OpenAI said on October 8, 2026 that it banned two covert influence operations, one from Russia and one from Iran, that used ChatGPT to support "false front" entities: seven invented journalists in the Iranian case, and a think tank staffed by unwitting people in Latin America in the Russian case. The Russian operation, nicknamed "Dark Clark," is rated Category 5 on the six-point IO Breakout Scale, which OpenAI says is the first Category 5 operation it has disrupted since it began publishing these reports.
The headline is not "AI makes propaganda unstoppable." OpenAI's own conclusion is closer to the opposite: these operations looked a lot like pre-AI influence campaigns, and AI mostly made the paperwork and polishing easier. The more important finding is about distribution: operations that land content in real media outlets travel much further than those that rely on fake social accounts.
Quick reference
| Item | Russian operation ("Dark Clark") | Iranian operation |
|---|---|---|
| Front entity | "Social Research Center," a Latin America think tank | Seven "journalist" personas |
| Main targets | Ukraine's reputation; politics in Argentina, Bolivia, Ecuador, Peru | Audiences around the world, topics around the US-Iran war |
| Content | Fake "leaked" documents, audio scripts, reports | Long-form articles pitched to small and medium outlets, batches of social comments |
| Breakout Scale rating | Category 5 (first ever for OpenAI) | Category 4 |
| How it reached ChatGPT | VPNs, since OpenAI does not offer access from Russia | Not covered here |

What OpenAI actually reported
OpenAI frames the report as the latest in a series spanning two and a half years, covering cyber attacks, scams and influence operations. In that time it says it has exposed 30 covert influence operations, and it plots them in a matrix by primary distribution method (social media, operation-run website, external publications) against Breakout Scale score.
The two newly banned operations both used what OpenAI calls false fronts: entities that look independent but are controlled by the operator.
- Iran: a stable of seven journalist personas pitched long-form articles to small and medium online outlets worldwide. The operation also generated batches of social media comments, mostly on topics related to the US-Iran war.
- Russia: operators appear to have co-opted unwitting people in Latin America to run a "think tank" on the ground, and also produced fake "leaked" documents and audio scripts, some of which OpenAI saw spreading online.
Both operations also used AI to draft internal reports, which the Russian operators did more than anything else. OpenAI adds that in both cases the actors used "questionable or outright deceitful methodologies" to exaggerate how effective they were.
Dark Clark in detail
OpenAI banned a cluster of ChatGPT accounts originating in Russia that targeted Latin America. Much of the activity aimed to undermine Ukraine's reputation in the region, with some aimed at local political outcomes, particularly in Argentina and Bolivia. Most operators prompted in Russian; one prompted in Spanish. OpenAI says it shared information on the case with the relevant authorities.
The name comes from "Mia Clark," the fake persona the operators appear to have used to control the Social Research Center (SRC). The SRC's website describes a focus on the Indian diaspora in Latin America. According to the operators' own reports, they made decisions on pay, hiring and firing, which OpenAI reads as control rather than cooperation. The evidence, it says, indicates the SRC's employees in Latin America did not know they were working for a Russian group, and did research in good faith. OpenAI identified well over 60 articles on the SRC site, most of them original compositions, which separates it from another Russia-linked think tank front OpenAI exposed recently that plagiarized most of its content.
Why it is rated Category 5
OpenAI points to two unusual features. First, it calls this the most complex attempt to run a front identity it has disrupted. Second, open-source evidence suggests some of the fakes spread widely enough to provoke fact checks and official denials, a degree of penetration beyond anything it disrupted in the past two years.
Examples OpenAI cites from the operators' internal reports, with its own corroboration notes:
- Peru and Poland, May 2026: a fake email address posing as a Lima education directorate told schools to hold Ukraine-themed events and reference Stepan Bandera. Operators claimed they then planted stories in Peru and Poland alleging that Ukraine was "exporting" ultra-nationalism. OpenAI says matching stories appeared in Peruvian and Polish press, and in a Hungarian English-language outlet, some since deleted, and that the fake fed into Ukraine-Poland tensions.
- Ecuador, June 2026: a different fake email tried to get schools to hold a ceremony pledging allegiance to President Daniel Noboa and Erik Prince. OpenAI found press coverage matching the claim and a detailed rebuttal from Ecuador's Minister for Education.
- Ecuador, March 2026: fake audio attributed to Ukraine's consul, and a fake video under a genuine news channel's logo. OpenAI found a matching TikTok post that got limited engagement, and fact checks of the video in April.
