ChatGPT Plus Billing Phishing Campaign Spoofs Stripe Checkout to Harvest Payment Card Data

ChatGPT Plus Billing Phishing Campaign Spoofs Stripe (TL-2026-1534), also tracked as Fake ChatGPT Stripe Checkout Phishing, is a medium-severity phishing campaign, first published 2026-07-19. It has no confirmed attribution, affects OpenAI ChatGPT Plus (billing/subscription impersonation target), maps to 16 MITRE ATT&CK techniques (T1027, T1036, T1056), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-1534

Threat ID
TL-2026-1534
Also known as
Fake ChatGPT Stripe Checkout Phishing, ChatGPT Payment Failed Phishing
Severity
MEDIUM
Status
ACTIVE
Category
PHISHING
First published
2026-07-19
Last reviewed
2026-07-19
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
all sectors - individual smb chatgpt plus subscribers, technology, professional services
Target regions
Global, australia, North America, Europe
Detection rules
9
Indicators of compromise
18

A phishing campaign impersonates ChatGPT/OpenAI billing notifications, falsely claiming a subscription payment failure to drive victims to a fake Stripe-branded checkout page hosted on the free tier of AlwaysData cloud hosting. The page simulates a VISA verification pop-up and a fabricated transaction-timeout error to coax victims into repeatedly re-entering card details, harvesting email address, full card number, expiry date, CVC, cardholder name, and billing address.

How ChatGPT Plus Billing Phishing Campaign Spoofs Stripe works

MailGuard intercepted a phishing campaign impersonating ChatGPT/OpenAI billing communications. The lure email, sent using the display name "Chat GPT" (a spacing/branding inconsistency versus OpenAI's actual "ChatGPT" branding) from the non-OpenAI sender domain imi2001.co.jp, informs the recipient that their most recent ChatGPT Plus subscription payment failed on a specified date and instructs them to check with their bank or card issuer before clicking through to resolve the issue. The message contains two links — an "Update your payment details here" call-to-action and a secondary "support article" link — both of which resolve to the same attacker-controlled destination rather than to distinct legitimate resources, a classic tell of a single-destination phishing lure dressed up with redundant pretexts.

Clicking either link delivers the victim to a spoofed Stripe checkout page that visually imitates OpenAI's real Stripe-hosted billing flow but is instead hosted on argentina.alwaysdata.net, a subdomain of the free tier of the French cloud host AlwaysData. AlwaysData's free plan only permits use of the provider's own *.alwaysdata.net subdomain (a paid plan is required to attach a custom domain), which is precisely why the attacker is operating from a *.alwaysdata.net address rather than a domain that could pass a superficial brand-name check — the giveaway is structural to the hosting tier, not incidental. AlwaysData's terms of service explicitly list phishing as prohibited/abuse-actionable content, and the provider maintains a public abuse-reporting channel (abuse@alwaysdata.com), consistent with this being an unauthorized abuse of a legitimate free-hosting service rather than attacker-owned infrastructure.

The fake checkout page requests the victim's email address, full primary account number (PAN), card expiry date, CVC, cardholder name, and billing address — the complete data set needed for card-not-present fraud. After submission, the page displays a VISA-branded modal with a loading/verification indicator to simulate a legitimate 3-D Secure-style authentication step, building victim confidence that the transaction is being processed normally. The modal is engineered to time out and return the victim to the payment form with a generic error, after which the page displays a message encouraging the victim to retry — a technique that both increases the odds of harvesting a second, potentially corrected/verified card number (catching typos or expired cards from the first submission) and desensitizes the victim to the abnormal flow. MailGuard also observed a page variant styled as a "PAYMENT ISSUE" screen with a red warning box, an urgency-escalation variant of the same kit deployed against the same lure.

This campaign fits a broader and recurring pattern of OpenAI/ChatGPT billing impersonation observed by multiple vendors through 2024-2026. Barracuda's October 2024 reporting documented a related large-scale "OpenAI Payments" billing-failure campaign sent to 1,000+ recipients from the unrelated sender domain mta.topmarinelogistics.com; that campaign's messages passed DKIM/SPF authentication because they were relayed through a legitimately-authorized (but abused/compromised) sending infrastructure, and used per-message variable/obfuscated hyperlinks — where the visible link text differed from the actual destination — to evade static email-security signatures. Separately, INKY documented a ChatGPT-impersonation credential-phishing kit that hosted its fake login page on IPFS decentralized storage (ipfs.dweb.link), used a URL-fragment parameter to dynamically personalize the phishing page per victim/target-company, and used JavaScript's window.location.replace() to redirect victims without leaving a browser-history entry, complicating post-incident triage. These related campaigns are NOT confirmed to share infrastructure or actor identity with the imi2001.co.jp / argentina.alwaysdata.net campaign documented here, but they establish that ChatGPT Plus's large, actively-billed subscriber base is a recognized high-yield target for payment-failure social engineering, and that the tooling/evasion techniques observed elsewhere in this campaign family (link obfuscation, decentralized/free-tier hosting abuse, anti-forensic JS redirects) are relevant defensive context for detection engineering. No CVE, malware family, or C2 beaconing infrastructure is associated with the specific imi2001.co.jp / argentina.alwaysdata.net campaign; it is a pure credential/payment-data harvesting phishing operation delivered via email and a static/JS-driven fake checkout kit, with no server-side C2 correlation found in BeaconBeagle for the observed hosting domain as of this writing.

