Money and business in the Middle East.

AI

OpenAI bans Russian network it rates most severe influence operation yet

A Russia-origin network that used ChatGPT to run a fake research platform across Latin America has been rated the most severe covert influence operation OpenAI has disrupted to date.

· Originally published by ontime+ · Last verified: 8 Oct 2026 (Nada Salam)

Key Points

  1. OpenAI banned two covert influence networks, one Russia-origin and one Iran-origin, that used ChatGPT for false-front content.
  2. The Russian cluster targeted Latin America with fabricated audio, video and letters, driving real reactions from governments and schools.
  3. OpenAI rated it Category 5 on the Brookings Breakout Scale, the first operation at that level it has disrupted.

The latest:

A Russia-origin network that used ChatGPT to run a fake research platform across Latin America has been rated the most severe covert influence operation OpenAI has disrupted to date. The company said in an October 8 announcement that it banned the cluster along with a separate Iran-origin operation that placed nearly 100 articles under invented journalist bylines.

Details:

  • The Russian cluster: OpenAI said accounts originating in Russia, dubbed Dark Clark, targeted Latin America mainly to damage Ukraine’s reputation, with some activity aimed at politics in Argentina and Bolivia. Operators prompted largely in Russian and relied on VPNs because OpenAI blocks direct access from inside Russia.
  • The false front: According to OpenAI, the operators used ChatGPT to draft internal reports, produce content and write performance reviews for a fabricated outfit called the Social Research Center, steered through an invented persona named Mia Clark. The platform published more than 60 mostly original articles.
  • The attribution: OpenAI said open-source researchers linked some of the fake personas to Politology, also referred to as La Compania, described as a successor network to the Wagner Group and to entities founded by Yevgeniy Prigozhin. OpenAI did not itself name a sponsoring state body.
  • Real-world effects: OpenAI listed a fake email that led Peruvian schools to hold Ukraine-related events referencing Stepan Bandera, drawing comment from a Polish MEP, and another that pushed Ecuadorian schools into a pledge ceremony honoring President Daniel Noboa and Erik Prince. Ecuador’s education minister issued an official rebuttal.
  • Fabricated media: The operation also circulated fake audio attributed to Ukraine’s consul in Ecuador, a fake video claiming Noboa’s government was recruiting men to fight in Ukraine, a fabricated clip alleging a water shutoff in La Paz during anti-government protests, later debunked, and a forged letter implicating Ukraine’s honorary consul to Panama in corruption.
  • The severity rating: OpenAI placed Dark Clark at Category 5 on the Brookings Breakout Scale, the first time it has assigned its top tier. The company said the rating reflects the operation’s reach beyond online platforms into institutional responses by governments and schools.
  • The Iranian cluster: A second network, labeled Bogus Bylines, ran from Iran and prompted in Persian while generating output in Persian and English. OpenAI said ChatGPT was used to polish long-form articles, pitch emails and social media comments pushed through seven invented journalist identities.
  • The placement: Nearly 100 articles were published or syndicated across roughly a dozen small-to-medium outlets, mostly covering the US-Iran conflict, with volume rising sharply after fighting began. OpenAI rated the articles Category 4 because they reached outlets with large followings, and the comment activity Category 2.
  • Low engagement: Batches of replies, often posted minutes apart, pushed anti-US and anti-Israel narratives, including more than two dozen batches of hostile Persian replies aimed at Iran International. OpenAI said engagement was very low and the campaign resembled commercial for-hire work, but it could not identify the actor.
  • The pattern: OpenAI said both operations closely resembled pre-AI influence campaigns and used the models mainly to accelerate existing workflows rather than invent new tactics. Operations placing content inside real media outlets, instead of relying on social platforms alone, achieved the widest reach.

Background:

OpenAI publishes periodic reports on malicious uses of its models. The company said this latest action brings the total number of covert influence operations it has exposed to 30 over roughly the past two and a half years.

Between the lines:

The severity rating turns less on content volume than on consequence: the Russian cluster produced just over 60 articles, fewer than the Iranian network’s nearly 100, yet earned the higher tier because schools held events and a sitting education minister was forced to respond publicly. OpenAI’s own finding that placement in real outlets drives reach points the same way — distribution channels, not generation speed, decide impact.

What’s next

Watch whether the Category 5 designation recurs in OpenAI’s next disruption report, whether governments in Ecuador, Peru or Bolivia pursue formal investigations, and whether the unidentified actor behind the Iranian for-hire campaign is named.

Read on ontime+ ↗