Beware, hackers have hijacked OpenAI’s ‘invite your team’ feature to break into your business

  • Fraudsters send emails from legitimate OpenAI addresses to trick users
  • Deceptive organization names hide malicious links designed to capture sensitive information
  • Businesses are targeted because multiple employees can receive malicious invitations simultaneously

Kaspersky has uncovered a sophisticated scam which exploits OpenAI’s team invitation system to attack unsuspecting users.

Fraudsters register accounts and embed deceptive links or phone numbers directly into the organization name field.

They then use the “invite your team” feature to send emails from legitimate OpenAI addresses, making the messages appear fully authentic.

Email contents are deceptive

Kaspersky warns these emails can easily trick recipients into clicking malicious links or calling fraudulent numbers, potentially causing serious data or financial losses.

The content of these scam emails varies, but the goals remain consistent. Some messages claim that a subscription has been renewed for an unusually large sum, while others promote fraudulent offers, including adult services.

Kaspersky notes attackers often combine email and voice tactics, using vishing to pressure recipients into acting immediately.

The text in these emails frequently shows structural inconsistencies, yet attackers rely on recipients overlooking these irregularities.

Businesses face higher risk because attackers can target multiple employees at the same time.

Kaspersky recommends treating all unsolicited invitations with suspicion, even when they appear to come from trusted platforms.

Users should carefully inspect all URLs before clicking, avoid calling numbers included in suspicious messages, and report unusual activity to the service provider.

Users should enable multi-factor authentication across all accounts to reduce risk, but stronger protection also requires technical defenses.

Endpoint protection and strong firewall setups remain essential, and immediate malware removal is necessary if any interaction with a scam link occurs.

The attack shows how criminals can turn even trusted collaboration features into tools for fraud.

To avoid these threats effectively, organizations and individuals must remain vigilant.

“This case highlights a vulnerability in how platform features can be weaponized for social engineering email attacks. By embedding deceptive elements in seemingly innocuous fields like organization names, scammers attempt to bypass traditional email filters and exploit user trust in reputable services,” said Anna Lazaricheva, senior spam analyst at Kaspersky.

“We urge all users to verify invitations carefully and avoid clicking embedded links without scrutiny. We also recommend that brands consider whether attackers could abuse their online services or platforms.”

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

Live Nation’s monopoly trial is reportedly fracturing Trump’s Justice Department

Live Nation executives have reportedly sidestepped the Justice Department's antitrust division to negotiate directly with more sympathetic senior officials in the hopes of avoiding...

HBO Max is finally launching in the UK next month

Warner Bros. Discovery has announced that streaming service HBO Max will make its long-awaited debut in the UK and Ireland on March 26th, having...

Animal Crossing started life as a dungeon crawler

Despite the convoluted journey between concept and finished product, despite all the many things that change between initial prototype and whatever ends up in...

PlayStation’s next big games showcase is on February 12th

Nintendo and Xbox each had their turn, and now PlayStation is up. Sony just announced its next big State of Play showcase, which will...

Discord will require a face scan or ID for full access next month

Discord announced on Monday that it's rolling out age verification on its platform globally starting next month, when it will automatically set all users'...

OpenAI will reportedly start testing ads in ChatGPT today

OpenAI plans to start testing ads in ChatGPT today, according to a report from CNBC. The "clearly labeled" ads will appear in a separate...

Siemens CEO Roland Busch’s mission to automate everything

Today, I’m talking with Roland Busch, who is the CEO of Siemens. Siemens is one of those absolutely giant, extremely important, but fairly opaque companies...

YouTube TV’s sports-focused package will cost $64.99 / month

YouTube TV has shared more details about the custom channel packages it will start rolling out this week. The new packages are cheaper than...

Linux 6.19 arrives with a teaser for Linux 7.0

Fedora systems like this one running Linux kernel 6.17 could soon get an update. | Image: Stevie Bonifield / The Verge On Sunday, Linux developer...

Leaked specs for Sony’s next flagship wireless earbuds reveal ANC upgrades

It’s been two-and-a-half years since Sony last upgraded its flagship ANC earbuds. | Image: The Walkman Blog Following images of Sony's new WF-1000XM6 earbuds shared by...