Fake ChatGPT Billing Email Phishing Campaign Targets OpenAI Passwords
What Happened — Attackers sent a fraudulent “ChatGPT billing” email that mimics an official OpenAI invoice. The message contains a Google‑redirect link that lands the victim on a replica OpenAI login page, where any entered username and password are captured by the threat actor.
Why It Matters for Trust & Control Assurance
- Demonstrates a classic credential‑theft scenario that continuous identity‑and‑access‑control programs are built to detect and log.
- Highlights the need for real‑time phishing‑email detection and evidencing of remediation steps for audit readiness.
- Provides a concrete example of why multi‑factor authentication (MFA) and privileged‑access monitoring are essential control evidence across frameworks.
Who Is Affected – Organizations that allow employees or customers to access ChatGPT or other OpenAI services, spanning technology SaaS, professional services, and any sector leveraging generative AI.
Recommended Actions
- Enforce MFA on all OpenAI accounts and enforce least‑privilege access policies.
- Deploy email security gateways that inspect URL redirects and flag Google‑API redirect patterns.
- Conduct a quick “address‑bar check” drill in security awareness training: verify the domain is
auth.openai.combefore entering credentials. - Monitor authentication logs for anomalous login attempts from unknown IP ranges and retain evidence for audit trails.
Source: Help Net Security
Technical Notes – The phishing email uses the sender support@9527db6e1a.nxcli.io and a Google API redirect (notifications.googleapis.com) that forwards the browser to nxcli.io/login.php or nxcli.io/key.php. The fake landing page replicates the OpenAI UI but posts credentials to the attacker’s server. Source: same as above