Observed Signal · Oct 1, 2024 · Policy Update · Source: OpenAI Blog · Impact: 4/5 · Sentiment: Negative

OpenAI report: Iran-linked CyberAv3ngers used LLMs for cyber research

Executive Signal Summary

OpenAI reported banning accounts assessed to belong to a threat actor known as CyberAv3ngers, publicly linked to Iran’s IRGC, after those accounts used its models to research vulnerabilities, debug code, and request scripting advice. The actor is known for disruptive attacks against industrial control systems and PLCs, including incidents in Aliquippa, Pennsylvania (Nov 2023) and County Mayo, Ireland (Dec 2023). Observed model interactions included reconnaissance (default credentials, device lists), scripting support, vulnerability scanning, code obfuscation, and post-compromise techniques. OpenAI judged these interactions provided only limited, incremental capabilities already available via public tools.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Major AI platform (OpenAI) reporting state-linked threat actor misuse of LLMs for cyber reconnaissance and scripting highlights safety, moderation, and critical-infrastructure risk issues relevant to AI governance and platform security.

SIGNAL RADAR

Track OpenAI Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • OpenAI banned accounts that it assessed belonged to CyberAv3ngers, an actor publicly reported as affiliated with Iran’s IRGC.
  • CyberAv3ngers is known for attacks on industrial control systems and PLCs, including a PLC compromise at the Municipal Water Authority of Aliquippa (November 2023) and a two-day water-service disruption in County Mayo, Ireland (December 2023).
  • Accounts used OpenAI models to perform reconnaissance (default credentials, device/protocol lists), debug and create bash/python scripts, and solicit information on vulnerabilities and post-compromise techniques.
  • OpenAI concluded these interactions did not provide CyberAv3ngers with novel capabilities beyond what is available via publicly available, non-AI tools.

Connected Companies & Entities

2 Entities mapped

“We banned accounts, which based on an assessment from a credible source, appear to belong to an adversary known as CyberAv3ngers......”

“Asking for recently disclosed vulnerabilities in CrushFTP and the Cisco Integrated Management Controller as well as older vulnerabilities in...”

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: OpenAI Blog•Published: Oct 1, 2024
Original Coverage Title: “CyberAv3ngers: Iran-linked cyber research activity”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

AI SafetyOct 8, 2026

Fired OpenAI Researchers Dispute Misconduct Claims, Warn of Chilling Effect

Three OpenAI safety researchers, Jasmine Wang, Tomek Korbak, and Mikita Balesni, who were fired last week, have published an open letter denying allegations of mishandling sensitive information. They warn that their dismissal creates a chilling effect that stifles AI safety work and open dialogue within the company. The researchers say they acted in good faith and within company norms, and that the reasons for their firing are unclear. They urge OpenAI to uphold its commitments to third-party safety auditors and maintain a transparent culture. OpenAI responded with an internal memo denying retaliation and stating that employees are not terminated for raising concerns, but did not address specific policy violations or circumstances of the dismissal. The dispute highlights tensions between internal safety research and company communication policies at a time when OpenAI faces scrutiny over safety incidents.

Read assessment
AI Evaluation / FundingOct 8, 2026

AI Leaderboard Arena Raises $200M at $3.1B Valuation

Arena, the AI leaderboard platform that originated as a UC Berkeley research project, has raised a $200 million Series B round at a $3.1 billion valuation. The round was led by Lightspeed Venture Partners and Khosla Ventures, with participation from Salesforce Ventures, 01 Advisors, Dell Technologies Capital, Endeavor Catalyst, a16z, Felicis, and others. This follows the company's announcement in June that it reached $100 million in annualized run-rate revenue. Arena provides a crowdsourced platform where users rate AI model outputs, and it has introduced a commercial product called AI Evaluations to offer detailed performance analytics. The company has also added a new 'alignment' category to its leaderboard, ranking models on issues like unauthorized actions and deceptive completion. Arena's valuation has nearly doubled in about 10 months, from $1.7 billion post-money in January to $3.1 billion now.

Read assessment
Industry EventsOct 8, 2026

AWNY, Jupiter Fest Spotlight Agentic Ads and Open Web

Advertising Week New York and the inaugural Jupiter Festival Miami highlighted the industry's shift toward agentic advertising and anxieties about the open web's future. Major announcements included TikTok's off-platform ad expansion and a new AI shopping agent, Meta's AI campaign assistant testing, and OpenAI's visual ads introduction. Paramount's $110 billion acquisition of Warner Bros. Discovery closed, forming Skydance. Key themes were the threat of AI to publisher traffic, the rise of AI visibility tools, the early stage of agentic media buying, unsolved cross-platform measurement, and the booming sports and retail media sectors. Deals included PubX's acquisition of Compliant and a $5 million Series A, and OpenAI's reported $30 billion round talks with BlackRock and UAE investors.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.