OpenAI’s latest threat report, “Disrupting Malicious Uses of AI,” published on Tuesday, details how malicious actors are leveraging its ChatGPT platform for cyberattacks, though the company found no evidence that the AI model itself is enabling fundamentally novel offensive techniques. The analysis, based on threat actor activity observed over recent months, reveals a consistent pattern: hackers are integrating ChatGPT into their existing attack workflows to augment—rather than reinvent—their malicious operations.
How Hackers Are Using ChatGPT for Malware Development and Fraud
OpenAI’s report identifies several distinct case studies that illustrate the specific ways ChatGPT is being exploited. In one notable example, Russian-speaking cybercriminals attempted to use ChatGPT to develop malware, including modules designed to evade detection, a remote-access trojan (RAT), and credential-stealing scripts. In each of these attempts, the company states that the chatbot detected the malicious intent and refused to generate the requested code, leading to the subsequent banning of the associated user accounts.
In a separate set of operations, scammers operating out of Cambodia, Nigeria, and Myanmar attempted to use ChatGPT to craft deceptive messages for large-scale fraud campaigns. These actors requested the AI to generate scripts for spreading messages across the internet designed to capture potential victims’ attention. The report notes that while the chatbot was able to generate the requested content, OpenAI’s automated systems flagged the activity and banned the users before the campaigns could achieve broad reach.
OpenAI’s Core Finding: AI as an Efficiency Tool, Not a Game-Changer
The most significant insight from the report is that threat actors are not using AI models to pioneer new attack vectors. Instead, they are using ChatGPT to make their existing methods more efficient. “Repeatedly, and across different types of operations, the threat actors we banned were building AI into their existing workflows, rather than building new workflows around AI,” the document states. OpenAI explicitly found “no evidence of new tactics or that our models provided threat actors with novel offensive capabilities.”
This suggests that current generative AI models, despite their broad capabilities, remain constrained by the same security guardrails that prevent them from being a direct enabler of advanced, zero-day-style cyberattacks. The primary threat remains the acceleration of already-known attack methods, such as social engineering scripts and basic malware components, rather than the generation of entirely new classes of threats.
Defenders Are Using ChatGPT More Than Attackers
A remarkable data point from the report highlights the dual-use nature of the technology. OpenAI estimates that ChatGPT is being used to detect and identify scams up to three times more frequently than it is being used to create them. This dynamic suggests that the defensive applications of AI are currently outpacing its offensive misuse, a trend the company expects to deepen as threat actors continue to adapt. “As the threatscape evolves, we expect to see further adversarial adaptations and innovations, but we will also continue to build tools and models that can be used to benefit the defenders,” OpenAI states.
Context: GPT-5 Security Concerns
The release of this threat report comes just weeks after cybersecurity experts raised concerns regarding the security posture of OpenAI’s latest flagship model, GPT-5. While the current findings focus on the misuse of existing models, the rapid evolution of AI capabilities underscores the need for continuous scrutiny of how newer, more powerful systems could be abused if their guardrails are not equally advanced.
What This Means for Users and Organizations
For the average user, the immediate risk from AI-assisted cyberattacks is a higher volume of more convincing phishing emails and social engineering attempts. Scammers can now generate grammatically precise and contextually relevant messages faster and cheaper than before. For organizations, the primary concern should be the potential for lower-tier attackers to produce more effective initial compromise tools.
How to Protect Yourself Against AI-Enhanced Threats
Given that AI is primarily being used to accelerate existing social engineering and credential theft, the fundamental principles of digital hygiene remain the most effective defense. To mitigate these evolving threats, security-conscious users should adopt a multi-layered approach to their digital security. This includes using a reputable antivirus solution with real-time threat detection and behavioral analysis capabilities to identify malicious scripts and downloads. A zero-knowledge password manager is critical for generating and storing unique credentials for every account, which prevents credential stuffing attacks. Additionally, enabling two-factor authentication (2FA) on all critical accounts provides a vital second layer of defense even if credentials are compromised.
The best protection against AI-generated phishing is a healthy skepticism. Always verify unsolicited messages through a separate communication channel, and never click on links or download attachments from unknown or unverified senders.