Phishing email aimed at subscribers presents a fraudulent billing page

Phishing email aimed at subscribers presents a fraudulent billing page

If you receive an email about a problem with your ChatGPT subscription, it’s likely to grab your attention. Perhaps your payment didn’t go through, or maybe your card has expired. Either way, you’d probably feel the urge to resolve the issue before it affects your account. That instinct is something cybercriminals are leveraging.

Security experts at Cofense have discovered a phishing campaign that pretends to be from OpenAI and ChatGPT. These deceptive emails appear to be standard subscription alerts. However, clicking the provided button can lead you to a convincing imitation of the actual ChatGPT login page. Cofense warns that this scheme aims to steal your account credentials and payment details.

They found that the email even uses the real ChatGPT logo, claiming that your subscription payment is due. It creates a sense of urgency by stating “Subscription Payment Required” and insists you must act within 48 hours. There’s a prominent button urging you to “Update Payment Information,” making it seem critical to respond quickly. When you’re casually checking emails or scrolling through on your phone, it could feel alarmingly real.

However, one of the biggest giveaways is the sender’s email address. Cofense identified the phishing emails as coming from support@9527db6e1a[.]nxcli[.]io, a domain unrelated to OpenAI. OpenAI uses various domains for legitimate communications, such as @openai.com and others. So, double-checking the sender’s email address is essential. Don’t be misled by a reassuring display name; scammers can easily disguise their addresses.

The email’s “Update Payment Information” button is another trick. Once clicked, it first redirects via a Google API before landing on the malicious site. While this may seem more credible because of the Google link, it can obscure the actual destination. Even if hovering over a button on a computer shows you where it goes, redirects can still complicate that check. The best practice? Avoid clicking links in emails entirely.

When you make it to the fake login page, it gets tricky. The phishing site closely mimics the genuine ChatGPT login experience, complete with familiar branding. But, if you look at the domain in the address bar, it won’t match the real ChatGPT URL. If someone enters their login details, they’re captured and sent to the attacker, who then might show an error page to cover their tracks. Therefore, it’s crucial to check the address bar before entering any credentials. Remember, a scammer can replicate the appearance of a login page, but they can’t control the domain.

Here are some tips to help you steer clear of these fraudulent ChatGPT billing emails:

1) Check your ChatGPT billing directly

If you see an email claiming a payment issue, avoid clicking any buttons. Instead, go to ChatGPT.com or the official app to log in yourself. For web users, check Settings → Billing, or for some, it may be Settings → Account → Payment → Manage. If you subscribed through Google Play or Apple, manage your subscription through those services.

2) Inspect the full sender address

Expand the sender information to reveal the actual email address. In this instance, the email came from an nxcli.io domain. OpenAI has a list of domains they use for valid communications, so check against that.

3) Verify the domain before signing in

Always look at the browser address bar before entering login credentials or payment info. If the domain seems off, exit the page and navigate to the service through its authorized channels. This is a good habit, especially since scammers sometimes create lookalike banking pages as well.

4) Use a unique password and consider a password manager

Avoid using the same password for ChatGPT and other accounts. It’s wise to have a distinct password and consider a password manager to handle it. That way, if one password is compromised, your other accounts remain secure.

5) Enable multi-factor authentication

OpenAI offers two-factor authentication (2FA). You can enable it in the Security section of your ChatGPT settings. Verification options might include an authenticator app, push notifications, or text messages, adding an extra layer of security.

6) Use strong antivirus software

Effective antivirus protection can alert you to malicious links and phishing sites, as well as block additional threats. Keep this software updated on any device where you access your email or important accounts.

7) Act quickly if you’ve shared your ChatGPT password

If you entered your password on a suspicious site, change it immediately. Then, log into ChatGPT and check Settings → Security → Active sessions. If you notice any unfamiliar devices or sessions, log them out.

8) Notify your card issuer if you shared payment details

Should you have provided payment info to a dubious site, contact your card issuer right away. Inform them of the potential compromise and review recent transactions for any unauthorized activity. They might advise you to replace your card.

9) Inform your workplace about any company accounts

Cofense indicates that this phishing scheme has impacted users of ChatGPT on both personal and work accounts. If you entered company credentials, reach out to your IT or security team for assistance.

Ultimately, this scam succeeds because the emails mimic something you’d expect. A routine payment issue can blur your defenses. If you get a similar billing alert from ChatGPT, don’t click any link in it. Instead, check your account directly. If you realize you entered your password on a suspicious site, change it quickly and monitor your active sessions.

Interestingly, have you ever received a subscription alert that seemed entirely credible? What gave it away for you? We’d love to hear your experiences!

Facebook
Twitter
LinkedIn
Reddit
Telegram
WhatsApp

Related News