Fake ChatGPT billing email targets work and home users
ChatGPT users are the target of a new phishing campaign — credential theft and payment fraud are now part of the AI workplace risk landscape.

Why it matters
As AI tools become embedded in enterprise workflows, they're becoming a vector for credential theft and payment fraud. Security teams need to brief users on ChatGPT-specific phishing threats alongside standard email hygiene.
The key facts
8 to knowCofense identified phishing campaign targeting ChatGPT users
Attackers targeting both work and home users
Credential theft and payment information theft are objectives
Fake billing emails used as social engineering vector
Cofense identified phishing campaign targeting ChatGPT credentials and payment information
Campaign targets both work and home users
Credential theft and payment fraud as attack vectors
September 2026 discovery
Go to the source
ITProitpro.com
Publisher excerpt: Cofense has uncovered a phishing campaign aimed at stealing ChatGPT credentials and payment information