Tales from the Hacked
The Fake ChatGPT Site That Wasn’t
It started the way most people start their day: a quick Google search for “ChatGPT.”
A P3C client clicked what looked like the right link — but it wasn’t. It was a hijacked ad, and here’s the part that should raise everyone’s eyebrows: the address bar actually said chatgpt.com. This wasn’t some obvious knockoff on a sketchy lookalike domain. It was a malicious “custom GPT” — a mini-app built on top of ChatGPT — hosted right on OpenAI’s own real domain, dressed up to look exactly like a normal ChatGPT conversation, right down to a fake chat history already sitting in the window.
A banner popped up inside that legitimate-looking chatgpt.com page: “We are experiencing high traffic now. Continue on our backup domain:” followed by a link to gpt-backup.com.
That’s the hook. There is no “backup domain” for ChatGPT, or for any major AI platform. We’ve seen this exact playbook used against Claude users too — a convincing fake site mimicking a real AI tool, waiting for someone to click through.
This is the detail worth sitting with: because the scam page was technically running inside chatgpt.com, standard security filtering that blocks known-bad domains would have let it right through. There was no malicious domain to catch yet — the trap was sitting on a trusted one. The malicious domain only entered the picture once the client was talked into clicking further, onto gpt-backup.com. Web filtering can help stop the second step, but by design, it can’t flag the first one.
The Trap: A Fake “Human Verification”
Once on the fake backup site, the client hit a familiar-looking Cloudflare “verify you’re human” prompt. But instead of just checking a box, it walked him through opening the Windows Run dialog and pasting in a command — a technique known as ClickFix, where the attacker convinces the victim to run the malicious code themselves rather than sneaking it in silently.
The client never entered a password. No credentials were typed anywhere. But that command he pasted quietly reached out to a remote server and installed a malware package disguised under an innocent-sounding name — a classic silent-install pattern our team has flagged before with a similar attack chain (PowerShell → WebDAV → disguised installer).
What We Did
- The client disconnected the machine from the internet within minutes — genuinely the best first move anyone can make.
- We advised him to treat the laptop as compromised, power it down, and bring it in for a full rebuild rather than trying to “clean” it.
- As a precaution, we reset his Microsoft 365 account and reviewed sign-in logs — no suspicious sign-ins were found.
- We advised resetting passwords and confirming MFA everywhere possible.
- We got him back up and running on a spare machine while his laptop comes in for remediation.
Because the install ran silently and could have opened the door for further access, our stance is simple: assume compromise, don’t try to trust the machine again — rebuild it.
Why This Matters
This client was on one of our more basic protection plans — one that doesn’t include the script-blocking and application allow-listing controls we offer under our Zero Trust protections. That kind of control can feel like an inconvenience day to day — an extra prompt, a blocked install, a “why won’t this just run?” moment. But it’s exactly why we put it there. Zero Trust wouldn’t have stopped the click. It would have stopped the command from ever being able to run.
Most people don’t type full website addresses anymore — they search for the thing they want and click the first result that looks right. Attackers know this, and they’re paying to put fake, hijacked ads right at the top of those searches. It’s not a sign of carelessness. It’s just how the web works now, and it’s exactly the gap attackers are exploiting.
And it’s also why “the URL looked fine” can no longer be the whole safety check. When the trap itself lives on the real, trusted domain, domain-reputation filtering has nothing to flag — which is exactly why layered controls that watch behavior (like blocking scripts and unapproved installs) matter more than ever.
The takeaway: If a “backup domain” ever shows up for a service that’s never needed one — ChatGPT, Claude, your bank, anything — stop. And if you’re ever prompted to open the Run dialog or a terminal to “verify” something, that’s not verification. That’s the attack.
Not sure if your current plan includes protections like this? We’ll tell you straight.
P3C Technologies • 262.423.6267 • support@p3ctech.com