ChatGPT News 07/31/2026 AI Rating: Medium

OpenAI Keeps Publishing "Disrupting Malicious Uses of AI" Reports — 44-Plus Cases From State Influence Ops to Scam Networks

#ChatGPT#OpenAI#Safety#Threat Intelligence#Misuse

Since May 2024, OpenAI has periodically published a report series called “Disrupting malicious uses of AI,” documenting more than 40 cases in which it detected and banned ChatGPT accounts tied to state-linked influence operations, scam and fraud networks, malware-development support, and election-related influence campaigns. This isn’t a single new announcement — it’s a roundup of that ongoing disclosure practice, which our automated tracker picked up all at once from OpenAI’s archive, together with a look at some of the more notable cases.

Details

  • What the series is: Not a one-off incident report, but a recurring disclosure from OpenAI’s threat intelligence team, published every few months — batches appeared in May and October 2024, February, June, and October 2025, and June 2026
  • Doppelganger (May 2024): A Russia-linked influence operation targeting Ukraine and Europe. Accounts used ChatGPT to generate English, French, German, and Polish comments and articles posted across multiple social platforms; OpenAI banned four related account clusters
  • Spamouflage (May 2024): A PRC-linked influence operation. Accounts used ChatGPT to research social media activity and generate multilingual content before being banned
  • STORM-2035 (October 2024 and June 2025): An Iran-linked operation that generated content about US and UK elections for distribution across multiple sites. It was reported twice — once for the original activity and again after the actors attempted to resume operations following the initial ban
  • SweetSpecter and CyberAv3ngers (October 2024): China- and Iran-linked cyber threat actors that used ChatGPT for early-stage reconnaissance, including vulnerability research and looking up default passwords for industrial control systems
  • DPRK-linked fraudulent employment schemes (February and June 2025): Accounts suspected of using AI to fabricate resumes, work history, and interview prep in order to secure remote jobs at foreign companies under false identities — part of a pattern OpenAI has repeatedly linked to North Korea
  • Cambodia-based scam networks (February and June 2025, August 2026): Groups running romance scams, investment fraud, and fake-job (“task scam”) schemes used ChatGPT to draft messages, translate across languages, and generate fake identity documents. The most recent entry, “Disrupting a Criminal Scam Operation,” describes a similar network with links to human trafficking
  • “Data Center Bandwagon” and “Tech and Tariffs” (June 2026): More recent, likely PRC-linked clusters that used AI to generate social media content criticizing US data center investment and tariff/tech policy — among the newest reports in the series
  • The consistent response: In every case, OpenAI bans the accounts and networks involved, shares the relevant indicators of compromise with industry peers, researchers, and authorities, and takes steps to make it harder for the same actors to regain access

What’s next

  • None of the 40-plus cases summarized here are new, standalone news items — they’re the history of an ongoing disclosure practice that our automated tracker happened to pull from OpenAI’s archive all at once, spanning reports from roughly May 2024 through mid-2026
  • OpenAI has indicated it will keep publishing this kind of report. Readers interested in how ChatGPT gets misused for influence operations, cyberattack preparation, or scam workflows — and how OpenAI detects and responds to it — can search OpenAI’s site for “Disrupting malicious uses of AI” to find the individual reports