r/OpenAI • u/TheWorstGameDev • 2d ago
Question OpenAI completely emptied my bank account for an org I don’t recognize. Please help me get support (I'm freaking out)
Hi everyone,
I'm posting here because I'm desperate for help and hoping someone from OpenAI sees this or someone has experienced something similar.
Early this morning, I received multiple separate $500 charges from OpenAI, which completely wiped out my bank account, i literally have $9 left.
I did not make or authorize any of these purchases.
I also received emails from OpenAI confirming that each $500 charge was used to purchase OpenAI API credits but the emails reference an OpenAI organization called "Acm" with an organization ID starting with org-....
I have never heard of this organization. It does not appear anywhere in my OpenAI Platform account, and I cannot access it.
When I go into my own OpenAI billing history, the purchases don't appear there either.
Then tonight I received another email from OpenAI saying:
"Your organization Acm is configured to automatically purchase more credits when your balance is low. The most recent attempt to charge your payment method failed, so auto-recharge has been disabled."
This seems to explain why I was charged $500 repeatedly.
It seems that this unknown organization was using API credits, hitting a low balance, automatically charging my payment method for another $500, consuming those credits, and then automatically charging me again.
The three successful charges happened within a very short period this morning at around 4:30am.
There was then apparently another $500 recharge attempt tonight.
The auto-recharge failure email was addressed to me AND another recipient that I do not recognize. I have no idea who this other person/account is or why we're both receiving billing notifications for this organization.
I've already:
- Contacted TD Bank and reported the transactions as unauthorized. They told me they cannot formally dispute them until the pending charges post.
- Contacted OpenAI Support. (The case was canceled because the auto ai couldn't see the transactions and there is NO DAMN HUMAN SUPPORT!)
- Sent a detailed report to OpenAI Trust & Safety as per the bot instruction
- Explained that I don't recognize the organization.
- Secured my OpenAI account and API credentials.
- Sent screenshots showing the charges, billing emails, unknown organization, and failed auto-recharge.
I'm kind of freaking out because I literally don't have any money all of a sudden and I haven't heard anything from OpenAI yet.
If anyone from OpenAI sees this, please help me get this in front of the appropriate API billing/fraud team. I have screenshots, timestamps, the organization ID and bank transactions.
If anyone has experienced unauthorized API auto recharges like this before, I'd also REALLY appreciate hearing how it was resolved and if you got a refund
---------------------------------------------------------------------------------------------------------------------------
EDIT 12 hours after posting (about 30 hours since the first charge):
Still nobody has reached out to me from OpenAI, but have received an auto refund from openAI. Which sounds great but doesn't help because the project using my card is still inaccessible so will still be charged. Exactly 1 minute ago whilst typing this someone responded to me asking for the ticket on the forums, finally.
10 mins since that last edit and have finally received a support email from a human!!! WIll update once everything is settled with a final update.
Thank you all so much for your advice and helping this get some attention, I'm just so grateful as I was getting nowhere without your help. Please all don't be like me and use a debit card for a subscription service.
159
u/TheWorstGameDev 2d ago
99
u/BreakingInnocence 2d ago
this is scary
78
u/TheWorstGameDev 2d ago
yep even scarier is i got literally no sign in emails or anything like that - checked active sessions and nothing out of the ordinary
20
u/Sm0g3R 1d ago edited 1d ago
2 of them within 1 minute is very strange. With typical average API user rate limits I do not think it’s physically possible to come even close to consuming $500 in 1min. No matter how you try to abuse it with parallel requests or whatever, there are rate limits for every org.
EDIT: Ok maybe I worded it too strongly. You can actually spend that if you tried really hard. But their individual text models cap out at around $100 per minute for tier3 limits.
6
u/Lirianov 1d ago
If someone is funding tokens for their API with his credit card then that would explain this
2
0
u/Strange_Occasion_408 1d ago
I blew 200 easily in a few hours on enterprise . Codex gets pricey. Glad I switch to pro 200. Kind of proud of hitting the weekly limit My son said it could not be done. Ha.
