Threat actors are exploiting the growing popularity of ChatGPT by sending out fake subscription-payment emails that create a sense of urgency and direct victims to credential-stealing websites This article explores cofense phishing. . The phishing campaign, identified by Cofense’s Phishing Defense Center (PDC), impersonates OpenAI and warns recipients that they need to update their payment details within 48 hours.

These emails target both personal and work users of ChatGPT, particularly those who have paid subscriptions or expect billing notifications. The allure of ChatGPT subscriptions makes them an attractive target for phishing because payment-update requests are common and can appear legitimate to busy users. Users should carefully examine sender addresses, as attackers often use unrelated domains while mimicking trusted logos, names, and email layouts.

However, the domain used in the URL does not match the official OpenAI authentication domain: auth.openai.com/log-in-or-create-account Instead, Cofense discovered malicious payload URLs hosted on the nxcli.io domain. This campaign highlights attackers' adaptability, urging users to be cautious of urgent payment requests, verify sender and destination domains, and enable multi-factor authentication to minimize the impact of stolen passwords. Join 16,000+ SOC teams using ANY.RUN to enhance threat investigations and minimize manual workload.