started · updated
OpenAI faces US regulatory probe as AI chatbot scams surge
Microsoft reported a wave of phishing and malware campaigns that misuse the names of popular AI chatbots such as ChatGPT, Claude and DeepSeek. One campaign sent more than 100,000 phishing emails pretending to be OpenAI and directing users to fake payment‑update pages. Other attacks distributed the Vidar infostealer via deceptive plugins and fake GitHub repositories promoted through SEO tricks. Microsoft advises users to verify sender domains, avoid urgent‑action emails and only download software from trusted sources.
At the same time, state attorneys general in the United States have subpoenaed OpenAI for extensive documentation on how ChatGPT protects users, handles advertising, data, and minors, amid preparations for a potential IPO valued at around $1 trillion. The inquiry follows other legal challenges, including a Canadian lawsuit over a suicide claim and a Florida case linking the chatbot to violent incidents. OpenAI says it will cooperate and stresses existing safety measures.