Hackers Are Impersonating ChatGPT

Overview

As ChatGPT becomes increasingly embedded in everyday work, attackers are beginning to exploit the trust users place in the platform. A phishing campaign identified by Cofense impersonates ChatGPT subscription notifications, warning recipients that their payment information must be updated and directing them to a fraudulent OpenAI login page. The objective is simple: steal account credentials by making an ordinary billing request appear urgent and legitimate. Importantly, this is not a compromise of ChatGPT or OpenAI infrastructure. It is social engineering designed to exploit the brand, the user’s trust and the expectation that subscription services occasionally require payment updates.

Why the Attack Looks Convincing

The phishing email uses familiar ChatGPT branding, payment terminology and wording such as “Subscription Payment Required”, while creating urgency by suggesting the recipient must act within a limited period. The malicious link first passes through a Google API redirect before sending the victim to attacker-controlled infrastructure. The resulting page closely imitates the genuine ChatGPT login experience. Credentials entered into the fake page are captured by the attacker before the victim is shown an error message. This demonstrates why phishing detection can no longer depend purely on recognising poor spelling, suspicious graphics or obviously fake websites. Modern phishing campaigns increasingly imitate legitimate digital experiences very effectively.

AI Accounts Are Becoming Valuable Identities

Compromising an AI account may provide more than access to another online subscription. People increasingly use AI platforms for business planning, technical troubleshooting, coding, document preparation, research and other professional activities. OpenAI itself notes that ChatGPT accounts can contain sensitive personal and professional context, making account protection increasingly important as AI becomes embedded in workflows. A compromised account could therefore expose previous conversations or provide information that helps attackers create more convincing follow-on phishing, impersonation or social-engineering attacks.

What Users and Organisations Should Do

Unexpected billing or subscription notices should be treated carefully. Rather than clicking the link in an email, users should open the service independently through a trusted bookmark or known address and verify the account status directly. Sender addresses and destination domains should also be checked carefully. OpenAI recommends using strong unique credentials, MFA, reviewing account activity and logging out active sessions when compromise is suspected. Where available, passkeys can provide stronger authentication because they rely on cryptographic credentials stored on a trusted device rather than a reusable password. Organisations should also ensure employees know how to report suspicious subscription and payment emails rather than acting on them immediately.

Shadow AI Creates Another Security Challenge

There is also a wider enterprise consideration. Employees may use AI services independently of formal IT processes, sometimes through personal accounts while handling business information. That means security teams may have limited visibility into which AI platforms are being used, what information is stored within them and how those accounts are protected. AI adoption therefore needs to become part of identity governance, security awareness and acceptable-use policy, rather than being treated purely as a productivity discussion.

Expert in the Cloud Insight

This campaign highlights an important shift in social engineering: attackers follow trust. Microsoft, banks and delivery companies have long been impersonated because users recognise those brands. As AI becomes part of everyday work, platforms such as ChatGPT naturally become attractive phishing themes as well. For CIOs and IT managers, the question should therefore extend beyond: “Are employees allowed to use AI?” Organisations should also ask: “How are those AI identities protected, and what business information could be exposed if one is compromised?” The more important a digital platform becomes to everyday work, the more valuable the trust surrounding that platform becomes to attackers. AI security is therefore not only about securing the models—it is increasingly about securing the people and identities that use them.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.