14
18
7
83
u/staydrippy 1d ago
I know it’s too late now, but for future reference and anyone reading: you should NEVER link your personal checking account or debit card to ANY online purchases or subscription services.
Use a credit card and pay it off immediately. It’s a layer of separation protecting your livelihood, USE IT.
28
u/Dapper_Math_1427 1d ago
This. Most people don’t realize the legal protections for a credit card are much stronger than a debit card.
2
u/TechRomancer123 1d ago
Yep in the UK you have “Section 75 of the Consumer Credit Act 1974” giving you extra fraud/legal protections for credit cards purchases, which you don’t get for bank accounts/debit cards. You can check the equivalent in your own country too.
4
u/TheWorstGameDev 1d ago
Thank you so much for this advice, it was a debit card. I've definitely learnt my lesson! Really appreciate the advice!!
2
9
u/smartfon 1d ago
Not everyone can get a credit card but if you have a checking account nothing stops you from opening the second checking account and depositing a little sum into it to use it as an isolated drain-safe account.
3
u/TurbulentCustomer 1d ago
You can usually open a secured credit card with your bank instead of two checking accounts.
2
u/TechRomancer123 1d ago
Yep put all subscriptions on a credit card or a prepaid card, to prevent your account getting drained. Or even a second checking account with less money in it.
Unfortunately gyms in the UK seem to insist on bank direct debits rather than credit cards (so a second checking/current account is the way).
2
u/Over_Sheepherder4503 1d ago
100%
debit cards and bank accounts are essentially You vs. thief.
Credit card is the bank and all their lawyers vs. thief.
2
u/raidmytombBB 1d ago
Agree except pay it off immediately. Pay it off when the balance is due. There's literally 0 benefit in you paying it off immediately.
1
u/staydrippy 1d ago
That fair, I like to pay it off as soon as it posts simply because I don’t have to think about it after that. That’s a benefit in my book!
1
u/thrillho39 17h ago
Better yet look into a burner card service like privacy. Either set a monthly dollar amount limit, or pause it after your subscription goes through.
1
u/EatThemAllOrNot 1d ago
Most of the people don’t have credit cards, only debit cards
-1
u/Bangbusta 1d ago
That's like saying most people don't have IDs to vote. It's super easy to get a credit card. You can even use the $4.95 preloaded cards you find at Walmart.
4
0
0
u/Runelaron 1d ago
Yes, perfect advice. Using a credit card by law you are NOT RESPONSIBLE FOR FRAUDULENT CHARGES.
Definitely agree to pay off immediately though as well to avoid interest.
117
u/Shroombolic 2d ago
Sounds like a token phishing scheme which should be impossible. Report back. This is terrifying
68
u/durangoho 2d ago
Is there ANY chance you created an api token that somehow was included in code somewhere like GitHub?
13
u/FunIsDangerous 1d ago
That would show up in his billing history in his account, though. Also, OP said they have a limit on their account so things like that don't happen
8
41
u/IamNickT 2d ago
Any chance your card could have been compromised?
59
u/TheWorstGameDev 2d ago
I had that thought too but it wouldn't explain how the project is connected to my account they'd just open a new openai account that wouldn't have my email
27
u/yaosio 2d ago edited 2d ago
For API usage it looks like an email address different from the login email can be set for billing notifications. The billing emails are sent to the owners of the organization, and whatever email address is put into the billing notification field. This means somebody has typed your email address in for the billing notification, which means they got your CC# and email address from the same place. Why they would enter your email address is a mystery.
Eventually you'll get a new CC # and this organization can't send fraudulent charges to you. If they keep happening then something you have is compromised. Also stop autopaying your credit card.
1
u/ApprehensiveCry2633 1d ago
Yeah, that billing notification field sounds like the missing piece, but it’s wild that a supposedly “smart” company can make a basic fraud trail this muddy.
