OpenAI reported that a ChatGPT account linked to Chinese law enforcement used the model to review and edit internal write-ups on so-called “cyber special operations,” which OpenAI assessed as activity consistent with covert influence operations and transnational repression aimed at harassing and silencing critics of the Chinese Communist Party. The uploaded materials described a sustained, resource-intensive campaign involving hundreds of staff, thousands of fake social-media accounts, mass content generation, and tactics such as flooding platforms with fraudulent complaints against dissidents, forging documents, and in some cases impersonating U.S. officials to intimidate targets. OpenAI said the activity was tied to a single account, which it banned.
OpenAI also described an attempted smear/propaganda operation targeting Japanese Prime Minister Sanae Takaichi, where the actor prompted ChatGPT for plans to amplify negative commentary on social media and to draft messages from fake accounts to pressure other Japanese politicians; when the model refused, the actor’s later prompts suggested the operation proceeded using other AI models. Separately, OpenAI attributed another cluster of accounts likely originating from mainland China that used ChatGPT to seek information on U.S. persons, online forums, and federal building locations, and to draft emails posing as a Hong Kong-based firm (Nimbus Hub Consulting), with OpenAI noting indicators such as VPN usage and prompts written in Simplified Chinese.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
On February 25, 2026, OpenAI published its threat disruption report describing the Chinese law-enforcement-linked abuse of ChatGPT for influence and harassment operations, while noting it found no evidence of direct offensive hacking via ChatGPT. OpenAI said it banned the associated accounts after identifying the activity.
Separately, OpenAI identified a likely mainland China-based cluster of accounts that sought information on U.S. persons, online forums, and federal building locations, and drafted outreach emails posing as a Hong Kong firm. The activity attempted to move conversations onto WhatsApp, Zoom, or Teams.
The same account later returned to ChatGPT to review and polish internal status reports and documentation describing harassment, silencing, and psychological-pressure campaigns against Chinese dissidents and other targets. The reports referenced tactics such as bogus platform complaints, fabricated content, hacked livestreams, and impersonation of U.S. officials.
After ChatGPT refused to help with the Takaichi smear effort, the actor appears to have continued the operation using other LLMs and tactics including impersonating Japanese citizens by email, coordinated hashtags, memes, and influencer outreach. OpenAI assessed the broader effort as large-scale and sustained, involving thousands of fake accounts and multiple Chinese AI models.
OpenAI observed limited real-world spread of at least one campaign hashtag across X, Pixiv, and Blogspot starting in late October 2025. The activity showed some cross-platform propagation but little meaningful engagement.
In October 2025, a ChatGPT account assessed to be linked to Chinese law enforcement tried to use the model to plan and amplify negative commentary against Japanese politician Sanae Takaichi after her criticism of CCP human-rights abuses. ChatGPT refused the overtly malicious requests.
OpenAI said it linked the doxxing site revealscum.com to the China-linked Spamouflage influence network in May 2024, providing earlier context for the broader activity later described in its report.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
thediplomat.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcedarkreading.com
Open sourcecyberscoop.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.