如果您订阅了 ChatGPT,一封声称您的订阅出现问题的邮件很容易引起您的注意。可能是您的信用卡过期了,也可能是付款失败了。无论如何,您可能希望在账户出现任何问题之前解决它。网络犯罪分子正是利用了这种反应。
If you pay for ChatGPT, an email saying there is a problem with your subscription could easily get your attention. Maybe your card expired. Maybe the payment failed. Either way, you probably want to fix it before anything happens to your account. Cybercriminals are counting on that reaction.
安全研究公司 Cofense 的研究人员发现了一场冒充 OpenAI 和 ChatGPT 的网络钓鱼活动。这封伪造的邮件看起来像是一份例行的订阅通知。然而,邮件中的按钮可能会引导您进入一个极具迷惑性的 ChatGPT 仿冒页面。Cofense 表示,该活动旨在窃取账户凭证和支付信息。
Security researchers at Cofense uncovered a phishing campaign that impersonates OpenAI and ChatGPT. The fake email looks like a routine subscription notice. However, the button inside can lead to a convincing copy of the ChatGPT page. Cofense says the campaign targets account credentials and payment information.
错过 CyberGuy 直播?观看“利用 AI 获得更好的医疗服务”回放 我们免费的 CyberGuy 直播课程“利用 AI 获得更好的医疗服务”已结束,但您仍可观看完整回放。Kurt "CyberGuy" Knutsson 将为您演示 AI 协助您整理病历、记录重要预约详情、理解复杂医疗信息、查询处方药以及为医生准备更明智问题的五种实用方法。无需任何技术背景。
Missed CyberGuy LIVE? Watch the Get Better Healthcare With AI replay Our free CyberGuy LIVE class, Get Better Healthcare With AI , has ended, but you can still watch the full replay. Kurt "CyberGuy" Knutsson walks you through five practical ways AI can help you organize your health history, remember important appointment details, understand complicated medical information, research prescriptions and prepare smarter questions for your doctor. No technical experience is needed.
骗子深知发短信的最佳时机 诈骗始于一封看起来足够专业、让您不得不停下来查看的邮件。根据 Cofense 网络钓鱼防御中心的报告,该邮件使用了真实的 ChatGPT 标志,并声称您的订阅付款需要关注。随后施加压力。邮件醒目地显示“需要订阅付款”,并警告您只有 48 小时采取行动。一个醒目的“更新付款信息”按钮为您提供了一个所谓的显而易见的解决途径。最后,邮件以“OpenAI 团队”署名。如果您在会议间隙查看邮件,或在手机上快速浏览,所有这些都会让人觉得可信。Cofense 指出,攻击者结合熟悉的图像、醒目的措辞和紧迫感,诱导人们仓促行动。
SCAMMERS KNOW THE BEST TIME TO TEXT YOU The scam starts with an email that looks polished enough to make you pause. According to the Cofense Phishing Defense Center, it uses the real ChatGPT logo and claims your subscription payment needs attention. Then comes the pressure. The message prominently displays "Subscription Payment Required." It also warns that you have 48 hours to act. A large "Update Payment Information" button gives you an obvious way to supposedly fix the problem. Finally, the message signs off as "The OpenAI Team." If you are checking email between meetings or quickly scrolling on your phone, all of that can feel believable. Cofense says the attackers combine familiar images, bold wording and urgency to push people into acting quickly.
发件人的电子邮件地址是最大的危险信号之一。Cofense 发现,该钓鱼邮件来自 support@9527db6e1a[.]nxcli[.]io。该域名与 OpenAI 毫无关系。OpenAI 目前列出了几个用于合法客户邮件的域名。它们包括 @openai.com、@mail.openai.com 和 @email.openai.com,以及用于特定通信的其他官方 OpenAI 域名。这使得检查完整的发件人地址变得值得。不要依赖收件箱中显示的名称。骗子可以让显示的名称看起来令人放心,而背后使用的却是完全无关的地址。
The sender's email address is one of the biggest red flags. Cofense found that the phishing message came from support@9527db6e1a[.]nxcli[.]io. That domain has nothing to do with OpenAI. OpenAI currently lists several domains that it uses for legitimate customer emails. They include @openai.com, @mail.openai.com and @email.openai.com, along with other official OpenAI domains used for specific communications. That makes the full sender address worth checking. Do not rely on the name that appears in your inbox. A scammer can make the display name look reassuring while using a completely unrelated address behind it.
