Europol details how LLMs can be exploited to fuel fraud, cybercrime, and terrorism, and claims people are already using ChatGPT to carry out illegal activities
There is no honor among chatbots — Criminals are already using ChatGPT to commit crimes, Europol said in a Monday report …
Context & Ripple Effects
Europol's warning lands two months after researchers reported cybercriminals were already using ChatGPT to write hacking tools and malware code and test it for dating-scam chatbots — so the agency is formalizing what the underground had demonstrated. By summer, that experimentation had hardened into a product market of purpose-built abuse chatbots like WormGPT and FraudGPT.
The report matters because it moves LLM misuse from researcher observation to law-enforcement doctrine: Europol now treats model access as a crime-enabler across fraud, cybercrime, and terrorism, a framing later echoed when Microsoft and OpenAI disclosed state-backed groups refining cyberattacks with LLMs.
First-order effects
- OpenAI and other frontier labs face direct pressure to harden abuse detection and prove their safeguards work, since Europol's claim that criminals are already using ChatGPT makes moderation failures a public-safety issue rather than a brand one.
- Cybercrime investigators gain a documented threat taxonomy — fraud, malware assistance, and terrorism support via LLMs — giving prosecutors and national CERTs a common frame for cases that previously looked like ordinary phishing or scams.
Second-order effects
- The underground responds by productizing around safeguards: as mainstream models lock down, demand shifts to dark-web offerings like the jailbroken and purpose-trained abuse chatbots, and vendors of manipulated Meta, OpenAI, and Anthropic models find a ready buyer base.
- Platform operators face lures riding the same wave — Meta already blocked over a thousand generative-AI-themed malicious links, showing attackers weaponize the hype itself even when they don't use the models.
Third-order effects
- If law enforcement treats model access as critical infrastructure for crime, expect sustained regulatory attention on lab safeguards, logging, and disclosure duties — the pattern Europol's report inaugurates runs straight into public-safety AI governance.
- The cat-and-mouse becomes structural: defenders and adversaries both iterate on the same commercial models, so security posture increasingly depends on who adapts faster to each model generation rather than on any fixed tooling advantage.
The trend: LLMs are becoming dual-use infrastructure whose criminal exploitation is tracked by police agencies and labs alike, making safeguard quality a matter of national security policy.