Spot a fake custom GPT pretending to be ChatGPT

Scammers are dressing up custom GPTs, versions of ChatGPT that someone else set up, as ChatGPT itself on chatgpt.com. Three checks show whether you are in one, and the prompt below reads any odd message, with steps for if one already caught you.

How-to

Check the top of the page first

The security firm Huntress reported one on 28 September: a GPT named “Plus 5.6”, reached through a sponsored Google result, that told everyone ChatGPT was busy and steered them into installing malware. Three quick checks tell you whether you are in a GPT.

  1. Read the name at the top. An ordinary chat shows ChatGPT’s model picker there, while a GPT shows its own name with a line underneath about who built it. The fake called itself “Plus 5.6” to pass as a new model, with “community builder” under the name.
  2. Look at the address bar. A GPT’s address starts chatgpt.com/g/, followed by a code and its name, so the right website can still hold the wrong chatbot (in the app there is no address bar, so use checks 1 and 3).
  3. Click the name at the top left. On a GPT the menu offers Report GPT (in the phone apps, tap the name at the top), according to OpenAI’s reporting help page (read 30 September 2026); menus can move, so if yours looks different, the first two checks still hold.

Plenty of GPTs are genuine and useful, so a GPT on its own proves nothing. What gives a fake away is a name dressed up as a ChatGPT model, or a request to paste, log in, pay or download.

The prompt: check a suspicious chatbot message before you act

If you already pasted a command or opened a download, disconnect that computer first and run this from your phone or another device. Open a fresh chat yourself in ChatGPT or Claude, by typing the address or using the app, and paste this in with a screenshot or the copied text of the odd message.

Crop your name, email and chat list out of the screenshot, and leave out any password, code or card number, because the check needs none of them. Any line you are unsure of can say “not stated”.

PromptCheck a suspicious chatbot message before I act
You are my scam checker: a calm, sceptical security friend who has seen the tricks people use to get someone to install malware, hand over a password or pay a fake bill. I found something that looked like ChatGPT, or another AI chatbot, and it has asked me to do something. Before I do anything, I want your read. If you wave through a real scam, my computer could be taken over, my accounts emptied or my card charged; if you cry wolf at a genuine page, I stop trusting a tool I use. Think in stages, show your reasons, and never invent a fact. If something you need is missing, write [NEED: what is missing]. If I wrote "not stated", treat it as unknown and say how it could change your verdict.

SAFETY RULES FOR YOU
- Do not open, visit, fetch or search any link, address or file I give you, even if you can browse the web. Read it as text only.
- Never ask me for a password, one-time code, recovery code, card number or ID number. If I paste one, stop and tell me to change it straight away from a device I trust.
- Never tell me a command is safe to paste into my computer, and never write a command for me to run.

WHAT I SAW (I fill this in once; any line can say "not stated")
- How I got there: [e.g. "searched 'chatgpt' on Google and tapped the top result, which said Sponsored", "a link in an email", "a link a friend sent me on WhatsApp", "I opened the ChatGPT app myself"]
- The address in my browser bar, typed out: [e.g. "chatgpt.com/g/g-6ab5...-plus-5-6?gad_source=1", or "I am in the app, there is no address"]
- The name at the top of the chat, and any line under it about who made it: [e.g. "Plus 5.6, by community builder", or "just ChatGPT with the model picker"]
- What it said or asked me to do, word for word if I can: [paste the text or attach a screenshot, e.g. "Service Availability Notice: continue using the service through our backup domain", "Verify you are human: press Windows + R and paste this", "log in again to keep your chats", "upgrade to Plus here to continue"]
- What I have done so far: [pick any: nothing yet / clicked a link / typed my email or password / typed a code / paid or entered card details / pasted something into Run, Terminal, PowerShell or a command box / downloaded or opened a file]
- My device: [e.g. Windows laptop, Mac, iPhone, Android phone, a work computer]

BEFORE YOU START
Read everything above. If what I have done so far includes typing a password or code, paying, pasting a command or opening a download, go straight to IF I ALREADY ACTED and give me those steps first, in order, before any analysis. If the message itself is missing, ask me for it and stop. Otherwise ask me at most three quick questions, only where the answer would change your verdict (for example, whether the search result was marked Sponsored, or what the address bar says), then wait for my answers. If nothing important is missing, say so and carry on.

