Cybersecurity firms have been targeted by a new type of social engineering attack in which attackers create fake OpenAI organizations that pretend to represent well-known companies. By sending legitimate invitations through OpenAI’s own email infrastructure, the attackers attempt to trick employees into joining fake ChatGPT workspaces where sensitive company information can later be collected.
Security company Push Security discovered the campaign, which has been named Poisoned Tenant, after several employees received invitations to join an OpenAI organization called “Push Security Inc.”. The invitations were sent from OpenAI's official sender address. [email protected], which made them basically indistinguishable from real organizational invitations.

However, it turned out that the organization had not been created by Push Security, but by an attacker who registered the ChatGPT workspace with private Gmail addresses.
OpenAI's own emails are being exploited
One of the most notable aspects of the campaign is that the invitations are sent from OpenAI’s own servers. Because the emails pass standard authentication checks like SPF, DKIM, and DMARC, they appear completely legitimate and look identical to the invitations companies typically send when inviting employees to a shared ChatGPT workspace.
OpenAI does display a warning that the sender's email address does not match the recipient's company domain, but the message only appears as a short line in the invitation and is therefore at risk of being overlooked.
Push Security also states that several other clients in the cybersecurity and technology sectors have reported that their employees have received similar invitations, indicating that the campaign is broader than a single attack.
Targeted attacks against selected employees
According to Push Security The invitations were targeted to specific individuals using their work-related email addresses, suggesting that the attackers had first mapped the organizations and identified relevant employees before launching the campaign.

To investigate the attack, accepted Luke Jennings, Vice President of R&D at Push Security, one of the invitations.
When he joined the organization, he discovered that it contained a single attacker-controlled account with a Gmail address that purported to belong to the company's CEO, Adam Bateman.

Additionally, all invited users had been granted administrator privileges in the organization, giving them full visibility into the fake workspace, where they could see other pending invitations and confirm that none of the affected employees had yet joined.

Researchers also discovered that the attackers had already linked a Visa credit card to the organization's billing account. According to Push Security, this may have been done to increase credibility and give invited users access to premium features without arousing suspicion.
The goal is believed to be to collect sensitive corporate information
The fake ChatGPTorganization contained no previous projects or conversations. Push Security therefore believes that the attackers' goal was to get employees to start using the fake workspace as the company's official ChatGPT environment.
If users start working for the fraudulent organization, attackers can gain access to large amounts of sensitive information that is fed into the AI service, such as:
- Source code
- Internal documents
- Customer data
- Security reports
- Business strategies
- Research materials
This type of information can be significantly more valuable than traditional usernames and passwords because it often contains the company's most business-critical data.
Push Security writes that the extensive preparation behind the attack, where the attackers mapped individual employees, created organizations with the company's names and also linked a payment method to the account, suggests that the goal is to get users to actually start using the fake AI environment for an extended period of time.
A growing trend of SaaS platforms being abused
Push Security believes that the campaign reflects a broader trend where attackers are exploiting legitimate invitation and notification features built into modern SaaS platforms.
Unlike traditional phishing campaigns, these invitations come directly from the platforms’ own servers. Since the messages are technically legitimate, they have a much greater chance of passing through email filters and gaining the trust of recipients.
As AI platforms such as ChatGPT becomes an increasingly important part of companies' daily work, the risk of these services being used as tools in advanced social engineering attacks also increases.
How companies can protect themselves against the attack
Push Security recommends that organizations train employees to always verify unexpected organizational invitations before accepting them, even if they come from a legitimate sender.
Companies should also monitor membership in external SaaS organizations and ensure that employees only use AI workspaces that have been approved by the organization's IT and security department.
As AI services are increasingly used to manage business-critical information, it will also be important to introduce clear guidelines for how sensitive data may be shared with generative AI platforms.
OpenAI has not yet commented on whether the company plans to implement additional protections against this type of abuse or whether similar campaigns have been reported by other organizations. If the company issues a statement, this article will be updated.








