Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Fake ChatGPT Billing Email Phishing Campaign Targets OpenAI Passwords

A phishing campaign impersonating ChatGPT billing emails directs users to a counterfeit OpenAI login page, harvesting credentials. This underscores the need for robust identity and access controls and continuous phishing detection to support audit readiness.

LiveThreat™ Intelligence · 📅 September 18, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
helpnetsecurity.com

Fake ChatGPT Billing Email Phishing Campaign Targets OpenAI Passwords

What Happened — Attackers sent a fraudulent “ChatGPT billing” email that mimics an official OpenAI invoice. The message contains a Google‑redirect link that lands the victim on a replica OpenAI login page, where any entered username and password are captured by the threat actor.

Why It Matters for Trust & Control Assurance

  • Demonstrates a classic credential‑theft scenario that continuous identity‑and‑access‑control programs are built to detect and log.
  • Highlights the need for real‑time phishing‑email detection and evidencing of remediation steps for audit readiness.
  • Provides a concrete example of why multi‑factor authentication (MFA) and privileged‑access monitoring are essential control evidence across frameworks.

Who Is Affected – Organizations that allow employees or customers to access ChatGPT or other OpenAI services, spanning technology SaaS, professional services, and any sector leveraging generative AI.

Recommended Actions

  • Enforce MFA on all OpenAI accounts and enforce least‑privilege access policies.
  • Deploy email security gateways that inspect URL redirects and flag Google‑API redirect patterns.
  • Conduct a quick “address‑bar check” drill in security awareness training: verify the domain is auth.openai.com before entering credentials.
  • Monitor authentication logs for anomalous login attempts from unknown IP ranges and retain evidence for audit trails.

Source: Help Net Security

Technical Notes – The phishing email uses the sender support@9527db6e1a.nxcli.io and a Google API redirect (notifications.googleapis.com) that forwards the browser to nxcli.io/login.php or nxcli.io/key.php. The fake landing page replicates the OpenAI UI but posts credentials to the attacker’s server. Source: same as above

📰 Original Source
https://www.helpnetsecurity.com/2026/09/17/chatgpt-phishing-email-openai-password/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →