top of page

Fake OpenAI org invites are the new phishing

  • Jun 29
  • 7 min read
Fake OpenAI

By Yonatan Hoorizadeh — CISSP, CISM, CRISC, AAISM

Published By: Purple Shield Security

Published: June 29, 2026

Last updated: June 29, 2026

Attackers are creating fake OpenAI organizations named after real companies and inviting employees to join. The invites come from OpenAI’s own email system, pass authentication checks, and look genuine. The goal is to get staff using the attacker’s ChatGPT workspace so the attacker can harvest whatever sensitive data they type into it.

Several employees at the security firm Push Security recently received emails inviting them to join an OpenAI organization called “Push Security Inc.” The emails came from OpenAI’s real notification address, passed every standard email authentication check, and looked exactly like a routine invitation to a company ChatGPT workspace. The problem: no one at Push had created that organization. An attacker had, using Gmail addresses, and had named it after the company on purpose.


Push Security, which documented the incident on June 26, 2026 and reported it to BleepingComputer, says other customers received nearly identical invitations — all of them at firms in the cybersecurity or technology space. The technique is old enough to have a name. Push coined “poisoned tenant” in 2023 as a theoretical attack. This is the first time the company has watched it used against its own people.


What actually happened with the fake OpenAI organization?


An attacker created an OpenAI organization, named it “Push Security Inc,” and sent invitations to specific Push employees at their real work email addresses. The invites came from OpenAI’s legitimate sender, noreply@tm.openai.com, and were indistinguishable from a normal workspace invite. The targeting was deliberate — the attacker had researched who worked there first.


Luke Jennings, VP of Research & Development at Push, accepted one invitation from a clean browser to see what was on the other side. Acceptance took a single click — no credentials, no extra authentication. He was dropped straight into the fake organization, where a single attacker-controlled Gmail account was posing as Push’s CEO, Adam Bateman.


Two details stood out. Every invited employee had been handed the “Owner” role, giving them full administrative control of the tenant — which let Jennings see that none of his colleagues had actually joined yet. And a Visa credit card was already attached to the billing account. Someone had set this up to look funded, configured, and real.


Why does a fake org invite get past email security?


Because, by every technical measure, it is not a fake email. The invitation is generated and sent by OpenAI’s own mail infrastructure, from OpenAI’s own domain, and passes SPF, DKIM, and DMARC authentication. There is no spoofed sender to flag, no malicious link to detonate, and no attachment to scan. The email is genuine; only the invitation inside it is hostile.


This is the part most defenses are not built for. As Push put it, “these invitations originate from the platform’s own infrastructure, and because they are legitimate, they are more likely to bypass email security controls.” OpenAI does add a warning line noting that the inviter’s domain (gmail.com) doesn’t match the recipient’s — but it’s a single line buried in an otherwise polished, trusted-looking email.


Push frames this as part of a broader pattern it calls SaaS notification abuse, and it is not limited to OpenAI. Cisco Talos documented the same approach across GitHub and Jira in April 2026, with phishing lures stuffed into commit messages and welcome notes that feed platform-generated emails. At its peak, Talos estimated roughly 2.89% of all emails sent from GitHub on a single day were tied to that activity. Any platform that lets anyone create an organization, name it anything, and email invitations through its own system is offering attackers a trusted delivery channel.


What is a “poisoned tenant” and what does the attacker get out of it?


A poisoned tenant is an account or organization an attacker registers on a legitimate SaaS platform using a target company’s name, then invites that company’s employees into. The payoff is not the invite itself — it’s what happens after someone joins. Once an employee treats the attacker’s workspace as the official company tool, the attacker has a trusted channel to harvest data or stage the next move.


On an AI platform, the data is the prize. Push’s read is that the attacker wanted employees to assume “we’ve got a company OpenAI org now” and start running real work through it. As an organization administrator, the attacker would then sit on a live feed of usage logs and API activity. And as Push noted, what people paste into AI prompts can be extraordinarily sensitive — source code, internal documents, customer data, security research, and strategic plans.


The stolen-looking credit card fits this theory. If the workspace hit a paywall, a curious employee might ask internally who set up billing — and the whole thing unravels. A pre-funded account removes that friction and lets staff use premium features without questioning where the org came from. Push also flagged a nastier follow-on path: a poisoned tenant can become the launch point for credential harvesting (an older technique it calls SAMLjacking) or for seeding shared projects with malicious instructions that an AI agent then executes against connected email, calendar, and cloud accounts.


