
Phishing Link Could Plant a Rogue ChatGPT Agent
Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…
Researchers say a one-click phishing link could trick ChatGPT into creating a malicious AI “agent” inside a company’s ChatGPT workspace. The agent could act using the employee’s existing access (Outlook, Teams, Slack, Google Drive, etc.), run on a schedule, and take instructions from attacker emails, effectively behaving like an insider account.
Researchers at Zenity Labs identified a flaw, referred to as AgentForger, in which a single click on what looked like an ordinary ChatGPT link could cause ChatGPT's agent builder to create and publish a malicious workspace agent on the attacker's behalf. The link carried embedded instructions that the agent builder accepted without requiring further input from the victim. Once built, the agent could wire itself into the victim's existing connectors, turn off approval prompts, publish itself, and run on a schedule, giving it persistence well beyond the original phishing email.
The technique did not rely on stealing passwords or browser sessions. Instead, it tricked ChatGPT into building an autonomous assistant that could act through the employee's own connected accounts and permissions, including Outlook, Teams, Slack, SharePoint, or Google Drive. Because the agent operated with the victim's real access, its actions looked like legitimate employee activity rather than an external intrusion. The attack also depended on the victim belonging to a workspace where agents were enabled and where they had permission to create them, conditions that are increasingly common as organizations adopt AI productivity tools.
Once active, the rogue agent could be controlled without traditional malware infrastructure. It simply checked the victim's inbox for attacker emails with "TASK" in the subject line, treating each one as a new assignment such as searching company files, collecting sensitive documents, or sending results back by email. The researchers also demonstrated that the agent could send convincing phishing messages through the victim's own Teams account, effectively impersonating the employee to coworkers. Warning signs include unexpected agent creation links, generic command-like email subjects, and outbound messages or file activity that the account owner did not initiate.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Researchers at Zenity Labs found that a ChatGPT link could carry embedded instructions that caused the agent builder to create and publish a new workspace agent after a single click, without further action from the victim.
Once published, the agent could inherit the victim's connected app permissions, such as Outlook, Teams, Slack, SharePoint, or Google Drive, and use them to search files, send messages as the employee, and collect sensitive documents.
Instead of typical command-and-control infrastructure, the agent polled the victim's inbox for emails from the attacker with 'TASK' in the subject line and treated each one as a new assignment.
Yes, the article states OpenAI reportedly fixed the issue quickly by removing the URL parameter that enabled the attack.
Imagine one click on a ChatGPT link quietly creating an AI “insider” that works as you. Zenity calls it AgentForger: one click on what looks like a normal ChatGPT link, and the agent builder secretly wires up your Outlook, Teams, Slack, SharePoint, and Drive, turns off approval prompts, publishes a new agent, and sets it on a schedule. Now that rogue agent just checks your inbox for emails from the attacker with 'TASK' in the subject, then rummages through company files, collects documents, and sends messages as if they came from you. Your move: if you ever get an unexpected link to create or configure a ChatGPT agent, don’t click it, open ChatGPT yourself and confirm in your workspace if that agent is actually needed.

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…

Authorities dismantled “Kratos,” a phishing-as-a-service platform used at scale to steal Microsoft account credentials and even bypass MFA by stealing session…

Zenity Labs described a real phishing-based technique (“AgentForger”) that could silently create an autonomous AI agent inside an OpenAI workspace after a…

Researchers disclosed a flaw in OpenAI ChatGPT Workspace Agents that could let an attacker trick an employee into creating an invisible, attacker-controlled…

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…