Sep 20 / Admin

New Scam Alert: Fake ChatGPT Email Wants Your OpenAI Password

Helpnet Security reported:  

A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing Defense Center traced the email’s payment button through a Google redirect to the attacker’s page.

The lure targets ChatGPT users on work and personal accounts alike, and it copies the kind of bill a subscriber already expects. Credentials entered on the fake page go to the attacker, and the victim is sent on to an error page.

Look for the red flag:  The From line is where it falls apart. It comes from support@9527db6e1a[.]nxcli[.]io, which is not an OpenAI address.

Find the original article and see a copy of the email here.
 
Key Takeaway:  Review the email to see if there are any red flags.  Use an AI Tool to help.  Check out the training session to see how to use Microsoft Copilot to spot red flags in an email or your inbox. 

Enroll in Training Sessions:  Last Thursday of Every Month is Training on Frauds and New Scam Alerts and How to Combat
Click Image to Enlarge
Created with