Cybertech Europe 2026-IT Industry Official Media Partner

Cybersecurity firms hit by fraudulent OpenAI invitations

OpenAI – Cybersecurity companies exposed to fraudulent OpenAI invitations | IT industry OpenAI – Cybersecurity companies exposed to fraudulent OpenAI invitations | IT industry
visualizes the new attack method where fake OpenAI organizations and legitimate invitations are leveraged to trick companies into sharing business-critical information via ChatGPT.

Cybersecurity firms have been targeted by a new type of social engineering attack in which attackers create fake OpenAI organizations that pretend to represent well-known companies. By sending legitimate invitations through OpenAI’s own email infrastructure, the attackers attempt to trick employees into joining fake ChatGPT workspaces where sensitive company information can later be collected.

Security company Push Security discovered the campaign, which has been named Poisoned Tenant, after several employees received invitations to join an OpenAI organization called “Push Security Inc.”. The invitations were sent from OpenAI's official sender address. [email protected], which made them basically indistinguishable from real organizational invitations.

Invitation email showing OpenAI branding, "Push Security Inc" org name, and the Gmail sender address

However, it turned out that the organization had not been created by Push Security, but by an attacker who registered the ChatGPT workspace with private Gmail addresses.

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

OpenAI's own emails are being exploited

One of the most notable aspects of the campaign is that the invitations are sent from OpenAI’s own servers. Because the emails pass standard authentication checks like SPF, DKIM, and DMARC, they appear completely legitimate and look identical to the invitations companies typically send when inviting employees to a shared ChatGPT workspace.

OpenAI does display a warning that the sender's email address does not match the recipient's company domain, but the message only appears as a short line in the invitation and is therefore at risk of being overlooked.

Push Security also states that several other clients in the cybersecurity and technology sectors have reported that their employees have received similar invitations, indicating that the campaign is broader than a single attack.

Targeted attacks against selected employees

According to Push Security The invitations were targeted to specific individuals using their work-related email addresses, suggesting that the attackers had first mapped the organizations and identified relevant employees before launching the campaign.

""Invite accepted" confirmation page.

To investigate the attack, accepted Luke Jennings, Vice President of R&D at Push Security, one of the invitations.

When he joined the organization, he discovered that it contained a single attacker-controlled account with a Gmail address that purported to belong to the company's CEO, Adam Bateman.

Settings screen showing the organization name “Push Security Inc”.

Additionally, all invited users had been granted administrator privileges in the organization, giving them full visibility into the fake workspace, where they could see other pending invitations and confirm that none of the affected employees had yet joined.

Members page showing the attacker's account and Luke's account.

Researchers also discovered that the attackers had already linked a Visa credit card to the organization's billing account. According to Push Security, this may have been done to increase credibility and give invited users access to premium features without arousing suspicion.

The goal is believed to be to collect sensitive corporate information

The fake ChatGPTorganization contained no previous projects or conversations. Push Security therefore believes that the attackers' goal was to get employees to start using the fake workspace as the company's official ChatGPT environment.

If users start working for the fraudulent organization, attackers can gain access to large amounts of sensitive information that is fed into the AI service, such as:

  • Source code
  • Internal documents
  • Customer data
  • Security reports
  • Business strategies
  • Research materials

This type of information can be significantly more valuable than traditional usernames and passwords because it often contains the company's most business-critical data.

Push Security writes that the extensive preparation behind the attack, where the attackers mapped individual employees, created organizations with the company's names and also linked a payment method to the account, suggests that the goal is to get users to actually start using the fake AI environment for an extended period of time.

A growing trend of SaaS platforms being abused

Push Security believes that the campaign reflects a broader trend where attackers are exploiting legitimate invitation and notification features built into modern SaaS platforms.

Unlike traditional phishing campaigns, these invitations come directly from the platforms’ own servers. Since the messages are technically legitimate, they have a much greater chance of passing through email filters and gaining the trust of recipients.

As AI platforms such as ChatGPT becomes an increasingly important part of companies' daily work, the risk of these services being used as tools in advanced social engineering attacks also increases.

How companies can protect themselves against the attack

Push Security recommends that organizations train employees to always verify unexpected organizational invitations before accepting them, even if they come from a legitimate sender.

Companies should also monitor membership in external SaaS organizations and ensure that employees only use AI workspaces that have been approved by the organization's IT and security department.

As AI services are increasingly used to manage business-critical information, it will also be important to introduce clear guidelines for how sensitive data may be shared with generative AI platforms.

OpenAI has not yet commented on whether the company plans to implement additional protections against this type of abuse or whether similar campaigns have been reported by other organizations. If the company issues a statement, this article will be updated.

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT