Scammers exploit OpenAI's official email infrastructure for phishing attacks

kieranklaassen · x · 2026-08-29

A sophisticated phishing exploit uses OpenAI's official email infrastructure. Attackers create an org like "OpenAI x X Partnership" and manipulate HTML to hide the real header, using whitespace to truncate the official body in Gmail. Users click the fake link at the top and get scammed. Disclosure sent to OpenAI.

Original post →

More from Safety

Safety channel →