Back to The Local Vocal
The Local VocalHigh
PhishingOpenAI
Email
High risk PhishingEncountered ViaEMAIL 15 September 2026
RegionOtagoNationwide

Dodgy OpenAI payment email doing the rounds

A phishing email is circulating that pretends to be from OpenAI and pressures you to update payment details, even though the sending systems cannot verify it is genuine.

You could receive an email with a blank subject line that appears to be tied to OpenAI, using a simple payment warning such as “Update your payment method to continue” and a button or link like “Verify & Pay Now”. It is designed to look routine and urgent, pushing you to fix a failed subscription payment before service is interrupted.

What gives it away is that the email could not be verified as coming from a legitimate sender. The normal checks that confirm who really sent a message all failed, which means your mail system had no trustworthy proof that haigpartners.com was authorised to send it. That domain is not brand new, but its age does not make this message safe, and a clean reputation on its own is not enough when the sender cannot be authenticated. If you reply or follow the prompt, you may also be dealing with someone other than the apparent sender.

The attacker is after your payment details, account credentials, or both. If you click through and enter information, you could hand over billing data, give criminals access to your account, or expose your business to follow-on fraud using the details you supplied.

Email authorisation
SPF
Fail
DKIM
Fail
DMARC
Fail
COMPAUTH
Fail
Sender Domain Intelligence

The domain the message claims to be from. Fresh registrations and known-bad reputations are the strongest technical tells of a spoofed sender.

Sender domainhaigpartners.com
Age4582 daysEstablished
Registered24/02/2014
ReputationCleanscore 0
Email Sample
Source
Decision1
Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Check: Treat unexpected payment failure emails with caution, especially if they push you to act immediately.
  • Verify: Go directly to your OpenAI or supplier account through your saved bookmark or official website, not the link in the email.
  • Do not: Click the payment link, reply to the message, or enter card details or passwords from the email prompt.
  • Report: Mark the message as phishing in your mail platform and escalate it to your IT provider or security team for review.
  • Contact Decision1: If you believe your business has been targeted, contact the Decision1 team immediately.