OpenAI Banned Iran-Linked Hackers Using ChatGPT to Hunt ICS Default Passwords
Curated by the Inblix editorial team
OpenAI has banned a cluster of accounts linked to CyberAv3ngers, an Iranian hacking group tied to the Islamic Revolutionary Guard Corps (IRGC) known for disrupting water systems and industrial controllers. The accounts were caught using ChatGPT for reconnaissance on industrial control systems (ICS), debugging code, and asking for default password combinations for programmable logic controllers (PLCs). This isn’t speculative attribution—OpenAI said the assessment came from a credible source and aligns with the group’s public profile.
Much of the activity looked like attackers trying to get a leg up on the boring blocking and tackling of cyber ops. They asked the model for default usernames and passwords for various PLCs, with some prompts suggesting a specific interest in Jordan and Central Europe. They also wanted help writing and refining bash and Python scripts, sometimes to programmatically scan for vulnerable infrastructure using publicly available pentesting tools. Beyond that, they queried the model on code obfuscation and weaponizing security tools typically used after a breach.
The group has a track record of making this low-tech approach sting. In November 2023, they compromised a Pennsylvania water authority’s PLC, and a month later knocked out water services in County Mayo, Ireland for two days. Their playbook is simple but effective: scan for devices still using factory credentials or unpatched vulnerabilities, then exploit them. ChatGPT just made the homework phase faster.
None of this should be read as a superpower. OpenAI’s impact assessment is blunt—these interactions didn’t give CyberAv3ngers any novel capability. It offered “limited, incremental” help that’s already achievable with non-AI tools. The real story here is the breadth of targets the prompts revealed. Beyond the group’s known ICS hammer, the queries exposed an interest in a wider set of technologies and software they may be looking to exploit. That’s the kind of intelligence that lets defenders widen their lens before the next PLC gets popped.
💡 Key Takeaways
- OpenAI banned IRGC-linked CyberAv3ngers accounts that used ChatGPT to research ICS vulnerabilities and default PLC passwords, confirming a credible external attribution.
- The group's reconnaissance activity extended beyond known ICS targets, with prompts revealing a potential interest in additional, undisclosed technologies and software.
- Despite the AI assistance, OpenAI assessed the interactions provided no novel capability and only marginal advantages over existing public hacking tools.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.