False Positive Cyber Abuse Warning / Possibly Related To False API billing

recently received a Cyber Abuse warning on my OpenAI account related to Codex activity, along with an unexpected API charge for services I have never used. Because both issues appeared around the same time and involve activity I do not recognize or understand, I am concerned they may be connected in some way.

My account was charged $46.29 for Responses and Chat Completions, even though I have not implemented or used those API categories in my project. The entire $46.29 charge occurred between 1:00 PM and 1:59 PM Chicago time, when I was not at home. I was also away from home for roughly four hours before and after that time period.

I am the only person who works on this project and the only person with access to it. I use Codex only for routine software development work on my own React Native/Django application, such as refactoring, debugging, and implementation support.

The unexpected API charges appear to be separate from my normal Codex usage, but I understand the Cyber Abuse warning may be related to Codex activity. That is why I explained my codex usage above.

The only OpenAI API functionality my application uses is text moderation and image moderation. My secret keys are locked down, my app is still very low-profile and not even publicly available, and I reviewed my login activity but did not see any activity from anyone other than myself. Because of that, I would be hard-pressed to believe my account was hacked, but I also do not understand how these charges occurred.

I contacted OpenAI separately about the billing issue and also submitted an appeal regarding the Cyber Abuse warning. However, OpenAI stated that they are upholding the warning and will not consider further appeals. I have not yet received a response regarding the separate billing issue.

I find this extremely unfair, especially because I am still seeking a refund for charges I know I did not incur, and I want my account record to accurately reflect that I did not violate any policies.

This is extremely frustrating because I know I did not do anything wrong. OpenAI is more than welcome to review my conversation history and account activity. I would appreciate a refund for the unexpected charge, but more than anything, I would really like the opportunity to speak with a real person who can help explain what happened.

I’m hoping this post can help me get some clarity and the opportunity to speak with a real person who can help me. I’m also more than willing to provide my appeal case number and billing support case number privately to OpenAI staff if that would help.

If you can post your case numbers that would be helpful and also ensure you have rotated (deleted and recreated) any API keys you may have been using.

Thank you so much for your response and for looking into this.

My billing/email support case number is 10444983.

My appeal case number is C-2Hqxy6ZudpxY.

I also removed the API key that I was using.

Hello, I just wanted to follow up to see if there are any updates or information on where I’m at in the process.

Well, I spoke with support, and unfortunately, the experience was pretty disappointing. I think I talked with a real person…, but I got no explanation of what happened. They just kept asking for stuff I already gave them, and they just kept repeating themselves. Ending with an email saying the original decision stands.

At this point, I got jipped out of $44. Which isn’t a big deal, but the bigger concern is trust. I wanted to continue using OpenAI’s text and image moderation services since it’s really good, but now I’m hesitant. If something like this can happen once for around $40, I do not feel confident that it could not happen again in the future for $1,000 or more.

It is honestly a real bummer. I have been a loyal user since the first month of launch and have always told people how great OpenAI is.

If anyone knows of any other good text and image moderation solutions that are comparable to OpenAI’s, I would appreciate the recommendation.

You know, this is precisely the kind of situation when you receive a notice and cannot understand what happened or what caused it.

I experienced a similar problem related to unusual token usage. I had a small quota set, I received a notification, and then noticed someone was using the newest model. As a result, I had to rotate all my API tokens. I suspect a token leaked or something else occurred — this happened about a month ago. I don’t know whether it was related to OpenAI security or something else, but in a very short period my budget was exhausted; in my case it was only $15, and it was charged unexpectedly. I was surprised because my usage is normally minimal and I do not consume tokens beyond the established quota.

The security flagging that followed was even more troubling. In my case I know why it happened: I implemented a single feature — more precisely, I asked an agent to implement it — and the next day my account was flagged. The feature allowed users in the interface of my SaaS application to select their own accounts and export their data (logins, passwords, and other items) in a specific format. I never considered that this functionality could be interpreted as cyberfraud.

The problem is that this is ambiguous: it’s a legitimate administrative feature for a SaaS product, but an automated system may interpret it as an attempt to facilitate fraud or data theft. That creates a false positive, and there is essentially no clear remedy because you are not told what triggered the restriction, where the detection occurred, or why you received the notice.

Instead you get a generic response, which is problematic because it prevents you from adjusting your usage, investigating the cause, and understanding what happened. When you receive only a vague subject line saying your usage violates policy, you are left guessing what exactly was flagged. In my case I can roughly infer the cause, but the lack of specificity is unacceptable. Administrative functions should not trigger such enforcement actions.

This issue raises questions, especially because it seemed to start with release 5.6. I first saw it reported by members of the community, and now I’ve received the notification myself. Incidents like this discourage me from using tools like Codex and push me toward alternative solutions where such risks do not arise. ChatGPT accounts often contain a lot of personal and useful information, which makes using the platform for work feel risky and impractical under these circumstances.

Hello everyone,

I’m hoping some of you might have gone through something similar and can share what happened for you.

A few days ago my ChatGPT account was permanently deactivated. I submitted an appeal explaining my background as a computer science graduate working in IT who used the platform for legitimate professional development and educational purposes. The appeal was denied (Case C-CKxDtO4DC1BO).

What has been hardest is losing the history. Over a long time I used the account heavily for programming work, technical learning, study notes, project planning, and personal reflection. It held a lot of material that was important to me, and losing access to it has been really difficult.

I also submitted a formal privacy request asking for an export of my data (Privacy Team cases 12507264 and 12532105). I verified ownership when asked, but I haven’t received any further response yet.

I’m mainly looking for real experiences from others:

  • Has anyone with a permanently deactivated account still managed to get their conversation history or personal data through a privacy request?
  • How long did it take for you to hear back after verifying ownership?
  • Is there anything else worth trying while waiting?

Even if the account is never restored, recovering the data would mean a lot to me.

@OpenAI_Support — I’ve already contacted the Privacy Team and verified ownership multiple times. Any chance this can be looked at?

Thank you for any advice or shared experiences.