OpenAI has banned ChatGPT accounts behind two state-linked influence operations, one Russian and one Iranian, which hid behind a fake think tank and invented Western journalists. The Iranian effort aimed hostile comments at UK-based broadcaster Iran International, and the Russian one is the first operation OpenAI has rated at the top of its impact scale.
What happened
On 8 October 2026 OpenAI published a report describing how it disrupted two covert influence operations that had been using its models. The company says it banned the clusters of ChatGPT accounts involved and passed information to the relevant authorities.
The first operation, which OpenAI calls “Dark Clark”, originated in Russia and targeted audiences across Latin America. Its centrepiece was a self-styled research platform called the Social Research Center (SRC), presented as a body studying the Indian diaspora in the region. According to OpenAI, Russian operators ran it through an invented manager persona, “Mia Clark”, while the local people writing for it appear to have had no idea who they were really working for. Open-source researchers have linked some of the material to a group known as Politology or La Compania, described as a successor to entities founded by Yevgeniy Prigozhin.
The second operation, “Bogus Bylines”, originated in Iran. It used seven fabricated journalist identities, most claiming to be American, to pitch long-form opinion pieces to online publications. OpenAI counted close to 100 pieces in around a dozen outlets, dating from July 2025 to this month, with output climbing sharply once the US-Iran conflict began. OpenAI could not name the actor behind it but says the activity looked like a commercial, for-hire campaign.
How it works
Neither operation used AI for anything exotic. OpenAI’s own summary is that both “closely resembled complex influence operations of the pre-AI age”, with the model making routine workflows easier. For defenders, the tradecraft is old but the cost of running it has fallen.
For Dark Clark, the main use of ChatGPT was administrative. Operators wrote and updated internal reports for an unidentified superior, translated Russian drafts into Spanish, checked accents and institutional tone, wrote audio scripts and even proofread a forged contract. The fakes themselves were a mix of documents, audio and video. OpenAI ties the operation to, among other things, fabricated audio attributed to a Ukrainian consul in Ecuador, a forged email instructing schools in Lima to hold Ukraine-themed events that referenced Stepan Bandera, and a fake recording of a La Paz water company worker warning of supply cuts, which the utility publicly denied. Several drew fact-checks or official rebuttals; other claims in the internal reports could not be verified.
Bogus Bylines used the model to polish articles, check drafts against each outlet’s submission rules and write the pitch emails sent to editors. The personas were backed up with profiles on X, Facebook, Instagram, Threads and Medium. Alongside the articles, the operators produced batches of replies in English and Persian on missile strikes, ceasefires and diplomacy, casting the United States as the aggressor and Iran as a resilient victim. Those replies won little genuine engagement, and the operators flattered their own results by counting views on the posts they replied to rather than on their replies.
OpenAI scores operations on its Breakout Scale, which measures how far content travels beyond the platforms where it was planted. Dark Clark reached Category 5, the first time OpenAI has given that rating since it began reporting. The Iranian operation was rated Category 4 overall, because its articles landed in real outlets, one of which had around two million Facebook followers.

Why it matters for UK organisations
The UK is not a bystander here. OpenAI says the Iranian operators posted more than two dozen batches of hostile Persian-language replies under posts from Iran International, the London-based broadcaster that is openly critical of the Iranian government. Any UK newsroom, think tank, diaspora group or campaign organisation that criticises Tehran should assume it can be a target of this kind of coordinated pile-on, and that the accounts doing it may look Western at first glance.
The bigger lesson is about the supply chain of content. Both operations got furthest when they placed material in third-party publications, not when they ran their own social accounts. UK editors who accept freelance or syndicated opinion pieces, and organisations that cite “independent research” in briefings, are exactly the route these groups want to exploit. A front organisation with plausible staff, original articles and a LinkedIn page is far harder to spot than a bot network. OpenAI found the SRC’s LinkedIn page claimed 200 to 500 staff while listing just two employees, the kind of inconsistency that basic due diligence can catch.
Expert view
In my experience, organisations treat influence operations as someone else’s problem, usually the platforms’ or the government’s. This report is a useful corrective. The attack surface it describes is an editorial inbox, a commissioning process and a communications team’s habit of trusting a professional-looking source. None of that is protected by a firewall.
When we run social engineering exercises, the most effective pretexts are rarely technical. They rely on a believable identity with a little backstory and a reason to be helpful. The fake journalists here followed the same pattern, and a language model removes the tell-tale spelling and fluency problems that used to give non-native operators away. That shift matters far more than any claim that AI makes propaganda more persuasive.
I would be cautious about the headline numbers, though. The Iranian replies largely went nowhere; the real risk is the handful of placements that reach legitimate audiences, as when the Bandera story drew comment from a Polish MEP.
What to do now
- Verify contributors before you publish them. Media, academic and policy organisations should confirm the identity of new freelance writers through a video call, a verifiable employment history or a known referee, not just an email address and a social profile.
- Check front organisations properly. Before citing or partnering with an unfamiliar research body, look for company registration, named staff who can be contacted, and consistency between claimed headcount and visible people.
- Prepare for coordinated harassment. If you publish on Iran, Russia or Ukraine, set up monitoring for sudden bursts of hostile replies, document them and report them to the platform. Brief staff so they do not engage.
- Protect the accounts that speak for you. Hijacked or impersonated corporate accounts amplify these campaigns. Apply Cyber Essentials user access control: multi-factor authentication on every social media and publishing account, named owners and prompt removal of leavers.
- Write a disinformation response plan. Decide in advance who confirms or denies a forged letter or audio clip in your organisation’s name, and how quickly. The Bolivian water utility’s public denial is the kind of rebuttal to have ready.
Bottom line
OpenAI’s report shows state-linked groups using AI as an office assistant for influence work rather than as a weapon in its own right. The result is cheaper, more fluent and more durable fakery that is most dangerous when it slips into legitimate publications. UK organisations that commission content, cite research or criticise hostile states should tighten verification now, because the barrier to building a convincing false front has dropped.
Sources
- OpenAI: Disrupting AI-enabled “false front” operations
- The Record: OpenAI says it disrupted Russian and Iranian influence ops that used ChatGPT
- Euronews: Iran and Russia used ChatGPT for propaganda by ‘fake journalists’, OpenAI says
- Anadolu Agency: OpenAI says it banned accounts linked to Russian, Iranian influence operations