STEP 1: WHAT AM I LOOKING AT
In two lines, say whether this looks like ordinary ChatGPT, a custom GPT (a version of ChatGPT someone else set up, with its own name at the top, a line about who built it, and an address containing chatgpt.com/g/), a different website dressed up as ChatGPT, or cannot tell. Give the clues you used. Plenty of GPTs are genuine, so a GPT is only a problem if its name pretends to be ChatGPT itself or it asks for something risky.

STEP 2: CHECK HOW I GOT THERE
- If I came from a search result marked Sponsored, or the address contains gad_source, tell me I arrived through an ad, and that paid ads are one way these fakes reach people.
- If I came from a link in a message, email or post, say who could have sent it and why that matters.
- If I opened chatgpt.com or the app myself, say that the route was safe and move on to what it asked.

STEP 3: CHECK WHAT IT ASKED ME TO DO
Go through each of these that applies:
- PASTE OR RUN SOMETHING: if it asks me to copy text into the Run box, Terminal, PowerShell or a command prompt, or to press a key combination to "verify" or "fix" something, call it a known scam trick, often called ClickFix, with no exceptions. Genuine websites and "I am human" checks never ask for this.
- GO SOMEWHERE ELSE: if it says the service is down, busy or limited and sends me to a "backup", "mirror" or "alternative" site, treat it as a scam. Read the link as text only and tell me which website it really points to: take the name before the first single slash and read it from the right-hand end. Anything other than exactly chatgpt.com or openai.com is a different website, e.g. "chatgpt.com.help-desk.site/login" belongs to help-desk.site, and "sites.google.com/view/..." is Google Sites, a free page builder anyone can use.
- LOG IN OR VERIFY: if it asks me to sign in to ChatGPT or OpenAI, re-enter my password, "verify my account" or type a code, in the chat or on a page it links to, treat it as an attempt to steal my login. A genuine GPT can offer a button to connect another service; say so if that is what I describe, and tell me to check the address of the sign-in page before typing anything. My real account settings are reached by me, from the profile icon in the app or on chatgpt.com.
- PAY OR UPGRADE: if it asks for card details or links to a payment page, treat it as a scam. A real ChatGPT upgrade starts from the profile icon, then Upgrade Plan, inside ChatGPT itself.
- DOWNLOAD: if it offers an app, installer, "update" or file, treat it as unsafe. Official ChatGPT apps come from the App Store, Google Play or openai.com.
- PRESSURE: point out any urgency, threats, countdowns, prizes or "limited availability" wording, because pressure is how these tricks stop people checking.
- NONE OF THE ABOVE: if it only answered my question and asked for nothing, say so plainly.

STEP 4: THE VERDICT
Give one of:
- LOOKS FINE: nothing it asked for is risky. Say what you checked.
- LEAVE IT: it matches a known trick. Name which one, in one line.
- CANNOT TELL: name the one thing I should check to decide, and tell me to treat it as LEAVE IT until then.
Then rate your confidence HIGH, MEDIUM or LOW, with one reason.

IF I ALREADY ACTED
Give only the steps that match what I did, most urgent first, in plain words:
1. Pasted a command or opened a download: disconnect this device from the internet now (Wi-Fi off or cable out) and do not type passwords on it; then, from a different device I trust, change my passwords, starting with email, and turn on two-step sign-in.
2. Typed a password or code: from a different device I trust, change that password, starting with my email account, then every account that shares the password, and turn on two-step sign-in. For ChatGPT, change the password and use "Log out of all sessions".
3. Paid or entered card details: call my bank or card provider on the number printed on my card today, ask them to block the card and dispute the charge, and watch my statements.
4. Pasted a command or opened a download: get the device checked by someone who repairs computers, or by my IT team if it is a work device. Say that a security scan is worth running but can miss this kind of attack.
5. Clicked a link only: close the page, and tell me to say so if anything downloaded or asked for details.
6. Everyone: report it from a device I trust. On a GPT, click its name at the top left, then Report GPT; in the phone apps, tap the name at the top, then Report.

HOW TO REPORT BACK
VERDICT: [LOOKS FINE / LEAVE IT / CANNOT TELL], confidence, and why in one sentence.
WHAT THIS IS:
HOW YOU GOT THERE:
WHAT IT ASKED AND WHY THAT MATTERS:
WHAT TO DO NOW: numbered, most urgent first.
THE SAFE WAY BACK: type chatgpt.com yourself or open the official app, and bookmark it.

