Calendly redirect feature abused in targeted phishing scam posing as OpenAI employee
Al_Grigor · x · 2026-09-15
A developer, Alexey, detailed a targeted phishing attempt: an account posing as an OpenAI employee named David contacted him about a partnership and sent a genuine Calendly scheduling link. Attackers abused Calendly's post-booking redirect feature—after filling the first form, victims are automatically sent to a lookalike site (calendly.openaiteams.com) asking for X login credentials. The scammer's account was stolen and had reposted OpenAI announcements to look legitimate. Most notably, even in incognito mode the fake page showed "Continue as Alexey," proving the link was personalized per target. An OpenAI contact confirmed no such employee exists. Lesson: verify identities before engaging with unsolicited "partnership" offers and beware third-party redirects in scheduling tools.
Related event: Fake OpenAI Employee Phishing Campaign Spreads via Calendly(2 posts)→
More from Safety
- David Sacks: AI firms should make products safe now, without waiting for regulation — whurley · 2026-09-15
- Critic warns against conflating vibes-based AI risk estimates with empirical likelihoods — merrierm · 2026-09-15
- New arXiv paper invites mathematicians to tackle AI safety, field by field — stevenstrogatz · 2026-09-15
- 'EU-hosted' doesn't tell you who runs the AI: a directory of real European AI providers — Square_Secretary_944 · 2026-09-15
- p(doom) is vibes, not statistics: researcher offers a VET framework for AI discourse — merrierm · 2026-09-15
- FT: UKAISI denied pre-release access to Mythos 5.1, UK MPs warn of security risk — Chris_Brannigan · 2026-09-15