← the record
WF-XLKAV4

AkiraBot Reportedly Used OpenAI to Spam Website Chats and Contact Forms at Scale

SentinelLabs reported that unknown operators used AkiraBot, a Python framework, plus OpenAI's chat API to generate customized SEO spam and bypass CAPTCHAs, posting via SMB websites' contact forms and Reamaze-style chat widgets. Researchers assessed >400k domains were targeted and ≥80k successfully spammed since 09/01/2024. OpenAI said the API key was disabled after disclosure.

Date it happened
2024-09-01
Organisation involved
Malicious actors, Unknown AkiraBot operators
Product, system or model
Telegram, SmartProxy, Selenium WebDriver, reCAPTCHA, OpenAI Chat Completions API, NextCaptcha, headless Chrome, hCAPTCHA, FastCaptcha, CAPTCHA, Capsolver, BeautifulSoup, AkiraBot
Where this came from
Share this incident
XLinkedInFacebookWhatsAppEmail
Attribution

This incident was imported from AI Incident Database and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.

This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.