Skip to content
OpenAI - H
GlobalGuardAug 18, 2026, 3:43:22 PM3 min read

ChatGPT 'Update Your Payment Details' Scam

A new phishing email campaign is impersonating ChatGPT and OpenAI billing. The scam claims that the recipient’s last ChatGPT Plus payment has failed and urges them to “update your payment details”, but instead directs them to a fake Stripe checkout page designed to steal email addresses, credit card details and billing information.

What the email looks like.

The body of the email informs the recipient that the last payment for their ChatGPT Plus subscription failed on a specific date and states there is a problem with the payment method. It instructs the user to check with their bank or card issuer, then click a link to update payment details and resubscribe. A second link is presented as a “support article”, but both links point to the same destination. 

OpenAI - 1

Example phishing content shown using ChatGPT branding. Not affiliated with ChatGPT.

How the scam works.

Clicking either the “Update your payment details here” link or the “support article” link takes the recipient to a phishing site that imitates a Stripe checkout page used for OpenAI billing.

This layout is designed to mimic legitimate Stripe‑powered billing flows and encourage users to enter full payment details.

OpenAI - 2

Example phishing content shown using ChatGPT branding. Not affiliated with ChatGPT.

When card details are entered, a VISA‑branded pop‑up appears withF a loading indicator, GlobalGuard’s analysis indicates this step is used to create the impression of a secure transaction being processed, reinforcing trust and encouraging users to wait while their details are captured. 

OpenAI - 3

Example phishing content shown using ChatGPT branding. Not affiliated with ChatGPT.

After a short period, the VISA pop‑up times out, and the user is returned to the payment page, where an error message is displayed. GlobalGuard’s operations team observed this behaviour during testing using fake card details, confirming that the phishing site is designed to simulate a failed transaction. This tactic encourages victims to retry with different cards or re‑enter their information, increasing the likelihood of capturing valid payment data. 

OpenAI - 4Example phishing content shown using ChatGPT branding. Not affiliated with ChatGPT.

In some variants, the phishing site presents a page titled “PAYMENT ISSUE” with a red warning box. This variant reinforces urgency and encourages immediate action to “fix” the problem.

OpenAI - 5

Example phishing content shown using ChatGPT branding. Not affiliated with ChatGPT.

Why this campaign is concerning. 

This campaign is notable because it targets a widely used AI service and leverages familiar subscription language to drive action. Many organisations now use tools like ChatGPT for productivity, development and research, making billing‑related emails more likely to be trusted and acted upon quickly.

The attackers are attempting to collect:

  • Email addresses

  • Full card numbers

  • Expiry dates and CVC codes

  • Cardholder names

  • Billing addresses

This combination of data can be used to conduct fraudulent transactions, commit card‑not‑present fraud, and support broader identity‑based attacks.

For risk, security, technology and business leaders, this type of attack highlights the importance of treating subscription and billing emails with the same scrutiny as traditional banking or utility communications.

Warning signs to watch for. 

There are several warning signs in this campaign:

  • The sender domain (imi2001.co.jp) does not match OpenAI or ChatGPT’s legitimate domains.

  • The display name “Chat GPT” is inconsistent with official branding.

  • Both the “Update your payment details here” link and the “support article” link point to the same non‑OpenAI site.

  • The Stripe checkout page is hosted on a domain such as argentina.alwaysdata.net, which is not associated with OpenAI or Stripe’s official infrastructure.

  • Error messages and repeated prompts to re‑enter card details are used to encourage multiple attempts.

Recipients should be cautious of any unexpected payment failure notifications, especially those that request full card details via embedded links. Accessing billing portals via known, bookmarked URLs or official account dashboards, rather than email buttons, significantly reduces the risk of successful phishing attacks.

Stay safe, know the signs. 

GlobalGuard advises all recipients of these emails to delete them immediately without clicking on any links. Responding or providing personal details can lead to identity theft, data breaches, and financial losses. 

Talk to our team

Reach out to speak to a GlobalGuard expert about securing your inboxes against advanced, malicious email-borne threats with our AI-powered email security solutions. 

COMMENTS

RELATED ARTICLES