OpenAI pulled a batch of accounts it says were using its AI tools to support phishing campaigns and scripting tasks.
The company's latest threat report describes a cluster of banned accounts whose activity overlapped with previously documented threat groups. OpenAI said the behavior showed hallmarks consistent with requirements tied to Chinese intelligence services. The accounts used the model to help draft phishing material and write scripts, rather than to build novel malware from scratch. OpenAI did not name the specific group or say how many accounts were involved.
This fits a pattern, not an anomaly. AI labs have been quietly playing whack a mole with state linked actors who treat chatbots as productivity tools for reconnaissance, translation, and code cleanup, not as autonomous hackers. The real story here is what these bans confirm: the bottleneck for this kind of espionage was never technical skill, it was time and polish, and that is exactly what a language model is good at cutting down.
None of this means AI is inventing new attacks. It means old attacks get written faster, with fewer typos, and OpenAI is left playing cleanup crew after the fact.