That ChatGPT Invite From Your CEO? It's a Trap.
Last week, employees at cybersecurity firm Push Security received email invitations to join their company's ChatGPT workspace. The emails came from OpenAI's legitimate notification address. They passed every email authentication check. They looked exactly like the real thing.
They were attacks.
A threat actor had created a fraudulent OpenAI organization named "Push Security Inc.," populated it with an account impersonating the company's CEO, and sent invitations to employees. Anyone who accepted was immediately granted Owner privileges — full administrative access to a workspace designed to harvest whatever sensitive information they typed into it.
Push Security's VP of R&D, Luke Jennings, accepted one of the invitations to investigate. He found a single attacker-controlled account using a Gmail address, posting as CEO Adam Bateman. The trap was set. All it needed was for someone to start working.
The Problem Isn't the Phishing. It's What People Type Next.
Traditional phishing steals a password or drops malware. This attack — which Push Security has dubbed the "Poisoned Tenant" campaign — is after something far more valuable. On an AI platform, people don't just type queries. They paste source code. They upload internal documents. They share customer data, strategic plans, security research. They use AI the way they used to use a trusted colleague — by telling it everything.
OpenAI does include a warning in the invitation email noting that the inviter's domain doesn't match the recipient's company domain. It's a single line of text, buried in an otherwise legitimate-looking email. In my experience, that kind of fine print might as well not exist.
Your AI Tools Are Your New Attack Surface
This is the conversation I keep having with boards and executive teams, and it's one I wrote about extensively in Cyber Risk Is Business Risk. Every new tool your organization adopts is a new door. AI platforms are particularly dangerous doors because of what walks through them — your most sensitive information, volunteered willingly by employees who think they're just doing their jobs.
Here's what makes this worse: according to the Awareways Trend Report, 59% of employees admit to using AI tools at work that their employer hasn't sanctioned. That's not a fringe behavior — it's the norm. And when employees are already accustomed to using ChatGPT for work, a fraudulent workspace invitation doesn't even raise an eyebrow.
Meanwhile, on the defensive side, attackers are getting creative in ways that should concern every executive investing in AI-powered security. A North Korea-linked macOS malware called "Gaslight," identified by SentinelOne researcher Phil Stokes this week, embeds 38 fabricated system-error messages inside its code — not to crash anything, but to confuse AI-powered malware analysis tools into thinking the sample is corrupted and abandoning their investigation. The technique is called prompt injection, and while SentinelOne reports it hasn't bypassed any production AI analysis platform yet, earlier North Korean samples used a single injected message. Now they're stacking 38. They're testing, iterating, and getting better.
The attackers are adapting to your AI defenses faster than most organizations are deploying them.
Apply the Three Questions
In the book, I talk about the Three Questions framework that every board and executive team should be asking about their cyber risk:
What can go wrong? An attacker creates a lookalike AI workspace for your company. Your employees accept the invitation and start pasting proprietary data into it — code, financials, customer records, strategic plans. Or your AI-powered security tools get fooled by malware specifically designed to exploit them. Both happened this week.
How likely is it? The Poisoned Tenant attack requires almost no technical sophistication. Anyone with a free email account can create an OpenAI organization with any name they want — domain verification is available but not required for basic organization creation. The attacker in this case even attached a Visa credit card to the billing account to add legitimacy. The barrier to entry is remarkably low.
What's the impact? Whatever your employees put into that workspace, the attacker sees. Source code. M&A documents. Security vulnerabilities. Customer PII. The damage scales with how much your people trust AI tools — and right now, that trust is growing faster than the controls around it.
What to Ask Your CISO This Week
If you're a board member or executive reading this, here are four questions to bring to your next security conversation:
- Do we have an inventory of every AI platform our employees are using? Not just the ones IT approved — the ones people signed up for with their work email on a Tuesday afternoon because a colleague recommended it. If you don't know what AI tools are in your environment, you can't secure them.
- What's our policy on joining external AI organizations or workspaces? The Poisoned Tenant attack exploits a gap that most organizations haven't thought about. Your employees may already be members of AI workspaces you don't control.
- Are we monitoring what data flows into AI tools? Data loss prevention for AI platforms isn't optional anymore. If your DLP strategy was designed for email and file shares, it's a generation behind.
- How are we validating that our AI-powered security tools actually work against adversarial techniques? If your security vendor is selling you AI-powered threat detection, ask them specifically how they test against prompt injection and adversarial evasion. "Gaslight" is a proof of concept. The production-grade version is coming.
The Bottom Line
AI adoption isn't slowing down, and it shouldn't. But the security conversation has to keep pace. Right now, most organizations are adopting AI tools faster than they can govern them — and attackers are exploiting that gap from both directions. They're using AI platforms as attack vectors to steal data, and they're designing malware to exploit AI defenses.
The organizations that will weather this are the ones treating AI governance as a board-level priority, not an IT checkbox. If you haven't had that conversation yet, this week's news is your agenda.
