The "ChatGPT Plus payment failed" email is phishing, and the card form is the whole point
Delete it. OpenAI does not fix a billing problem by sending you to an outside page for your full card number. Check Point Research's Q2 2026 Brand Phishing Report, published July 23, 2026, put ChatGPT among the ten most impersonated brands for the first time, and the campaign it singled out is this one: an email dressed as an OpenAI billing notice, leading to a page built to harvest card details.
TL;DR
An email saying your ChatGPT Plus payment failed, with a link to update your card, is phishing. Real OpenAI billing lives inside your own account, not behind a link in a warning email. Close the message and open chatgpt.com yourself, then go to your profile icon, Settings, Account, Payment. If your card genuinely needs updating, you will see it there. Subscribed through Apple's App Store or Google Play? The subscription is managed on that store instead, and no OpenAI web page can change it. The page the email points at wants one thing: your card number, expiry, security code and billing address, all in one form.
Why ChatGPT landed on the phishing top ten for the first time
Check Point Research ranks the brands criminals wear most often, quarter by quarter. The Q2 2026 Brand Phishing Report, out on July 23, 2026, has the usual heavyweights on top: Microsoft at 23% (22.6% in Check Point's own chart) of all brand phishing attempts, LinkedIn at 11.6%, Google at 6.7%, Apple at 5.8% and Amazon at 5.2%. Those five together cover more than half of everything tracked in the quarter.
The new name is further down. ChatGPT entered the top ten for the first time at 1.1%, in the same band as PayPal, WhatsApp and Facebook. Small share, big signal. As Infosecurity Magazine reported on July 24, the campaign behind the entry was seen in June: "a fake 'ChatGPT Plus payment failed' email the cybersecurity company observed in June. The malicious email was dressed up to look exactly like an OpenAI billing notice and led victims to a page built purely to steal full credit card details."
It works because it is boring. A paid AI subscription is now a routine monthly line item next to the streaming charges, and a declined card is the least dramatic thing that can happen to an account. Microsoft has held first place for years on the same instinct, which we break down in our guide to spotting a fake Microsoft email. Note that this is a different operation from the two other AI-branded campaigns we have documented: not the run hiding malware behind genuine chatgpt.com share links, nor the malvertising pushing a fake ChatGPT and Sora desktop download. No malware here at all. Just a form, and your card.
What the email actually says
The wording rotates, the script does not. Subject lines run along the lines of "Your ChatGPT Plus payment could not be processed", "Action required: update your payment method", or "Your subscription has been suspended". The body says your card was declined, Plus access ends shortly, and a button fixes it.
A first-hand report on the OpenAI Developer Community forum from May 2025 shows the same pattern in a private inbox: an email claiming the recipient's "payment method for ChatGPT subscriptions is no longer working", urging them to update payment details through a button. The sender was a personal mailbox at a Canadian consumer ISP, a legitimate provider but an outside account with no relationship to OpenAI.
Press the button and you land on a page reproducing the OpenAI billing screen well enough to survive a glance: wordmark, typeface, dark panel, a line naming your plan. Then it asks for everything at once. Full card number, expiry, security code, name, billing address. Here is the part most advice gets wrong: those fields are not the tell. A genuine card update asks for exactly the same ones, because the payment processor holds your OLD card, not the new one you are adding. The tell is how you arrived. A real update only ever happens on a page you opened yourself from inside your account, never on a page an email handed you.
Check Point did not publish domains for this campaign, so we are not going to invent evidence. The naming patterns are worth recognising, though. Expect something like openai-billing-update[.]com, chatgpt-plus-renew[.]help, or the sneakier shape where the brand sits in a subdomain and the real registrable domain hides at the end, as in chatgpt[.]account-billing[.]top. All three are illustrative examples, shown as plain text rather than links. The lesson holds whatever the string: read the domain from the right, at the last dot before the first slash, and ask whether OpenAI would own it.
