Timeline

OpenAI publishes 'Disrupting malicious uses of AI: June 2025'

OpenAI said it had banned accounts behind ten operations, including Chinese-linked cyber-espionage and North Korean fake-job schemes, using ChatGPT.

  • Security & misuse
  • Minor

OpenAI published the third in a periodic series of reports on abuse of its models, describing ten operations it said it had detected and banned since its previous disclosure three months earlier. The report continued a pattern of naming and disrupting state-linked and criminal misuse of ChatGPT rather than treating such cases as isolated incidents.

The operations spanned several countries. Four cases were linked to China, including social-engineering and cyber-espionage activity OpenAI codenamed “Keyhole Panda” and “ScopeCreep.” Russian and Iranian-linked accounts, in operations named “Sneer Review” and “High Five,” used the models to draft propaganda for covert influence campaigns. Cambodian and Philippine-based networks used ChatGPT to generate scam messaging and comment-spam at scale, while a further cluster of accounts, consistent with tactics OpenAI associated with North Korea, drafted fabricated résumés and interview answers in an apparent scheme to place workers inside Western companies under false identities.

OpenAI said investigators identified the activity from usage patterns — unusual prompt phrasing and repeated sequences — rather than the content of individual outputs, and used its own models to help analysts sift logs at scale. The report was one of several such disclosures during 2025 by both OpenAI and Anthropic documenting the industrialisation of scam and influence operations built on commercial chatbots, part of an emerging norm of publishing periodic threat-intelligence findings rather than responding only when reporters surfaced abuse independently.