Why is this worse on an AI platform than on Slack or Jira?


Because an AI workspace is increasingly where the sensitive work actually happens, and because the same prompts that make AI useful are a perfect data-exfiltration funnel. A poisoned Slack tenant gets an attacker some chatter. A poisoned ChatGPT tenant, if employees start using it, gets them the raw material people feed an assistant: contract language, unreleased financials, incident details, code. That is a different risk class.


Here is the part the coverage underplays. The reason this attack has a target-rich field is that most companies have no idea which AI tools their staff already use, sanctioned or not. When there is no approved, clearly labeled corporate AI workspace, a fake one is far more believable — employees have no baseline to compare it against. A vCISO or fractional CISO triaging this in the first 72 hours wouldn’t start with the invite. They’d start with the inventory question: do we have a single, official AI platform our people know to expect invitations from — and would anyone here recognize an invite that didn’t come through it?


That is a governance gap, not a malware problem, and it is the gap this campaign is built to exploit. Shadow AI — employees using AI tools the company hasn’t approved or doesn’t know about — is what turns a clumsy impersonation into a plausible one.


What should your business do this week?


Treat an organization invitation — from OpenAI, Microsoft, GitHub, Atlassian, or any SaaS platform — as a security-relevant action that gets verified before anyone clicks accept. The defensive problem here isn’t a bad link; it’s a legitimate email carrying an illegitimate invitation. A few concrete moves close most of the exposure:

  • Tell staff now that an unexpected invite to join a company workspace on any platform should be confirmed through an internal channel before accepting — even when the email is clearly genuine.

  • Establish and name your sanctioned AI platform, so employees have a baseline and a fake “company OpenAI org” stands out instead of blending in.

  • Get visibility into which SaaS and AI organizations your employees are joining — through browser telemetry, identity-provider monitoring, or platform APIs — since most teams currently have none.

  • Where a platform allows it, claim your organization name yourself so an attacker can’t register it first; recognize that some platforms, OpenAI included, don’t fully prevent name reuse.

  • Update awareness training so it covers authentic-but-hostile invitations, not just spoofed senders and bad attachments.


If your company is rolling out AI tools without a written policy for who approves them and how staff are told which ones are official, that is the gap to close first. Purple Shield works with mid-market and regulated firms on exactly this — building the AI security governance guardrails that make shadow AI visible and unsanctioned invitations obvious.


Frequently asked questions


Was this a real phishing email or a real OpenAI email?

Both, in a sense. The email was a genuine OpenAI organization invitation, sent from OpenAI’s real address and passing all authentication checks. What made it an attack was the organization behind it — created by an attacker using Gmail addresses and named after the target company. That’s why traditional email security doesn’t catch it: there’s nothing technically forged to detect.


We don’t use ChatGPT at work. Are we still exposed?

Yes, and possibly more so. If your company has no official AI workspace, employees have no baseline to judge an invite against, which makes a fake “company org” more believable, not less. The same technique also works on Slack, GitHub, Jira, and other platforms that let anyone create a named organization and send invites. The exposure is the pattern, not the specific product.


Can we stop people from creating an OpenAI org with our company name?

Not reliably today. On some platforms you can register your organization name defensively to claim it first. But as Push Security found, OpenAI currently allows multiple tenants with the same name and doesn’t prevent someone with an unrelated email address from creating a realistic-looking org under your brand. Until vendors add domain verification, detection and employee verification are the practical controls.


Does our phishing awareness training already cover this?

Probably not. Standard training teaches people to spot spoofed senders, suspicious links, and bad attachments — none of which are present here. Employees need to learn that an email can be technically authentic and still be part of an attack, and that joining any organization on any platform should be verified internally first. If your last training cycle didn’t address SaaS invitation abuse, it’s out of date.


Most companies adopting AI right now have the tools moving faster than the governance around them, and attackers know it. If you want a second set of eyes on how your team approves AI platforms, tells staff which ones are official, and spots an invitation that doesn’t belong, that’s the kind of work Purple Shield’s AI security and governance practice is built for.

 
 
bottom of page