Sophisticated phishing exploit abuses OpenAI's verified domain to target users

altryne · x · 2026-08-26

Security researchers uncovered a sophisticated phishing attack exploiting OpenAI's systems. Emails were sent from the verified domain [email protected] with a blue checkmark, making them appear legitimate. The scam directed users to a fake login portal (authportal.co). Users also received deceptive iOS app notifications, which further enhanced the attack's credibility.

Related event: Phishers Abuse OpenAI's Verified Domain to Target Users(3 posts)→

Original post →

More from Safety

Safety channel →