
Phishing Link Could Plant a Rogue ChatGPT Agent
Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…
Researchers disclosed a flaw in OpenAI ChatGPT Workspace Agents that could let an attacker trick an employee into creating an invisible, attacker-controlled “autonomous agent” inside the company. The attack depends on a phishing message that gets a logged-in user to click a weaponized URL, after which the agent can take instructions from attacker emails and use already-connected apps (like Gmail/Outlook) to act and send results back out.
The flaw, disclosed by Zenity Labs and referred to as AgentForger, targeted ChatGPT Workspace Agents. It relied on getting a logged-in employee to click a single weaponized initialization URL. That link carried parameters selecting a powerful agent template and injecting instructions through an over-permissive prompt parameter, effectively standing up an autonomous agent the victim never intended to create.
Once active, the agent could be remotely controlled by the attacker through ordinary email. Messages with subjects starting with "TASK" were treated as commands. The agent would process these instructions using whatever apps were already connected to the victim's account and email the results back out, all without further interaction from the employee.
The attack depended on a narrow but realistic set of conditions: the victim had to be logged into ChatGPT, have access to Workspace Agents, and already have at least one authorized connector such as Gmail or Outlook. Because that connector was already authorized, creating the new agent did not trigger a fresh OAuth consent screen, removing one of the usual visual cues that something unusual was happening.
This meant the entire compromise hinged on one social engineering moment: getting the employee to click the setup link. After that, the agent operated inside the organization's existing trust boundary, using tools the employee had already approved.
Organizations using ChatGPT Workspace Agents or similar tools connected to email and business apps should treat agent setup links with the same caution as credential phishing links, verifying unexpected requests through a trusted channel before clicking. Security awareness training should expand beyond classic credential theft to cover the idea of a "forged insider," an automated agent granted trust and access without the usual signs of compromise. Teams should also watch for automation that requests unredacted data be sent externally, since this is a strong signal of data exfiltration regardless of whether a human or an AI agent is performing the action.
This attack technique aligns with phishing and social engineering methods described in MITRE ATT&CK, including spearphishing links and user execution via malicious links.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
AgentForger is a flaw disclosed by Zenity Labs in ChatGPT Workspace Agents that could let an attacker trick a logged-in employee into launching an invisible, attacker-controlled autonomous agent with a single phishing click.
No. If the victim already has an authorized connector such as Gmail or Outlook, the agent can be created without triggering a new OAuth consent screen, making the activity harder to notice.
The attacker sends emails with subjects starting with "TASK," which the agent treats as commands, then uses connected apps to carry out the instructions and email results back to the attacker.
Yes. Zenity reported the issue on June 4 and OpenAI fixed it by June 8.
Imagine: one click on a ChatGPT link, and you’ve just hired a secret AI “insider” working for someone else. Zenity found an issue called AgentForger: a weaponized ChatGPT Workspace Agent URL that, once you click it while logged in, silently spins up an autonomous agent using your existing Gmail or Outlook connector, no new consent screen, no warning. Here’s the twist: that hidden agent just waits for emails with subjects starting with “TASK” from the attacker, does exactly what they say using your connected apps, then emails raw, unredacted results back out, like a forged insider living in your tools. If you ever get an email telling you to click a ChatGPT Workspace Agent setup link you didn’t ask for, stop and verify it with the supposed sender over chat or a call before you touch that link.

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…

Zenity Labs described a real phishing-based technique (“AgentForger”) that could silently create an autonomous AI agent inside an OpenAI workspace after a…

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment…

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…