Disrupting AI-enabled “false front” operations
Over the past two and a half years, OpenAI has reported on threat actors using its models for cyber attacks, influence operations, scams, and other policy violations. They disrupted a Russia-origin operation, assessed as Category 5 on the IO Breakout Scale, and an Iran-origin operation, assessed as Category 4. Both operations managed to place content, some not AI-generated, in mainstream media, indicating a pattern of higher potential reach and impact when targeting real media outlets rather than social media. One example involved a fake email from a Peruvian education directorate instructing schools to hold Ukraine-themed events referencing Stepan Bandera.
Time & source
Times shown in UTC
Display time zone: UTC
Local time zone unavailable; showing UTC.
PublishedOffset at this time: UTC+0Oct 8, 2026, 00:00 UTC
IngestedOffset at this time: UTC+0Oct 8, 2026, 16:00 UTC
- Published
- Oct 8, 2026, 00:00
- Ingested
- Oct 8, 2026, 16:00
- Source type
- Official
- Tier
- First-party
- Source status
- Healthy
Tier is a per-source editorial setting, not a per-item score.
Discussion trend
The percentage is based on collected discussion signal, not new comments or independent people. The curve only compares the same topic across time.
Over the past two and a half years, we’ve reported on many of the ways in which threat actors tried to use our models to conduct cyber attacks, covert influence operations (IO), scams, and other violations of our Usage Policies. We publish these reports to inform regulators, our industry peers, and wider society of how we see threat actors trying to leverage AI, and to shine a light on the vulnerabilities they try to exploit.
We recently banned two IO—one from Russia and one from Iran—that used our models in combination with more traditional techniques and technologies to support sophisticated “false front” entities. They used those entities to launder geopolitical, conflict-related messaging into their target audiences. The Iranian operation included a stable of seven “journalist” personas which it used to pitch long-form articles to small and medium online outlets around the world; the Russian operation appears to have co-opted unwitting people in Latin America to run a “think tank” on the ground.
Both operations were multi-dimensional, trying a range of different tactics to achieve their goals. As well as long-form articles, the Iranian operation generated batches of social media comments, generally on topics related to the US-Iran war. As well as controlling the “think tank,” the Russian operation created fake “leaked” documents and audio scripts, some of which we identified being spread online. Both operations also made heavy use of AI to draft internal reports (the Russian operation did this more than anything else); in both cases, the actors used questionable or outright deceitful methodologies to exaggerate the operators’ effectiveness.
What is most striking about these operations is that they closely resembled complex influence operations of the pre-AI age, but used AI to make some of the workflows easier. The journalist personas run by the Iranian operation bore a family resemblance to the fake journalist “ Alice (opens in a new window) Donovan (opens in a new window) ,” a front for Russian military intelligence whose articles were published by a range of Western outlets in 2016-17. In 2020, individuals associated with past activity by the Russian Internet Research Agency ran a fake “news” outlet called “ PeaceData (opens in a new window) ,” which co-opted unwitting journalists around the world into writing for it.
These operations were also unusual for their potential reach. Using the IO Breakout Scale (opens in a new window), which rates IO on a scale of 1 (lowest) to 6 (highest), we would assess the Russia-origin operation as belonging in Category 5. This is the first Category 5 operation we’ve disrupted since we began our reporting. The Iran-origin operation reached Category 4. Both managed to land their content (not all of which was generated from our models) in mainstream media outlets, rather than simply posting it on social media. This is consistent with a pattern we’ve observed across the 30 covert influence operations we’ve exposed in the last two and a half years: the operations which try to land their content in real media outlets, rather than relying on fake social media distribution, tend to have the highest potential reach and impact.
Matrix of the 30 IO we’ve exposed since early 2024, assessed by primary distribution method (social media, operation-run website, external publications) and score on the Breakout Scale. Operations which used more than one distribution method, such as running a website and promoting it on social media, are classified by the method which appeared to constitute the core of the operation.
AI can give such false-front operations greater scale, efficiency, linguistic fluency, and editorial ability. The operators can use these advantages to exploit unsuspecting victims, such as employees or editors, and plant their content in front of audiences who have no idea who was behind it, or what their motivations were. These operations also demonstrate the complexity and sophistication of threat actors’ use of false personas and entities to achieve their goals. Understanding the vulnerabilities that threat actors exploit in these efforts, and how those vulnerabilities can translate into audience and reach, will be essential to maintaining robust defenses across organizations.
