Threat actors are running a 'Poisoned Tenant' campaign by creating fraudulent OpenAI/ChatGPT organizations that impersonate legitimate companies and inviting targeted employees to join them. Discovered by Push Security after their own employees received invites, the attack uses OpenAI's legitimate notification infrastructure (noreply@tm.openai.com), bypassing email security controls. Attackers research specific employees, attach a real credit card to add legitimacy, and grant invited users Owner privileges. The goal appears to be tricking employees into using the fake workspace as a corporate ChatGPT environment, exposing sensitive data like source code, internal documents, and customer data through AI prompts. The campaign targets cybersecurity and technology firms specifically. Push Security recommends training employees to verify unexpected organization invitations and monitoring SaaS memberships.