Iranian state backed hackers are systematically using Western AI models like ChatGPT and Gemini to write malware, generate perfect Hebrew and Arabic phishing emails, and build fake personas for intelligence gathering,... Google's Threat Intelligence Group had already identified Iran as the most aggressive state abus...

Create a landscape editorial hero image for this Studio Global article: What are the key findings of the Financial Times investigation into Iran's use of Western AI tools like ChatGPT and Gemini for cyber operati. Article summary: Here are the key findings from the recent **Financial Times** investigation (published late May 2026) on Iran's weaponization of Western AI tools, as reported by multiple outlets that have summarized the FT's reporting.. Topic tags: general, general web, user generated. Reference image context from search candidates: Reference image 1: visual subject "According to a report by the Financial Times, Iranian-linked operators have used Western AI tools including ChatGPT and Gemini to develop malware, craft phishing campaigns in Hebre" source context "Report: Iran Uses Western AI for Cyberattacks | Let's Data Science" Reference image 2: visual subject "# Financial Ti
A Financial Times investigation published in late May 2026 has exposed how Iran's military and intelligence apparatus is systematically weaponizing Western commercial AI tools, including OpenAI's ChatGPT and Google's Gemini, to accelerate cyber operations against the United States, Israel, and Gulf states. The report, citing cybersecurity researchers and Iranian officials, paints a picture of a state actor that has rapidly lowered barriers to sophisticated cyberattacks by using the same generative AI tools available to consumers .
The findings come as the UAE disclosed it is absorbing between 500,000 and 700,000 cyberattack attempts daily—roughly triple the rate before the conflict escalated—with officials directly attributing the surge to Iran-linked actors using AI .
The FT investigation details a full-spectrum integration of AI into Iran's offensive cyber playbook. Hackers are not merely experimenting with these tools; they are embedding them across the entire attack chain.
Malware Development: Iranian operators are prompting ChatGPT and Gemini to write malicious code, accelerating the production of malware targeting US and Israeli networks . This represents a significant escalation from earlier observations. Google's Threat Intelligence Group noted in a January 2025 report that while Iranian spies had used Gemini for scripting, the company's guardrails at that time had stopped the model from generating actual malware
. By May 2026, those guardrails appear to have been circumvented or overwhelmed.
Fluent Phishing in Hebrew and Arabic: One of the most operationally significant findings is Iran's use of AI to craft phishing messages in flawless Hebrew and Arabic. Previously, poor grammar and unnatural phrasing were red flags that helped targets identify malicious emails. AI-generated lures now read as if written by a native speaker, allowing Iranian operators to impersonate trusted contacts convincingly and manipulate US and Israeli officials into clicking malicious links .
Fake Online Personas: Iranian hackers are using AI to generate complete fake identities—photos, professional backgrounds, and conversational styles—to build trust with targets over time before deploying social engineering attacks . This lengthens the engagement window and increases the likelihood of successful compromise.
Full Kill-Chain Integration: A cyber security analyst told the Financial Times, "We are seeing signs that they are using AI prompts the entire way," describing how AI supports operations from initial reconnaissance and target research through to payload delivery .
The human cost of this AI acceleration is most visible in the Gulf. According to the Abu Dhabi Emergency, Crisis and Disaster Management Center, the UAE is facing between 500,000 and 700,000 cyberattack attempts per day from Iran-linked state actors .
Mohammed Hamad Al Kuwaiti, Head of Cyber Security for the UAE Government, confirmed to Khaleej Times in April 2026 that daily attacks had surged from around 200,000 to approximately 600,000 since the regional escalation began . Al Kuwaiti specifically cited state-linked hackers using ChatGPT and other AI tools to engineer these attacks, noting that the AI integration has made them more sophisticated and harder to detect
.
Phishing incidents alone rose 32% in the first quarter of 2026, according to the Crisis and Disaster Management Center's "Cybersecurity Awareness Guide During Crises," which also warned of deepfake-driven disinformation campaigns designed to cause public panic . The attacks have targeted critical infrastructure across the Gulf, with Iranian state-sponsored actors operating through more than 40 proxy organizations and sympathizers
.
The FT investigation builds on earlier intelligence. In January 2025—more than a year before the full escalation of the Iran conflict—Google's Threat Intelligence Group reported that Iranian government-backed cyber actors accounted for 75% of all identified state-backed misuse of Gemini among four monitored countries (China, Russia, Iran, and North Korea) .
Google's report at the time identified over 10 Iranian cyber groups using Gemini for phishing campaigns, reconnaissance of defense organizations, and writing software scripts. The company acknowledged its guardrails had prevented malware generation at that stage, but the FT's May 2026 findings suggest those defenses have since failed or been bypassed .
The FT report makes clear that Iran's weaponization of commercial AI is not confined to cyber operations. The Islamic Revolutionary Guard Corps (IRGC) and broader Iranian military institutions are actively promoting AI integration across all branches .
Key areas of military AI development include:
This institutional push places Iran at the center of a broader trend in which commercial AI tools—built by Western companies for civilian use—are becoming instruments of asymmetric warfare.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
Iranian state backed hackers are systematically using Western AI models like ChatGPT and Gemini to write malware, generate perfect Hebrew and Arabic phishing emails, and build fake personas for intelligence gathering,...
Iranian state backed hackers are systematically using Western AI models like ChatGPT and Gemini to write malware, generate perfect Hebrew and Arabic phishing emails, and build fake personas for intelligence gathering,... Google's Threat Intelligence Group had already identified Iran as the most aggressive state abuser of Gemini, responsible for 75% of all identified state backed misuse across four monitored countries as of January 2025.
Beyond cyber operations, the IRGC is integrating AI into drone guidance, electronic warfare, and battlefield decision making, signaling a comprehensive institutional push to weaponize commercial AI tools.