- Fraudsters send emails from legitimate OpenAI addresses to trick users
- Fraudulent organization names hide malicious links designed to obtain sensitive information
- Companies are being targeted because multiple employees can receive malicious invitations at the same time.
Kaspersky has discovered a sophisticated scam that uses the OpenAI team invitation system to attack unsuspecting users.
Scammers register accounts and insert fake links or phone numbers directly into the business name field.
They then use the “Invite Your Team” feature to send emails from real OpenAI addresses, so the messages look completely authentic.
The content of the email is fraudulent.
Kaspersky warns that these emails can easily trick recipients into clicking on malicious links or calling fake numbers, which could lead to serious financial or data loss.
The content of these scam emails varies, but the goals remain the same. Some reports claim that subscriptions have been extended for an unusually large amount, while others advertise fraudulent offers, including adult services.
Kaspersky notes that attackers often combine email and voice tactics, using phishing to get recipients to take immediate action.
The body of these emails often shows structural inconsistencies, but attackers rely on recipients to ignore these irregularities.
Companies are at high risk because attackers can attack multiple employees at the same time.
Kaspersky recommends treating all unwanted invitations with suspicion, even if they appear to come from trusted platforms.
Users should check all URLs carefully before clicking, avoid calling numbers listed in suspicious messages, and report unusual activity to service providers.
Users should enable multi-factor authentication on all accounts to reduce risk, but strong protection also requires technical protection.
Endpoint protection and a robust firewall configuration are critical, and any interaction with fraudulent links requires immediate malware removal.
The attack shows how criminals can turn even trusted collaboration features into fraud tools.
To effectively avoid these threats, organizations and individuals must be vigilant.
“This incident highlights a vulnerability in how platform features can be a weapon for social engineering email attacks. By embedding fraudulent elements in seemingly innocuous fields such as organization names, fraudsters try to bypass traditional email filters and exploit users’ trust in reputable services,” said Anna Lazarichova, senior spam analyst at Kaspersky.
“We encourage all users to check invitations carefully and avoid clicking on unverified embedded links. We advise brands to consider whether their online services or platforms could be abused by attackers.”
Follow TechRadar on Google News I Add us as your preferred source Get news, reviews and opinions from our experts in your feed. Don’t forget to click the follow button!
And, of course, you can Siga TechRadar on TikTok Get our regular updates in the form of news, reviews, unboxing and videos. WhatsApp very

