a suspicious page, change the password, log out active sessions, review the account for unfamiliar activity, and contact OpenAI Support. If payment-card information was exposed, contact the card issuer promptly.

Why this development matters

This campaign demonstrates a useful evolution in phishing: criminals can hide the final malicious destination behind a legitimate redirect service. Consumers who have learned to hover over a link and look only for a familiar company name can still be misled. The safest approach for unexpected billing notices is to bypass the message entirely and navigate to the service independently.

Source attribution

Primary threat-intelligence source: Cofense Phishing Defense Center, Josh Varden, September 17, 2026 — https://cofense.com/blog/chatbot-conundrum-phishing-attempts-of-openai-s-chatgpt

Independent corroboration: Help Net Security, September 17, 2026 — https://www.helpnetsecurity.com/2026/09/17/chatgpt-phishing-email-openai-password/

Independent corroboration: ITPro, September 18, 2026 — https://www.itpro.com/security/phishing/fake-chatgpt-billing-email-targets-work-and-home-users

Official account-security guidance: OpenAI Help Center — https://help.openai.com/en/articles/8304786

Official communication-verification guidance: OpenAI Help Center — https://help.openai.com/en/articles/11725090-verifying-communications-from-openai

AigiShield reminder

Think it might be a scam? Let AigiShield check it out for you.

Think Before You Click. Verify Before You Trust.

 
 
 

Recent Posts

See All

Comments


bottom of page