Calendly redirect feature abused in targeted phishing scam posing as OpenAI employee

Al_Grigor · x · 2026-09-15

A developer, Alexey, detailed a targeted phishing attempt: an account posing as an OpenAI employee named David contacted him about a partnership and sent a genuine Calendly scheduling link. Attackers abused Calendly's post-booking redirect feature—after filling the first form, victims are automatically sent to a lookalike site (calendly.openaiteams.com) asking for X login credentials. The scammer's account was stolen and had reposted OpenAI announcements to look legitimate. Most notably, even in incognito mode the fake page showed "Continue as Alexey," proving the link was personalized per target. An OpenAI contact confirmed no such employee exists. Lesson: verify identities before engaging with unsolicited "partnership" offers and beware third-party redirects in scheduling tools.

Related event: Fake OpenAI Employee Phishing Campaign Spreads via Calendly(2 posts)→

Original post →

More from Safety

Safety channel →