Chronicle/Attacks & incidents

Microsoft and OpenAI report state-backed hackers using LLMs as a productivity tool

AttackMisuse reportSignificance assistant-drafted

Microsoft Threat Intelligence, publishing jointly with OpenAI, describes five state-affiliated actors from Russia, North Korea, Iran and China using LLMs for tasks such as research, scripting help and drafting phishing content. Microsoft says it and OpenAI had not seen novel or unique AI-enabled attack techniques, and that assets and accounts associated with the actors were disrupted.

Why it matters

It is the earliest provider disclosure in this record of named state actors using LLMs, and the baseline that later reports of agentic misuse are measured against.

Key facts

As stated in the sources, with where to find them.

  • Names five state-affiliated actors: Forest Blizzard (Russia), Emerald Sleet (North Korea), Crimson Sandstorm (Iran), and Charcoal Typhoon and Salmon Typhoon (China).Threat actor sections
  • Microsoft states that it and OpenAI had not observed particularly novel or unique AI-enabled attack or abuse techniques from these actors.Introduction
  • Microsoft announces principles for acting against threat actors using its AI services, including disabling accounts and notifying other AI providers.A principled approach to detecting and blocking threat actors

Findings that cite this record

Sources

Related records