Hello OpenAI Security Team,
I discovered and successfully reproduced a serious vulnerability involving ChatGPT Business seat billing and the subscription grace period.
Approximately one hour before a Business subscription expires, fraudsters purchase 99 premium seats while paying only a very small prorated charge. Before the subscription expires, they use unauthorized automated scripts to rapidly add users to the workspace.
After the subscription enters the grace period, new users can no longer be invited. However, users who were added beforehand remain inside the workspace and can continue using the premium access. The vulnerability therefore does not rely on sending invitations during the grace period—the attackers preload the workspace with users before expiration and then exploit the continued access during the grace period.
This method is currently being abused at scale. Fraudsters sell or repeatedly resell the preloaded access to users, charge significantly more than they paid, and may remove access without warning after receiving payment. This enables large-scale user fraud and generates substantial illicit profits at minimal cost.
Please urgently investigate:
- Workspaces purchasing 99 seats shortly before expiration;
- Automated bulk addition of users during the final hour;
- Continued premium access during the grace period;
- Workspaces linked to repeated or bulk resale activity;
- Usage that is significantly disproportionate to the prorated payment.
I can privately provide reproduction steps, billing records, screenshots, timestamps, and evidence of active resale.
Please confirm receipt and escalate this matter to the security, billing, fraud-prevention, and platform-integrity teams.