A Capital Cyber practiceLeesburg, Virginia

AI governance

Where does your organization's trust in AI assistants end?

By Cybersecurity Consulting · Published

As of

On October 8, 2026, an IT administrator at a managed service provider reported on Reddit's r/msp forum that a user's ChatGPT conversation displayed a message signed "OpenAI Security Team". It linked to a fake verification page that told the user to paste a command into Windows Terminal. The user tried twice and endpoint protection stopped both attempts. The cause is unknown, and the author does not claim OpenAI was compromised. For leadership, the useful part is the boundary it exposes: staff now act on instructions from AI tools without asking who is accountable for them.

What exactly was reported?

A user asked ChatGPT to turn a PowerPoint into investor material. Partway through, a message in the chat said the service had elevated automated traffic and required a security check, and it linked to a page imitating an OpenAI verification service. That page copied a command to the clipboard and told the user to press Win + X, open Windows Terminal, paste and press Enter.

Endpoint protection ended both attempts, and the security provider found no sign the payload ran. The author lists prompt injection, other manipulation of the conversation and an unsafe response as possible causes and has not established which occurred. As of October 10, 2026 OpenAI has not commented. This is one team's account, so treat the ChatGPT element as unconfirmed.

Is the attack technique new?

No. It is called ClickFix. Proofpoint published a security brief on it in November 2024, and Microsoft documented it in August 2025: a fake verification or error message persuades the victim to paste a command into the Windows Run box or a terminal, and the victim runs the attacker's code personally.

What changed is the delivery channel. The instruction arrived inside an assistant the user already trusts, with the service's own name on it. The control that failed was not technical. It was the assumption that anything inside an approved tool is approved.

What is the AI trust boundary?

It is the line between what an AI tool may tell your people to do and what only your own procedures can authorize. Today most organizations have not drawn it. Staff treat the assistant like a colleague, and a colleague's instruction to complete a security step feels routine.

Draw the line in one sentence that every employee can repeat: no tool, website or message, including an AI assistant, can instruct you to paste a command into a computer. Instructions that change how a machine behaves come from IT through known channels.

What should leadership decide this quarter?

Four decisions, none of them technical. First, which AI tools are approved, for which data, and who may approve a new one. Second, who is accountable when an AI tool is involved in an incident, since the vendor is not. Third, whether a blocked attempt is recorded as a security event, with a named owner for the record. Fourth, whether the endpoint protection that stopped this attempt is deployed on every machine that touches sensitive data, and who watches its alerts.

For a contractor handling Controlled Unclassified Information under DFARS 252.204-7012 and NIST SP 800-171 Rev 2, these decisions belong in the System Security Plan and the incident response plan, so the written program matches what staff actually do.

How do you test the boundary?

Run a short tabletop exercise using this scenario. A message inside an approved tool tells an employee to run a command. Ask who the employee calls, who decides whether it is an incident, who tells the customer or prime if required, and where it is recorded. Gaps in the answers are the findings.

Where are the sources?

Reddit r/msp incident report, October 8, 2026: https://www.reddit.com/r/msp/comments/1x0wtus/a_chatgpt_conversation_directed_a_user_to_a_fake/

Microsoft Security blog, Think before you Click(Fix), August 21, 2025: https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/

Proofpoint, Security Brief: ClickFix Social Engineering Technique Floods Threat Landscape, November 18, 2024: https://www.proofpoint.com/us/blog/threat-insight/security-brief-clickfix-social-engineering-technique-floods-threat-landscape

Engagements

Which engagements cover this?

Questions

What else do readers ask?

Was OpenAI compromised?

Nobody has said so. The author of the report states they are not claiming OpenAI's infrastructure was compromised, and the cause is unknown. OpenAI has not commented as of October 10, 2026.

Should we ban AI assistants?

That is a leadership decision, and a ban is not the only answer. Approving specific tools for specific data, with a clear rule that no tool can instruct staff to run commands, addresses this scenario without losing the productivity.

Who owns the risk when an AI tool is involved in an incident?

The organization does. Decide in advance who is accountable, who makes the incident call and who is told, because the AI vendor will not do any of those for you.

This article is general information about the regulations as written, not legal advice. Read your contract clauses and the regulation text, and take legal advice where the answer matters.

Book a call

Ready to talk it through?

Pick a time for a 30 minute call with the practice.