Back to The Local Vocal
The Local VocalHigh
Email
High risk PhishingEncountered ViaEMAIL 30 September 2026
RegionOtagoNationwide

Dodgy ChatGPT billing email doing the rounds

A phishing email is circulating that pretends to be from OpenAI and pushes you to update billing details for a supposed ChatGPT Plus payment issue.

You could receive an email with a blank subject line that appears to be about your ChatGPT Plus subscription, using OpenAI branding and a headline like Action Needed, Subscription Payment. It directs you to click Update Billing Details, making it look like your payment has failed and your subscription needs urgent attention. The sender comes from 567a03578c.nxcli.io, not an official OpenAI domain.

What gives it away is that the email does not properly prove it was sent by who it claims to be. Key checks that normally help confirm a legitimate sender were missing or failed, which means your mail system could not reliably verify the message as genuine. Even though the sending domain does not yet have a bad reputation, that is not reassurance. Low-history or little-used infrastructure is regularly utilised in phishing because it has not been widely recognised and blocked yet.

The attacker wants you to click through and hand over payment details, account credentials, or both on a fake billing page. If you engage, you could lose access to your account, expose your card details, or give criminals a foothold to target your business further. A message like this is designed to create urgency first, then capture whatever you enter.

Email authorisation
SPF
None
DKIM
Fail
DMARC
None
COMPAUTH
Pass
Sender Domain Intelligence

The domain the message claims to be from. Fresh registrations and known-bad reputations are the strongest technical tells of a spoofed sender.

Sender domain567a03578c.nxcli.io
ReputationCleanscore 0
Reply-To Domain Intelligence

Where a reply to this message would actually be delivered. When it differs from the visible From address, an unsuspecting reply lands with the attacker instead.

Reply-To domain567a03578c.nxcli.io
Email Sample
Source
Decision1
Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Check: Verify any billing or subscription issue by going directly to your OpenAI account through the official website, not through links in the email.
  • Do not: Click the Update Billing Details button or enter payment or login details from this message.
  • Check: Look closely at the sender domain. If it does not match the real organisation, treat the message as suspicious and delete it.
  • Report: Send the email to your IT provider or internal security contact so it can be blocked and investigated.
  • Contact Decision1: If you believe your business has been targeted, contact the Decision1 team immediately.
OpenAI (ChatGPT) logo
Is it real?
Got an email from OpenAI (ChatGPT)?

See what a genuine OpenAI (ChatGPT) message looks like, the real sender domain, the real link destination, and where to report a fake.

Check the real thing