OpenAI terminated Russian-language accounts that were using its models to develop malware, refine loaders, and troubleshoot offensive cyber tooling. The operation, dubbed 'ScopeCreep,' represents a disclosed enforcement action against AI-assisted malicious cyber activity. This is a concrete case of AI misuse for cyberweapon development being detected and disrupted by a frontier lab.
OpenAI identified and banned accounts likely associated with Russian-speaking criminal groups that were using AI to develop malware loaders, evasion layers, credential-theft scripts, and command-and-control infrastructure. The action is part of OpenAI's ongoing effort to disrupt malicious uses of its platform. This case documents a concrete instance of threat actors operationalizing frontier AI for offensive cyber tooling.
OpenAI identified and banned accounts using its models to support malware development, debugging, phishing, and credential-theft workflows, with the activity conducted in Korean. The disclosure is part of OpenAI's ongoing series of threat-actor disruption reports. This is a concrete example of AI models being weaponized for offensive cyber operations and the countermeasures being applied.
OpenAI identified and banned accounts that were using its AI systems to generate comments criticizing a Russian anti-corruption foundation and associated figures. The operation represents a documented case of AI-enabled influence operations being disrupted by a frontier lab. This is relevant to AI misuse tracking and platform safety enforcement.
OpenAI terminated accounts associated with 'Spamouflage', a PRC-linked covert influence operation that used OpenAI tools to research social media activity, generate posts, and debug a previously unreported website. The action represents OpenAI's enforcement against state-linked misuse of its AI systems for information operations. This is notable as a documented case of a major lab detecting and disrupting foreign influence activity leveraging generative AI.
OpenAI terminated accounts potentially linked to North Korea-affiliated threat actors who were using AI to research intrusion tooling, phishing campaigns, malware development, and cryptocurrency targeting. The action is part of OpenAI's ongoing effort to disrupt malicious uses of its platform by state-affiliated actors. This represents a concrete case of AI being weaponized for offensive cyber operations by a nation-state actor.
OpenAI banned a cluster of accounts linked to a Russia-origin influence operation dubbed 'Stop News,' which used AI tools to generate multilingual articles and social media posts targeting audiences in Ukraine and Western countries. The operation represents a documented case of AI being weaponized for coordinated inauthentic behavior at scale. OpenAI's disclosure is part of its ongoing effort to detect and disrupt malicious uses of its platform.
OpenAI terminated accounts assessed as likely originating from China that were using its AI systems to draft pitches for surveillance tools, analyze documents, and debug related code. The operation, dubbed 'Peer Review,' is part of OpenAI's ongoing effort to disrupt malicious uses of its platform. The case illustrates how AI tools are being leveraged by state-adjacent actors for surveillance infrastructure development.
OpenAI identified and banned accounts associated with online fraud networks that were using its models to generate scam scripts, impersonate individuals, translate content, and engage with victims. The action is part of OpenAI's ongoing effort to disrupt malicious uses of AI. This represents a concrete enforcement case documenting how threat actors are operationalizing LLMs for fraud at scale.