Dodgy ChatGPT billing email doing the rounds
A phishing email is circulating that pretends to be from OpenAI and pushes you to update billing details for a supposed ChatGPT Plus payment issue.
You could receive an email with a blank subject line that appears to be about your ChatGPT Plus subscription, using OpenAI branding and a headline like Action Needed, Subscription Payment. It directs you to click Update Billing Details, making it look like your payment has failed and your subscription needs urgent attention. The sender comes from 567a03578c.nxcli.io, not an official OpenAI domain.
What gives it away is that the email does not properly prove it was sent by who it claims to be. Key checks that normally help confirm a legitimate sender were missing or failed, which means your mail system could not reliably verify the message as genuine. Even though the sending domain does not yet have a bad reputation, that is not reassurance. Low-history or little-used infrastructure is regularly utilised in phishing because it has not been widely recognised and blocked yet.
The attacker wants you to click through and hand over payment details, account credentials, or both on a fake billing page. If you engage, you could lose access to your account, expose your card details, or give criminals a foothold to target your business further. A message like this is designed to create urgency first, then capture whatever you enter.
The domain the message claims to be from. Fresh registrations and known-bad reputations are the strongest technical tells of a spoofed sender.
Where a reply to this message would actually be delivered. When it differs from the visible From address, an unsuspecting reply lands with the attacker instead.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Check: Verify any billing or subscription issue by going directly to your OpenAI account through the official website, not through links in the email.
- Do not: Click the Update Billing Details button or enter payment or login details from this message.
- Check: Look closely at the sender domain. If it does not match the real organisation, treat the message as suspicious and delete it.
- Report: Send the email to your IT provider or internal security contact so it can be blocked and investigated.
- Contact Decision1: If you believe your business has been targeted, contact the Decision1 team immediately.
See what a genuine OpenAI (ChatGPT) message looks like, the real sender domain, the real link destination, and where to report a fake.

