Sophisticated Phishing Attack Targets ChatGPT Users
A new phishing campaign is exploiting the popularity of ChatGPT to steal user login credentials. According to cybersecurity firm Cofense, victims receive emails that appear to be billing notifications from OpenAI. These emails warn users that they must update their payment information within 48 hours, often citing a balance of $23.80 and including a button to update payment details.
The emails are not from OpenAI. The link, initially routed through Google APIs, leads to a malicious website designed to mimic ChatGPT's login screen. Users who enter their credentials on this fake page are not logging into ChatGPT; instead, their information is sent to the attackers, and they are then redirected to an error page.
Cofense cautions that the presence of a Google API address in a link does not guarantee its safety. This attack does not involve a breach of OpenAI's systems but rather a social engineering tactic to trick users into voluntarily surrendering their account details. OpenAI advises users who receive suspicious billing notices to log into their ChatGPT account directly through the official website and check their billing settings, rather than clicking on links in emails.
For users concerned about compromised passwords, OpenAI recommends immediately changing their password, logging out of all devices, and enabling multi-factor authentication.