TL;DR: Cofense uncovered a phishing campaign that impersonates ChatGPT billing to steal OpenAI logins and payment details. The email is headed 'Urgent: Update Your Payment Method to Avoid Service Interruption' and demands an outstanding $23.80 within 48 hours. It targets both work and personal users. Manage billing only by logging in directly.
👉 Check my digital footprint — free 30-second check →
ITPro reported on September 18, 2026 that a fake ChatGPT subscription invoice is being used to steal account credentials for OpenAI accounts. The lure is a small, believable amount and a short deadline.
What the fake email looks like
- Subject line along the lines of 'Urgent: Update Your Payment Method to Avoid Service Interruption'.
- A claim that you owe $23.80 and must pay within 48 hours.
- A button that leads to a fake page collecting your login and card details.
- It reaches both personal and work inboxes, so a stolen login can expose company data too.
Why small amounts work
A $23.80 charge sits below the level that makes people stop and question a bill. Scammers count on you paying or logging in to make it disappear. The same trick drives fake renewal notices such as the Geek Squad renewal email scam.
How to protect yourself
- Do not use buttons in billing emails. Open the app or type the official address yourself and check your subscription status.
- Look at the sender address, not the display name.
- Use a unique password and two-factor authentication for AI tools, which often store conversation history and work material.
- If you entered a password, change it and any account that shares it. Use what to do if your password was leaked as a checklist.
- If you entered card details, call your card issuer and ask for a replacement.
Also this week: a fake TV Licence direct debit email in the UK and a FINAL WARNING Facebook text in the US use the same panic pattern, and scammers are also copying real refund news in Amazon Prime refund scam texts.
FAQs
Is the ChatGPT billing email asking for $23.80 real?
Researchers at Cofense identified it as a phishing lure. Check your subscription only by logging in directly, never through the email.
What should I do if I clicked the link?
Change your OpenAI password, any account that used the same password, and turn on two-factor authentication. Report the email to your IT team if it reached a work inbox.
How can I tell a real billing email from a fake?
A real one can be confirmed inside your account without clicking anything. Fake ones push urgency, use odd sender addresses and link to lookalike sites.
Before scammers use your details, see them first: check what is already public about you.
Curious what's already out there? Scan My Shadow checks a phone number and email across 1,500+ sources and sends a clear report — no guesswork, just facts. Start your scan.