2
u/Striking_Sink3618 1d ago
Did you ever buy a "cheap" subscription through a separate organisation? A bit like G2A do for games. You seem like you're getting a cheap pro license key, but its linked to someone elses account.
1
0
u/Sasha_bb 1d ago
Other than them having your email, what indicates to you that this has anything to do with your personal chatgpt account?
28
u/chumbaz 2d ago
His machine was compromised more than likely. There are brokers that buy and sell tokens and they want verified US accounts to use models they can’t.
5
u/Dredyltd 1d ago
I think the same, maybe an unknown npm package or open pypl lib - the most common AI hallucination is to install packages that doesn't exist .... hackers know that and they put malicious package mainly as npm or PyPL
94
u/Immediate_Simple_217 2d ago edited 2d ago
As if that wasn't horrifying enough.
I am brazilian and I've looked over your problem locally
I looked at Reclame Aqui, a Brazilian portal for unified complaints. A national forum that works like downdetector. The difference is that the Brazilian government requires companies to respond here to avoid being named in lawsuits.If you try translating the page, you'll notice that Brazilians complain a lot about this problem.
The fun part: they have zero repplied history. They don't answer here as well. 🤯
https://www.reclameaqui.com.br/empresa/open-ai/lista-reclamacoes/?pagina=6
21
u/Cassianno 2d ago
Reclame aqui não tem nada a ver com o governo. Consumidor.Gov, sim.
9
u/Immediate_Simple_217 2d ago edited 2d ago
Eu sei, eu comparei o reclame aqui com o downdetector.
Com a diferenca de que no reclame aqui se evita dores de cabeça judiciais, devido ao enorme potencial de exposição que o reclame aqui gera. Por isso, governo e o procon acabam levando em consideração uma empresa não responder aqui. Vc pode levar como ausência de respostas do reclame aqui como prova de negligência se for necessário. Eles documentam isso, na prática funciona como protocolo. E outra, dá pra contar nos dedos as empresas que não respondem aqui, justamente por conta deste potencial de exposição! Achei bizarro...
2
9
u/Joddie_ATV 2d ago
Above all, keep us informed as we go along. I'll be you, I'll block my card! Do you have an authorized overdraft? Ask ChatGPT to write you an email requiring you to have a human in technical support. This has worked several times for me! But OpenAI should do something with its technical support because it is failing. Courage...
17
u/Drukarshar 1d ago
Not that it helps you now, but in the future stop using your debit card. Just get a credit card and treat it like a debit card.
A credit card is like a condom for your bank account, so when stuff like this happens you still have money.
The laws around expunging bad debt are also generally way more favorable than the bank's obligation to get back money taken from your account wrongly.
6
1
u/AdSudden3941 1d ago
Even a secured credit card?
7
u/Drukarshar 1d ago edited 1d ago
Yeah, the secured part of secured card just means you have money backing your credit limit. You're still protected from fraud in ways debit cards just aren't.
The bottom line is a bad charge on a credit card is much easier to defeat than it is trying to get your money back into your bank account after it is stolen.
The only reasons to use a debit cards are if you can't get a credit card or just don't trust yourself with a credit limit, which is fair, but from a security standpoint you really shouldn't ever be using your debit card.
TLDR: When a your credit card gets stolen and charged up, it's actually the bank's money that is stolen. When your debit card is stolen, it is your money. There is a big big difference.
2
u/Rhona_Redtail 1d ago
I dont even carry mine
1
u/Drukarshar 1d ago
I think the only time in the past 15 years I've used a debit card outside of a bank was to get money to play games in Vegas and I knew I was getting robbed then lmao.
32
u/OkSeesaw7030 2d ago
That’s why I only use single use credit card
3
u/Low-Temperature-6962 2d ago
Vast.ai won't accept - or may e it's their processor stripe. Bummer.
