Phishing Campaign Impersonates ChatGPT Subscription Billing Alerts to Steal OpenAI Credentials via Google API Open-Redirect and nxcli.io Infrastructure
Phishing Campaign Impersonates ChatGPT Subscription Billing (TL-2026-2567), also tracked as ChatGPT Subscription Billing Phishing, is a medium-severity phishing campaign, first published 2026-09-18. It has no confirmed attribution, affects OpenAI ChatGPT / OpenAI account (subscription billing and, maps to 10 MITRE ATT&CK techniques (T1036.005, T1056.003, T1078.004), and is covered by 9 detection rules and 13 indicators of compromise.
Key facts for TL-2026-2567
- Threat ID
- TL-2026-2567
- Also known as
- ChatGPT Subscription Billing Phishing, OpenAI Fake Invoice Phishing Campaign, nxcli.io ChatGPT Credential Harvesting
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-09-18
- Last reviewed
- 2026-09-18
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- cross-sector, technology
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 13
Malware and tooling in Phishing Campaign Impersonates ChatGPT Subscription Billing
Malware and tooling: PHP credential-harvesting kit (key.php / login.php)
Cofense's Phishing Defense Center identified a credential-phishing campaign impersonating OpenAI/ChatGPT subscription billing, sending a fake $23.80 invoice with a 48-hour deadline that routes victims through a legitimate notifications.googleapis.com open-redirect before landing on a nxcli.io-hosted fake ChatGPT login page. Harvested credentials risk exposure of saved conversations, API usage, and payment data, with follow-on account-takeover and cross-account-reuse risk for both personal and work OpenAI users.
How Phishing Campaign Impersonates ChatGPT Subscription Billing works
On 2026-09-17/18, Cofense's Phishing Defense Center (analyst Josh Varden) publicly disclosed a phishing campaign impersonating official OpenAI/ChatGPT billing notifications. The lure email, subject-lined 'Urgent: Update Your Payment Method to Avoid Service Interruption' and signed 'The OpenAI Team,' claims an outstanding $23.80 subscription charge and gives the recipient a 48-hour deadline to 'Update Payment Information,' a classic urgency/scarcity social-engineering pattern. Independent analysis (gblock.app) notes the $23.80 figure was deliberately calibrated near the real ~$20/month ChatGPT Plus price point, and that the lure exploits subscriber uncertainty over which billing path (web, Apple App Store, or Google Play) actually charges their card. The email itself is sent from support@9527db6e1a.nxcli.io — a hash-prefixed subdomain of nxcli.io/nxcli.net, the default shared-hosting domain used by hosting provider Liquid Web's Nexcess.net LLC platform — rather than any openai.com-controlled address (OpenAI's legitimate mail-sending domains are ads.openai.com, c-openai.com, email.openai.com, mail.openai.com, openai.com, sales.openai.com, and tm.openai.com).
The embedded 'Update Payment Information' button does not link directly to attacker infrastructure. It first routes through notifications.googleapis.com/email/redirect, a legitimate Google API endpoint that Google itself uses for notification links; because this domain is broadly trusted by secure email gateways and URL-reputation engines, wrapping the malicious destination behind it materially improves inbox delivery and evades casual link inspection. The Google redirect ultimately forwards the victim to a second hash-prefixed nxcli.io subdomain (e83cedb076.nxcli.io) hosting a PHP-based credential-harvesting kit under /fertaq/app/, with distinct key.php and login.php endpoints. That page closely mimics OpenAI's real authentication UI (auth.openai.com/log-in-or-create-account) — matching logos, layout, and branding — but is served from unrelated attacker-controlled infrastructure. Submitted credentials are captured server-side by the kit before the victim is bounced to a generic error page, a technique intended to reduce victim suspicion post-submission.
Independent reporting (Help Net Security, GBHackers, Cyberpress, Hackread, Mallory, gblock.app) corroborates the same sender address, redirect chain, and phishing paths, and notes the campaign targets both personal ChatGPT subscribers and employees using work-provisioned/Team or Enterprise OpenAI accounts. Successful credential theft exposes saved conversation history, API usage and key metadata, and subscription/payment details, and — because users frequently reuse passwords or use organizational SSO/email habits across personal and work accounts — creates a pivot risk into broader account-takeover and follow-on scam activity beyond the OpenAI account itself. No malware payload, exploit, or CVE is involved; this is a pure social-engineering / credential-harvesting operation.
nxcli.io/nxcli.net's disposable, auto-provisioned hash-named subdomain pattern (registrant Nexcess.net LLC, part of the Liquid Web hosting group) has an independently documented history of abuse well beyond this single campaign. Security researcher writeup 'The Birdling' documents a separate, unrelated MetaMask-themed crypto-wallet credential-phishing wave that paired nxcli.net-hosted mail envelope fronting (e.g. cloudhost-14816648.us-midwest-1.nxcli.net) with AWS S3-hosted landing pages, describing nxcli's disposable subdomains as deliberately 'cheap' and 'takedown-resistant' infrastructure reused across multiple unrelated campaigns; public abuse-reporting trackers (spam.org) list dozens of independent complaints against the nxcli.io domain. This indicates the hosting platform itself — not this specific threat actor — is a recurring low-cost staging ground for credential phishing, which is why defenders are advised to flag the *.nxcli.io / *.nxcli.net pattern broadly rather than only the two specific hashes observed in this campaign.
