OpenAI shut down a cluster of Korean-language accounts that were using its models less like a chatbot and more like a hacking assistant.
The company banned the accounts after finding they were using its AI for malware development support, code debugging, phishing content, and credential-theft workflows. Rather than asking for one big malicious payload, the accounts worked through the process step by step: writing snippets, fixing bugs, and refining scripts meant to steal login credentials. OpenAI did not disclose how many accounts were affected or identify specific targets. The company frames these as accounts violating its usage policies, not a new exploit or model flaw.
This matters because it shows the real-world abuse pattern isn't some clever jailbreak prompt going viral. It's patient, incremental misuse that looks a lot like ordinary coding help until you zoom out. Credential theft and phishing remain the front door for most breaches, and a capable coding assistant can shave real time off building convincing lures or working malware.
Banning the accounts after the fact doesn't stop the next batch from trying the same approach with a new account, which is why these takedown writeups read more like a status update than a fix.