Timeline

OpenAI publishes 'Disrupting malicious uses of AI: October 2025'

OpenAI's latest threat report said threat actors mostly bolt AI onto existing malware and phishing playbooks rather than gain genuinely new offensive capability.

  • Security & misuse
  • Notable

OpenAI published its latest periodic account of how its models are being misused, reporting that it had disrupted and reported more than 40 networks that violated its usage policies since it began this public threat-reporting series in February 2024. The report is one of a running series through which OpenAI discloses accounts it has banned for state-linked and criminal misuse.

The recurring finding, OpenAI said, was that threat actors mostly bolt AI onto existing playbooks rather than gain genuinely new offensive capability from its models — using chatbots to speed up drafting, debugging and translation rather than to invent novel attacks. Case studies in the report included a Russian-language group attempting to refine components of remote-access trojans and credential stealers, Korean-language operators developing command-and-control infrastructure, and an alleged China-linked group using the models to craft phishing content and debug malware aimed at Taiwan’s semiconductor sector. OpenAI also described authoritarian-linked users attempting to design large-scale population-monitoring systems, and recurring use of multiple AI tools together with iterative obfuscation to mask AI-generated text.

The report added to a body of evidence, echoed by other labs’ own disclosures, that generative models are being used across the existing spectrum of cybercrime and state-linked operations, but as an accelerant for known techniques rather than as a source of qualitatively new attacks — a distinction OpenAI and outside researchers have repeatedly stressed against more alarmist framing of AI-enabled offence.