ChatGPT Subscription Renewal Phishing
Targeted phishing campaign impersonating ChatGPT (OpenAI) via disposable infrastructure to harvest payment credentials.
A new phishing campaign impersonating OpenAI’s ChatGPT service has been detected targeting New Zealand organisations. The emails utilise subdomains of the mass-hosting infrastructure nxcli.io to deliver urgent billing alerts, claiming that a ChatGPT Plus subscription is renewing within 24 hours.
The attack is designed to create a sense of urgency, prompting users to click a "Manage Subscription" link to verify their payment details. This link redirects to a sophisticated clone of the ChatGPT billing portal, where users are prompted to enter full credit card details and account credentials.
A critical identity mismatch is evident in the sender address support@3f4927d3b0.nxcli.io. Official OpenAI communications originate strictly from @openai.com or @email.openai.com domains. The use of nxcli.io subdomains allows the attackers to generate new sender identities rapidly, staying ahead of static domain blacklists.

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Audit the Sender. Verify the sender domain (nxcli.io) is not related to openai.com.
- Use Your Bookmarks. Never click billing links in emails. Log in directly via the official ChatGPT app or website.
- Identify Mismatches. Train staff to look for the mismatch between the professional branding and the unrelated private sender domain.
- Report Phishing. Forward any suspicious alerts to your security team or report them to CERT NZ (report@phishing.cert.govt.nz).
See what a genuine OpenAI (ChatGPT) message looks like, the real sender domain, the real link destination, and where to report a fake.


