Hackers Pose as OpenAI Employees Using Stolen X Accounts to Phish via Calendly Links
Al_Grigor · x · 2026-09-15
A warning is circulating about a phishing campaign: attackers take over legitimate X accounts, impersonate OpenAI employees, and use the stolen account's follower count and reposted official announcements to appear credible, then send Calendly links that likely aim to hijack more X accounts.
- Multiple users, including @tunguz, report being approached by fake OpenAI staff
- The account and link were reported to X and Calendly
- The poster calls on OpenAI to publicly warn users
Verify identities before clicking meeting links from anyone claiming to be AI company staff.
Related event: Fake OpenAI Employee Phishing Campaign Spreads via Calendly(2 posts)→
More from Safety
- Human attacker hits machine-speed exploitation of Marimo RCE, pivots in 8 seconds — ChuckDBrooks · 2026-09-15
- Google GTIG: threat actors steal model weights, API keys and hijack cloud AI workloads — ChuckDBrooks · 2026-09-15
- AI Overview auto-applies the 'creative writing' jailbreak, researcher shows — conitzer · 2026-09-15
- Lina Khan and David Sacks on their unlikely AI consensus — ambaonadventure · 2026-09-15
- ZDI discloses Linux kernel clsact qdisc UAF local privilege escalation bug, CVE-2026-23413 — sh4dy_0011 · 2026-09-15
- PNAS study: hidden AI instructions shift users toward worse options by 38 points yet stay rated helpful — ValerioCapraro · 2026-09-15