OpenAI identified and banned accounts linked to the Iran-affiliated threat actor STORM-0817, which was using OpenAI's models to debug Android malware, scrape social media platforms, and translate offensive tooling. The disclosure is part of OpenAI's ongoing threat intelligence reporting on state-linked misuse of AI systems. This case illustrates concrete adversarial use of frontier AI for cyberoffense and surveillance tooling.
OpenAI identified and banned accounts associated with STORM-2035, a likely Iran-linked influence operation using AI to generate political content targeting audiences in the US, UK, Ireland, and Venezuela. The action is part of OpenAI's ongoing effort to disrupt malicious uses of its AI systems. This represents a concrete case of a frontier AI provider taking enforcement action against state-linked information operations.
OpenAI identified and banned accounts linked to Iranian influence networks IUVM and STORM-2035 that were using AI to generate articles and social media posts as part of coordinated influence operations. The action represents a cross-platform disruption effort targeting state-linked misuse of AI-generated content. This is a concrete example of AI being weaponized for information operations and of a major lab taking enforcement action against such abuse.
OpenAI identified and banned a cluster of accounts linked to an Iran-origin influence operation designated STORM-2035, which used AI to generate election-related content targeting US and UK audiences. The content was distributed across multiple sites as part of a coordinated influence campaign. This is a concrete case of AI-enabled information operations being disrupted by a frontier lab.
OpenAI identified and banned accounts likely associated with Russian-speaking criminal groups that were using AI to develop malware loaders, evasion layers, credential-theft scripts, and command-and-control infrastructure. The action is part of OpenAI's ongoing effort to disrupt malicious uses of its platform. This case documents a concrete instance of threat actors operationalizing frontier AI for offensive cyber tooling.
OpenAI identified and banned accounts associated with CyberAv3ngers, an Iran-linked threat actor, that were using OpenAI's models to research industrial control systems, default credentials, and potential targets. The action is part of OpenAI's ongoing effort to disrupt malicious uses of its AI platform. This case is notable as an example of state-linked actors leveraging frontier AI for critical infrastructure reconnaissance.
OpenAI identified and banned accounts using its models to support malware development, debugging, phishing, and credential-theft workflows, with the activity conducted in Korean. The disclosure is part of OpenAI's ongoing series of threat-actor disruption reports. This is a concrete example of AI models being weaponized for offensive cyber operations and the countermeasures being applied.
OpenAI terminated accounts potentially linked to North Korea-affiliated threat actors who were using AI to research intrusion tooling, phishing campaigns, malware development, and cryptocurrency targeting. The action is part of OpenAI's ongoing effort to disrupt malicious uses of its platform by state-affiliated actors. This represents a concrete case of AI being weaponized for offensive cyber operations by a nation-state actor.
OpenAI terminated Russian-language accounts that were using its models to develop malware, refine loaders, and troubleshoot offensive cyber tooling. The operation, dubbed 'ScopeCreep,' represents a disclosed enforcement action against AI-assisted malicious cyber activity. This is a concrete case of AI misuse for cyberweapon development being detected and disrupted by a frontier lab.