OpenAI has published details of a criminal scam operation it says it disrupted, describing how the group used its AI models — including ChatGPT — to help generate fraudulent content, code and communications as part of a broader scam infrastructure. The company outlined the action in a post on its site, OpenAI, as part of its ongoing disclosures about malicious use of its tools.
According to OpenAI, the operation involved actors using its models to accelerate parts of a scam workflow — the company did not specify the exact financial scale or the number of victims affected, and those figures remain unconfirmed. OpenAI said it identified the activity through its internal monitoring systems, banned the associated accounts, and is sharing indicators publicly so other platforms and researchers can watch for similar patterns. The company has published similar takedown reports periodically as it tracks how bad actors attempt to use generative AI for fraud, influence operations and cyber-enabled crime.
This disclosure sits alongside a string of comparable reports from OpenAI and other AI labs over the past two years, documenting attempts to use large language models for phishing content, malware assistance, and fake account creation at scale. The pattern is consistent: criminal groups are treating generative AI the same way legitimate businesses do — as a way to produce more content, faster, with less manual labor. The difference is what that content is used for.
For B2B operators, the relevant fact isn't the specifics of this one operation — it's the trend it confirms. Scam content generated with AI assistance is increasingly polished, personalized and produced at volume, which means the traditional red flags (bad grammar, generic phrasing, obvious formatting errors) are becoming less reliable as a filter. Support teams handling inbound tickets, sales teams responding to inbound leads, and finance teams processing vendor invoices are all plausible entry points, because these are high-volume, semi-automated workflows where a single missed check can have real cost.
OpenAI's own framing is that detection and enforcement happen on the platform side, but the report is also an implicit signal to downstream users: the tools your business relies on for legitimate automation are the same tools attackers are testing against your defenses. That doesn't mean pulling back on automation — it means being deliberate about where human review sits in a process. A ticket auto-routed to a support queue is low risk. A wire transfer or credential reset auto-approved by workflow logic is not. Companies running lean ops teams should treat this as a prompt to audit which processes currently skip human sign-off and whether that's still the right call given how convincing AI-generated scam attempts have become.
No specific industries or company sizes were named as targets in OpenAI's disclosure, and the company has not indicated whether the operation targeted businesses specifically versus consumers. That distinction remains unconfirmed and is worth watching as more detail emerges.