Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Phishing Campaign Targets OpenAI ChatGPT Users with Fake Subscription Invoices

Threat actors are sending fake OpenAI billing emails that redirect victims to credential‑stealing pages. The lure exploits brand trust and urgency, underscoring the need for robust security‑awareness controls and audit‑ready evidence of employee training.

LiveThreat™ Intelligence · 📅 September 17, 2026· 📰 cofense.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
2 recommended
📰
Source
cofense.com

Phishing Campaign Targets OpenAI ChatGPT Users with Fake Subscription Invoices

What Happened — Threat actors are sending fraudulent “subscription payment required” emails that spoof the official OpenAI branding. The messages contain a malicious button that redirects through a Google API wrapper to a credential‑stealing page, aiming to capture OpenAI account passwords and payment details. Cofense’s Phishing Defense Center has observed multiple variants of this lure, often using urgency (“48 hours”) to pressure recipients.

Why It Matters for Trust & Control Assurance

  • Demonstrates a gap in user‑focused security awareness—continuous training and simulated phishing are core controls that help prove an organization’s diligence.
  • Highlights the need for verifiable evidence that credential‑handling policies (e.g., MFA enforcement, password vault usage) are enforced and audited.
  • Aligns with the Security Awareness Training control area, which maps to many frameworks (e.g., NIST CSF 2.0) and provides a defensible audit trail of employee readiness.

Who Is Affected — Enterprises and individuals that use ChatGPT for work or personal tasks, spanning technology SaaS providers, professional services, and broader corporate environments.

Recommended Actions

  • Deploy or refresh a security‑awareness program that includes AI‑specific phishing simulations and clear reporting mechanisms.
  • Enforce multi‑factor authentication on all OpenAI accounts and require password managers for credential storage.
  • Capture training completion and phishing‑test results as continuous control evidence for audit readiness. Source: https://cofense.com/blog/chatbot-conundrum-phishing-attempts-of-openai-s-chatgpt

Technical Notes

  • Attack vector: phishing email with spoofed OpenAI logo and a malicious button linking to a Google API wrapper that redirects to a credential‑stealing page.
  • No public CVE; the threat leverages social engineering rather than a software flaw. Source: https://cofense.com/blog/chatbot-conundrum-phishing-attempts-of-openai-s-chatgpt
📰 Original Source
https://cofense.com/blog/chatbot-conundrum-phishing-attempts-of-openai-s-chatgpt ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →