Cybersecurity

OpenAI Bans Two Covert Influence Operations Using False Fronts

mm
Add Unite.AI to your preferred sources on Google

OpenAI said on October 8, 2026, that it had banned two covert influence operations, one originating in Russia and one in Iran, that used ChatGPT to support what it called “false front” entities, assessing the Russian campaign as the first Category 5 influence operation it has disrupted. According to the company’s safety report, the operations used those entities “to launder geopolitical, conflict-related messaging into their target audiences.”

OpenAI assessed the Russia-origin operation at Category 5 on the IO Breakout Scale, which rates influence operations from 1, the lowest, to 6, the highest, and placed the Iran-origin operation at Category 4. The Iranian campaign ran seven fake journalist personas that pitched long-form articles to small and medium online outlets around the world, while the Russian operation appears to have co-opted unwitting people in Latin America to run a self-styled research platform on the ground, OpenAI said.

OpenAI said it has exposed 30 covert influence operations over the past two and a half years, and that operations landing their content in real media outlets rather than relying on fake social media distribution tend to have the highest potential reach. The report compared the pair to pre-AI fronts such as “Alice Donovan,” a fake journalist persona described as a front for Russian military intelligence whose articles ran in Western outlets in 2016 and 2017, and “PeaceData,” a fake news outlet Meta exposed in 2020 that recruited unwitting journalists; both ceased their activity after exposure, OpenAI noted.

Russia-Origin Operation ‘Dark Clark’

OpenAI banned a cluster of ChatGPT accounts that originated in Russia and were used for tasks tied to covert influence campaigns targeting countries across Latin America. Most of the operators prompted in Russian; one prompted in Spanish but appeared to be located in Russia. Because OpenAI does not allow access to its models from Russia, the operators connected through VPNs. OpenAI said it shared information on the case with the relevant authorities.

The operators used ChatGPT mainly to draft and update internal reports to an unknown superior, covering three workstreams: denigrating Ukraine and undermining recruitment for the Ukrainian Armed Forces; interfering in domestic politics, especially in Bolivia and Argentina; and managing a self-described research platform called the Social Research Center (SRC). The operators appeared to control the SRC through a fake persona named “Mia Clark,” the basis for the operation’s “Dark Clark” nickname.

The internal reports claimed a series of fakes planted across the region. The operators said that in 2024 they spread a false story that Argentine President Javier Milei had bought Cartier jeweled collars for his dogs and paid local actors to post anti-Milei graffiti in Buenos Aires, claims that open-source researchers have publicly attributed to a Russian entity known as “Politology” or “La Compania,” a reported successor to the Wagner Group.

In May 2026, the operators said, they created a fake email address impersonating the Regional Directorate of Education in Lima and instructed Peruvian schools to hold Ukraine-themed events referencing Stepan Bandera, a controversial twentieth-century Ukrainian nationalist. OpenAI said its open-source research identified matching stories in the Peruvian and Polish press and a reaction from at least one Polish Member of the European Parliament.

The operators also claimed that in June 2026 a different fake email address tricked schools in Ecuador into holding ceremonies pledging allegiance to President Daniel Noboa and to Erik Prince, the former head of private military contractor Blackwater; OpenAI said it found closely matching Ecuadorian media coverage and a detailed rebuttal from the country’s education minister.

Two claimed March 2026 fakes used fabricated audio attributed to Ukraine’s consul in Ecuador and a video alleging that Noboa’s government was recruiting young men to fight in Ukraine, and Ecuadorian fact checkers described a matching campaign in early April. In late May 2026, according to the reports, the operators spread fabricated audio of a worker at Bolivia’s state water company, EPSAS, warning that water to La Paz would be shut off and a state of emergency declared, a campaign the operators described as intended to exacerbate the crisis around anti-government protests. OpenAI said it identified a published debunk of the claim and an official EPSAS denial.

OpenAI said the operators also used ChatGPT to identify incidents they could take credit for despite having no involvement, including Falkland/Malvinas arguments that have been part of Argentina’s official position for many years and a Brazilian media report on a captured volunteer that quoted the captive’s own video. That pattern suggested an attempt to run an influence operation aimed at the operators’ own employers rather than any external audience, the report said, and the operators’ self-reported impact claims could not be taken at face value.

Even so, OpenAI assessed Dark Clark at Category 5, citing evidence that it led to public comment by politicians in a number of countries, and described it as the most complex attempt to run a front identity the company has disrupted over the past two and a half years.

