Fake ChatGPT Work giveaway targets users
A post on X promotes a fake OpenAI campaign offering $100 in free ChatGPT Work credits for the first 10,000 users who share their thoughts about the product. The links provided redirect to a typosquatted phishing domain (share-chatgpt-work.openai.chatgpt.site), which mimics OpenAI branding in an attempt to steal user credentials or distribute malware.
Threat actors are actively capitalizing on OpenAI's brand recognition to deploy social-engineering campaigns that leverage viral social media sharing. The domain chatgpt.site is unauthorized and masquerades as official OpenAI infrastructure. Requiring users to tweet about the promotion increases the reach and velocity of the phishing campaign, and these campaigns frequently lead to credential harvesting or malware distribution.
DISCOVERED
11h ago
2026-07-20
PUBLISHED
12h ago
2026-07-20
RELEVANCE
AUTHOR
gdb