MITRE ATT&CK techniques used in TL-2026-2567
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1684.001 Impersonation
Credential Access
Initial Access
T1078.004 Cloud Accounts; T1566.002 Spearphishing Link
Execution
Resource Development
T1583.006 Web Services; T1585.002 Email Accounts; T1608.005 Link Target
Reconnaissance
Affected products and versions in Phishing Campaign Impersonates ChatGPT Subscription Billing
- OpenAI — ChatGPT / OpenAI account (subscription billing and authentication)
Vulnerable versions: N/A — social-engineering campaign, not a software defect; any personal, Team, or Enterprise OpenAI/ChatGPT account holder who receives and acts on the lure email is a potential victim
Remediation for Phishing Campaign Impersonates ChatGPT Subscription Billing
Patches
- Not a software vulnerability — no vendor patch applies. Ensure secure email gateway anti-phishing signature sets and URL-reputation feeds are current so newly-registered nxcli.io/nxcli.net-style disposable subdomains are caught quickly
Immediate actions
- Search email gateway/proxy logs for sender addresses matching *.nxcli.io (specifically support@9527db6e1a.nxcli.io), the notifications.googleapis.com/email/redirect token observed in this campaign, and requests to e83cedb076.nxcli.io/fertaq/app/{key,login}.php
- Force-reset OpenAI/ChatGPT account passwords and revoke active sessions and API keys for any user who reports clicking the link or submitting credentials
- Push an org-wide alert reminding users that legitimate OpenAI billing and authentication pages live only on openai.com / auth.openai.com, never on third-party hosting subdomains, and that legitimate OpenAI mail originates only from ads.openai.com, c-openai.com, email.openai.com, mail.openai.com, openai.com, sales.openai.com, or tm.openai.com
- Quarantine and block any inbound mail with envelope-from or Reply-To domains matching the *.nxcli.io / *.nxcli.net pattern
Workarounds
- Instruct users to reach ChatGPT/OpenAI billing pages only via bookmarks or by typing chatgpt.com/openai.com directly rather than clicking emailed payment links, and to verify billing status directly under Settings > Billing on chatgpt.com
- Add explicit inspection/logging rules for notifications.googleapis.com/email/redirect chains at the email security gateway where automatic redirect-following cannot be disabled
Longer-term hardening
- Tune secure email gateway and web proxy rules to flag or inspect links wrapped in notifications.googleapis.com/email/redirect and other Google API open-redirect endpoints rather than trusting the wrapper domain outright
- Require MFA (hardware key, authenticator app, or passkeys — not SMS) on all OpenAI ChatGPT Enterprise/Team accounts, and evaluate OpenAI's Advanced Account Security option, to blunt password-only credential theft
- Review DMARC/DKIM/SPF enforcement to catch spoofed 'The OpenAI Team' display-name sender impersonation
- Run recurring user-awareness training on billing-lure phishing patterns: artificial deadlines, brand-mimicking payment buttons, and sender-domain mismatches
Timeline of Phishing Campaign Impersonates ChatGPT Subscription Billing
- gblock.app publishes independent analysis noting the $23.80 lure amount was calibrated near the real ChatGPT Plus price point and lists OpenAI's legitimate mail-sending domains for defender reference.
- GBHackers reports the campaign targets both work/Enterprise and personal OpenAI accounts, citing exposure risk to API usage, prompts, and payment data.
- Cyberpress.org publishes a technical breakdown of the three-stage redirect chain and recommends MFA adoption and bookmark-based navigation as mitigations.
- Help Net Security publishes Cofense's findings on the fake ChatGPT billing email, detailing the $23.80 lure and the notifications.googleapis.com redirect to nxcli.io.
- Cofense Phishing Defense Center analyst Josh Varden identifies and traces the fraudulent ChatGPT/OpenAI subscription-billing phishing campaign, per Help Net Security.
- Threadlinqs Intelligence Platform HUNT phase ingests the campaign from the Cyber Security News feed and opens TL-2026-2567 for research.
- Cyber Security News publishes a detailed IOC writeup naming the sender domain (9527db6e1a.nxcli.io), the Google API redirect, and the e83cedb076.nxcli.io/fertaq/app/{key,login}.php harvesting endpoints — the source article ingested by the harness for TL-2026-2567.
Sources cited for Phishing Campaign Impersonates ChatGPT Subscription Billing
- Hackers Impersonate ChatGPT Subscription Alerts to Steal OpenAI Account Credentials
- A fake ChatGPT billing email is after your OpenAI password
- ChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts
- Hackers Give ChatGPT Users 48 Hours to "Update Payment" in Credential-Stealing Phishing Attack
- Fake OpenAI Billing Emails Target ChatGPT Users in Credential Harvesting Phishing Scam
- Fake ChatGPT Billing Emails Steal OpenAI Credentials
- Fake ChatGPT Billing Email Steals OpenAI Passwords
- AWS S3 + nxcli Crypto-Themed Phishing Campaign
More in phishing
- Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+ Disposable Azure Blob Storage Sites)
- Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Details
- Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flow
- Revolut Phishing SMS Campaign Follows Social-Engineering Data Breach Exposing 680 Customers' KYC Data
- Fake ChatGPT Billing Email Phishing Campaign Abuses Google API Redirect to Steal OpenAI Credentials via nxcli.io
Detection coverage for TL-2026-2567
As of 2026-09-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2567 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.