假 Chrome 更新诈骗可能感染您的电脑 这封钓鱼邮件中的按钮增加了另一层欺骗。Cofense 发现,点击“更新付款信息”首先会通过 Google API 重定向将用户发送出去。然后该链接将他们转发到攻击者的恶意网站。这会让可疑链接乍一看更具说服力,因为过程中出现了 Google。我们以前见过罪犯在类似攻击中滥用受信任的服务。CyberGuy 此前曾报道过黑客如何利用合法的 Google Cloud 工具发送看起来像真实 Google 通知的钓鱼邮件。因此,链接中出现 Google 并不能告诉你最终会跳转到哪里。在电脑上,将鼠标悬停在按钮上有时可以在点击前显示目标地址。尽管如此,重定向会让这种检查变得不那么有用。更安全的做法是完全跳过邮件中的链接。
FAKE CHROME UPDATE SCAM COULD INFECT YOUR COMPUTER The button inside this phishing email adds another layer of deception. Cofense found that clicking "Update Payment Information" first sent users through a Google API redirect. The link then forwarded them to the attacker's malicious site. That can make a suspicious link look more convincing at first glance because Google appears along the way. We have seen criminals abuse trusted services in similar attacks before. CyberGuy previously covered how hackers used legitimate Google Cloud tools to send phishing messages that looked like authentic Google notifications. So, seeing Google somewhere in a link does not tell you where you will eventually land. On a computer, hovering over a button can sometimes reveal the destination before you click. Still, redirects can make that check less useful. The safer option is to skip the email link entirely.
一旦有人点击进入,骗局就更难识别了。Cofense 表示,该钓鱼页面高度仿制了 ChatGPT 的体验,包括熟悉的标志、文字和图标。然而,浏览器中的域名与 Cofense 确认的合法 ChatGPT 域名不符。如果受害者输入信息,虚假网站会捕获并发送给攻击者。随后页面会将受害者重定向到一个错误屏幕,这很容易让人误以为只是暂时故障。到那时,攻击者可能已经窃取了凭证。这就是为什么在输入密码前检查地址栏至关重要。骗子可以复制页面的外观,但无法让无关域名归属于 OpenAI。我们已联系 OpenAI 置评,但截至截稿前未收到回复。
Once someone clicks through, the scam gets harder to spot. Cofense says the phishing page closely copies the ChatGPT experience, complete with familiar logos, text and icons. However, the domain in the browser does not match the legitimate ChatGPT domain identified by Cofense. If a victim enters information, the fake site captures it and sends it to the attacker. The page then sends the victim to an error screen, which could easily look like a temporary problem. By then, the attacker may already have the credentials. That is why it is worth checking the address bar before you enter a password. Scammers can copy the look of a page. They cannot make an unrelated domain belong to OpenAI. We reached out to OpenAI for comment but did not hear back before our deadline.
如果邮件称存在付款问题,请勿点击按钮。直接访问 ChatGPT 或打开官方应用自行查看。对于网页订阅,OpenAI 建议检查“设置 → 账单”。部分账户可能显示“设置 → 账户 → 付款 → 管理”。如果您通过 Apple 或 Google Play 订阅,请通过相应商店管理订阅。
If an email says there is a payment problem, skip the button. Go directly to ChatGPm or open the official app and yourself. For web subscriptions, OpenAI says to check Settings → Billing . Some accounts may show Settings → Account → Payment → Manage instead. If youd through Apple or Google Play, manage your subscription through that store.
展开发件人信息,查看实际邮箱地址。在此次活动中,发件人使用了 nxcli.io 域名。OpenAI 公开了其用于合法通信的域名,供您核对比对。
Expand the sender information and look at the actual email address. In this campaign, the sender used an nxcli.io domain. OpenAI publishes the domains it uses for legitimate communications, which gives you something concrete to compare against.
在输入密码或付款信息前,请检查浏览器地址栏。如果域名看起来陌生,请关闭页面。然后通过官方应用或网站自行打开服务。这一习惯同样能保护您免受假冒银行网站的侵害。我们近期曾报道,犯罪分子购买赞助搜索广告,将受害者引导至仿冒银行页面。
Check the browser address bar before entering a password or payment information. If the domain looks unfamiliar, close the page. Then open the service yourself through its official app or website. This same habit can protect you from fake banking sites. We recently covered criminals who bought sponsored search ads that sent victims to lookalike bank pages.
