ChatGPT Share Links Become a Trusted Phishing Host

The break is not the fake link. It is that the lure can sit inside a real chatgpt.com page, so users see a trusted AI interface and let their guard down. That also weakens browser reputation checks and desktop-only download controls, because the malicious content is delivered from the platform the user already trusts. Researchers disclosed ChatGPhish, which abuses ChatGPT’s Markdown rendering so attacker-controlled links, images, and security-style alerts appear inside the assistant UI after a page is summarized. BleepingComputer also reported an active LLMShare campaign using shared chatgpt.com links to show fake OpenAI outage pages that push malware downloads from a legitimate OpenAI domain. The forward risk is platform trust itself. Any workflow that renders untrusted content inside a SaaS page can turn the vendor domain into the phishing surface, not just the destination URL.

Part of the PlainSec briefing for 2026-05-30

Sources