Attackers use fake OpenAI organization invites to impersonate companies and target employees

Attackers are creating fraudulent OpenAI ChatGPT organizations that look like real companies and inviting employees to join them through legitimate OpenAI emails. Push Security said the campaign targeted employees in cybersecurity and technology firms using work addresses, with fake tenants named after the victim company and attacker-controlled Gmail accounts inside posing as company staff. The apparent goal is to get victims to use the workspace and paste in sensitive data such as source code, internal documents, customer information, or research.
Why it matters: This matters because the emails are sent by OpenAI itself, so they can bypass normal phishing suspicion and email defenses. Organizations using ChatGPT Enterprise or shared AI workspaces should warn staff to verify who created tenant invites and avoid joining unexpected workspaces or sharing sensitive data in them.

Sources

In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting
SecurityWeek News 2026.07.03 88% relevant
The roundup adds a concrete example of the poisoned-tenant technique being used against Push Security through OpenAI organization invitations that impersonated the company and could have enabled spying or follow-on social engineering.
Cybersecurity firms targeted by fraudulent OpenAI organization invites
Lawrence Abrams 2026.06.26 100% relevant
This article establishes a distinct social-engineering campaign centered on attacker-created OpenAI tenants and legitimate organization invitation emails, not a patch, CVE, or previously tracked OpenAI abuse event.
← Back to all stories