Would you notice anything wrong if an email said your ChatGPT Plus payment didn't go through? On a busy morning, most of us wouldn't. You pay for a handful of subscriptions and you barely think about them; that's the whole point of a subscription. So when the email says update your card, the reflex is to fix it quickly, before anything gets cut off. That reflex is exactly what the scam is built around.
Why is a billing notice a better lure than a scary warning?
Most phishing tries to frighten you: your account was hacked, your parcel is held, your bank has locked you out. A failed-payment email doesn't need any of that. It's mundane. Cards expire. Banks decline things for no reason. A billing hiccup is boring and completely believable, which is precisely why it gets clicked.
It also asks for the one thing the attacker actually wants, and asks for it in a way that feels perfectly normal. Nobody is surprised that a payment-update page wants a card number. That's what a payment-update page is for.
Security firm Check Point flagged this exact campaign in its Q2 2026 brand phishing report, published on July 23, 2026. Their description is short and worth quoting in full: "One example from June involved a fake ChatGPT Plus billing email, built to look exactly like an OpenAI payment failure notice, that led to a page designed to harvest full credit card details."
Note the phrase "built to look exactly like." There is no bad logo to spot here.
And it isn't a handful of emails. In a September 10, 2026 post, Microsoft's security team described a ChatGPT-themed campaign that "sent up to 100,000 emails in a single day," tricking people into updating their ChatGPT Plus payment information and stealing personal and credit card data.
What did one of these emails actually look like?
Check Point described the campaign but didn't publish the addresses involved. An Australian email security company, MailGuard, intercepted and documented a version of it on July 10, 2026, and their write-up is the concrete one. Here's what they observed:
- The email claimed the recipient's ChatGPT Plus payment had failed and urged them to "update your payment details."
- The display name read "Chat GPT": the name your mail app shows in bold, which anyone can type as anything.
- The sender domain was
imi2001.co.jp. As MailGuard put it plainly, that domain "does not match OpenAI or ChatGPT's legitimate domains." - The link led to a counterfeit Stripe checkout page hosted at
argentina.alwaysdata.net: a free hosting subdomain, nothing to do with Stripe or OpenAI. - The page asked for email address, full card number, expiry, CVC, cardholder name and billing address. Not a partial verification. Everything needed to use the card.
And one nasty detail worth remembering: MailGuard notes the page threw fake error messages and retry prompts, so a victim would type their card details in more than once. If a payment page ever tells you "something went wrong, please try again," treat that as a reason to stop, not a reason to retype. 😅
imi2001.co.jpdisplay name said "Chat GPT"; the domain says otherwiseargentina.alwaysdata.neta free hosting subdomain wearing Stripe's designThis isn't even a clever lookalike. Nobody swapped a letter or registered openai-billing.com. It's an unrelated domain that presumably got compromised or was simply bought cheap, which tells you how little effort the design of the email required to work. The people who clicked weren't fooled by the domain. They never looked at it.
The lure isn't new, either. Someone posted a near-identical complaint to OpenAI's own community forum back in May 2025: a "your payment method stopped working" email, sent from a random address with no connection to OpenAI. Different year, same script.
Which check actually works? Read the domain after the @
Every email has two sender fields, and they are nothing alike:
- The display name. "Chat GPT," "OpenAI Billing," "Support." Free text. The sender types whatever they want. It carries no information at all.
- The actual address. The part after the
@. This is a real domain that someone had to register and control. It's the one part of the email the design team can't fake.
On most mail apps the address is hidden behind the display name until you tap or hover on the sender. Do that. Then read the domain right to left: the real owner is the last two chunks before the first slash. billing.openai.com is owned by openai.com. openai.com-billing-update.info is owned by com-billing-update.info, and the brand name at the front is bait. (We went through that reading trick in detail in read the domain right to left.)
Then there's the check that costs nothing and beats all of this: don't use the link. If you genuinely might have a billing problem, open a new tab, type the service's address yourself, and look at your billing page there. A real failed payment will be waiting for you inside your account. A fake one won't exist.
Where does IP Tracker fit?
IP Tracker is a free Chrome extension. Paste in a full email address, the whole thing, something@imi2001.co.jp, and it pulls out the domain and checks that. The free tier is 50 checks a day, no account, no tracking. Only the value you paste is looked up.
For a sender domain, it does three things at once. It compares the domain against the official domains of about 125 widely impersonated brands, normalizing look-alike characters first (the number 1 and capital I become a lowercase l, zero becomes the letter O, common Cyrillic look-alikes map back to Latin), so a letter-swap fake gets named even when your eye slid past it. It checks whether Google Safe Browsing (Google's list of reported dangerous sites) has flagged it, and how many security vendors flag it on VirusTotal. And it shows the domain's registration date, because a domain created eleven days ago that's emailing you about your subscription is a signature worth seeing.
What you get back is plain English: flagged as a lookalike, on a blocklist, or nothing found, plus who owns the domain and when it was registered, so you can decide.
What can't it do?
Honesty matters more than comfort here, so four real limits:
- An unrelated domain isn't a lookalike. This is the big one for this scam.
imi2001.co.jpisn't imitatingopenai.comin any way a computer can measure; it's just a domain that has nothing to do with OpenAI. The lookalike check won't light up on it. What the tool can tell you is who owns it, when it was registered, and whether it's been reported. The judgment call ("is this plausibly OpenAI's billing domain?") stays with you. - Blocklists lag. Google Safe Browsing is strong on known bad sites. A page put up this week may not be reported yet; see why a brand-new domain is a warning, not an all-clear.
- Compromised legitimate domains are hard. When phishing is sent through a real company's hijacked mail server, the domain has years of clean history behind it. Age and reputation checks say the wrong thing.
- It doesn't block anything. IP Tracker checks what you paste and reports what it finds. It doesn't watch your inbox, doesn't sit between you and the web, and can't stop you clicking. It surfaces signals; the decision is yours.
The design of the email is the part the attacker controls completely, so it's the part that will always look perfect. The domain it came from is the part they have to actually own, which is why that's the part worth two seconds of your attention.
To summarize:
- ✓ A failed-payment notice works because it's boring and believable, and because asking for a card looks normal.
- ✓ Ignore the display name. Read the domain after the
@, right to left. - ✓ A payment page that "errors" and asks you to re-enter your card is collecting it twice.
- ✓ Never fix a billing problem through an emailed link; go to the site yourself and check your account.
- ✓ Or paste the sender's address into IP Tracker and see what's known about that domain.
Nothing about a subscription is ever that urgent. Let the panic wait five minutes. 😉
Sources
- Which brands are impersonated most? Inside the Q2 2026 brand phishing report, Check Point, July 23, 2026.
- Detect and disrupt AI-themed attacks with Microsoft Defender, Rob Lefferts, Microsoft Security Blog, September 10, 2026.
- ChatGPT "Update your payment details" phishing email leads to fake Stripe payment page, MailGuard, July 10, 2026.
- Infosecurity Magazine and Help Net Security, coverage of the Check Point report.
- Scam alert: fake OpenAI subscription email requesting payment details, OpenAI Developer Community, May 2025.