Breaking

OpenAI says we are running out of time to take action on cyber defense. Here’s what you can actually do about it.

OpenAI says we are running out of time to take action on cyber defense. Here's what you can actually do about it.

OpenAI CEO Sam Altman Bloomberg/Getty Images

This week brought a new warning from technology leaders about the growing threat of AI cyber attacks – and I ask again what I, an ordinary person, should do about it.

OpenAI published an open letter on Thursday, joined by more than 100 organizations, warning that the window needs to be strengthened cyber defense was quickly closed as AI attacks became more sophisticated and widespread.

AI and technology leaders have warned so often about the growing capabilities of large language models that the warnings themselves have become a bit of a meme: In July, OpenAI said its models had escaped from a test environment and hacked Hugging Face. A week later, Anthropic said its models had hacked not one but three different companies, leading some to wonder how many the warnings were about hyping their product.

Rather than a corporate warning about the capabilities of its own models, this letter was different: it was a stark, collective warning calling on all organizations: technical companiesand governments worldwide to prioritize cyber defense.

“I don’t think they’re going to do marketing,” said Kevin Powers, faculty director for cybersecurity, risk and governance at Boston College Law School. “I think they are really concerned.”

Powers said the letter appeared to be a direct call for policymakers in Washington, D.C., to start treating cybersecurity as the national security issue that it is. The letter specifically mentioned the potential for AI to be used to disrupt critical infrastructure such as hospitals, water treatment plants and the internet itself.

Those of us who don’t run water utilities or control financial systems are still vulnerable. Advances in AI mean that attacks on individuals are also becoming more sophisticated – and harder to spot.

AI makes phishing attacks more sophisticated

Dominic Sellitto, a professor of management science and systems at the University at Buffalo, said that while AI changes the quantity and quality of attacks, the fundamentals often remain the same.

He said AI created phishing attacks in which scammers trick their victims into sharing money or personal information by pretending to be someone else “more cost-effective, faster, more personalized and much easier for criminal organizations to scale.”

The FBI received more than 22,000 complaints about AI-related internet crime in 2025, accounting for more than $893 million in reported losses, according to the annual Internet Crime Report released in April.

A common plan is for a parent or grandparent to receive a call from someone who looks like their child or grandchild and say that he or she is in trouble and needs help. The scammer tends to create a sense of urgency, which in itself can be a warning sign.

Peter Swire, professor in the School of Cybersecurity and Privacy at the Georgia Institute of Technology, agree that for the average person and small businesses, the biggest risk from AI now is deepfakes. A few years ago, it would have been more likely that an email or phone call from a fraudster would have alerted the victim that something was wrong.

“A lot of times these days the fake doesn’t reveal itself,” Swire said.

AI has improved so much that it can be done convincingly pretend to be a real person during a phone or video call and fooling someone close to him.

Steps you can take to avoid being tricked by AI

“The basics still matter,” Cliff Steinhauer, director of information security and engagement at the National Cybersecurity Alliance, said in an email. “Enable multi-factor authentication, keep your software up to date, use strong and unique passwords or passcodes, and otherwise verify unusual requests before acting on them.”

Swire said if you get an urgent call from someone you trust, a good first step is to simply hang up and call back. Lots of scammers use tools that make it look like they’re calling you from a phone number you know. If you call a number you know immediately, you can avoid being fooled by spoofed caller ID.

Another option is to use a family codeword to confirm that you are actually talking to the person you think you are. Swire suggested that the next time you all sit around the table, such as at Thanksgiving, think of a code word or ask a question that only your family would know.

Sellitto said consumers should also not assume that the tools they use are automatically secure and should ensure they have security measures enabled where possible.

In addition to AI-powered attacks, Steinhauer noted that the AI ​​tools people are actively using aren’t necessarily secure either.

“An AI chatbot is not automatically a safe place for sensitive information,” he says. “People need to understand how their information is stored, used or shared before putting personal, financial or confidential information into an AI tool.”

NY Breaking News Technology Desk

Technology Reporter

The NY Breaking News Technology Desk covers technology and digital-policy developments with clear source attribution. For corrections or editorial questions, contact editor@nybreaking.com.