OpenAI Confirms Chinese Hackers Used ChatGPT in Cyberattack Campaign
OpenAI has identified misuse of its ChatGPT platform by operators linked to China. These activities are part of a campaign involving cyber operations, online harassment, and influence tactics, as detailed in their threat report titled "Disrupting…
OpenAI has identified misuse of its ChatGPT platform by operators linked to China. These activities are part of a campaign involving cyber operations, online harassment, and influence tactics, as detailed in their threat report titled "Disrupting Malicious Uses of AI."
Although ChatGPT was not used to directly create exploits or infiltrate networks, it was misused to plan and amplify operations targeting critics, dissidents, and foreign political figures online.
One notable case involved the banning of a ChatGPT account tied to an individual associated with Chinese law enforcement. This account was used to document activities known as "cyber special operations," which included intimidating dissidents abroad, fabricating news of their deaths, and orchestrating trolling and smear campaigns across social media platforms.
OpenAI's investigation matched account activity with real-world actions on various platforms, revealing campaigns targeting opponents of the Chinese government and impersonating U.S. officials with forged legal documents.
ChatGPT was central to drafting narratives, refining propaganda, and tracking the status of operations, despite some content being posted via other platforms.
OpenAI has identified misuse of its ChatGPT platform by operators linked to China.
The report highlights operations using OpenAI's models to generate content supporting pro-Beijing or pro-Russian narratives while attacking critics. In Japan, operators attempted to smear the country's first female prime minister with conspiracy-themed content. Another operation, "Silver Lining Playbook," involved spear-phishing emails crafted with ChatGPT, masquerading as communications from a Hong Kong consultancy.
These models enabled attackers to produce localized content rapidly, supporting large-scale information and harassment campaigns. OpenAI's systems blocked requests for explicit malware or attack instructions, leading actors to use other AI tools.
Drafting threat messages and fake legal notices aimed at silencing dissidents and forcing content removals. Writing phishing-style emails and spoofed communications for information harvesting or pressuring targets. Producing propaganda articles, memes, and comment scripts for dissemination on social networks and forums.
These activities are a part of modern cyberattacks, combining psychological pressure, identity fraud, and information control with technical intrusion. Generative AI increases the reach and persistence of such campaigns by lowering the cost of creating convincing text at scale.
OpenAI has banned the accounts identified in these activities, tightened abuse detection, and is sharing indicators with governments and platforms to help track related networks. Sophisticated actors increasingly mix commercial AI services with custom or open-source models, necessitating vigilance for AI-generated content beyond traditional threats.
Organizations are advised to approach polished emails, legal threats, and social messages with caution, even when they appear linguistically accurate and localized. Security teams should expand threat models to include AI-assisted social engineering and disinformation campaigns, especially those linked to state-backed groups.
Based on reporting by GBHackers.