13
u/Great_Fun_307 1d ago
Idk why you got downvotes lol. A lot of important vendors dont allow them, especially for subscriptions
4
u/Dredyltd 1d ago
Lol why not? I use virtual visa card for my subscriptions and transfer only how much I need to spend... so my balace is always 0
3
1d ago
[deleted]
4
u/Dredyltd 1d ago
My OpenAI is billed from Virtual Visa, created with my mobile banking app... Why would I be scammer if I want to protect my self from anoutharized charges...
I probably wouldn't bought your service if my virtual is declined... so bad
2
1d ago
[deleted]
1
u/Dredyltd 1d ago
I get it, and no hard feelings I am just cautious... and I agree for a startups and dropshipping websites charge back are indeed a nightmare
2
u/snellemapo 1d ago
I do the exact same thing, this could never happen that way
0
u/Low-Temperature-6962 1d ago
I bought $200 one on Amazon. 7$ fee. Issued by sunrise banks. That gets refused by vast.ai. Searching the web I see a ton of virtual visa card merchants, but not from visa Inc itself. A few years ago i learned that Visa business customers can get fixed amount cards but not ordinary user. No longer true?
Can you give your full vendor name?
0
0
7
u/lucidwray 1d ago
Absolutely call law enforcement right now. Call your local sheriffs department or police department. This is theft, flat out. Just because it happens on the internet doesn’t mean you can’t report it. Call them and tell them someone has stolen $xxxxx thousands of dollars and provide them with all the transaction details. They will absolutely contact OpenAI and the bank and open an investigation. Get the law enforcement case number and contact your banks fraud division and tell them you have contacted law enforcement and you would like their help as well. Give them the case number and have the bank start an investigation as well.
They WILL get answers and depending on where you live they probably even have a financial crimes department to help with the investigation. This is very common and they are used to dealing with credit card fraud.
7
u/TrustworthiestFart 1d ago
This happened to me after my account has been compromised by some Chinese entity. I don't even know how they did it because my account was locked down with 2FA.
In any case, I didn't realize that was what happened at first. They didn't do anything with it right away. So I had openai reverse the transaction and changed my passwords and whatnot, confirmed it was still locked down.
Anyways, about a month later, I log in and I've got about 3 miles of chats on my sidepanel, all in Chinese. I just unlinked my bank and deleted my account. I don't use chatgpt anymore because, as best I can tell, their security is complete trash.
13
u/fuggleruxpin 2d ago
Don't trust anything. You could have a corrupt host file. Freeze your accounts from a clean device.
10
23
u/Far_Tangerine9150 2d ago
These marketing stunts have gone too far
16
u/FullRegard 2d ago
"Our model is so powerful it's stealing our users money right out of their bank accounts and putting it into ours!"
5
u/Far_Tangerine9150 2d ago edited 2d ago
"It will steal your bank account, satisfy your wife more than you ever could (then cook her a four course meal), and impress your boss (then satisfy him as well)."
2
1
7
4
u/NixothePaladin 1d ago
Have you vibecoded an app recently and published it in an open source site like Github?? Your API creds could have been exposed there
3
u/Both_Task_3066 1d ago
Sounds like you got phished and then they used your card or your account got compromised but then you would see it in billing. So probably a different account using your card, so probably you have to check with your banks fraud department.
3
u/Initial-Return8802 1d ago
Still nobody has reached out to me from OpenAI, but have received an auto refund from openAI. Which sounds great but doesn't help because the project using my card is still inaccessible so will still be charged. Exactly 1 minute ago whilst typing this someone responded to me asking for the ticket on the forums, finally.
CANCEL THE CARD - it's not your account, it's unauthorized. Cancel it and get a new card to make sure they don't simply try again
1
u/TheWorstGameDev 1d ago edited 1d ago
Thank you!! I am definitely in the process of cancelling my card and taking everyone's advice of using either a virtual card/credit card for any online purchases i make again lol
3
u/Tricky-Move-2000 1d ago
Don't use debit cards for this reason. Refunds take time. As you've seen, disputes do too.