Where real OpenAI billing actually lives
OpenAI documents its billing flow in its own help centre at help.openai.com, and you reach it from inside the product. On the web you open chatgpt.com, select your profile icon, then Settings, then the Account tab, then Payment, then Manage. Payment method, billing history and invoices all sit behind that. Manage hands off to OpenAI's own hosted billing portal at pay.openai.com, which is run on Stripe, so seeing that address after you clicked Manage yourself is expected. The company's main site is openai.com. Those are the legitimate surfaces, and the route matters as much as the address: reaching any of them by clicking a link in an email is the part that is never safe.
One wrinkle scammers rely on people not knowing: ChatGPT subscriptions are billed through the web, Apple's App Store, or Google Play, and are managed wherever they were bought. Subscribe on an iPhone and the payment method lives in your Apple account settings. An email pushing a web card form at an App Store subscriber contradicts itself before you even reach the domain.
ChatGPT Plus is a $20 per month individual plan, and lures in this family quote sums nowhere near it. Kaseya's researchers documented an OpenAI-themed invoice run in January 2026 whose fake charge was $763.99, with no link at all: its only call to action was a phone number. That is the callback pattern behind the fake invoice with a phone number scam and the [email protected] invoice scam.
Check the link, not the logo
SafeBrowz is a free browser extension for Chrome, Firefox and Edge, with Safari pending, plus an Android app. Its job here is narrow and useful: the moment an "update your payment method" link opens an OpenAI-branded billing form on a domain OpenAI does not own, you get a hard warning before the card fields are worth filling in. The local layer carries 550+ brands, OpenAI and ChatGPT included, and checks the brand shown on the page against the domain you actually landed on. The AI deep scan (Premium, $14.99/year) reads billing pages registered that same morning, the window where blocklists still have nothing.
Not sure where that billing link goes? Scan it free here first →
A genuine OpenAI sender address does not make the mail safe
Most advice about billing phishing stops at "check who sent it". With OpenAI, that advice has already been beaten twice this year. In June 2026, BleepingComputer reported a campaign uncovered by Push Security in which attackers created OpenAI organisation tenants named after real companies, then used OpenAI's own invite feature to mail employees of those companies. The invitations came from OpenAI's legitimate notification address, [email protected], and passed email authentication, because they were real OpenAI invitations. The tenant behind them was the fraud. That campaign wanted workspace access rather than card details, but the lesson transfers: a sender field can be genuine while the intent behind the message is hostile.
Separately, Kaseya reported in January 2026 that an OpenAI-themed invoice campaign was sent through a SendGrid account configured on the openai.com domain, so the messages passed SPF, DKIM and DMARC for that domain. Take that as reported by Kaseya rather than settled fact, but the direction is clear. Authentication proves an email left through an authorised door. It does not prove who was standing at it.
So tm.openai.com is real, and seeing it should not end your investigation. The durable check is not who sent the message. It is where the link lands, and whether your account agrees with the story. We work through that test brand by brand in our guide to telling whether an email is really from the company it claims.
Five things that give this campaign away
- It asks for a card on a page you reached from an email. The one rule that survives every redesign of every phishing kit.
- The registrable domain is not chatgpt.com or openai.com. Brand words in a hostname are free. Read from the right and check the actual domain, not the reassuring words in front of it.
- The amount does not match your plan. A charge nowhere near your normal figure is engineered outrage, not a billing error.
- There is a deadline. "Within 24 hours", "suspended today", "final notice". Real billing systems retry a declined card quietly over days and tell you inside the product.
- It wants everything, or it wants you to call. It asks you to arrive by link. The card fields themselves are normal, a real update asks for the same ones, so judge the route rather than the form. A phone number instead of a link is the callback variant, aimed at people trained not to click.
Still unsure? The account settles it. Open ChatGPT yourself and look at the billing page. No problem there, no problem. The same test works for every subscription lure, from the long-running Netflix account on hold email onward.
If you already typed your card details
Assume the number is being tested within minutes, and move in this order.
Call your card issuer now, using the number printed on the back of the card or inside your banking app, never a number from the email. Say the card was entered on a phishing page and ask them to block it and issue a replacement. A frozen card beats a dispute filed later, and a stolen card is usually validated with a tiny test transaction first, so report every charge you did not make, however trivial.
If you also typed an OpenAI password, change it by going to chatgpt.com directly, turn on two-factor authentication while you are there, and check whether any workspace you do not recognise has been added to the account. Change that password anywhere else you reused it.
