openai-fake-invoice

Fake emails sent in the name of OpenAI claim that the ChatGPT subscription payment "failed" and ask recipients to update their credit card information in order to steal their account password through a fake login page.

More and more companies are using a paid ChatGPT subscription, and this has become a common scam. The message is sent on behalf of OpenAI, stating that the last payment failed and asking you to update your payment information, with a threat that the service will be suspended if you don't act quickly.

The "Update Payment" button goes through an intermediary domain and leads to a login page that looks exactly like the real OpenAI page. The information entered there—username and password—goes directly to the attacker.

A stolen corporate AI account is valuable: the conversation history may contain customer data, code snippets, or internal documents, and the account becomes a springboard for other attacks launched on behalf of the company.

For a small business, security costs nothing: it's a matter of habits, not technology.

What you need to do:

  • Check your invoices and payment details only by going directly to the official website—never by clicking a link in an email.
  • Check the address in the address bar before entering your password: it must be the actual OpenAI domain.
  • Enable two-factor authentication (2FA) on your OpenAI account.
  • If someone has already accessed your account, change your password immediately and review your account activity.

Sources: Help Net Security | https://www.helpnetsecurity.com/2026/09/17/chatgpt-phishing-email-openai-password/

This article was generated with AI assistance.

Request a quote

← All news