- Bolivia, late May 2026: fake audio of a supposed worker at the state water company EPSAS saying water to La Paz would be cut. OpenAI found a debunk and an official EPSAS denial.
Other claims could not be corroborated, such as a story about a Brazilian influencer, fake audio about the Central Bank of Bolivia and a fake fuel-sales letter. OpenAI notes these may have been taken down or may simply have failed to spread.
Claiming credit for things they did not do
A revealing detail is how much of ChatGPT use went into padding the operators' own reports. They asked the model to help find incidents they could take credit for. One example: they claimed Argentina's Foreign Minister cited their operation at a UN committee meeting on the Falklands/Malvinas, while OpenAI notes the arguments are long-standing official Argentine positions. Another: they tried to claim a Brazilian news story about a citizen captured in Ukraine reproduced their messaging, when it quoted the captive's own video. OpenAI reads this as possibly an influence operation aimed at the operators' own superiors.
Where the operators did ask for content, it was small in proportion: help matching accent, vocabulary and institutional style by country, a Russian-language draft of a letter implicating Ukraine's honorary consul to Panama in corruption, then a Spanish translation and an audio script, later posted on TikTok by an account posing as a news outlet.
The pre-AI lineage
OpenAI draws a deliberate historical line. The Iranian personas resemble "Alice Donovan," a front for Russian military intelligence whose articles ran in Western outlets in 2016-17. The unwitting-staff think tank echoes "PeaceData," which Meta exposed in 2020 as tied to people associated with the Internet Research Agency. Both of those fronts stopped after exposure, which is why OpenAI argues that publishing details makes continuing such operations harder.
That framing matters for how you read the news. If AI were the decisive ingredient, you would expect very different tradecraft. Instead the pattern is: invent a credible source, get real people to carry it, and let ordinary media dynamics do the amplification. AI lowers the cost of fluency, translation and volume. It does not solve the hard part, which is getting a real editor or a real employee to take the bait.
What this means for builders and readers
- For platform and product teams: the report is a reminder that abuse often shows up as boring productivity use (report drafting, translation, style matching), not as obviously malicious prompts. Detection tends to depend on behavioral signals across accounts, which is what this report describes.
- For editors and journalists: the highest-reach operations in OpenAI's dataset are the ones that placed content in mainstream outlets. Checking a new contributor's identity and history matters more, not less, with cheap fluent prose.
- For analysts: be careful with self-reported impact. The Dark Clark reports show operators inflating results, so an operation's claimed reach is not evidence of real reach.
- For everyone: a fake leak, a fake consular audio clip or a fake official email is a social-engineering attack with a media payload. The same verification habits apply as for deepfake-enabled fraud.
What is not yet confirmed
This post relies on OpenAI's own report. We have not independently verified the open-source corroboration it cites, and details of the Iranian operation beyond the summary above are not covered here. OpenAI says open-source researchers have attributed some of the Russian fakes to "Politology" or "La Compania," and that in two cases its evidence ties the operators to that public reporting. Treat all attributions as OpenAI's and researchers' assessments, not court findings. Governments and the outlets named may respond in the coming days.
How this fits the rest of the AI-misuse picture
This report concerns people misusing models. A different, growing category involves AI agents acting on third parties on their own or after being talked into it. See our coverage of hackers talking Cursor's agent into breaching seven companies, an OpenAI agent that breached an Australian government portal, and the Netflix and Hugging Face agent incident record. We track agent incidents in Felony Bench, and the legal angle is in our CFAA liability explainer. For how OpenAI tests models before release, see deployment simulation, and for the security side of agent platforms see AgentCorruption on AWS Bedrock AgentCore.
OpenAI's earlier influence-operation reporting is also useful background: in May 2024 it removed operations tied to Russia, China and Israel and found they had not gained significant traction with real audiences. The October 2026 report suggests the interesting change is not the model quality but the operators' move toward real outlets and real, unwitting people.
Related reading
- Hackers talked Cursor's AI agent into breaching 7 companies
- OpenAI agent and the Australian Medicare portal breach
- Felony Bench and AI agent legal liability
- Deepfake fraud and video-call verification
- OpenAI deployment simulation for pre-release safety
- Official OpenAI report
Details reflect OpenAI's report as published on October 8, 2026 and may be updated as OpenAI, researchers and affected governments add information.
