Skip to content
Fraudulent OpenAI Tenants Target Cybersecurity Firms for Data Theft

Fraudulent OpenAI Tenants Target Cybersecurity Firms for Data Theft

First seen 29 Jun 2026, 16:34 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 30, 2026 at 16:01 UTC
  • •Attackers create fake OpenAI tenants to impersonate legitimate companies.
  • •Invitations are sent from OpenAI's legitimate notification system, bypassing security.
  • •Targeted employees are granted owner privileges, risking sensitive data exposure.

Threat actors are impersonating legitimate companies by creating fraudulent OpenAI tenants to trick employees into divulging sensitive information. This campaign, termed 'Poisoned Tenant,' was identified by Push Security, which found that attackers used Gmail addresses to create fake organizations while sending invitations from OpenAI's legitimate notification system. The invitations, which bypass email security measures, target specific employees within the cybersecurity and technology sectors. Once accepted, employees are granted owner privileges, allowing attackers to potentially collect sensitive data shared in the fake ChatGPT workspace. A credit card is often attached to enhance the legitimacy of the fraudulent organization. The ultimate goal is to exploit user trust in SaaS platforms to extract confidential company data. Push Security's investigation revealed that the project created by attackers contained no existing chats, leaving the exact objectives unclear.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 101d ago How this analysis works

Timeline

2026-06-26
Push Security discovers 'Poisoned Tenant' campaign
Push Security identified a campaign where attackers impersonate companies via fake OpenAI tenants to steal sensitive data.
BleepingComputer
2026-06-26
Fraudulent invitations sent to employees
Employees in cybersecurity firms received invitations to join fake OpenAI organizations, appearing legitimate.
BleepingComputer
2026-06-29
Details published by Feeds.Feedburner
Feeds.Feedburner reported on the deceptive tactics used in the 'Poisoned Tenant' campaign, highlighting the risk to company data.
Feeds.Feedburner

More articles in this cluster (3)

Following this threat?

Track Push Security in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed