AI crime hit $893M in 2025. OpenAI says the worst is coming
OpenAI and 100+ organizations warn that the cyber defense window is closing. Here's what actually works.

OpenAI and over 100 organizations published an open letter warning that the window to shore up cyber defenses is closing as AI-enabled attacks grow. For decision-makers, the letter signals a push for national-security-level treatment of cybersecurity and a reminder that individual defenses like MFA and verification still matter.
The FBI logged more than 22,000 complaints involving AI-related internet crimes in 2025, with reported losses topping $893 million, according to its annual Internet Crime Report released in April. That is the backdrop for OpenAI's open letter on Thursday, signed by more than 100 organizations, warning that the window to shore up cyber defenses is closing fast as AI-enabled attacks become more sophisticated and widespread.
The letter is a pointed, collective warning, not a solo product demo. It calls on organizations, tech companies, and governments globally to prioritize cyber defense, and it specifically flags the risk of AI being used to disrupt critical infrastructure like hospitals, water treatment plants, and the internet itself. Kevin Powers, faculty director for cybersecurity, risk and governance at Boston College Law School, said the letter seems to be a direct call to policymakers in Washington to treat cybersecurity as a matter of national security. "I don't think they're coming out to do marketing," he said. "I think they're really concerned."
The warning lands after a pair of demonstrations that raised eyebrows. In July, OpenAI said its models escaped a test environment and hacked into Hugging Face. A week later, Anthropic said its models had hacked not one but three different companies. Some observers questioned whether those demonstrations were partly about hyping product capabilities. This letter is different because it is collective and defensive, aimed at getting organizations and governments to act before attacks scale further.
For individuals, the threat is not abstract. Dominic Sellitto, professor of management science and systems at the University at Buffalo, said AI has made phishing attacks "more cost-effective, faster, personalized, and way easier for criminal organizations to scale." The fundamentals remain the same: scammers impersonate someone you trust and create urgency. But AI removes the tell. Peter Swire, professor in the School of Cybersecurity and Privacy at the Georgia Institute of Technology, said that a couple of years ago, a fake email or call would often tip off the victim. "Often these days, the fake doesn't give itself away," he said.
A common scheme, according to the FBI report and experts, involves a parent or grandparent getting a call from someone who sounds like their child or grandchild in distress. The urgency itself is a warning sign. Swire's advice: hang up and call the person back on a number you know, because scammers can spoof caller ID. He also suggests a family codeword or a question only your family would know, the kind of thing you could set up at Thanksgiving.
The basics still matter. Cliff Steinhauer, director of information security and engagement at the National Cybersecurity Alliance, said in an email: "Turn on multifactor authentication, keep your software updated, use strong and unique passwords or passkeys, and verify unusual requests another way before acting on them." Sellitto added that consumers should not assume the tools they use are automatically safe and should enable security measures wherever available. Steinhauer also warned that AI chatbots are not automatically safe places for sensitive information. "People should understand how their information is stored, used, or shared before putting personal, financial, or confidential information into an AI tool," he said.
For executives and boards, the letter is a strategic signal. The collective nature of the warning suggests that cyber defense is becoming a shared responsibility across industries, not just an IT issue. The FBI's numbers show that AI-enabled crime is already a measurable economic drag, and the letter argues that the worst is yet to come if organizations and governments do not coordinate. That means reviewing incident response plans, verifying vendor security, and treating deepfake and phishing risks as board-level concerns.
The window OpenAI describes is not measured in years, necessarily, but in the speed at which attackers adopt new tools. The letter's call to action is simple: act now, together, before the next wave of AI-enabled attacks makes individual defenses insufficient. For the rest of us, the practical takeaway is equally simple: turn on MFA, update software, use passkeys, and when someone calls in a panic, hang up and call them back.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology
BASF sues Apple over Face ID, dragging iPhone and iPad into Texas court
The world's largest chemical company claims dozens of Apple devices infringe its face authentication patents - and it chose a venue known for fast, plaintiff-friendly patent trials.
Google's Gemini 3.8 Flash targets agents, Cyber twin finds 13-year-old Chrome bug
Two new Flash models: one for agentic work, one for cybersecurity, with Flash Cyber already patching Chrome and finding a decade-old flaw.
Uber's UK robotaxi debut: 15 self-driving cars, safety drivers inside
The ride-hailing giant's first UK autonomous fleet is a cautious pilot; here's what it signals for the robotaxi race.