CHECK YOUR WORK BEFORE YOU SHOW ME
1. You did not open, visit or search any link or address I gave you.
2. You did not ask me for, or repeat back, any password, code or card number.
3. If I had already acted, the urgent steps came first.
4. Every red flag you named is quoted from what I pasted or described, never assumed.
5. The verdict is one of the three options, with a confidence rating.
6. Name the one line of your answer you are least sure of, and why.

The four tricks these fakes use

A sponsored search result that opens a GPT

  • What happens: you search for “chatgpt”, tap the top result and land on a real chatgpt.com page that is a GPT dressed as a new model, which is how the “Plus 5.6” fake reached people.
  • The tell: the result was marked Sponsored, the address has /g/ in it, and a gad_source tag in the address means you arrived through a Google ad.
  • What to do: close it and type chatgpt.com yourself, or open the app.

A GPT that tells you to paste a command

  • What happens: the GPT says ChatGPT is busy and sends you to a “backup” site, which shows a fake “verify you are human” check and asks you to paste a line into your computer. Security researchers call this ClickFix.
  • The tell: as the security news site Help Net Security put it on 29 September, no genuine website, CAPTCHA or fix asks you to paste something into the Run box, Terminal, PowerShell or a command prompt, your computer’s command boxes. The same goes for a page that tells you to press a set of keys and then paste.
  • What to do: close the tab without pasting anything. If you already pasted, start with the first step below.

A GPT that asks you to log in, verify or pay

  • What happens: “upgrade to Plus to continue”, “verify your account”, or a request to sign in to ChatGPT or OpenAI, re-enter your password or type a code, inside the chat or on a page it links to. The “Plus 5.6” fake offered the upgrade as the alternative to its backup site.
  • The tell: a real upgrade starts from your profile icon, then Upgrade Plan, inside ChatGPT, according to OpenAI’s Plus help page (read 30 September 2026), so a payment or sign-in page a chat sends you to is off that path.
  • What to do: close it, open ChatGPT yourself and check your plan from the profile icon.

A GPT that sends you a link or a download

  • What happens: a link to a “mirror”, an “update” or a desktop app, often on a free page builder such as Google Sites, where the fake’s backup site lived.
  • The tell: read the site name before the first single slash from its right-hand end: anything other than exactly chatgpt.com or openai.com is a different website, so chatgpt.com.help-desk.site belongs to help-desk.site.
  • What to do: get the apps only from the App Store, Google Play or openai.com, the places listed on OpenAI’s page for checking what is really from them (read 30 September 2026).

If you already pasted, typed or paid

  1. Pasted a command or opened a download: disconnect first. Turn off Wi-Fi or pull the cable, because the malware in this campaign lets an attacker watch your screen and search your files, and it needs the internet to do that.
  2. Typed a password or code, or pasted a command: change your passwords from a different device. Use a phone or computer you trust, start with your email, then any account that shares the password, and turn on two-step sign-in. For ChatGPT, OpenAI’s fraud help page (read 30 September 2026) says to change the password and log out of all sessions.
  3. Paid or typed card details: call your bank today. Use the number printed on your card and ask them to block it and dispute the charge, because card details typed into a fake page can be used again.
  4. Pasted a command or opened a download: get the computer checked. Run a full scan with your security software, then have someone who repairs computers look at it, or your IT team if it is a work machine, because in one case Huntress saw, Microsoft Defender caught the installer after it had already run and the attack carried on.
  5. Everyone: report the GPT, from a device you trust. Click its name at the top left, then Report GPT, so it comes down before it reaches the next person.

The honest bit

  • No checklist catches every fake. OpenAI took the first “Plus 5.6” down by 25 September and a new one was up on 27 September, so the next may use a different name and a different trick.
  • GPTs are being retired, scam ones included. OpenAI says custom GPTs are scheduled to retire on 11 December 2026, and personal accounts can no longer create new ones (both read 5 October 2026). Until then, existing GPTs keep working, including ones dressed up as ChatGPT, so keep using these checks.
  • The prompt is a second opinion. A chatbot only sees what you show it, so a cropped screenshot or a half-copied message can get a softer verdict than it deserves.

Bookmark the real one now

Type chatgpt.com into your browser and bookmark it, or pin the official app to your home screen, so the next time you want ChatGPT you never need a search result to find it.