Hackers Are Using Fake OpenAI Organizations to Silently Steal Your Work Data
Want more insights like this?
Security researchers at Push Security have uncovered a "poisoned tenant" attack where hackers create fake OpenAI organizations — impersonating real companies — and send employees legitimate-looking invitations straight from OpenAI's own notification system, noreply@tm.openai.com. One click joins the victim to an attacker-controlled tenant with zero additional verification.
Once inside, anything the employee does — prompts, uploaded files, API calls — is visible to the attacker. The fake orgs go to some lengths to look real: executive impersonation, Owner-level privileges for everyone, even a credit card attached to avoid friction on paid features. Push found the technique when it saw itself impersonated, and the invites observed so far have targeted cybersecurity and tech firms.
No spoofed domains, no malicious links. Just a trusted platform being weaponized against its own users. The one visible tell is a small domain mismatch warning on the invite. Beyond that, defences are organizational: restrict who can join external tenants, enforce domain verification, and get visibility into which SaaS orgs staff are actually joining.
Source: Cybersecurity News