Stolen session led to $293.37 CAD fraudulent Pro upgrade — and total OpenAI support lockout
Zylora · reddit · 2026-09-15
A nearly 4-year ChatGPT paying user details how his account was hijacked and how OpenAI's support system then locked him out entirely.
- An infostealer infection in May left an active ChatGPT browser session token alive; the attacker used it weeks later
- On Aug 24 the intruder fraudulently upgraded the account from Plus to Pro, charging $293.37 CAD, and ran abusive Codex scripts
- OpenAI deactivated the account for cyber abuse on Sept 11; the user's incomplete appeal (filed before knowing the full scope) was denied
- Since then: emails to support auto-bounce, the Help Centre chat closes the instant he enters his email, and appeal form submissions vanish with no confirmation
The post highlights both the risk of unexpired session tokens and the lack of human fallback in OpenAI's automated support flows.
More from Safety
- 1557 Printing Monopoly Mirrors Today's Compute Thresholds — alexcovo_eth · 2026-09-15
- AI Safety Paradox: Labs Ask Models to Break Into Systems, Then Act Surprised — dreamwieber · 2026-09-15
- Musk proposes AI companies peer-test each other's models before release — EthanJPerez · 2026-09-15
- One Guardian AI safety story: reporter, outlet, subject and experts all Open Phil-funded — JacquesThibs · 2026-09-15
- Hugging Face breach postmortem: 95% of rogue agents came from one internal OpenAI model — TobyWalsh · 2026-09-15
- Beff Jezos: "There is no slowing down. Accelerate or fall by the wayside" on AI pauses — beffjezos · 2026-09-15