OpenAI published a threat intelligence report on October 8 disclosing that it had banned two covert influence operations that abused ChatGPT. One originated in Russia and targeted Latin America; the other originated in Iran and targeted small and mid-sized online news outlets scattered around the world. Despite the different origins and targets, both operations followed essentially the same playbook: build a credible-looking “front” first, then lean on it to push content out to real audiences.
OpenAI rated the Russian operation a Category 5 on its Breakout Scale, the highest rating the company has issued since it started publishing this kind of report. The scale runs from 1 to 6, and a higher number means the content managed to travel further — across more platforms and more distinct audiences — pulling closer to mainstream political discourse rather than staying contained in a small corner of the internet.
Russia: a “think tank” run by real people
OpenAI gave the operation the internal name Dark Clark. Its operators invented an AI journalist persona named Mia Clark and presented her publicly as the head of a “Social Research Center,” or SRC. That center, notably, has real, flesh-and-blood staff working in Latin America, and the evidence OpenAI gathered shows those employees had no idea they were actually working for a Russian group operating behind the SRC's name.
The content the operation pushed out was concentrated on damaging Ukraine's image across Latin America and nudging local politics in a particular direction. The cases documented in public reporting span Argentina, Bolivia and Ecuador, and they include a fabricated audio clip in which a Ukrainian consular official can be heard insulting Ecuadorian citizens, plus a fabricated story claiming that shell companies in Ecuador were quietly recruiting combatants to fight on Ukraine's behalf. Both pieces of content were picked up and fact-checked by mainstream Latin American outlets, and both drew official denials once they surfaced.
Beyond the public-facing content, the operators also leaned on ChatGPT to handle mundane internal business — things like setting wage rates for staff and making hiring decisions for the front. OpenAI's own assessment of the operation's sophistication was blunt:
“The most complex attempt to run a front identity that we've disrupted over the past two and a half years.”
Iran: seven fake reporters, nearly 100 bylined articles
The Iranian operation, which OpenAI calls Bogus Bylines, kept up seven distinct “journalist” personas at once. Those personas pitched long-form articles — most of them centered on the broader U.S.-Iran conflict — to small and mid-sized online outlets around the world that cover international affairs, while a separate, parallel effort mass-produced social media comments to accompany the articles.
“We identified almost 100 articles published or syndicated under the operation's bylines across roughly a dozen online outlets around the world.”
OpenAI rated the article-placement side of that operation a Category 4 on the Breakout Scale. Its reach on social media, by contrast, only hit Category 2 — the posts went out, but genuine, organic engagement with them was minimal.
Looking back at the 2024 report
OpenAI first published this kind of threat report back in May 2024, when it named five separate operations tied to Russia, China, Iran and Israel. None of those five broke above Category 2 on the Breakout Scale at the time. More than two years on, a single operation has now reached Category 5 — and what changed in between is less the ambition than the method. Both of the newly disclosed operations paired AI tools with decidedly old-fashioned tactics: hiring real staff, pitching articles the traditional way, and standing up entire institutions as cover. AI handled the parts that scale — churning out bulk copy and keeping fabricated personas consistent over time — while actual human beings did the work of making the front look believable to outsiders.
Banning accounts only severs one link in that chain: the ChatGPT piece. The public reporting this article draws on doesn't say how many accounts were banned in total, doesn't say whether the SRC is still operating on the ground in Latin America, and doesn't address how OpenAI — or anyone else — is handling the unwitting employees who worked there, or the outlets that unknowingly published the operation's articles.
Sources: OpenAI threat intelligence report, CyberScoop, CocoLoop, France 24; CyberScoop and France 24 cross-checked the Breakout Scale ratings and article counts for both operations.