KOM CLOUDSERVICE
All Insights

The ChatGPT Billing Email Is a Phishing Scam. Here's the Tell.

Fake ChatGPT and AI subscription renewal emails are landing at month-end to steal your payment details. Here's how to spot them and what to do.

A new batch of phishing emails is impersonating ChatGPT and other AI services, and the timing is deliberate. Security researcher Xavier Mertens at the SANS Internet Storm Center spotted one landing at the end of the month, right when your normal billing cycle resets and a “your subscription needs to renew” email doesn’t look out of place. The goal is simple: get you to type your payment details into a fake page.

If your business pays for ChatGPT, Claude, Copilot, or any AI tool on a company card, this one is aimed at you.

Why AI billing scams work right now

Phishing works by making you afraid to lose something. Usually that’s money or account access. What’s changed is that AI tools have quietly become part of how a lot of small businesses operate. Your bookkeeper drafts letters with it. Your office manager summarizes documents. Somebody on your team may be paying $20 or $30 a month for a subscription nobody else even knows about.

So when an email arrives saying “your ChatGPT payment failed, update your card to keep access,” it lands on fertile ground. The person reading it doesn’t want to lose the tool mid-task. They click. They don’t stop to check the address the email actually came from, or where the “update payment” button really goes.

The criminals aren’t installing malware here. They just want the card number, the expiration, the security code, and often the billing address. That’s enough to run charges or resell the card. It’s the same trick behind the fake Fortnite reward pages Malwarebytes wrote about this week, where scam sites promise free rewards and instead serve up a fake login page to harvest credentials. Different bait, same machine underneath.

What this means for your business

A single stolen company card is annoying but survivable. The bigger risk is what the pattern tells you about your team.

If someone will type payment details into a fake ChatGPT page, they’ll do the same for a fake Microsoft 365 renewal, a fake QuickBooks invoice, or a fake Google Workspace notice. The AI angle is just this month’s costume. The habit of clicking the button in the email and trusting the page that loads is the actual vulnerability, and it doesn’t care which brand is being faked.

There’s also the shadow-subscription problem. When staff sign up for AI tools on personal or company cards without telling anyone, you have no idea how many billing relationships exist, which means you can’t tell a real renewal notice from a fake one. That gap is exactly what these emails exploit.

What to do this week

None of this needs a big project. Here’s the order I’d handle it in.

  1. Send a two-line heads-up to your whole team today. Tell them fake ChatGPT and AI billing emails are going around, and that nobody should ever update payment details from a link in an email. This costs nothing and stops most of these cold.

  2. Set the rule: go to the site directly. If an email says your AI subscription needs attention, don’t click anything. Open a browser, type the real address yourself (chatgpt.com, claude.ai, microsoft.com), and check your account there. If there’s a real problem, it’ll show up when you log in normally.

  3. Check the sender and the link before trusting either. A real OpenAI email won’t come from a random domain. Hover over the button (don’t click) and look at where it actually points. If the address looks off, or is a lookalike with an extra word or a different ending, it’s fake.

  4. Inventory who’s paying for what. Ask your team, in writing, which AI and SaaS tools they’re subscribed to and on which card. You can’t spot a fake renewal for a service you didn’t know you had. This also catches wasted spend, which pays for itself.

  5. Put AI tools on one account with a shared card where you can. Fewer scattered subscriptions means fewer emails your team has to judge, and a clearer picture of what a legit notice looks like.

  6. Turn on card alerts. Real-time transaction texts from your bank mean a fraudulent charge gets caught in minutes instead of on next month’s statement.

If someone did enter card details already, call the bank, kill the card, and watch the statement. If they reused that password anywhere, change it there too.

The thread running through all of this is that no amount of software fully covers a team that clicks first and checks later. Good email filtering (part of what we run for clients) catches a lot of these before they land, and it’s worth having. But the habit of going to the site directly instead of clicking the button is the part that protects you when a new scam slips through, and one always eventually does.

If you’re not sure whether your email filtering and staff would catch something like this, that’s a quick thing to check together. Book a free 15-minute consult and we’ll take a look at where you stand.

Talk to the person who'll actually run your IT.

Book a free 15-minute consult. No sales pitch from a stranger, just a straight conversation about what your business needs.

Book your free consult

Or call (732) 701-7012

Monthly agreements, not multi-year lock-ins  ·  No call centers, ever