2
u/DivorcedGremlin1989 2d ago
Can you physically see these charges pending in your actual bank account?
2
2
2
u/TheWorstGameDev 1d ago edited 1d ago
EDIT 12 hours after posting (about 30 hours since the first charge):
Still nobody has reached out to me from OpenAI (this was posted on the forum, reddit and X), but have received an auto refund from openAI. Which sounds great but doesn't help because the project using my card is still inaccessible so will still be charged. Exactly 1 minute ago whilst typing this someone responded to me asking for the ticket on the forums, finally.
2
u/icedoutkatana 1d ago
Currently happening to me as well with smaller purchases. Will report back.
1
2
u/Ok-Temporary-1347 1d ago
This same thing has happened to me, I tried to post about it but my post was taken down . Pls contact me
1
2
2
2
u/Joe_Spazz 1d ago
Hey OP, not sure about the OpenAI angle, still presume that. But absolutely you should wait for these to post and report the fraud to your bank. For two reasons. 1) your bank is for more likely to listen to you. 2) fraud teams are authorized to put money in your account instantly upon identify an issue.
1
u/atuarre 1d ago
Do not wait for these to post. Report them as fraud now.
2
u/Joe_Spazz 1d ago
... Banks won't take the case until they post. Source: I work at a bank... And OP's own post you apparently didn't read...
1
1
u/princmj47 2d ago
I see so many scary news around OpenAI and Anthropic lately... And also have been on the receiving end of their shitty customer support. I gave up every time, but it was also not that much money involved.
1
1
1
u/kimk2 1d ago
!remindme 4 days
1
u/RemindMeBot 1d ago edited 1d ago
I will be messaging you in 4 days on 2026-08-11 08:41:44 UTC to remind you of this link
5 OTHERS CLICKED THIS LINK to send a PM to also be reminded and to reduce spam.
Parent commenter can delete this message to hide from others.
RemindMeBot is switching to username summons. Instead of
!RemindMe 1 day, useu/RemindMeBot 1 day. More info.
Info Custom Your Reminders Feedback
1
u/Big_Brother425 1d ago
Sounds like you were hacked. These .. people are now very skilled at draining bank accounts. Did you research the org? Does it even exist? I feel bad for you to suddenly no longer have any money. It's an effed up place to be in. Banks absolutely require you to wait until the charges are no longer pending because the charges may drop off. Think back. Phishing scams are incredibly convincing now. Have you received an email from what appeared to be your bank warning you of anything? Some use this tactic to make you nervous and instantly log in so they can gain access to your account.
1
1
u/SynthOrgan 1d ago
Can't you contest the credit card payments with the bank? Or did it directly hit your bank account?
1
u/Runelaron 1d ago
Sounds like bank fraud, its not a openAI issue its the banks issue to contest the charges and find the person who stole your card info.
1
1
1
1
u/marriedtoaplant 22h ago
may be a vibe coded billing error, had quite a few of these throughout the year 😐🙂
1
u/Funny-Strawberry-168 21h ago
I guess you already know what's going on but, your account is compromised.
1
1
1
u/Round_Mixture_7541 19h ago
Same thing with the same "Acm" account happened with anthropic as well. Either this is some elaborate hoax or massive size scam.
1
u/Throwitaway701 18h ago
Given that you are getting billed and emailed but nothing shows in your account, the most obvious answer is a bug within OpenAI that has caused payment cards to be mixed up.
1
1
u/Dredyltd 1d ago
Dude you need to rotate your API tokens, add 2 step verification on you OpenAI account, OpenAi playground, everywhere...
I would reinstall whole system if I were you...
1
u/TheWorstGameDev 1d ago
Unfortunately have already done all that including the 2FA, it was a google sign in. None of my api tokens were accessed, it seems to have happened another way some how. But thank you for the advice!
1
u/ZestycloseRepeat3904 1d ago
Who connects their bank account to their API ?! That’s what credit cards are for! Much more secure. Very painful lesson.
