<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/cybersecurity-firms-targeted-by-fraudulent-openai-organization-invites-wswidh9bo" -->

---
title: Cybersecurity firms targeted by fraudulent OpenAI...
description: Threat actors are running a &#x27;Poisoned Tenant&#x27; campaign by creating fraudulent OpenAI/ChatGPT organizations that impersonate legitimate companies and inviting...
canonical: https://daily.dev/posts/cybersecurity-firms-targeted-by-fraudulent-openai-organization-invites-wswidh9bo
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Cybersecurity firms targeted by fraudulent OpenAI organization invites | daily.dev
og:description: Threat actors are running a &#x27;Poisoned Tenant&#x27; campaign by creating fraudulent OpenAI/ChatGPT organizations that impersonate legitimate companies and inviting...
og:url: https://daily.dev/posts/cybersecurity-firms-targeted-by-fraudulent-openai-organization-invites-wswidh9bo
og:image: https://api.daily.dev/og/posts/wSWidH9bO.png
og:image:alt: Cybersecurity firms targeted by fraudulent OpenAI organization invites
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Cybersecurity firms targeted by fraudulent OpenAI organization invites

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 4 min read · 0 upvotes · 0 comments

## Summary

Threat actors are running a 'Poisoned Tenant' campaign by creating fraudulent OpenAI/ChatGPT organizations that impersonate legitimate companies and inviting targeted employees to join them. Discovered by Push Security after their own employees received invites, the attack uses OpenAI's legitimate notification infrastructure (noreply@tm.openai.com), bypassing email security controls. Attackers research specific employees, attach a real credit card to add legitimacy, and grant invited users Owner privileges. The goal appears to be tricking employees into using the fake workspace as a corporate ChatGPT environment, exposing sensitive data like source code, internal documents, and customer data through AI prompts. The campaign targets cybersecurity and technology firms specifically. Push Security recommends training employees to verify unexpected organization invitations and monitoring SaaS memberships.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/cybersecurity-firms-targeted-by-fraudulent-openai-organization-invites>

## Similar posts on daily.dev

- [Security shifts to the human layer as AI scams surge](https://daily.dev/posts/security-shifts-to-the-human-layer-as-ai-scams-surge-uermo5dgq) · CSO Online · 0 upvotes · 0 comments
- [Schneier on Security](https://daily.dev/posts/schneier-on-security-a7rpdugyv) · Schneier on Security · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#openai](https://daily.dev/tags/openai), [#chatgpt](https://daily.dev/tags/chatgpt), [#phishing](https://daily.dev/tags/phishing)

[View this post on daily.dev](https://daily.dev/posts/cybersecurity-firms-targeted-by-fraudulent-openai-organization-invites-wswidh9bo)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Cybersecurity firms targeted by fraudulent OpenAI organization invites","url":"https://daily.dev/posts/cybersecurity-firms-targeted-by-fraudulent-openai-organization-invites-wswidh9bo","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/cybersecurity-firms-targeted-by-fraudulent-openai-organization-invites-wswidh9bo"},"datePublished":"2026-06-26T17:49:34.409Z","dateModified":"2026-06-26T17:49:59.116Z","description":"Threat actors are running a 'Poisoned Tenant' campaign by creating fraudulent OpenAI/ChatGPT organizations that impersonate legitimate companies and inviting...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1c4a264ed67f637a17bf2c22b3808dd0?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1c4a264ed67f637a17bf2c22b3808dd0?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/cybersecurity-firms-targeted-by-fraudulent-openai-organization-invites-wswidh9bo","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,openai,chatgpt,phishing","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Cybersecurity firms targeted by fraudulent OpenAI organization invites"}]}
```

