Affected PlatformOpenAI ChatGPT Free, Plus, Team, and Enterprise Accounts
Records ExposedThis is an active ongoing harvesting technique rather than a single breach event
Data Types At RiskAI prompt content, uploaded files, API call metadata, pasted credentials, customer and employee personal data
StatusActiveExploitation confirmed by Push Security researchers
Identity Risk LevelElevated
Push Security researchers have identified an active campaign in which attackers create fake OpenAI organizations that impersonate real companies, then invite employees to join using OpenAI’s own legitimate invitation system.
Once an employee accepts the invite, every prompt, uploaded document, and API request that employee submits inside that organization becomes visible to the attacker who created it.
In the case Push Security documented, attackers built an organization named “Push Security Inc” to target employees of the real Push Security, using company branding and executive impersonation to make the invitation appear routine.
Why These Invitation Emails Pass Every Standard Security Check
The invitations are not spoofed and do not originate from attacker-controlled infrastructure. OpenAI’s own notification system sends them from the address noreply@tm.openai.com, which means the messages pass SPF, DKIM, and DMARC authentication because they are, technically, genuine OpenAI emails carrying attacker-defined organization names.
Standard email security tools that flag spoofed domains or malicious links find nothing to detect, since the sender domain is legitimate and no malicious URL is present anywhere in the message.
The single visible warning sign is a small footer notice stating that the inviting organization’s domain does not match the recipient’s corporate email domain, a detail that is easy to miss inside an otherwise convincing message referencing real company names and branding.
Accepting the Invite Requires One Click and No Additional Verification
Push Security confirmed that joining the fake organization requires a single click on the invitation link, with no multi-factor authentication challenge, no re-login requirement, and no secondary verification step of any kind. Even from a completely fresh browser session with no prior OpenAI login history, clicking the invite immediately links the account to the attacker-controlled organization.
Attackers reinforce the illusion of legitimacy by naming a real company executive as the inviter and by granting every invited user Owner-level privileges with full administrative control over the fake workspace. A valid credit card had also been added to the fraudulent organization, a detail Push Security believes exists specifically to unlock paid ChatGPT features and remove any friction that might cause an employee to question the organization’s authenticity.
Attackers Are Not After Passwords, They Are Harvesting Ongoing Work Activity
Unlike a conventional data breach that exposes a fixed set of stolen records, this technique captures data continuously for as long as an employee keeps using the poisoned organization for daily work. Prompt content submitted inside the fake tenant frequently contains customer names, financial figures, medical details, or confidential internal strategy discussions that employees would never paste into an unsecured public channel.
Don’t Let Cybercriminals Turn You Into a Bestseller.
Enter your email below to scan for any breaches or leaks on the dark web instantly.
Uploaded files inside the organization can include contracts, spreadsheets, source code repositories exported as text, and internal security reports. API usage logged inside the tenant can expose which production systems an engineering team is actively calling.
Employees debugging code frequently paste API keys, database connection strings, and authentication tokens directly into ChatGPT prompts, all of which become visible to the attacker controlling the organization.
Human resources and finance teams working inside the poisoned tenant risk exposing employee records, payroll data, and other regulated personal information.
The Eight-Step Sequence Attackers Follow From Setup to Data Harvesting
The attack chain requires minimal infrastructure and relies almost entirely on OpenAI’s own legitimate systems to execute. First, the attacker creates a fake OpenAI organization branded with the target company’s actual name. Second, the attacker adds a valid credit card to the organization to unlock paid features and avoid triggering suspicion. Third, the attacker configures the invite to display a real company executive as the sender.
Fourth, OpenAI’s legitimate notification system delivers the invitation from noreply@tm.openai.com, which passes every standard email authentication check. Fifth, the targeted employee clicks accept, with no re-authentication or multi-factor prompt required at any point.
Sixth, the employee becomes a member of the attacker’s organization with Owner-level administrative privileges. Seventh, every prompt, upload, and API call the employee makes inside that organization becomes visible to the attacker.
Eighth, if the tenant is connected to third-party integrations such as Gmail, Google Drive, GitHub, or Slack, attackers can attempt OAuth abuse or lateral movement into those connected services.
This technique extends the poisoned tenant concept first documented in 2023 into a new context where AI platforms now function as core enterprise productivity infrastructure, making the captured data considerably more valuable than earlier poisoned tenant campaigns targeting less sensitive SaaS tools.
Any Company Whose Employees Use ChatGPT Is a Potential Target
This is not a targeted attack limited to a single organization. The technique is repeatable against any company whose employees can be identified through LinkedIn, public directories, or company websites, since the attacker only needs a company name and a plausible executive identity to construct a convincing fake organization.