MITRE ATT&CK techniques used in TL-2026-1534

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading

Collection

T1056 Input Capture

Command and Control

T1102 Web Service

Credential Access

T1111 Multi-Factor Authentication Interception

Initial Access

T1566 Phishing

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1608 Stage Capabilities

Reconnaissance

T1589 Gather Victim Identity Information

reconnaissance

T1598 Phishing for Information

Impact

T1657 Financial Theft

stealth

T1684.001 Impersonation

Affected products and versions in ChatGPT Plus Billing Phishing Campaign Spoofs Stripe

  • OpenAI — ChatGPT Plus (billing/subscription impersonation target)
    Vulnerable versions: N/A - brand impersonation, not a software vulnerability
  • Stripe — Stripe Checkout (visual/brand impersonation target)
    Vulnerable versions: N/A - brand impersonation, not a software vulnerability

Remediation for ChatGPT Plus Billing Phishing Campaign Spoofs Stripe

Immediate actions

  • Block/quarantine inbound mail from sender domain imi2001.co.jp at the secure email gateway
  • Block or sinkhole DNS/web requests to argentina.alwaysdata.net and the *.alwaysdata.net free-hosting namespace where not required for business use
  • Search mailbox logs (Message Trace / EDR mail telemetry) for prior delivery of emails referencing 'ChatGPT Plus' payment failure from non-openai.com senders
  • Notify any employees/users who clicked the phishing link or submitted payment data to immediately contact their card issuer to cancel/reissue the card
  • Report the phishing page to AlwaysData abuse (abuse@alwaysdata.com) and via phish.report to accelerate takedown

Workarounds

  • Access ChatGPT Plus billing exclusively via chat.openai.com / platform.openai.com account settings rather than any emailed link
  • Verify Stripe checkout URLs resolve to checkout.stripe.com before entering any payment data

Longer-term hardening

  • Deploy brand-impersonation / lookalike-display-name detection rules in the email security gateway tuned for 'ChatGPT', 'OpenAI', and 'Stripe' billing lures
  • Enforce DMARC/SPF/DKIM alignment checks and flag mail claiming OpenAI/Stripe branding from unauthenticated or mismatched sending domains — note that DKIM/SPF-pass alone is insufficient (related Barracuda campaign passed both via abused legitimate infrastructure)
  • User-awareness training emphasizing that legitimate billing portals should be reached via bookmarked/known URLs, never via emailed 'update payment' links
  • Deploy web-proxy/DNS category blocking for newly-observed *.alwaysdata.net and other free-hosting-tier or decentralized (e.g. *.ipfs.dweb.link) subdomains associated with phishing kits
  • Extract and compare visible link text vs. actual href destination in inbound mail to catch obfuscated/mismatched-hyperlink phishing kits

Weaknesses (CWE) in ChatGPT Plus Billing Phishing Campaign Spoofs Stripe

CWE-451, CWE-601, CWE-1021

Timeline of ChatGPT Plus Billing Phishing Campaign Spoofs Stripe

  • Barracuda reported a related, large-scale OpenAI/ChatGPT billing-failure phishing campaign sent to 1,000+ recipients from the unrelated sender domain mta.topmarinelogistics.com, using DKIM/SPF-authenticated abused infrastructure and per-message obfuscated hyperlinks — establishing the recurring campaign family this incident belongs to.
  • Approximate window in which the phishing lure impersonating ChatGPT Plus billing began circulating, based on MailGuard's interception and publication timeline (exact first-seen date not published by source).
  • INKY's separately-published ChatGPT-impersonation phishing-kit analysis (IPFS-hosted fake login page, URL-fragment per-victim personalization, window.location.replace() anti-forensic redirect) was reviewed as related-pattern defensive context; not confirmed to share infrastructure with this campaign.
  • MailGuard published a public blog advisory detailing the campaign's red flags, infrastructure, and recommended protective measures.
  • A 'PAYMENT ISSUE' page variant with red warning box urgency styling observed as part of the same phishing kit deployment.
  • Sender domain imi2001.co.jp and phishing hosting domain argentina.alwaysdata.net identified as the campaign's core email and web infrastructure.
  • MailGuard intercepted and publicly reported the phishing email campaign impersonating ChatGPT/OpenAI billing notifications with a fake Stripe checkout page.
  • TL-Intel Harness RESEARCH phase reviewed the campaign, cross-referenced BeaconBeagle for C2/infrastructure correlation (no match found for argentina.alwaysdata.net), and compiled this expanded threat record covering the primary incident plus related campaign-family precedents.

Sources cited for ChatGPT Plus Billing Phishing Campaign Spoofs Stripe

Threats related to ChatGPT Plus Billing Phishing Campaign Spoofs Stripe

Detection coverage for TL-2026-1534

As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1534 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats