“Failure to pay ChatGPT subscription”: the new email scam targeting OpenAI users

Written by Jason Miller

"Failure to pay ChatGPT subscription": the new email scam targeting OpenAI users

Many are receiving fraudulent emails reporting “failure to pay for the ChatGPT subscription”, OpenAI’s artificial intelligence. How to recognize them and what to do to protect yourself.

ChatGPTthe linguistic model of artificial intelligence developed by OpenAIis at the center of a fraud which is spreading to various parts of the world, Italy included. In simple words, users, too do not subscribe to the service, they are receiving fraudulent emails to your email address, in which you are notified of a failure to pay the subscription and to do so by clicking on a specific one link. As always happens in the cases of phishingthe text is set to increase the sense of urgency for the user, under penalty of suspension of service. The emails seem authentic, genuine, with the tone, setting and layout of the messages that actually come from OpenAI, however upon closer inspection different ones emerge anomalies which reveal the scam. We will discuss it shortly.

The objective of the scammers is not to obtain – possibly – the “unpaid” monthly fee mentioned in the email, but rather to recover credentials, identity, login and banking details in order to execute fraudulent transactions on behalf of the unfortunate person who ends up clicking on the link. This data can be used immediately to make withdrawals or organize other scams, or be resold in the infamous darkweb to criminal organizations. What is certain is that the risks for those who fall into the trap are very high. With phishing, which is increasingly sophisticated and plausible, scammers shoot into the mix hoping that someone take the baitleveraging precisely the need to regularize one’s position as soon as possible, with the risk of losing the precious service, which many now also use for Work. Losing access can have serious repercussions and so someone might act on impulse following the instructions of a plausible, but absolutely false, email. After all, with more 1 billion users monthly, of which well 15 million in Italy, ChatGPT is one of the most used language models in the world.

One of these emails also arrived in the inbox of a user of one of the main companies he deals with software for IT security (such as antivirus and similar). As explained in his post, analyzing the message it emerges that thee-mail address of the sender – in his case – is linked to a compromised German domain and not to an official OpenAI one. The company generally writes from the following official addresses: openai.com; chat.openai.com and occasionally notices.openai.com, as reported by systemscloud.co.uk. Furthermore, hovering the mouse over the refresh button displayed a URL confusing that has nothing to do with OpenAI’s official billing system. The links included in the email – such as “unsubscribe” and “privacy policy” – probably led to clone sites official ones, designed to steal the data of the unsuspecting user.

They promise free Spotify Premium but steal personal data: the new scams on Instagram and TikTok

systemscloud.co.uk also shows one of these ChatGPT-themed scam emails, warning of non-payment of the subscription and the need to update the billing information. Upon closer inspection, the sender of the email was not linked to an OpenAI domain but to that of one telecommunications company from Mauritius. Even though it is a legitimate domain, why would OpenAI send an email from such a route? In the text of the email, although exposed with cordial tone but always set to instill a sense of urgency in the user, basic information such as the name of the is missing recipient and his tariff planspecific information that – theoretically – only OpenAI could have known. Everything is designed to make you click without thinking too much on the “update payment method” button, where you end up on the aforementioned clone site and above all in trouble if you have to enter the real data.

The advice, when receiving emails of this type, is always the same: verify that the sender is genuine; do not click on any links; log in to your official ChatGPT account (or other service) to check the real status of payments; cross-check other platforms (like Reddit); and report to the appropriate authorities, should it be confirmed that we are dealing with a fraudulent email. Taking your time, not acting on impulse and checking (without clicking anywhere in the email) is the best way to protect yourself from phishing and other types of online scams.

Jason Miller

I'm Jason Miller, and I've been passionate about technology and storytelling for over a decade. As a lead writer at Herald Editorials, I strive to bring clarity and creativity to complex tech topics. When I'm not writing, you'll find me exploring the latest gadgets or hiking in the great outdoors.