Developers, security researchers, executives, human resources staff, legal teams, and customer support employees carry the highest individual risk because their daily ChatGPT usage tends to involve the most sensitive categories of data. Customers, patients, and other third parties whose information is discussed inside a poisoned tenant face exposure risk even though they themselves never interact with ChatGPT directly.
Prompt Data Harvested This Way Enables More Severe Identity Fraud Than Typical Breach Data
Data captured directly from an active prompt carries higher fraud value than data pulled from a static breach dump, because the attacker sees information at the exact moment an employee is actively working with it, often in its most sensitive and unredacted form.
Full names, dates of birth, and Social Security numbers pasted into human resources or finance prompts create direct exposure to synthetic identity fraud, a scheme in which criminals combine real personal details with fabricated information to open fraudulent accounts. Passwords and API keys pasted during debugging sessions enable direct credential stuffing attacks against other corporate systems and account takeover attempts against connected services.
Leaked executive communications and internal project names give attackers the specific details needed to craft convincing business email compromise attempts and targeted spear phishing campaigns against colleagues. Regulated data such as W-2 forms or insurance records pasted into prompts creates direct exposure to tax fraud and medical identity theft.
Steps Employees and Security Teams Should Take Within the First 24 Hours
Every employee should audit their OpenAI organization memberships immediately at platform.openai.com/settings/organization and inside the ChatGPT application settings menu. Any organization membership that is not recognized or was not explicitly requested should be left immediately using the account settings interface.
Suspicious invitations should be reported directly to OpenAI so the fraudulent organization can be investigated and removed. Any credentials, API keys, or authentication tokens that may have been pasted into ChatGPT during a period of uncertain tenant membership should be rotated immediately, regardless of whether exposure has been confirmed.
Steps to Take During the First Week Following Discovery
Security teams should review ChatGPT chat history for any sensitive data shared while the account may have been linked to an unrecognized organization. If customer or employee personal data may have been exposed during that period, affected individuals should be notified in accordance with applicable data breach disclosure requirements.
Organizations with access to OpenAI’s enterprise tier should enable single sign on authentication, since SSO configuration blocks external tenant joins and prevents this specific attack vector entirely. Any API keys tied to a potentially compromised account should be revoked and reissued rather than simply rotated, to ensure the old key cannot be used even if it was already copied by an attacker.
How PureVPN Identity Protection Addresses This Specific Exposure Route
PureVPN Identity Protection runs continuous dark web monitoring across breach dumps, criminal marketplaces, and paste sites, which means a user’s email address, Social Security number, or financial details are flagged the moment they surface in a leak, including data harvested through AI platform abuse techniques like this one.
div class=”dark-web-scanner-wrapper”>
Don’t Let Cybercriminals Turn You Into a Bestseller.
Enter your email below to scan for any breaches or leaks on the dark web instantly.
Real time breach alerts notify users immediately when their information appears in a new incident rather than requiring them to check manually. Credit monitoring tracks new account openings and credit inquiries tied to a user’s identity, which is the specific fraud outcome that synthetic identity schemes using leaked Social Security numbers and dates of birth are designed to produce.
Personal information tracking across the surface web, deep web, and dark web gives affected employees and companies a measurable head start on freezing credit, rotating credentials, and shutting down fraudulent activity before financial damage occurs.
Indicators Security Teams Can Use to Detect This Specific Technique
This is OpenAI’s genuine notification address and cannot be blocked without disabling legitimate OpenAI emails entirely
Organization naming pattern
Organization name matches the target company’s real name
This is the core social engineering mechanism that makes the invite appear routine
Domain mismatch footer
Small notice stating the inviter’s domain does not match the recipient’s domain
This is the only user facing warning OpenAI currently displays
Inviter identity
Name of a real company executive used as the sender
Should be cross checked against the company directory before any invite is accepted
Privilege level granted
Owner or full administrative access
External invitations should never carry this privilege level and should be treated as a red flag on sight
This Technique Reflects a Broader Pattern of Trusted SaaS Platforms Being Weaponized
Security researchers at Kaspersky and Cisco Talos have documented similar notification abuse patterns across OpenAI, GitHub, and Jira, in which attackers embed malicious content or fraudulent organizational structures inside platform generated notifications that originate from legitimate, high reputation sending domains. The previously disclosed LLMShare campaign used ChatGPT itself as a distribution mechanism for malware, demonstrating that AI platforms are now being treated by attackers as core infrastructure rather than peripheral tools.
Because these notifications rely on sender reputation that email security systems are specifically designed to trust, traditional indicators such as spoofed domains or malicious links are absent, and the same technique is likely to expand to other AI platforms as their enterprise workspace features continue to mature.