Platform Impersonation & SaaS Abuse
Platform Impersonation & SaaS Abuse
Articles on attackers abusing legitimate SaaS and AI platform features — including fraudulent tenant creation, organization impersonation, invitation-system exploitation, and social engineering via trusted platform notification channels.
platform impersonation saas abuseJun 30, 20266 min
The Poisoned Tenant: How Threat Actors Use Fraudulent OpenAI Organizations to Harvest Corporate Secrets
Push Security has uncovered a "Poisoned Tenant" campaign in which threat actors create fraudulent OpenAI tenants impersonating legitimate companies, then invite employees via platform-originated notifications to trick them into submitting sensitive data through ChatGPT prompts and projects.