切勿在其他账户重复使用 ChatGPT 密码。我们建议使用唯一密码,并推荐使用密码管理器生成和存储。这样,即使一个密码被盗,也难以轻易解锁您的多个账户。
Never reuse your ChatGPT password on other accounts. We recommend using a unique password and suggest a password manager to generate and store it. That way, one stolen password cannot easily unlock several of your accounts.
OpenAI 支持双因素认证,即 2FA。您可以在 ChatGPT 设置的“安全”部分启用它。根据您的账户,可用的验证方式可能包括验证器应用、推送通知、短信或通行密钥。如果有人获取了您的密码,2FA 会增加一道防线。不过,启用 2FA 不会自动结束已登录的会话。
OpenAI supports two-factor authentication, or 2FA. You can enable it from the Security section of your ChatGPT settings. Depending on your account, available verification methods may include an authenticator app, push notification, text message or passkey. 2FA adds another hurdle if someone gets your password. However, enabling 2FA does not automatically end sessions that are already logged in.
强大的杀毒软件可以帮助警示您有关恶意链接和钓鱼网站的信息。它还可以拦截可能通过诈骗邮件到达的其他威胁。请在您用于查看电子邮件或访问重要账户的每台设备上保持该防护处于最新状态。请访问 Cyberguy.com 查看我为您的 Windows、Mac、Android 和 iOS 设备推荐的 2026 年最佳杀毒保护软件。如果您在可疑网站上输入了密码,请立即更改密码。然后打开 ChatGPT,前往“设置”→“安全”→“活动会话”。查看列出的设备和会话。如果发现不认识的内容,请将其登出。
Strong antivirus software can help warn you about malicious links and phishing websites. It can also block other threats that may arrive through scam emails. Keep that protection updated on every device where you check email or to important accounts. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com Change your password immediately if you entered it on a suspicious site. Then open ChatGPT and go to Settings → Security → Active sessions . Review the listed devices and sessions. If you see something you do not recognize, log it out.
OpenAI 还允许您前往“设置”→“安全”→“活动会话”,然后选择“退出所有会话”。该公司表示,在所有设备上退出登录可能需要长达 30 分钟。如果您使用 Google、Microsoft 或 Apple 账户登录 ChatGPT,请同样保护好该账户。
OpenAI also lets you go to Settings → Security → Active sessions and choose Log out of all session s. The company saysg out across every device can take up to 30 minutes. If you use Google, Microsoft or Apple to to ChatGPT, secure that account as well.
如果您向可疑网站提供了银行卡信息,请拨打卡背面的电话号码。告知发卡机构您的支付信息可能已泄露。然后检查近期交易,看是否有不认识的项目。发卡机构可能会建议更换银行卡。请遵循其指示操作,而不要等到出现欺诈性收费才采取行动。
If you gave a suspicious site your card information, call the number on the back of the card. Tell the issuer that your payment information may have been compromised. Then review recent transactions for anything you do not recognize. Your card issuer may recommend replacing the card. Follow its instructions rather than waiting for a fraudulent charge to appear.
Cofense 表示,该网络钓鱼活动针对通过个人和工作账户使用 ChatGPT 的人员。如果您输入了工作凭据或使用了公司管理的账户,请联系您的 IT 或安全团队。他们可以审查账户活动,并在必要时采取进一步措施。
Cofense says the phishing campaign targeted people using ChatGPT through personal and work accounts. If you entered work credentials or used a company-managed account, contact your IT or security team. They can review account activity and take additional steps if necessary.
这类诈骗之所以奏效,是因为邮件看起来像是你真正可能收到的内容。支付问题让人感觉很常规,这会让人放松警惕。如果你收到来自 ChatGPT 的账单警告,请勿使用信息中的链接。请自行打开 ChatGPT 并在该处查看你的账户。如果你已在可疑页面输入了密码,请立即修改密码并检查你的活动会话。如果你共享了支付信息,请联系你的发卡机构。
This scam works because the email looks like something you might actually expect to receive. A payment problem feels routine, and that can make people lower their guard. If you get a billing warning from ChatGPT, do not use the link in the message. Open ChatGPT yourself and check your account there. If you already entered your password on a suspicious page, change it right away and review your active sessions. If you shared payment information, contact your card issuer.
你是否曾收到过看起来完全合法的订阅警告,是什么让你在点击前察觉到了异常?请写信至 Cyberguy.com 告诉我们。注册我的免费 CyberGuy 报告
Have you ever received a subscription warning that looked completely legitimate, and what tipped you off before you clicked? Let us know by writing to us at Cyberguy.com Sign up for my FREE CyberGuy Report