TLDRocket
Sign in

Cyber Operation: Phishing and scripting support

OpenAI Covered by 3 sources

OpenAI shut down accounts using ChatGPT to help build phishing emails and scripts. The activity looked linked to Chinese state intelligence targets, not random scammers.

Based on reporting by OpenAI — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

OpenAI's latest threat report reads less like a routine content-policy update and more like a counterintelligence memo. The company says it banned a cluster of accounts whose behavior lined up with publicly documented threat groups, and whose targeting patterns matched what researchers describe as PRC intelligence collection priorities. The overlap wasn't subtle, apparently: the accounts weren't just chatting with the model, they were using it as a workbench for phishing lures and scripting tasks.

That distinction matters. AI models being used to write better-sounding phishing emails is old news at this point, something security teams have expected since large language models went mainstream. What's notable here is the specificity OpenAI is willing to attribute — not just "malicious use," but activity consistent with the operational fingerprints of state-linked groups already known to researchers. Scripting support suggests these operators leaned on the model for automation, not just prose, likely to speed up reconnaissance or payload delivery rather than crafting a single convincing email.

OpenAI has been increasingly public about these takedowns over the past year, part of a broader pattern among AI labs of publishing threat intelligence alongside their usual product announcements. Google, Microsoft, and Anthropic have all done versions of this, disclosing nation-state actors probing their models for offensive utility. It's become a quiet admission that frontier AI tools are now treated by intelligence services the way search engines and social media were a decade ago: infrastructure worth exploiting, not just a novelty to poke at.

What's missing from the disclosure, as usual, is scale. How many accounts, how much traffic, whether any operation actually succeeded downstream — none of that is spelled out. OpenAI's incentive is to show it's vigilant without handing adversaries a roadmap of what got caught and why, which is a defensible position but leaves outside observers guessing at how serious the intrusion attempts actually were.

My take — AI-written commentary, not fact-checked reporting

I'll say what I usually say about these bans: good, but this is a game of whack-a-mole and everyone knows it. State-linked operators will just route through another provider, a jailbroken open model, or their own fine-tuned setup, and the fact that OpenAI can identify PRC-linked patterns at all says more about their detection tooling than about the threat being contained. The real story nobody's telling yet is how much of this shifts to open-weight models nobody's monitoring.

Read more about this at: OpenAI

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.