🚨 Fake ChatGPT Billing Emails Use a Google Redirect to Steal Logins
VERIFIED EMERGING SCAM ALERT
Report date: September 20, 2026
Scam type: ChatGPT/OpenAI billing impersonation phishing / credential theft / payment-information theft
What happened
Cofense's Phishing Defense Center documented a phishing campaign impersonating ChatGPT and OpenAI billing communications. The fraudulent email claims that a subscription payment needs attention and pressures the recipient to act quickly to avoid service interruption. One documented version claims an outstanding balance of $23.80 and gives the recipient 48 hours to update payment information. The message copies familiar ChatGPT branding, but it is not an OpenAI billing notice.
The campaign is especially notable because the malicious button can first route through a legitimate Google API redirect before sending the victim to an attacker-controlled page. That means a quick hover over the button may initially show a Google-owned domain rather than the final phishing destination. Independent cybersecurity reporting from Help Net Security and ITPro corroborates Cofense's findings.
How the scam works
The victim receives an email that appears to be a routine ChatGPT subscription or billing warning. It uses urgency, a plausible small balance, official-looking branding, and a prominent payment-update button. Clicking the button can route the browser through a Google redirect service and then to a counterfeit ChatGPT sign-in page hosted on an unrelated domain. Credentials entered on the fake page are captured by the attacker. Other versions of the broader billing lure have also sought payment-card information.
Who is targeted
The campaign can target both personal ChatGPT users and people who use ChatGPT at work. Anyone with a paid AI subscription may be more likely to believe a routine-looking billing notice because subscription renewals and payment updates are expected parts of using online services.
Warning signs
Watch for unexpected billing warnings that create a short deadline, threaten account suspension, use a sender address outside OpenAI's official domains, or send you through a link that does not ultimately lead to an official OpenAI site. A copied logo, polished formatting, or even an intermediate Google-owned redirect does not prove the destination is legitimate.
What consumers should do
Do not use an unexpected email's payment or login button to investigate a claimed ChatGPT billing problem. Open ChatGPT independently and check your account from the service itself. OpenAI advises users to double-check email addresses and URLs before entering account details, use strong unique credentials, enable multi-factor authentication, and act quickly if an account may have been compromised. If you entered credentials on a suspicious page, change the password, log out active sessions, review the account for unfamiliar activity, and contact OpenAI Support. If payment-card information was exposed, contact the card issuer promptly.
Why this development matters
This campaign demonstrates a useful evolution in phishing: criminals can hide the final malicious destination behind a legitimate redirect service. Consumers who have learned to hover over a link and look only for a familiar company name can still be misled. The safest approach for unexpected billing notices is to bypass the message entirely and navigate to the service independently.
Source attribution
Primary threat-intelligence source: Cofense Phishing Defense Center, Josh Varden, September 17, 2026 — https://cofense.com/blog/chatbot-conundrum-phishing-attempts-of-openai-s-chatgpt
Independent corroboration: Help Net Security, September 17, 2026 — https://www.helpnetsecurity.com/2026/09/17/chatgpt-phishing-email-openai-password/
Independent corroboration: ITPro, September 18, 2026 — https://www.itpro.com/security/phishing/fake-chatgpt-billing-email-targets-work-and-home-users
Official account-security guidance: OpenAI Help Center — https://help.openai.com/en/articles/8304786
Official communication-verification guidance: OpenAI Help Center — https://help.openai.com/en/articles/11725090-verifying-communications-from-openai
AigiShield reminder
Think it might be a scam? Let AigiShield check it out for you.
Think Before You Click. Verify Before You Trust.
Comments