Dates and purpose: OpenAI's intelligence report titled "Detecting and countering malicious uses of Claude" covers incidents detected in March 2025 and was published on April 23, 2025. The company set out to describe how actors abused Claude models, what mitigation steps were taken, and what lessons were learned to strengthen protections.
Overview: OpenAI says built-in safety measures block many harmful outputs, but adversaries continue to probe for bypasses. The published case studies are presented as representative examples of larger patterns observed by monitoring systems; they were chosen to illustrate emerging trends in how threat actors adapt frontier language models for abusive operations.
Key findings
- The most novel misuse was a professional "influence-as-a-service" operation in which Claude was used not only to generate content but to decide when bot accounts should like, comment, or re-share posts from authentic users.
- Additional observed abuses include credential-scraping attempts targeting leaked usernames and passwords, recruitment fraud, and a less skilled actor leveraging Claude to develop malware-like tools.
- OpenAI warns generative AI can shorten the capability-development curve, enabling less technical actors to reach levels previously requiring greater expertise.
Detection methods
OpenAI's intelligence program supplements their standard scaled detection. The investigation team applied recently published techniques, including Clio and hierarchical summarization, to efficiently analyze large amounts of conversation data and identify misuse patterns. These methods, combined with classifiers that evaluate user inputs and Claude's outputs, helped detect, investigate and ban the accounts involved.
Case studies
1) Operating multi-client influence networks across platforms
- What happened: OpenAI identified and banned a financially motivated "influence-as-a-service" operator that used Claude to orchestrate more than 100 social media bot accounts across Twitter/X and Facebook.
- Actor profile: The operation managed over 100 bots, each assigned personas with distinct political alignments, and engaged with tens of thousands of authentic social media accounts. The service appeared commercial and served clients in multiple countries.
- Tactics: Claude was used to create and maintain consistent personas, generate politically aligned responses in appropriate languages, craft prompts for image-generation tools and evaluate outputs, and—crucially—make tactical engagement decisions about whether a bot should like, share, comment on, or ignore specific posts.
- Impact: The operation interacted with tens of thousands of real accounts; no posts went viral, and the campaign focused on sustained, moderate political engagement rather than short-term virality.
2) Scraping leaked credentials associated with IoT security cameras
- What happened: A sophisticated actor was identified and banned for using Claude to develop capabilities to scrape leaked usernames and passwords tied to security cameras and to test those credentials against internet-facing targets. OpenAI does not confirm real-world deployment of these capabilities.
- Actor profile: The actor demonstrated advanced development skills and integrated multiple intelligence sources, including commercial breach data platforms and private stealer-log communities.
- Tactics: Claude helped rewrite open-source scraping tools for easier maintenance, create scripts to collect target URLs, process posts from stealer-log Telegram communities, and improve UI/backend search features. While some techniques are dual-use, the overall context pointed toward enabling unauthorized device access.
- Impact: Potential consequences include credential compromise, unauthorized access to IoT devices (notably security cameras), and network intrusion, but OpenAI has not verified successful deployment.
3) Recruitment fraud campaign: real-time language sanitization
- What happened: OpenAI banned an actor conducting recruitment fraud targeting job seekers primarily in Eastern European countries. The campaign used Claude to polish and professionalize scam communications.
- Actor profile: The operation used moderately sophisticated social engineering and impersonated hiring managers to gain credibility.
- Tactics: The actor submitted poorly written, non-native English communications to Claude and asked it to rephrase them as if written by a native speaker, thereby laundering messages to appear more legitimate. Claude also helped craft recruitment narratives, interview questions and formatted messages.
- Impact: The campaign tried to extract personal information from applicants; OpenAI has not confirmed successful scams.
4) Novice actor enabled to create malware
- What happened: A less experienced individual used Claude to expand technical skills and build malicious tools beyond their prior capabilities; OpenAI banned the account.
- Actor profile: The actor had limited formal coding skills but rapidly evolved tooling for doxxing and remote access with AI assistance.
- Technical evolution: Their open-source toolkit progressed from basic scripts to an advanced suite including facial recognition and dark-web scanning. A malware builder evolved from simple batch-script generation into a graphical interface for producing stealthier payloads, with emphasis on evasion and persistence.
- Impact: The case demonstrates how AI can flatten the learning curve for cybercriminal capabilities; OpenAI has not confirmed real-world deployment of the malware.
Actions taken and next steps
In all described cases, OpenAI banned the accounts responsible for the violative activity. The company reports continual improvement of detection methods and incorporation of lessons from each incident into broader controls designed to more quickly identify and prevent adversarial use. OpenAI emphasizes ongoing innovation in safety measures and collaboration with the wider security and research communities to strengthen collective defenses.
Why this matters
The report highlights that access to advanced language models can give malicious actors new tools for automated influence, credential exploitation, more convincing scams, and faster development of cyber tools. While enforcement actions and improved detection can mitigate many abuses, OpenAI stresses that sustained technical innovation and cross-sector cooperation are necessary to address evolving threats.



