Attackers Exploit OpenAI Invitation System in Tenant-Poisoning Attack
In a tenant-poisoning attack, threat actors create a tenant on a SaaS platform using a company's name and then lure employees into joining through legitimate invitations. Push Security first identified the technique in 2023. With OpenAI's ChatGPT and API now serving as gateways to work, prompts, code, customer data and usage records could be monitored by an administrator if they enter a fraudulent tenant.
Push Security disclosed on June 26, 2026, that attackers had created an OpenAI organization called “Push Security Inc,” impersonated its CEO and sent authenticated invitations from noreply@tm.openai.com. They also linked a Visa card and designated invitees as Owners. The company confirmed that no other employees had joined, found no evidence of data leakage and blocked similar emails.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.