AIPolicyTracker

AI incident ·

ChatGPT Abused to Develop Malicious Softwares

25 news reports Snapshot 7 Sep 2026

In brief

An AI system built and deployed by Openai allegedly harmed Internet Users.

Risk domain
Malicious Actors & Misuse Cyberattacks, weapon development or use, and mass harm
Occurred
Coverage
25 reportsDec 2022 - Apr 2023

What happened

OpenAI's ChatGPT was reportedly abused by cyber criminals including ones with no or low levels of coding or development skills to develop malware, ransomware, and other malicious softwares.

Laws that address this harm

Policy angle: Classified under Malicious Actors & Misuse (Cyberattacks, weapon development or use, and mass harm) in the MIT AI Risk Repository taxonomy; 5 recorded instruments address this use case.

Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).

News reports (25)

Titles link to the original publisher; report text is not reproduced here.

  1. OPWNAI: Cybercriminals Starting to Use ChatGPT
    research.checkpoint.com · Check Point Research
  2. ChatGPT is helping hackers write malware codes
    thehindu.com · The Hindu Bureau
  3. El lado oscuro de ChatGPT: generar malware funcional
    muycomputerpro.com · Sergio Delgado
  4. Malware con IA: online il codice generato con ChatGPT
    punto-informatico.it · Luca Colantuoni
  5. Yes, ChatGPT can write malicious code — but not well
    washingtonpost.com · Tim Starks, Aaron Schaffer
  6. Exploring The Dark Side Of ChatGPT
    augustman.com · Manas Sen Gupta

Who was involved

Alleged deployer
Openai
Alleged developer
Openai
Alleged harmed party
Internet Users

Classification (MIT AI Risk Repository taxonomy)

Causal entity
Human
Intent
Intentional
Timing
Post-deployment
Harm level
—
Sectors
—
Countries
—

Risk entries describing this failure mode

Entries from the MIT AI Risk Repository coded to subdomain 4.2.

  • Business operations/infrastructure damage

    "Business operations/infrastructure damage - Damage, disruption, or destruction of a business system and/or its components due to malfunction, cyberattacks, etc."

    A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms (Abercrombie2024)

  • Violence/armed conflict

    "Violence/armed conflict - Use or misuse of a technology system to incite, facilitate or conduct cyberattacks, security breaches, lethal, biological and chemical weapons development, resulting in violence and armed confl...

    A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms (Abercrombie2024)

  • Security & Defense

    "AI could enable more serious incidents to occur by lowering the cost of devising cyber-attacks and enabling more targeted incidents. The same programming error or hacker attack could be replicated on numerous machines....

    The Rise of Artificial Intelligence - Future Outlooks and Emerging Risks (Allianz2018)

  • Catastrophic risk due to autonomous weapons programmed with dangerous targets

    "AI could enable autonomous vehicles, such as drones, to be utilized as weapons. Such threats are often underestimated."

    The Rise of Artificial Intelligence - Future Outlooks and Emerging Risks (Allianz2018)

  • Warfare and Physical Harm

    "The use of AI in warfare is highly alarming and may pose dangers to human safety (Hendrycks et al., 2023). Autonomous drone warfare is being aggressively pursued as a tactic in the current war in Ukraine (Meaker, 2023),...

    Foundational Challenges in Assuring Alignment and Safety of Large Language Models (Anwar2024)

  • Hazardous Biological and Chemical Technologies

    "AI systems such as LLMs, chemical LLMs (Skinnider et al., 2021; Moret et al., 2023), and other LLM- based biological design tools might soon facilitate the production of bioweapons, chemical weapons, and other hazardous...

    Foundational Challenges in Assuring Alignment and Safety of Large Language Models (Anwar2024)

  • Dual use science risks

    "General- purpose AI systems could accelerate advances in a range of scientific endeavours, from training new scientists to enabling faster research workflows. While these capabilities could have numerous beneficial appl...

    International Scientific Report on the Safety of Advanced AI (Bengio2024)

  • Cyber offence

    "General- purpose AI systems could uplift the cyber expertise of individuals, making it easier for malicious users to conduct effective cyber- attacks, as well as providing a tool that can be used in cyber defence. Gener...

    International Scientific Report on the Safety of Advanced AI (Bengio2024)

Incidents in the same risk subdomain

All incidents in this subdomain

Other incidents involving Openai

Source record: incident #443 on the AI Incident Database · all 25 reports