Cybersecurity firms targeted with fake OpenAI organization invites.

26.06.2026

Cybersecurity firms targeted with fake OpenAI organization invites. Threat actors are creating fraudulent OpenAI tenants that impersonate real companies and then inviting employees to join them. Push Security found the campaign after its staff received legitimate-looking OpenAI…

Източник: www.bleepingcomputer.com

Cybersecurity firms targeted with fake OpenAI organization invites.

Threat actors are creating fraudulent OpenAI tenants that impersonate real companies and then inviting employees to join them. Push Security found the campaign after its staff received legitimate-looking OpenAI organization invitations for a fake “Push Security Inc.” tenant created by attackers. The emails came from OpenAI’s real notification address and passed normal email authentication checks, making them harder to spot as suspicious. The suspected goal is to lure employees into submitting sensitive company data inside attacker-controlled ChatGPT workspaces.