Cyber Security News reported September 1, 2026 that scammers are using real shared ChatGPT links to fool Windows users into installing malware. The shared page is on chatgpt.com. The trap is a fake message that claims there is too much traffic and tells people to take extra steps outside the normal site.
This is feature abuse, not a reported OpenAI or ChatGPT platform hack. Analysts quoted by CSN stress that the legitimate ChatGPT domain was not compromised. Push Security documented the same trusted-share pattern on May 29, 2026 under the name LLMShare. BleepingComputer independently covered that campaign the same day.
This is not a duplicate of ClickLock Stealer (macOS locker, not a ChatGPT share) or Chameleon SEO poisoning (fake bank logins in search results). Those posts are siblings: trusted-looking pages that ask you to do something unsafe.
Type chatgpt.com or chatgpt.com/download yourself. Do not download a “desktop app” from a shared chat, and do not paste anything a share page tells you to run.

Snapshot
| Field | Detail |
|---|---|
| Consumer alert | Cyber Security News — September 1, 2026 |
| Technical spine | Push Security LLMShare + BleepingComputer — May 29, 2026 |
| Platform breach | Not reported — share-page content, not a ChatGPT outage |
| CourtListener | 0 matching RECAP dockets on share-link malware (searched Sep 1, 2026) |
| Official hosts | Type chatgpt.com · openai.com |
Who is at risk
Windows users who open shared ChatGPT links are most at risk — especially anyone who then downloads a file, follows a “backup site,” or pastes a command into Windows. Google ads and lookalike search terms have also sent people to these pages. Push also saw a related playbook on Claude share pages. MFA on the OpenAI account does not stop this, because the victim is not signing in.
What to watch for
Watch for a shared ChatGPT page that:
- Claims high traffic, an outage, or a desktop-app workaround
- Asks you to download something, run a file, or copy and paste a command
- Sends you to a backup or human verification page off the official site
- Shows Show code or Remix with ChatGPT on what looks like a system notice — that is rendered HTML, not an OpenAI outage page
A real ChatGPT share should look like a conversation, not a service desk.
What to do
- Close the page if it asks for extra steps. Do not download or run anything from a shared ChatGPT link.
- Type chatgpt.com or chatgpt.com/download yourself if you need the official desktop app.
- Never open Run, Terminal, or PowerShell because a web page said you were verifying you are human.
- If you already followed the instructions, disconnect, run a full scan, and treat saved passwords on that PC as exposed.
- Report the lure to OpenAI and, if money or accounts were stolen, IC3.
Two documented variants
Keep these separate. Both borrow the real chatgpt.com/s/ host. Neither is a reported platform breach.
| Variant | What the page does | Typical next step |
|---|---|---|
| LLMShare (May 29) | Fake high-traffic card rendered as HTML/CSS | Lookalike desktop-app download host |
| Sep 1 ClickFix | Same high-traffic lure, then a backup site | Fake human-check that wants Win+R / paste / Enter |
Push named a lookalike download host for the May campaign. CSN describes a separate lookalike backup host for the September ClickFix chain and says analysts recovered a NetSupport remote-control client after device fingerprinting. We do not republish share URLs, hashes, or commands.

