Malicious Custom GPT Phishing: What Businesses Should Know

Malicious Custom GPT Phishing Attempt Shows Why AI Security Must Extend Beyond the Platform

October 9, 2026

As businesses become more comfortable using artificial intelligence, cybercriminals are testing ways to take advantage of the trust users place in those tools.

A recent security incident involving a malicious Custom GPT offers a useful example — and an important reminder that responsible AI adoption requires more than trusting the platform itself.

In the incident, a user interacting with a Custom GPT was directed to a malicious Google Sites URL presented as a “backup” website. The interaction then attempted to persuade the user to execute commands that could install remote-access malware.

The investigation determined that the activity occurred within a Custom GPT rather than standard ChatGPT, with no evidence that the ChatGPT platform itself had been compromised.

The incident aligns with a broader malicious Custom GPT campaign documented in September 2026. At least 40 related incidents were investigated, and identified malicious GPTs were removed. The appearance of additional malicious instances, however, reinforces an important lesson for businesses adopting AI.

Phishing is expanding beyond the inbox

Most employees have been taught to be cautious about an unexpected email link. The same behavior now needs to extend to AI interactions.

An AI assistant can feel more trustworthy than an unsolicited email because the user intentionally opened the application and initiated the conversation. Attackers can try to exploit that trust.

That makes several familiar security habits newly relevant: question unexpected links, verify unusual instructions, and do not execute commands or install software simply because an AI interaction recommends doing so.

AI platform security is only one layer

Technology providers have an important role in identifying and removing malicious content. But businesses should not depend exclusively on platform-level safeguards.

A practical AI security strategy should combine:

  • Endpoint security capable of detecting or limiting malicious activity.
  • Appropriate identity and access controls.
  • Employee security awareness that includes AI-specific scenarios.
  • Clear policies covering approved AI tools and custom agents.
  • Monitoring and incident-response processes.
  • AI governance that defines ownership, acceptable use, and escalation.

These controls are useful because security doesn’t depend on every employee making the perfect decision every time.

What business leaders should do next

This incident should not be a reason to retreat from AI. It is a reason to mature the way AI is adopted.

Leadership should know which AI platforms employees are using, what information is appropriate to share with them, which custom agents are approved, and what employees should do when an AI interaction asks them to leave the platform, download something, provide credentials, or execute a command.

It is also worth updating security awareness training. If training only teaches employees how to recognize suspicious emails, it is increasingly incomplete.

AI is becoming another part of the workplace. Security practices need to follow it there.

At amshot, we believe responsible AI adoption starts with the business outcome and adds the governance, security, and practical guidance people need to use the technology with confidence. If your organization is expanding its use of AI, this is a good time to review whether your security and employee guidance have expanded with it.

Book a Consultation

Blog IT Archives

Tag Cloud