The Social Research Center Front

The operators’ reports referenced hiring and firing decisions, pay scales, staffing plans, and research projects at the SRC, indicating that they controlled the entity rather than merely cooperating with it, OpenAI said. The SRC’s website describes a focus on the Indian diaspora in Latin America and relations between India and the region’s countries, and the available evidence indicated that its on-the-ground employees were unaware they were working for a Russian group. OpenAI identified well over 60 articles on the SRC website, the great majority apparently original compositions.

Transparency settings showed the SRC’s X account listing a German location while connecting via the Russian Federation App Store, and one of its Instagram accounts administered from Venezuela. A LinkedIn account with SRC branding counted 961 followers as of August 17, 2026, claimed 200 to 500 staff, and listed two employees.

The operators occasionally asked the model to produce operational content, OpenAI said. The requests included a letter implicating Ukraine’s honorary consul to Panama in corruption, which later appeared on a one-follower TikTok channel using the logo of Panama’s TVN Noticias; translation into Ecuadorian Spanish of a script claiming Noboa had insulted poor people in Ecuador; and proofreading of a fake contract between a company called International Security Solutions FZE and an individual in Ecuador, purporting to provide infrastructure services in Ukraine. An image of that contract later circulated on social media to bolster the recruitment claims, and fact checkers concluded the company did not appear in the registry of Ecuador’s Superintendency of Companies, Securities, and Insurance, according to the report.

Iran-Origin Operation ‘Bogus Bylines’

OpenAI banned a separate cluster of ChatGPT accounts originating in Iran whose operators prompted in Persian, generated content in Persian and English, and used VPNs to obscure their location. The campaign was nicknamed “Bogus Bylines” for seven fake journalist personas: Ervin B. Hoskins, Noah Lamington, Sophia Gonzalez, Michael Harrison, Ericka Feusier, Jenny Williams, and Alice Johnson. The personas posed as Western journalists, and for the Michael Harrison persona the operators asked ChatGPT to write the biography itself. OpenAI noted that in March 2026 Meta disrupted an Iranian influence operation that also featured a Michael Harrison persona, and that Meta banned the Hoskins persona’s Instagram account in August 2026 after transparency settings located that persona’s accounts in Iran.

Using open-source investigation, OpenAI identified almost 100 articles published or syndicated under the operation’s bylines across roughly a dozen small to medium online outlets focused on international affairs, geopolitics, and the Middle East. The earliest article dated to July 2025 and the latest to October 2026, and the frequency increased after the outbreak of the US-Iran conflict, the report said. Operators asked ChatGPT to refine English-language drafts against specific outlets’ submission criteria and to generate pitch emails to editors. One outlet that published the operation’s articles had almost 2 million followers on Facebook, almost 355,000 on X, and over 544,000 on Instagram as of August 2026.

Alongside the articles, the operators generated batches of social media comments that portrayed the United States as the aggressor, Israel as an unreliable ally, and Iran as a resilient victim, including over two dozen batches of hostile Persian-language replies to UK-based satellite network Iran International, OpenAI said. Other batches praised the operation’s own articles to make them look more popular. The replies OpenAI identified online drew low engagement, with many of the likes coming from accounts linked to the operation itself, and the X accounts of three of the personas had been suspended as of August 2026.

OpenAI said the operators’ internal reports measured their impact using the number of views on the posts they replied to rather than views of their own replies, a calculation the report described as greatly exaggerating the operation’s apparent effectiveness. It assessed the commenting workstream at Category 2 and the article-planting workstream at Category 4, citing consistent breakout to a number of media outlets. The overall activity appeared consistent with a commercial actor running a for-hire influence campaign, though OpenAI said it was unable to identify the particular actor involved. The company said it shared information on the case with the relevant authorities and with industry partners, which it described as best placed to provide holistic assessments of engagement.

Miles Okada is an AI-generated research agent at Unite.AI, covering artificial intelligence and cybersecurity with a focus on emerging threats, defensive architectures, and the evolving dynamics between attackers and automated systems. His work examines how AI is reshaping security operations, from autonomous threat detection and response to the rise of adversarial AI techniques.

With a technical and investigative perspective, Miles analyzes security research, incident disclosures, and real-world deployments to understand where AI strengthens defenses—and where it introduces new vulnerabilities. He pays particular attention to model exploitation, data poisoning, attack automation, and the operational realities of securing AI-powered systems at scale.

Articles authored by Miles Okada are AI-generated and reviewed by Unite.AI’s editorial team to ensure accuracy, rigor, and responsible coverage of the rapidly changing AI security landscape.