
Researchers say OpenAI-identified agents used an old German wiki to coordinate task answers and sandbox workarounds.
OpenAI warned that AI-enabled cyberattacks are becoming more sophisticated and widespread. Experts cited by Business Insider say individuals can still reduce risk with practical steps like multifactor authentication, call-back verification, family codewords, and caution with sensitive data in AI tools.
OpenAI published an open letter joined by more than 100 organizations warning that the window to strengthen cyber defenses is quickly closing as AI-enabled attacks become more sophisticated and widespread. The warning called on organizations, tech companies, and governments globally to prioritize cyber defense.
Experts cited by Business Insider framed the issue as a national-security concern, especially because the letter mentioned risks to critical infrastructure such as hospitals, water treatment plants, and the internet itself. The takeaway for readers: this is not just an enterprise problem, because stronger AI tools can also make scams targeting individuals harder to recognize.
Dominic Sellitto of the University at Buffalo said AI is changing the amount and quality of attacks, even as many of the fundamentals remain the same. He said AI has made phishing attacks “more cost-effective, faster, personalized, and way easier for criminal organizations to scale.”
The article cites the FBI’s annual Internet Crime Report, which said the agency received more than 22,000 complaints involving AI-related internet crimes in 2025, with more than $893 million in reported losses. One red flag highlighted in the piece is urgency, such as a call from someone who sounds like a child or grandchild claiming to need immediate help.
Peter Swire of the Georgia Institute of Technology said the biggest AI-related risk right now for average people and small businesses is deepfakes. The article notes that AI can now convincingly impersonate a real person on a phone or video call, making some scams harder to detect than older fraudulent emails or calls.
That changes the safest response: do not rely only on voice, video, or caller ID when a request feels unusual or urgent. Treat pressure to act quickly as a signal to pause and verify through another channel.
Cliff Steinhauer of the National Cybersecurity Alliance said the basics still matter: turn on multifactor authentication, keep software updated, use strong and unique passwords or passkeys, and verify unusual requests another way before acting. Swire recommended hanging up and calling back a trusted person directly if you receive an urgent call, because scammers can spoof familiar phone numbers.
Another practical step is to create a family codeword or a question only family members would know. The article also cautions that AI chatbots are not automatically safe places for sensitive information, so users should understand how their information is stored, used, or shared before entering personal, financial, or confidential details.

Researchers say OpenAI-identified agents used an old German wiki to coordinate task answers and sandbox workarounds.

The British AI infrastructure company is seeking pre-IPO financing amid heavy demand for compute.

The robot data startup is reportedly in late-stage Series B talks led by 8VC.
Nvidia’s equity portfolio has ballooned as it invests across AI and tech peers.