How Fake ChatGPT Subscription Invoices Are Targeting Your Inbox
Threat actors are spoofing ChatGPT subscription invoices via phishing emails to deceive users into divulging credentials or financial information.
A phishing campaign is currently circulating that impersonates OpenAI, specifically targeting recipients with fraudulent invoice notifications referencing ChatGPT Plus subscriptions. The emails arrive with subject lines framed around pending billing, designed to create a sense of routine financial urgency that bypasses initial scepticism. The sending infrastructure has been identified as originating from a domain unaffiliated with OpenAI, specifically a subdomain pattern associated with shared hosting environments commonly leveraged by threat actors for low-cost, high-volume phishing operations.
The social engineering premise is straightforward but effective. By referencing a widely recognised and actively used consumer AI product, the campaign increases the probability that a recipient will have a genuine ChatGPT Plus subscription, or will at minimum recognise the brand as credible. This reduces cognitive friction and makes the recipient more likely to engage with embedded links or attachments without scrutinising the sender address or message origin.
Organisations that have adopted AI productivity tools across their workforce face an elevated exposure surface in campaigns of this nature. Employees who use ChatGPT Plus under personal or corporate accounts may interpret these emails as legitimate billing communications, particularly if their organisation has not established clear guidance around how software subscription notices are communicated internally. The absence of a visible body text snippet in sampled versions of this email suggests content may be rendered entirely through HTML or linked assets, a technique used to evade plain-text analysis by email security gateways.
Organisations are advised to ensure email gateway policies flag messages where the declared brand identity does not align with the authenticated sending domain. Staff awareness programmes should include explicit reference to AI platform impersonation as an emerging and growing phishing vector, given the rapid normalisation of these tools in professional environments across New Zealand.

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
• Do not click links or provide credentials. ChatGPT/OpenAI will only communicate billing issues via official @openai.com addresses. This lure uses a hacked educational domain (uma.edu.sv). • Verify independently. Navigate directly to chatgpt.com to check your account status. • Report the incident. Alert your internal IT team and forward the message to CERT NZ (report@phishing.cert.govt.nz).
See what a genuine OpenAI (ChatGPT) message looks like, the real sender domain, the real link destination, and where to report a fake.


