ISLAMABAD: ChatGPT users face a potential data theft and malware risk from a new online scam that uses fake service messages to push people toward malicious links.
Reports suggest the scheme can surface when users search for ChatGPT on Google and enter through a sponsored result. They may then encounter a Custom GPT that repeatedly displays a fake service availability notice, creating the impression that access to the main domain is restricted.
The message offers users the option to upgrade to ChatGPT Plus or move to an alternative domain, where the real danger begins.
Because the user can still appear to be on the genuine ChatGPT domain — and may even remain logged in — the message can look legitimate enough to build trust.
Reports identify the fake Custom GPT as “Plus 5.6,” a name that could easily be mistaken for a new ChatGPT model or Plus feature.
The scam becomes dangerous when users click the so-called backup domain or other external links. These may lead to malicious websites capable of installing malware or stealing sensitive personal information.
Users have been advised not to blindly trust sponsored search results, avoid clicking links in unexpected “Service Availability Notice” messages, and never download files or software from unknown websites.

