News · curated 27 Jun 2026

Cybersecurity firms targeted by fraudulent OpenAI organization invites

Coverage timeline

26 Jun 2026bleepingcomputer.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

Attackers are abusing legitimate AI platform features like organization invites to harvest sensitive corporate data, turning enterprise LLM adoption into a new social-engineering vector.

Threat actors are creating OpenAI tenants impersonating legitimate companies and inviting employees to join them, aiming to trick targets into submitting sensitive company information through chats and projects. Cybersecurity firms have been among those targeted.