OpenAI has formally acknowledged that extensive covert cyberattack campaigns were planned and documented using a ChatGPT account connected to a person connected to Chinese law enforcement This article explores operation openai. . One of the most thorough public revelations of how state-affiliated actors are using AI tools as weapons to carry out coordinated influence operations and targeted harassment against dissidents, foreign officials, and critics of the Chinese Communist Party (CCP) was made in OpenAI's February 2026 threat disruption report.
The operation, which OpenAI internally named "Cyber Special Operations" after the Chinese phrase used in the threat actor's own status reports, is an organized, resource-intensive attempt to stifle dissent, control public opinion, and stifle free speech both domestically in China and internationally.
Investigators had a unique look into the inner workings of a Chinese state-affiliated disinformation machine as the ChatGPT account was mainly used to edit and polish periodic status updates on ongoing campaigns. It is remarkable how extensive the activities detailed in the threat actor's own ChatGPT sessions are. A website that poses as the FBI's IC3 unit and is connected to this scam (Source: OpenAI) The following measures should be taken by organizations and individuals who are worried about AI-enabled influence operations.
It is recommended that social media companies improve their coordinated detection of inauthentic behavior, especially for accounts that use AI-fabricated evidence to mass-report users. Government officials, activists, and public figures should be on the lookout for unsolicited communications from phony legal entities or unreliable consulting firms.
Governments ought to keep exchanging threat intelligence regarding clandestine activities connected to foreign states and alert civil society organizations to the dangers of online harassment in the real world. To guarantee that the entire industry is aware of the misuse of their platforms, AI providers should continue to publish thorough threat reports and enforce stringent content policies.












