OpenAI identified and banned accounts associated with CyberAv3ngers, an Iran-linked threat actor, that were using OpenAI's models to research industrial control systems, default credentials, and potential targets. The action is part of OpenAI's ongoing effort to disrupt malicious uses of its AI platform. This case is notable as an example of state-linked actors leveraging frontier AI for critical infrastructure reconnaissance.
OpenAI identified and banned accounts linked to Iranian influence networks IUVM and STORM-2035 that were using AI to generate articles and social media posts as part of coordinated influence operations. The action represents a cross-platform disruption effort targeting state-linked misuse of AI-generated content. This is a concrete example of AI being weaponized for information operations and of a major lab taking enforcement action against such abuse.
OpenAI identified and banned accounts likely associated with Russian-speaking criminal groups that were using AI to develop malware loaders, evasion layers, credential-theft scripts, and command-and-control infrastructure. The action is part of OpenAI's ongoing effort to disrupt malicious uses of its platform. This case documents a concrete instance of threat actors operationalizing frontier AI for offensive cyber tooling.
OpenAI identified and banned accounts associated with two PRC-attributed threat actors, dubbed Vixen and Keyhole Panda, who were using AI tools to support vulnerability research, scripting, translation, and operational troubleshooting. The disclosure is part of OpenAI's ongoing effort to detect and disrupt malicious uses of its platform by state-linked actors. This is a concrete case of AI being weaponized in nation-state cyber operations.
OpenAI terminated accounts potentially linked to North Korea-affiliated threat actors who were using AI to research intrusion tooling, phishing campaigns, malware development, and cryptocurrency targeting. The action is part of OpenAI's ongoing effort to disrupt malicious uses of its platform by state-affiliated actors. This represents a concrete case of AI being weaponized for offensive cyber operations by a nation-state actor.
OpenAI identified and banned accounts linked to the Iran-affiliated threat actor STORM-0817, which was using OpenAI's models to debug Android malware, scrape social media platforms, and translate offensive tooling. The disclosure is part of OpenAI's ongoing threat intelligence reporting on state-linked misuse of AI systems. This case illustrates concrete adversarial use of frontier AI for cyberoffense and surveillance tooling.
OpenAI identified and banned accounts associated with STORM-2035, a likely Iran-linked influence operation using AI to generate political content targeting audiences in the US, UK, Ireland, and Venezuela. The action is part of OpenAI's ongoing effort to disrupt malicious uses of its AI systems. This represents a concrete case of a frontier AI provider taking enforcement action against state-linked information operations.
OpenAI terminated accounts whose activity overlapped with publicly reported threat groups displaying hallmarks consistent with PRC intelligence requirements. The banned accounts were using AI to support phishing campaigns and scripting workflows. This is part of OpenAI's ongoing effort to detect and disrupt malicious use of its platform by state-affiliated actors.
OpenAI terminated accounts associated with IUVM, an Iran-origin influence operation that used AI tools to generate and translate pro-Iran, anti-Israel, and anti-US website content. The action is part of OpenAI's ongoing effort to disrupt malicious uses of its platform. This case documents a concrete instance of AI-assisted state-linked information operations being detected and disrupted.