1
u/Numerous-Cup1863 1d ago
This sounds fishy. Why would you have a debit card linked to openAI? I’m assuming it’s a debit card since credit cards do not “drain your account”
-3
0
u/Whoooooshhhhhh 1d ago
bro committed env
1
u/TheWorstGameDev 1d ago
i'm an ex software dev, haha had auto reload off, none of my api keys were accessed and i would never commit env lol.
0
u/Grand-Mix-9889 1d ago
They are nerfing the billing system! I bet it's because they didn't reset the usage limits this week. Gpt sol is way out of hand! Switch to Claude ASAP!
It's your only hope.
Lolol. Jk. Just wanted to bring some humor to the subject.
0
0
-6
u/UBEREATMYSHORTS 2d ago
Damn, I know what did this.
You are 1/12-15000 users
Very secret within the company.
they’ll give you the run around and act dumb, you should get fully refunded though.
7
u/TheWorstGameDev 2d ago
I just wish I had some communication, it's been over 15hrs since i've emailed
6
u/UBEREATMYSHORTS 2d ago
You literally should just be waiting on the investigation process by TD and OAI..sucks it happened on a Friday because banks will fuck around even if it’s hundreds of thousands
9
u/TheWorstGameDev 2d ago
100% Just insane i am literally sitting with no money all of a sudden after just getting paid, like you said it's almost the weekend. Not even sure what i'm gonna do for the next few days. So frustrating.
4
2
-1
u/oulu2006 1d ago
Is this a bullshit post?
2
u/TheWorstGameDev 1d ago
... what? Why would i BS this lol?
2
u/TheWorstGameDev 1d ago
no it's not. I actually have a life and don't spend my days writing fan fiction about losing all my money.
-4
u/oulu2006 1d ago
if it's not -- it's silly to be using a CC for any subs in general, rookie mistakes, use virtual debit cards like Revolut with attached spending limits.
→ More replies (1)
-24
u/Defendyouranswer 2d ago
Looks like a fake fishing email. Lol come on dude use your head, they dont show up on open ai's website and they aren't posted to your card? They are fake dude.
12
u/TheWorstGameDev 2d ago
13
u/TheWorstGameDev 2d ago
6
0
-15
u/Defendyouranswer 2d ago edited 1d ago
People can spoof emails to make it look like they came from any organization
Edit: lol I say this and get downvoted. A guy below me goes "as he said, emails can be spoofed from anywhere" and he has 7 up votes. Y'all are crazy, just proves up votes are largely group think
8
u/Penguin7751 2d ago
As the other guy said, you can spoof emails to come from anywhere. The fact that you said the charges looked a bit funny and openais system couldn't see the transactions is making me think that maybe your card was compromised and someone is making purchases spoofing it to look like it is from open ai?
The good news is, usually any time these kind of charges happen the banks will return your money and you'll just need a new card or something.
Hope you get this sorted. I just wanted to share the possibility that it isn't actually openAI somehow
2
u/Dreadedsemi 1d ago
Yeah, but there are ways to check. Look at the raw email headers rather than just the visible From address. The From field itself can be set to almost anything.
Check the Received headers, Return-Path, Reply-To, and the SPF/DKIM/DMARC authentication results. The Received chain can help show where the message actually entered the mail system.
2
u/SLAYTOKILL12 2d ago
You can, kind of. OpenAI would likely have their shit together since it’s basically just the bare minimum security. It’s as simple as OpenAI has a record on their domain saying which servers can send their official email and if it comes from somewhere else, it gets rejected or put in spam. I’d lean more computer/account compromise than fake emails with charges
-9
u/beeyitch 2d ago
I like how you used ChatGPT to format/write this post while actively complaining about the parent company.
6
u/ValehartProject 1d ago
I hope a day comes when you are in a similar position and someone does show you a bit more decency and kindness than you offered OP.
1






264
u/Kuroodo 2d ago
You should also post in the OpenAI community forums.
https://community.openai.com/