Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 18, 2026 · 7 min read

Fake ChatGPT Billing Email Steals OpenAI Passwords

A $23.80 overdue notice, a 48 hour suspension threat and a green button that starts on a Google domain: Cofense traced the lure to a lookalike ChatGPT login page on a temporary hosting subdomain.

The email looks like the most boring message ChatGPT could send you. You owe $23.80; pay within 48 hours or lose access. That dullness is the trick: a charge that small feels too petty to be a scam. On 17 September 2026, Josh Varden of the Cofense Phishing Defense Center published an analysis of this exact lure. The detail that should worry Gmail users is where the button points first: a real Google address.

Key Takeaways

  • Cofense reported on 17 September 2026 a phishing email posing as ChatGPT that claims an outstanding balance of $23.80 and threatens suspension within 48 hours.
  • The email's Update Payment Information button first loads notifications.googleapis.com, a Google redirect that then forwards the browser to a fake ChatGPT login page.
  • The message came from support@9527db6e1a.nxcli.io, and nxcli.io is registered to the hosting company Nexcess.net LLC, not to OpenAI.
  • The fake page collects your email address and password, then sends you to an error page after passing them to the attacker.
  • OpenAI publishes seven official sender domains, nxcli.io is not among them, and real ChatGPT billing can be checked directly under Settings, then Billing.

What Does the Fake ChatGPT Billing Email Say?

It says your ChatGPT payment failed and your account will be suspended within 48 hours. Help Net Security's summary of the campaign describes the pieces:

  • Sender name: ChatGPT
  • Subject: "Urgent: Update Your Payment Method to Avoid Service Interruption"
  • Body: the ChatGPT logo, a final notice tag and an outstanding balance of $23.80
  • Button: a large green "Update Payment Information" link
  • Signature: "The OpenAI Team"

In the original Cofense analysis, Varden explains why the deadline is there: a 48 hour window "encourages the recipient to take immediate action without carefully evaluating the legitimacy of the email." When we loaded OpenAI's ChatGPT pricing page from Europe on 18 September 2026, Plus was listed at €23 a month. A $23.80 balance looks like an ordinary monthly charge.

A person at a kitchen table at night frowning at a laptop showing an urgent billing email with a red warning banner, a smartphone lying beside the laptop

Why Does a Google Link Help the Scam Get Through?

Because the first address in the chain belongs to Google, which filters and people tend to trust. Cofense says the button "uses a Google API wrapper URL, which then redirects to the real malicious payload." The link begins with notifications.googleapis.com/email/redirect?t= followed by a long opaque token. The phishing site's address appears nowhere in the visible link.

That breaks the most common piece of phishing advice. Google's own Gmail help page says you can "hover over any links before you click on them." Hover over this button and you see googleapis.com, which most readers would pass.

Cofense does not claim this email beat Gmail specifically, only that attackers keep "finding unique pathways through security systems and secure email gateways (SEGs)." In December 2025, according to Check Point research reported by The Hacker News, attackers sent 9,394 phishing emails to roughly 3,200 customers through Google Cloud Application Integration, bouncing victims through storage.cloud.google.com. Earlier this year we covered how 30,000 Facebook Business accounts were phished through noreply@appsheet.com. Three campaigns, three different Google services, one idea: borrow Google's reputation for the first hop.

Who Actually Sent the Email?

Not OpenAI. The sender was support@9527db6e1a.nxcli.io, and Cofense states plainly that "this is not a legitimate address from OpenAI or ChatGPT." A WHOIS lookup we ran on 18 September 2026 lists the registrant organization for nxcli.io as Nexcess.net LLC. Nexcess documentation describes its similar nxcli.net subdomains as temporary addresses for testing a site "that's not yet ready to go fully live."

OpenAI publishes the domains it really sends from on its Verifying Communications from OpenAI page: @ads.openai.com, @c-openai.com, @email.openai.com, @mail.openai.com, @openai.com, @sales.openai.com and @tm.openai.com. A billing notice from anything else is not from OpenAI.

What Does the Fake Login Page Steal?

It steals the email address and password you type into it. Cofense describes a page that "looks strikingly similar to the ChatGPT login," hosted at e83cedb076.nxcli.io under a /fertaq/app/ path with two files, login.php and key.php. After you submit, the page forwards you to an error screen "after stealing the entered information and sending it to the attacker."

Cofense does not say the kit asks for a one time code, and it does not explain what key.php does. Despite the payment theme, neither source reports card numbers being collected. The host e83cedb076.nxcli.io no longer resolved when we checked DNS on 18 September 2026, so expect the lure to return on a new subdomain.

With multi factor authentication on, a stolen password alone should not get the attacker in. The bigger risk is reuse: that password will be tried against your Gmail and everything else.

What Can Someone Do With Your ChatGPT Account?

Anyone signed in as you can read your account and use what it connects to. That starts with your chat history, which for many people includes work drafts and medical questions.

OpenAI's Google app data controls FAQ says that when you connect Gmail, Calendar or Drive, "ChatGPT can access information needed for the supported requests you make." An intruder in your session can make those requests too. The same FAQ says that with Memory on, eligible information from connected Google apps may help personalize ChatGPT.

ChatGPhish abused ChatGPT's own output to phish you, and earlier this month the prompt injection flaw that leaked Gmail data needed a bug. This one needs nothing but your password, and if your ChatGPT account is linked to Gmail, a phished ChatGPT login can become a route into your inbox.

What This Means for Your Inbox

Billing lures work because they fit your routine. ChatGPT subscriptions can be billed through the web, the Apple App Store or Google Play, as OpenAI's billing help page notes, and many subscribers could not say which one they used.

The Google redirect matters more than the brand. The same googleapis.com trick could front a fake Netflix or bank notice unchanged. Google's June 2026 scam advisory covers other lures built on the same urgency.

How to Check a ChatGPT Billing Email and Protect Your Account

  1. Never pay from the email. Open chatgpt.com yourself, go to Settings, then Billing, as OpenAI describes. If you subscribed through Apple or Google, check that store instead.
  2. Check the real sender. In Gmail on a computer, open the message and check the full address shown next to the sender name, not just the display name. Anything outside OpenAI's seven listed domains is fake.
  3. Read the whole link, not the first domain. Hover on desktop or long press on mobile. A Google redirect link carrying a long token is hiding its destination.
  4. Turn on MFA or passkeys. OpenAI's passkeys guide says to go to Settings, Security, then Add passkey. A passkey will not work on a lookalike domain.
  5. Consider Advanced Account Security. For eligible personal accounts, OpenAI's Advanced Account Security disables password sign in and email or SMS codes entirely, so a phished password is useless.
  6. If you already typed your password, change it, sign out of all sessions from Settings, then Security, and review connected apps and saved memories.
  7. Report it. In Gmail, open the message, click More next to Reply, then Report phishing.

What We Could Not Verify

The $23.80 figure and the subject line come from Help Net Security's report; the text of the Cofense post itself does not repeat them. Cofense did not say how many people received the email, whether Gmail's filters caught it, or what key.php collects, and we found no evidence the email carried a tracking pixel.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.