# Attackers Create Fake OpenAI Tenants to Trick Employees into Sharing Sensitive Data
A new social engineering campaign is leveraging OpenAI’s legitimate invitation system to create fraudulent organizations that impersonate real companies, with the goal of luring employees into submitting confidential information through ChatGPT.
## The “Poisoned Tenant” Campaign
Push Security has uncovered what it calls the “Poisoned Tenant” campaign, in which threat actors create OpenAI organizations bearing the names of legitimate companies and send invitations to actual employees of those firms. The invitations arrive directly from OpenAI’s official notification address, `noreply@tm.openai.com`, and pass standard email authentication checks, making them virtually indistinguishable from genuine invitations.
The campaign first came to light when multiple Push Security employees received invitations to join an OpenAI organization named “Push Security Inc.” While the email itself was legitimate — sent by OpenAI’s own infrastructure — the tenant had been created by an attacker using a Gmail address rather than by anyone affiliated with the company.
## How the Attack Works
According to Push Security’s research, the invitations were carefully targeted. Attackers used employees’ work email addresses, indicating they had conducted prior research on the individuals and their organizations. All identified targets were in the cybersecurity or technology sector.
Although OpenAI does include a warning in the invitation email noting that the inviter’s email domain does not match the recipient’s company domain, this notice appears as a single line within an otherwise legitimate-looking email, making it easy to overlook.
To investigate the campaign’s objectives, Luke Jennings, VP of Research & Development at Push Security, accepted one of the fraudulent invitations. Upon joining, he found himself added to an organization impersonating Push Security, containing a single attacker-controlled account with a Gmail address posing as the company’s CEO, Adam Bateman.
Notably, all invited employees were assigned **Owner privileges** within the organization, granting them administrative access. This allowed Jennings to view other pending invitations and confirm that none of the targeted employees had yet joined the fake tenant. He also discovered that a Visa credit card had already been attached to the organization’s billing account, lending an additional layer of credibility to the fraudulent setup.
## The Endgame: Harvesting Sensitive AI Prompts
The fraudulent tenant’s project space was empty, with no existing chats or projects, leaving the immediate purpose unclear. However, Push Security believes the attackers’ ultimate goal is to convince employees to use the ChatGPT workspace as though it were a legitimate corporate platform. Once employees begin interacting with the AI, any information they submit in prompts — including source code, internal documents, customer data, security research, and strategic plans — could be harvested by the attackers.
“An attacker who just wants to spray scam content through a trusted email channel doesn’t name the organization after their target, research individual employees, or attach a credit card,” Push Security noted. “That investment only pays off if employees actually join the organization and start using it. And on an AI platform, the data people put into prompts can be extraordinarily sensitive.”
The attachment of a payment method also serves a strategic purpose: it removes another potential red flag by allowing invited users to access premium features without questioning the organization’s legitimacy.
## A Broader SaaS Abuse Trend
Push Security warns that this campaign reflects a growing trend of attackers exploiting legitimate invitation and notification features built into SaaS platforms. Unlike traditional phishing campaigns, these invitations originate from the platform’s own infrastructure, making them far more likely to bypass email security controls and reach their intended targets.
## Recommended Defenses
To mitigate the risk of such attacks, Push Security recommends that organizations:
– **Train employees** to carefully verify unexpected organization invitations, particularly those involving AI and SaaS platforms.
– **Monitor SaaS organization memberships** to detect unauthorized or suspicious tenants.
BleepingComputer reached out to OpenAI to inquire whether the company has received additional reports of similar campaigns, what protections organizations can implement, and whether additional safeguards are planned to prevent attackers from creating organizations that impersonate legitimate companies.
—
*Source: BleepingComputer — [“Attackers create fake OpenAI tenants to phish employees with legitimate invites”](https://www.bleepstatic.com)*



