Threat actors are abusing legitimate email and collaboration workflows to make social-engineering lures appear trustworthy. A reported campaign weaponizes OpenAI’s “invite your team” feature by placing malicious URLs or scam phone numbers in the organization name field, causing invitations to be sent from legitimate OpenAI email infrastructure and increasing the likelihood recipients will click links or call attacker-controlled numbers; the approach is particularly effective against businesses because a single invite workflow can target multiple employees.
Separately, consumers are being targeted by a seasonal surge of tax-refund/back-tax impersonation scams delivered via SMS and email that direct victims to malicious links or fraudulent call centers to “verify” identity—harvesting SSNs and banking details for identity theft and refund fraud. Compounding the broader email-risk environment, Gmail’s spam filtering and tab categorization reportedly malfunctioned at large scale, pushing promotional mail into Primary inboxes and flagging legitimate senders with warnings; such misclassification can increase exposure to phishing by reducing the effectiveness of inbox triage and user trust signals during active scam waves.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
By 2026-01-26, researchers reported a scam campaign exploiting OpenAI's team invitation workflow to send phishing-style emails from legitimate OpenAI infrastructure, using malicious links or scam phone numbers embedded in organization names.
By 2026-01-26, tax authorities and the FTC were warning consumers about a surge in tax-season scams using texts and emails impersonating the IRS and state tax agencies to steal personal and financial information.
Google later announced the Gmail issue was fixed at 9:55 a.m. Pacific time on 2026-01-24, while warning that residual effects could continue as systems recovered.
Google acknowledged the Gmail filtering problem on its official status dashboard on 2026-01-24 and said it was actively working to resolve the incident.
On 2026-01-24, Gmail's spam filtering and inbox categorization systems reportedly malfunctioned, causing promotional and social emails to land in Primary inboxes and some legitimate messages to be flagged with suspicious security warnings for users globally.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcescworld.com
Open sourcescworld.com
Open sourcetechrepublic.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.