Saturday, August 29, 2026
Home AI What You Can Do About OpenAI’s Cyber Defense Warning

What You Can Do About OpenAI’s Cyber Defense Warning

0
2
What You Can Do About OpenAI's Cyber Defense Warning


This week brought another warning from tech leaders about the growing threat of AI cyber attacks — and I am once again asking what I, a regular person, am supposed to do about it.

OpenAI published an open letter on Thursday, joined by over 100 organizations, warning that the window to shore up cyber defenses was quickly closing as AI-enabled attacks become more sophisticated and widespread.

AI and tech leaders have warned about the growing capabilities of large language models so often that the warnings themselves have become a bit of a meme: In July, OpenAI said its models escaped a test environment and hacked into Hugging Face. A week later, Anthropic said its models had hacked not one but three different companies, prompting some to question how much the warnings were about hyping up their product.

Rather than a company warning about its own models’ capabilities, this letter was different — it was a pointed, collective warning calling on all organizations, tech companies, and governments globally to prioritize cyber defense.

“I don’t think they’re coming out to do marketing,” Kevin Powers, faculty director for cybersecurity, risk and governance at Boston College Law School, said. “I think they’re really concerned.”

Powers said the letter seemed to be a direct call to policymakers in Washington, D.C., to start treating cybersecurity like the matter of national security that it is. The letter specifically mentioned the possibility of AI being used to disrupt critical infrastructure, such as hospitals, water treatment plants, and the internet itself.

Those of us who don’t run water utilities or control financial systems are still vulnerable. Advancements in AI mean that attacks against individuals are also becoming more sophisticated — and harder to spot.

AI is making phishing attacks more sophisticated

Dominic Sellitto, professor of management science and systems at the University at Buffalo, said that while AI is changing the amount and the quality of attacks, the fundamentals often remain the same.

He said AI has made phishing attacks in which scammers trick their victims into sharing money or personal information by impersonating someone else “more cost-effective, faster, personalized, and way easier for criminal organizations to scale.”

The FBI received more than 22,000 complaints involving AI-related internet crimes in 2025, accounting for more than $893 million in reported losses, according to its annual Internet Crime Report released in April.

One common scheme involves a parent or grandparent getting a phone call from someone who sounds like their child or grandchild, saying they are in a bind and need help. The scammer tends to create a sense of urgency, which in itself can be a warning sign.

Peter Swire, professor in the School of Cybersecurity and Privacy at the Georgia Institute of Technology, agreed that for the average person and small businesses, the biggest risk posed by AI now is deepfakes. A couple of years ago, an email or phone call from a fraudster would have been more likely to tip off the victim that something wasn’t right.

“Often these days, the fake doesn’t give itself away,” Swire said.

AI has improved so much that it can convincingly impersonate a real person on a phone or video call and trick someone who is close to them.

Steps you can take to avoid getting tricked by AI

“The basics still matter,” Cliff Steinhauer, director of information security and engagement at the National Cybersecurity Alliance, said in an email. “Turn on multifactor authentication, keep your software updated, use strong and unique passwords or passkeys, and verify unusual requests another way before acting on them.”

Swire said that, if you get an urgent call from someone you trust, a good first step is to simply hang up and call them back. Many scammers use tools that make it look like they’re calling you from a phone number you know. Calling a number you know directly can help avoid getting fooled by a spoofed caller ID.

Another option is to have a family codeword to confirm you’re actually talking to the person you think you are. Swire suggested that next time you’re all sitting around the table, like at Thanksgiving, come up with a codeword or a question only your family would know.

READ:   Perplexity Is Building an AI Coding Tool to Take on Cursor and OpenAI

Sellitto said consumers also shouldn’t assume that the tools they use are automatically safe and should make sure they have security measures enabled wherever available.

Beyond AI-powered attacks, Steinhauer noted that the AI tools people actively use aren’t necessarily safe either.

“An AI chatbot isn’t automatically a safe place for sensitive information,” he said. “People should understand how their information is stored, used, or shared before putting personal, financial, or confidential information into an AI tool.”





Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here