But the covert nature of these false-front operations also makes them particularly vulnerable to responsible disclosure. Both “Alice Donovan” and “PeaceData” ceased their activity after they were exposed. That’s why our goal in reporting these false-front operations is to make further research and disruption easier—and make continuing the operations harder.
Russia: Operation “Dark Clark”
Russia-origin actors running influence campaigns across Latin America.
Actor
We banned a cluster of ChatGPT accounts that originated in Russia. They used ChatGPT for a range of tasks associated with covert influence operations targeting countries across Latin America. Much of this activity appeared aimed at undermining Ukraine’s reputation in the region, but some appeared aimed at influencing local political outcomes, especially in Argentina and Bolivia. Most of the operators prompted in Russian; one prompted in Spanish, but nevertheless appeared to be located in Russia. We have shared information on this case with the relevant authorities.
The operators used ChatGPT to perform three main tasks: writing internal reports on their activities (and other people’s activities which they could plausibly take credit for), creating content for their operations, and drafting reports on the performance of a self-described “research platform” in Latin America called the Social Research Center (SRC). They appear to have controlled the SRC via a fake persona named “Mia Clark”; in honor of the name, we have nicknamed this operation “Dark Clark.” Since we do not allow access to our models from Russia, they used VPNs to connect to our services.
In their internal reports, the operators claimed to have spread fake stories across Latin America to undermine Ukraine or local leaders. Some of these fakes have been attributed by open-source (opens in a new window) researchers (opens in a new window) to a Russian entity known as “Politology” or “La Compania,” a reported successor to the Wagner Group and other entities founded by Russian oligarch Yevgeniy Prigozhin. The operators also asked our models to translate or explain public reporting about Politology and Wagner, far more than asking about any other Russia-origin networks.
This operation was unusual in two ways. First, it appears to have successfully co-opted individuals in Latin America to work for the SRC. The Russian operators’ reports on the SRC referred to decisions over issues such as pay scales, hiring, and firing, suggesting that they controlled the entity, rather than cooperating with it. The available evidence indicates that the SRC’s employees in Latin America were not aware that they were working for a Russian group. Unlike another Russia-linked “think tank” that we recently exposed, the SRC appears to have produced a majority of original content via its co-opted staff. This stands out as the most complex attempt to run a front identity that we’ve disrupted over the past two and a half years.
Second, some open-source evidence suggests that Dark Clark’s fakes spread widely enough to provoke fact checks (opens in a new window) and official denials (opens in a new window), indicating a degree of penetration which goes beyond any of the influence operations we disrupted over the past two years. One fake that the operation claimed to have planted in Peru even fed into public tensions between Ukraine and Poland.
Internal reporting
The main way the operators used ChatGPT was to draft and update internal reports to an unknown superior. These regular reports described efforts to conduct covert influence campaigns across Latin America. They encompassed three main workstreams: efforts to denigrate Ukraine and undermine recruitment for the Ukrainian Armed Forces; efforts to interfere in the domestic politics of certain countries, especially Bolivia and Argentina; and management of the SRC. In the majority of cases, we did not observe the threat actors using our models to create content for the campaigns, only to report on them (the few exceptions are described below ).
The reports were rich in tactical detail, shining a light on how the operation sought to undermine Ukraine and some national leaders, notably the presidents of Argentina, Bolivia, and Ecuador. Some described efforts to trick locals into carrying out activities that the operators could weaponize; others described fake “leaks” that the operators claimed to have spread.
In two cases, the evidence ties the operators to public reporting on “Politology.” The operators reported that, in 2024, they ran two campaigns targeting Argentina’s President Javier Milei. First, they said they spread a false report that Milei had bought Cartier jeweled collars for his dogs. Second, they claimed that they paid local actors to post anti-Milei graffiti in Buenos Aires. Based on leaked documents, both these claims have been publicly (opens in a new window) attributed (opens in a new window) to “Politology” and “La Compania.”
Many more fakes have not been previously tied to Russian IO. For example, the operators claimed that in May 2026, they created a fake email address purporting to come from the Regional Directorate of Education in Lima, Peru. They used this to instruct schools in the district to hold events dedicated to Ukraine on the national Day of Cultural and Linguistic Diversity (May 21). The emails included explicit instructions to reference, among others, controversial twentieth-century Ukrainian nationalist Stepan Bandera, who is seen by some Ukrainians as an independence figure, but associated in Russia and Poland with fascism, wartime collaboration, and atrocities. According to the operators, some schools replied to the fake email address, confirming that they had held such events and even providing pictures.