Report it. In the United States, file with the FTC at reportfraud.ftc.gov. Elsewhere, use your national fraud reporting body. Then reduce next time's exposure: a dedicated virtual card number per subscription caps the damage of exactly this scenario, as covered in the virtual card defence guide.
How SafeBrowz reads a fake OpenAI billing page
SafeBrowz runs a 3-layer detection architecture: Local + APIs + AI. The email sits in your inbox, out of reach. The theft happens one step later, in the browser, on the card form, and that is the step the extension stands in front of.
- Layer 1 - Local detection: 60+ URL patterns and a 550+ brand database run inside the extension before the page paints. OpenAI and ChatGPT are tracked brands, so their names in a hostname that is not an official OpenAI domain trip the brand-impersonation signal at once, no network call needed. The subdomain trick is exactly what this layer unpicks.
- Layer 2 - API checks: the domain is cross-referenced server-side against Google Safe Browsing, PhishTank, URLhaus, ScamAdviser feeds and a 30+ scam TLD watchlist. A days-old domain hosting a payment form is a weighted signal in itself.
- Layer 3 - AI deep scan (Premium): AI content analysis via our proxy reads the page as an investigator would: an OpenAI-branded billing panel, a card form wanting number, expiry and security code together, suspension copy, a domain unrelated to OpenAI. That combination earns a danger verdict in seconds, even on a page registered this morning.
The honest limit: SafeBrowz flags the counterfeit billing page when you open the link. It cannot stop the email arriving, and it cannot recall a card number already submitted. What it buys you is a warning at the one moment that decides the outcome, the second before the card goes in.
Detection signatures are derived from threat-intelligence research and our internal brand database, not from user browsing data. SafeBrowz does not store per-user browsing history.
Check that "update your payment method" link right now
Got a ChatGPT or OpenAI billing email and unsure where its link leads? Paste it here. Our 3-layer engine (Local + APIs + AI) returns a verdict in about three seconds. Free, no signup. Never type a card number on a page an email sent you to.
Frequently asked questions
Is the "ChatGPT Plus payment failed" email real?
No. Check Point Research named this exact lure in its Q2 2026 Brand Phishing Report, published July 23, 2026: a fake subscription failure email leading to a page built to steal full credit card details. It is the campaign behind ChatGPT entering the ten most impersonated brands for the first time. Treat any billing email that sends you off-site for card details as phishing, and check your real status by opening chatgpt.com yourself.
How do I check my real ChatGPT Plus billing status?
Do it in the product, never from a link. Open chatgpt.com or the ChatGPT app yourself, select your profile icon, then Settings, then the Account tab, then Payment, then Manage. Payment method, invoices and billing history all sit there, and OpenAI documents the flow at help.openai.com. If you subscribed through Apple's App Store or Google Play, the subscription is managed in that store instead.
Is [email protected] a genuine OpenAI address?
Yes, it is OpenAI's real notification address, which is why checking the sender alone is not enough. In June 2026 BleepingComputer reported a campaign, uncovered by Push Security, in which attackers created OpenAI organisation tenants named after real companies and used OpenAI's own invite system, so the emails came from that genuine address and passed authentication. The reliable checks are where the link lands and whether your account confirms the story.
I entered my card details on the fake OpenAI page. What should I do?
Call your card issuer immediately, using the number on the back of the card rather than any number from the email, and ask them to block it and send a replacement. Watch for a small unfamiliar charge, which is how a stolen card is usually tested, and dispute anything you did not authorise. If you typed an OpenAI password too, change it at chatgpt.com and enable two-factor authentication. In the US, report it at reportfraud.ftc.gov.
Why is ChatGPT suddenly being impersonated so much?
Because paying for AI became ordinary. Check Point's Q2 2026 data still has Microsoft far in front at 23% of brand phishing, with the top five brands covering more than half of all activity. ChatGPT's 1.1% is a first appearance, and it tracks the fact that millions of people now manage a recurring AI subscription. Attackers follow routine payments, which is why streaming, storage and now AI services all attract the same billing lure.
Last updated 2026-07-24