Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    HackTheBox – WingData

    June 28, 2026

    Data breach exposes up to 14.2 million email logins at six ISPs

    June 28, 2026

    Real Folks of Cyber | Pearce Barry | Day in the Life

    June 27, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Cybersecurity firms targeted by fraudulent OpenAI organization invites
    News

    Cybersecurity firms targeted by fraudulent OpenAI organization invites

    adminBy adminJune 26, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    OpenAI

    Threat actors are creating OpenAI tenants that impersonate legitimate companies and inviting employees to join them, in what appears to be a ploy to trick targets into submitting sensitive company information in chats and projects.

    Push Security discovered what they dub as the “Poisoned Tenant” campaign after multiple employees received invitations to join an OpenAI organization named “Push Security Inc.”  While the invite was legitimate, coming directly from OpenAI, the ChatGPT tenant had been created by an attacker using Gmail addresses rather than by the company.

    The invitation emails were sent from OpenAI’s legitimate notification address, noreply@tm.openai.com, passed email authentication checks, and were identical to a normal invitation to join an organization’s ChatGPT workspace.

    image
    Fake Push Security OpenAI tenant invite sent to employees
    Fake Push Security OpenAI tenant invite sent to employees
    Source: Push Security

    Push Security told BleepingComputer that other customers have also received similar invitations and that all are in the cybersecurity or technology space.

    Attacker-controlled OpenAI organizations

    According to a new report by Push Security, the invitations targeted specific employees using their work email addresses, suggesting the attackers had researched the employees who work at the company before launching the campaign.

    Although OpenAI includes a warning stating that the inviter’s email domain does not match the recipient’s company domain, the notice appears as a single line within the legitimate invitation email.

    To better understand the attack’s goal, Luke Jennings, VP, Research & Development at Push Security, accepted one of the invitations.

    After accepting, the researcher was immediately added to the fraudulent organization, which impersonated Push Security and contained a single attacker-controlled account with a Gmail address that posted as the company’s CEO, Adam Bateman.

    The invited employees had all been assigned Owner privileges within the organization, giving them administrative permissions over the tenant.

    As they had administrative access, they could view other pending invitations and confirm that none of the targeted employees had joined the fake ChatGPT organization. They also found that a Visa credit card had already been attached to the organization’s billing account, adding further legitimacy.

    Other Push Security employees invited to the OpenAI tenant
    Other Push Security employees invited to the OpenAI tenantS
    Source: Push Security

    Push Security told BleepingComputer that the project was empty and contained no existing chats or projects, making it unclear what the goal of the attack was.

    Push Security believes the attackers’ objective is to convince employees to use the ChatGPT workspace as if it were a legitimate corporate platform, which would then allow the attackers to collect any sensitive information that was submitted.

    “An attacker who just wants to spray scam content through a trusted email channel doesn’t name the organization after their target, research individual employees, or attach a credit card,” wrote Push.

    “That investment only pays off if employees actually join the organization and start using it. And on an AI platform, the data people put into prompts can be extraordinarily sensitive — source code, internal documents, customer data, security research, strategic plans.”

    The company also believes that attaching a payment method removes another potential warning sign, allowing invited users to use premium features without questioning whether the organization is legitimate.

    Push Security says the campaign reflects a broader trend of attackers abusing legitimate invitation and notification features built into SaaS platforms.

    Unlike normal phishing campaigns, these invitations originate from the platform’s own infrastructure, and because they are legitimate, they are more likely to bypass email security controls.

    To reduce the risk of these types of attacks, Push recommends training employees to verify unexpected organization invitations and monitoring SaaS organization memberships.

    BleepingComputer contacted OpenAI to ask whether it has received additional reports of similar campaigns, what protections organizations can use against these attacks, and whether it plans to introduce additional safeguards to prevent attackers from creating organizations impersonating legitimate companies. We will update this article if we receive a response.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleCISA sets urgent deadline to fix Cisco flaw exploited in attacks
    Next Article Black Hat Europe 2025 | Silence On macOS: What 70K Binaries Reveal About The macOS Malware Ecosystem
    admin
    • Website

    Related Posts

    News

    Data breach exposes up to 14.2 million email logins at six ISPs

    June 28, 2026
    News

    Scientists Think They’ve Uncovered the 15-Million-Year-Old Origin of Laughter

    June 27, 2026
    News

    Clean GitHub repo tricks AI coding agents into running malware

    June 27, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202633 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202632 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202633 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202632 Views
    Our Picks

    HackTheBox – WingData

    June 28, 2026

    Data breach exposes up to 14.2 million email logins at six ISPs

    June 28, 2026

    Real Folks of Cyber | Pearce Barry | Day in the Life

    June 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.