In a significant disclosure on February 25, 2026, OpenAI revealed that it has dismantled a sophisticated global intimidation campaign linked to Chinese law enforcement. The operation, which utilized ChatGPT to refine reports and track critics of the Chinese government both domestically and abroad, underscores the evolving role of generative AI in state-sponsored surveillance and harassment.
The Mechanics of the Operation
According to OpenAI’s latest threat intelligence report, the activity centered around a single, high-volume account that was used to process reports on what the operators termed “cyber special operations.” These operations involved a massive, resource-intensive infrastructure consisting of hundreds of human staff and thousands of fake social media accounts.
The Chinese agency reportedly used ChatGPT to:
-
Draft and Edit Surveillance Reports: The model was used to summarize and refine intelligence gathered on dissidents and critics.
-
Target Political Figures: The operators attempted to use the AI to plan a propaganda campaign specifically targeting Japanese Prime Minister Sanae Takaichi.
-
Impersonate U.S. Officials: In several instances, the actors used the AI to craft messages that mimicked the tone and authority of U.S. government officials to intimidate targets and extract information.
-
Conduct Social Engineering: The group generated English-language emails to U.S. state officials and financial policy analysts, inviting them to “paid consultations” in an attempt to move conversations to encrypted platforms like WhatsApp or Zoom for further exploitation.
A Pattern of Escalation
This latest discovery is part of a broader trend of state-affiliated actors attempting to weaponize AI. OpenAI noted that while the agency’s use of ChatGPT didn’t involve direct offensive hacking, it served as a “force multiplier” for tasks like language translation, content generation, and social media automation.
Similar activity has been observed in previous months. In 2025, OpenAI disrupted operations like “Sneer Review” and “Uncle Spam,” which targeted U.S. political discourse and issues like tariffs and USAID funding. However, the February 2026 report highlights a more direct link to law enforcement agencies and a specific focus on the physical tracking of individuals, with actors prompting the model for information on U.S. federal building locations and employee distributions.
Global Reach and Technical Tactics
The investigation found that the actors often used VPNs to mask their location, though they frequently prompted the model in Simplified Chinese—a hallmark of mainland China operations. Beyond simple text generation, at least one account sought technical instructions for installing “FaceFusion,” a real-time face-swapping software, suggesting an interest in creating more convincing deepfake personas for social engineering.
OpenAI’s report also detailed concurrent disruptions of:
-
Romance Scams: A Cambodian network that blended human operators with AI to conduct “pig butchering” scams.
-
Malware Development: Russian-linked groups attempting to use AI to debug code for remote-access trojans.
The Industry Response
OpenAI has reiterated its commitment to a “multi-pronged approach” to safety, which includes monitoring for state-affiliated abuse and sharing intelligence with industry peers like Microsoft and Meta. The company stated that it uses its own AI models to “pursue leads and analyze how adversaries interact with the platform,” effectively using AI to catch AI-driven threats.
Despite these attempts at misuse, OpenAI maintains that ChatGPT is currently used to identify and report scams up to three times more often than it is used to facilitate them.
Sources:
-
Chinese group’s ChatGPT use reveals worldwide harassment campaign – Cyberscoop
-
Disrupting Malicious Uses of AI: October 2025 Update – OpenAI
-
OpenAI Bans ChatGPT Accounts Linked to Nation-State Threat Actors – Dark Reading
-
OpenAI Bans ChatGPT Accounts Used by Chinese Group for Spy Tools – SecurityWeek
ChatGPT’s Role in Chinese Surveillance Operations
This video provides additional context on how individuals have been impacted by AI-driven narratives and the broader security concerns surrounding the platform’s misuse by state actors.













































