WorkOctober 1, 2025via OpenAI Blog
Cyber Operation: Phishing and scripting support
Why it matters
AI is becoming an operational tool for nation-state cyber campaigns. OpenAI's enforcement action signals both the scale of the threat and the platform's role as a geopolitical chokepoint — practitioners need to understand how their tools are being weaponized and what platform accountability looks like.
Key signals
- OpenAI disrupted accounts linked to PRC intelligence requirements
- Accounts used AI for phishing and scripting workflows
- Activity overlapped with publicly reported threat groups
- October 1, 2025 enforcement action
- First major platform enforcement against state-sponsored AI abuse reported
- OpenAI banned accounts tied to PRC intelligence operations
- Accounts used AI for phishing workflow support and scripting
- Hallmarks consistent with state-sponsored intelligence requirements
- Enforcement action demonstrates detection capability at provider level
The hook
OpenAI banned accounts tied to PRC intelligence operations using AI for phishing and scripting — the first major public disruption of state-sponsored AI abuse.
OpenAI banned accounts involved in activity that overlapped with publicly reported threat groups and displayed hallmarks consistent with PRC intelligence requirements, using AI to support phishing and scripting workflows.