The fake ChatGPT bill is for $23.80, and that is the clever bit
Twenty-three dollars and eighty cents. That is the number doing the work in a phishing campaign Cofense took apart this week, and its size is most of the trick.
The email turns up looking like a ChatGPT billing notice. Correct logo, a final notice tag, an outstanding balance of $23.80, and a warning that the account will be suspended within 48 hours unless payment details are updated. The subject line reads "Urgent: Update Your Payment Method to Avoid Service Interruption" and the whole thing signs off as "The OpenAI Team". Small enough that you might genuinely owe it. Annoying enough that you deal with it now rather than think about it. Josh Varden of Cofense's Phishing Defense Center followed the green button to see where it really went, and the sender address already gives the game away: support@9527db6e1a.nxcli.io, which is nobody's idea of OpenAI.
The link itself is the part worth understanding. It does not point at the fake site. It starts at notifications.googleapis.com, a genuine Google address, which then forwards the browser onward. Hovering to inspect a link, the advice everybody has been given for twenty years, shows you a Google domain and teaches you nothing. The same redirect problem turned up in Google's own search results last week. The page at the end of it copies the ChatGPT sign-in screen, takes the password, then drops you on an error page so it feels like nothing happened.
Judge the address bar after you land, not the link before you click: OpenAI's real sign-in lives at auth.openai.com. Better still, close the email and open the service yourself. If a password has already gone somewhere it should not have, Tendvane's privacy and accounts check is a reasonable next stop.