Mark RadarMARK RADAR
EN

Attackers Exploit OpenAI Invitation System in Tenant-Poisoning Attack

1 reports · First detected 2026-06-29 · Last active 2026-06-29

In a tenant-poisoning attack, threat actors create a tenant on a SaaS platform using a company's name and then lure employees into joining through legitimate invitations. Push Security first identified the technique in 2023. With OpenAI's ChatGPT and API now serving as gateways to work, prompts, code, customer data and usage records could be monitored by an administrator if they enter a fraudulent tenant.

Push Security disclosed on June 26, 2026, that attackers had created an OpenAI organization called “Push Security Inc,” impersonated its CEO and sent authenticated invitations from noreply@tm.openai.com. They also linked a Visa card and designated invitees as Owners. The company confirmed that no other employees had joined, found no evidence of data leakage and blocked similar emails.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR