# Fraudulent OpenAI Tenants Target Cybersecurity Firms in "Poisoned Tenant" Campaign


Threat actors are exploiting OpenAI's legitimate infrastructure to create fake organizational workspaces that impersonate well-known cybersecurity companies, inviting employees to join with the goal of harvesting sensitive corporate data. The campaign, dubbed "Poisoned Tenant" by security researchers at Push Security, represents a sophisticated social engineering attack that leverages the trust users place in official platform invitations to bypass traditional email security controls.


## The Threat: OpenAI Organizations as Attack Vector


Cybersecurity and technology companies have become the target of a coordinated campaign designed to trick employees into joining fraudulent ChatGPT organizational workspaces. Attackers create OpenAI tenants using non-corporate email addresses—typically Gmail accounts—that mimic legitimate company branding and invite specific employees to join using their work email addresses.


Key characteristics of the attack:


  • Invitations originate from OpenAI's legitimate notification address (noreply@tm.openai.com)
  • Emails pass standard authentication checks (SPF, DKIM, DMARC)
  • Invites are formatted identically to genuine OpenAI organization invitations
  • Targeted employees receive administrative-level (Owner) privileges upon joining
  • A fraudulent billing account with an attached Visa card adds apparent legitimacy
  • Multiple cybersecurity firms have reported receiving similar invitations

  • The sophistication lies not in technical complexity but in understanding how employees evaluate trust signals. Because the email originates from OpenAI's actual infrastructure, it bypasses many email security filters that would flag external phishing attempts.


    ## Background and Context: Discovery at Push Security


    Push Security discovered the campaign after multiple employees received invitations to join an OpenAI organization falsely claiming to be "Push Security Inc." While the invitations were technically sent through legitimate OpenAI channels, the underlying organization had been created by an attacker using personal Gmail addresses rather than corporate infrastructure.


    Luke Jennings, Vice President of Research & Development at Push Security, decided to accept one of the fraudulent invitations to investigate the attack's true objective. Upon joining, he found:


  • A single attacker-controlled account posting as the company's CEO, Adam Bateman
  • No existing chats, projects, or collaborative content
  • Owner-level permissions assigned to all invited employees
  • A Visa credit card already attached to the organization's billing account
  • Pending invitations to other targeted employees

  • Push Security has since confirmed that other cybersecurity and technology firms have experienced identical attacks, suggesting a coordinated campaign rather than isolated incidents.


    ## Technical Details: How the Attack Works


    The attack exploits the fundamental mechanics of SaaS platform invitations and the psychology of organizational trust. Unlike traditional phishing emails, which originate from external addresses and often contain suspicious links or requests, the "Poisoned Tenant" campaign uses OpenAI's legitimate infrastructure to deliver invitations that appear authentic.


    | Attack Element | Details | Significance |

    |---|---|---|

    | Email Source | noreply@tm.openai.com (official OpenAI notification address) | Passes authentication checks; appears in employee inbox as legitimate |

    | Impersonation | Company name (e.g., "Push Security Inc.") in organization title | Matches expected correspondence |

    | Account Creation | Gmail addresses rather than corporate domains | Keeps attacker anonymous; won't trigger domain verification tools |

    | Permissions | Owner-level privileges granted to invited employees | Provides administrative access; removes suspicion |

    | Payment Method | Valid Visa card attached to billing account | Eliminates concerns about fraudulent or abandoned accounts |


    The invitation emails include a subtle warning stating that the inviter's email domain does not match the recipient's company domain. However, this warning appears as a single line within the larger, legitimate-looking invitation email and is easily overlooked by busy employees—precisely as the attacker likely intended.


    Once employees accept the invitation, they have full administrative control over the fraudulent organization, including the ability to view other pending invitations and confirm which colleagues may also be targeted.


    ## The Objective: Data Harvesting at Scale


    While the immediate goal of the campaign remains unclear, Push Security's analysis suggests the attackers are attempting to establish fake corporate platforms designed to harvest sensitive information through chatbot interactions. Unlike generic phishing schemes, this campaign demonstrates deliberate targeting and resource investment:


  • Research: Attackers identified specific employees and obtained their work email addresses
  • Legitimacy signals: Attached a valid Visa card to suggest an established, funded operation
  • Naming precision: Created organizations with exact company names rather than generic templates
  • Privilege assignment: Granted administrative access to lower employee suspicion

  • Push Security noted: *"An attacker who just wants to spray scam content through a trusted email channel doesn't name the organization after their target, research individual employees, or attach a credit card. That investment only pays off if employees actually join the organization and start using it."*


    The actual danger lies in what employees might share once inside a workspace they believe is corporate-controlled. AI platform prompts often contain extraordinarily sensitive information: source code repositories, internal documentation, customer databases, security research findings, and strategic business plans. Employees accustomed to using ChatGPT for work tasks might naturally assume a company-branded workspace is an appropriate place to discuss confidential matters.


    ## Implications: A Broader Trend of SaaS Abuse


    The "Poisoned Tenant" campaign reflects a growing pattern of attackers exploiting legitimate invitation and notification features built into popular SaaS platforms. Unlike traditional phishing, which relies on convincing users to click malicious links or download attachments, this approach weaponizes the platforms themselves.


    Why this attack vector is particularly dangerous:


  • Platform trust: Invitations originating from official SaaS infrastructure are less likely to trigger suspicion than external emails
  • Email security bypass: Standard email security filters allow invitations from legitimate platform addresses
  • Organizational psychology: Employees expect to receive organizational invitations and join workspaces regularly
  • Data sensitivity: AI platforms are increasingly used for sensitive business discussions
  • Attribution difficulty: Attackers remain anonymous behind fake organizations

  • Organizations across all industries—not just cybersecurity firms—should recognize that their employees may receive similar invitations for other platforms: Slack organizations, GitHub teams, Microsoft Teams workspaces, or Notion databases.


    ## Recommendations: Defense and Detection


    Organizations can reduce the risk of falling victim to "Poisoned Tenant" attacks through a combination of technical controls and employee awareness:


    For security teams:


  • Monitor for suspicious organizational creation across SaaS platforms used by your company
  • Implement strict identity verification policies before granting administrative access to new organizational accounts
  • Log and audit all invitation acceptance events, particularly those granting high-level permissions
  • Maintain an up-to-date inventory of legitimate corporate tenants and shared workspaces
  • Configure email security controls to flag invitations from external users claiming company affiliation

  • For employees:


  • Verify unexpected organizational invitations through independent channels (company Slack, IT helpdesk) before accepting
  • Check the inviter's email domain closely—look for mismatches between the sender and organization name
  • Be cautious when granting administrative permissions, especially from unfamiliar accounts
  • Avoid sharing sensitive information in organizational workspaces until verifying legitimacy through IT
  • Report suspicious invitations immediately to your security team

  • For SaaS platforms:


  • Implement additional verification steps when creating organizations with names resembling existing companies
  • Require corporate email domain verification before granting administrative access to new users
  • Display domain mismatch warnings more prominently in invitation emails
  • Implement rate limiting on organization creation to slow large-scale impersonation campaigns

  • ---


    ## HackWire Analysis


    The "Poisoned Tenant" campaign exposes a fundamental vulnerability in how modern security architecture treats platform notifications: we've trained employees to trust email from SaaS providers implicitly, and attackers have adapted to exploit that trust.


    What makes this campaign particularly noteworthy is that it specifically targets the cybersecurity industry—organizations whose employees should theoretically be most skeptical of such attacks. Yet the sophistication lies not in evading technical controls but in understanding human psychology. A warning message buried in a legitimate-looking email from OpenAI is cognitive noise. The attacker's investment in research, targeting precision, and even attaching a real payment method signals that they understand their audience expects legitimacy signals.


    The broader implication is that the attack surface has fundamentally shifted. We've spent two decades securing perimeter defenses—firewalls, email filters, endpoint protection—only to discover that the most dangerous invitations come through the front door, signed with the platform's official seal.


    This also represents a strategic shift in how attackers think about data theft. Rather than attempting to steal credentials or inject malware, they're creating dedicated environments where victims willingly submit sensitive information, believing they're using authorized tools. It's the intellectual ancestor of business email compromise but with the platform's own infrastructure doing the heavy lifting.


    The immediate concern is that this technique will proliferate across other platforms. Every SaaS tool that sends organizational invitations—Slack, GitHub, Notion, Asana, Monday.com—becomes a potential attack vector. We can expect rapid iteration as attackers refine targeting and develop context-specific lures.


    Defenders should recognize that user training alone won't solve this. Employees cannot be expected to verify every organizational invitation through alternative channels, nor should they bear full responsibility for authenticating their own tools. This requires platform-level mitigations: stronger verification for new organizations, more prominent warnings about domain mismatches, and better logging for incident investigation. Until those arrive, assume your organization is already on these attack lists and structure your email security and user onboarding policies accordingly.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Policy](https://www.hackwire.news/category/policy) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)