One Click, One Attacker-Controlled Agentic Insider: Zenity Labs Uncovers ‘AgentForger,’ a ChatGPT Vulnerability
A single link could hijack OpenAI’s ChatGPT Agent Builder to stand up an attacker-controlled AI agent with a real employee’s access and its approvals switched off. Until OpenAI’s fix, any organization using Workspace Agents was exposed.
Zenity Labs today disclosed AgentForger, a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that allowed a single phishing link to silently build, authorize and deploy an autonomous AI agent inside a victim’s organization. All it took was one click. An employee opened a normal-looking ChatGPT link, and without a single confirmation, a new AI agent began running inside their company, answering not to the employee but to an attacker. Rather than stealing one session or one file, as most AI attacks do, AgentForger forged an attacker-controlled, agentic insider that fully inherited the victim’s identity.
The finding highlights a new class of AI security risk in which attackers can create autonomous AI insiders that operate with legitimate employee identity and access.
Once created, the forged agent inherited access to the enterprise applications the employee had already authorized in ChatGPT, including email, calendar, cloud storage, and collaboration tools such as Slack and Teams. It could exfiltrate sensitive data, harvest credentials and MFA tokens, impersonate the employee, and continue operating long after the initial phishing attack. Any organization using ChatGPT Workspace Agents with authorized enterprise connectors was exposed until OpenAI issued its fix.














