Wouldn't a company responsible for an escalating frequency and severity of cybercrime normally be sanctioned by law enforcement? Wouldn't such a company normally stop these activities for fear of civil and criminal liability?
Typically only if it would go in against the interest of the government. In this case, OpenAI and its peers are carrying the complete US stock market, and the govt has a huge interest in not making it collapse anytime near election dates.