MFA: YubiKey and Google Authenticator
A hardware key or authenticator code does not stop a paste lure or a fake installer. It does protect the OpenAI / ChatGPT account if someone later tries the stolen password. Grades match our MFA directory.
| Grade | Meaning |
|---|---|
| Fail | Documented second factor is SMS, voice, or email OTP |
| Pass | Self-serve Google Authenticator-style open TOTP |
| Strong | FIDO2 / YubiKey-class security key for sign-in |
| Platform | Grade | YubiKey | Authenticator |
|---|---|---|---|
| OpenAI / ChatGPT | Strong | Yes | Yes |
| Microsoft Account | Strong | Yes | Yes |
OpenAI’s MFA help names Google Authenticator and Authy, passkeys, and hardware keys. OpenAI also publishes an OpenAI + Yubico YubiKey bundle. SMS and WhatsApp codes still exist as weaker options — enroll a key. Workspace admins cannot force MFA for every seat today.
Microsoft Account stays Strong (security key + authenticator). It is in this table because the September lure targets Windows. MFA on the Microsoft account does not stop Win+R paste either.
Directory: MFA support directory · Category → Email & Identity.
Recommended MFA tools
| Product | Best for | Get it |
|---|---|---|
| YubiKey 5C NFC | USB-C laptops + NFC phones | Amazon |
| YubiKey 5 NFC | USB-A desktops + NFC phones | Amazon |
| Proton Pass | Passkeys + authenticator-style TOTP | Proton Pass |
We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Independent cybersecurity audits
We audited the official ChatGPT, OpenAI, researcher, and Windows-vendor hosts on September 1, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not mean ChatGPT was hacked.
| Organization | Domain | Overall | vs 100% |
|---|---|---|---|
| Push Security | pushsecurity.com | 74% | −26 |
| Microsoft | microsoft.com | 71% | −29 |
| OpenAI | openai.com | 70% | −30 |
| ChatGPT | chatgpt.com | 68% | −32 |
| Domain | Identity | Transport | Website |
|---|---|---|---|
| pushsecurity.com | 65% | 15% | 90% |
| microsoft.com | 90% | 70% | 37% |
| openai.com | 90% | 15% | 45% |
| chatgpt.com | 95% | 15% | 43% |
Audit links: pushsecurity.com · microsoft.com · openai.com · chatgpt.com
chatgpt.com Identity is 95% with Transport 15% and a thin mail path — treat it as the product host, not “OpenAI mail was breached.” Transport 15% on openai.com and pushsecurity.com means spoofed “ChatGPT outage / security update” mail is easier to deliver than the overall scores suggest.

Website stack note
Passive website-tech probes on September 1, 2026:
| Domain | Stack signal |
|---|---|
| chatgpt.com | Undetected CMS; Let’s Encrypt TLS expires 2026-11-30 |
| openai.com | Undetected CMS; Let’s Encrypt TLS expires 2026-11-15 |
| pushsecurity.com | Nuxt; Amazon Trust TLS expires 2026-10-30 |
| microsoft.com | Undetected CMS; Microsoft TLS expires 2027-01-17 |
Point-in-time only. A live marketing homepage is not a share-link forensic finding.
Blacklist and lookalike domains
Email blacklist checks (public DoH, September 1, 2026): chatgpt.com, openai.com, and pushsecurity.com were clear on mail/domain lists we can query. Web/CDN IPs on ChatGPT and OpenAI showed informational SPFBL notes — not mail-reputation hits. microsoft.com showed a low-signal SPFBL note on a shared Outlook MX — do not read that as “Microsoft is blacklisted.”
DNS lookalike scans (BEC profile, registered signals only):
| Brand scanned | To review | Likely owned | BEC staging |
|---|---|---|---|
| chatgpt.com | 92 | 9 | 0 |
| openai.com | 87 | 1 | 4 |
| microsoft.com | 134 | 17 | 0 |
| pushsecurity.com | 7 | 0 | 0 |
High-interest registered names (investigate; not proof this wave used them):
| Lookalike | Technique | Note |
|---|---|---|
| chatgpt-support.com | affix | Live NS + A + MX |
| chatgpt.org | tld-swap | Not the product host |
| account-openai.com | affix | BEC staging (NS + MX) |
| openai.org | tld-swap | BEC staging (NS + MX) |
| login-microsoft.com | affix | Live NS + A + MX |
Several chatgpt.* TLD swaps redirect to the real product host (likely owned). Type chatgpt.com and openai.com, not a support-affix or .org swap. Continuous monitoring: Cybersquat Domain Monitoring.
Related coverage
- ClickLock Stealer — macOS ClickFix locker
- Chameleon SEO poisoning — fake bank logins in search
- Chambers of commerce — ransomware and fake CAPTCHA
- MFA support directory
Run a free audit at audit.emailmenow.com or contact EmailMeNow for DMARC / MTA-STS and phishing response aimed at the 100% ideal.
Sources: Cyber Security News — real ChatGPT links abused (Sep 1, 2026) · Push Security — LLMShare (May 29, 2026) · BleepingComputer — ChatGPT share links / fake outage pages · OpenAI MFA help and Yubico bundle. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches September 1, 2026. Domain scores: audit.emailmenow.com only.