METAL for iPhone

Read AI news in the METAL app.

Download METAL and discover fresh AI stories every day.

Download on the App Store

For iPhone · Free download

Search for METAL AI Magazine in the App Store on your iPhone.

METAL

OpenAI Disrupts Russian and Iranian False-Front Operations

OpenAI uncovered two Russian and Iranian false-front operations that hid behind a fake think tank and fake journalists, and banned the accounts involved. Russia's "Dark Clark" became the first operation to reach Category 5 on the breakout scale since OpenAI began reporting.

OpenAI Disrupts Russian and Iranian False-Front Operations

Image: METAL

Summary

  • On October 8, OpenAI published a threat report saying it had uncovered two influence operations, Russia-origin "Dark Clark" and Iran-origin "Bogus Bylines," and banned the ChatGPT accounts involved.
  • Dark Clark ran a Latin American research platform, the SRC, through a fake persona and used unwitting local staff, and it sent fake directives to schools in Peru and Ecuador that led to real press coverage and reactions from politicians.
  • Bogus Bylines placed nearly 100 articles in about a dozen outlets under seven fake journalist bylines; OpenAI rated the Russian operation Category 5 and the Iranian article pitching Category 4.

OpenAI on October 8 (local time) published a threat report saying it had uncovered two false-front operations originating in Russia and Iran and banned the related ChatGPT accounts. Both operations mixed AI with traditional techniques, put a fake think tank and fake journalists out front, and laundered geopolitical messaging under other people's names into real media outlets. OpenAI assessed the Russia-origin operation as Category 5 on the influence-operation Breakout Scale (1 to 6). It is the first Category 5 operation OpenAI has disrupted since it began reporting.

OpenAI named the Russian operation "Dark Clark." The accounts targeted countries across Latin America, seeking to undermine Ukraine's reputation and interfere in politics in Argentina and Bolivia. Most operators prompted in Russian, and the one who used Spanish also appeared to be in Russia. OpenAI said the operators used VPNs to get around its block on access from Russia. The task they used ChatGPT for most was not producing propaganda but writing internal reports for an unknown superior.

The operation's front was a research platform in Latin America called the Social Research Center (SRC). On the surface, the SRC said it studied the Indian diaspora in Latin America and relations between India and the region. The operators created a fake persona, "Mia Clark," to run the SRC's social media and deal with local staff, and their reports covered pay scales, hiring and firing decisions. According to OpenAI, the local employees did not know they were working for a Russian operation and carried out expert interviews and research in good faith. The SRC website carried well over 60 articles, most of them original rather than plagiarized. As of August 17, a LinkedIn account under the SRC name had 961 followers and claimed 200 to 500 staff, but listed only two employees.

The fakes touched the real world. In May 2026, the operators impersonated the Regional Directorate of Education in Lima, Peru, emailing schools to hold events dedicated to Ukraine on the Day of Cultural and Linguistic Diversity on May 21 and to reference the controversial nationalist Stepan Bandera. The operators reported that some schools replied with confirmation and even photos. Stories about the events then appeared in Peruvian and Polish media, and a Polish Member of the European Parliament proposed declaring people who showed "anti-Polishness" persona non grata. In June, the operators sent a fake directive telling schools in Ecuador to hold a ceremony pledging allegiance to President Daniel Noboa and former Blackwater head Erik Prince, and Ecuador's Minister for Education issued a rebuttal. In Bolivia, at the height of anti-government protests in late May, a fake audio clip impersonating a worker at the state water company EPSAS spread claims of a water shutoff in La Paz and a state of emergency.

The Iranian operation was named "Bogus Bylines." The operators prompted in Persian and hid their location with VPNs. Their core technique was to use ChatGPT to polish long-form English articles on the US-Iran conflict to fit a specific outlet's submission criteria, and then to write the pitch emails to editors. The pitches went out under seven fake bylines: Ervin B. Hoskins, Noah Lamington, Sophia Gonzalez, Michael Harrison, Ericka Feusier, Jenny Williams and Alice Johnson. The accounts of Hoskins, who claimed to be "an American freelance writer," were located in Iran according to transparency settings. OpenAI found nearly 100 articles published under these bylines across about a dozen online outlets, one of which had almost 2 million followers on Facebook. The first article appeared in July 2025 and the latest in October 2026, and articles clustered from March 2026, after the US-Iran conflict broke out.

The same operation's comment campaign fared poorly. The operators fed in screenshots of posts and generated batches of replies portraying the US as the aggressor and Iran as a resilient victim, posting them minutes apart, and they produced more than 20 batches of hostile Persian-language replies to posts by Iran International, a satellite broadcaster critical of the regime. The likes, views and replies on the comments OpenAI found were in the single or double digits. OpenAI rated the commenting at Category 2 and the article pitching at Category 4. In their internal reports, the operators inflated their numbers by counting views on the original posts as their own impact.

"What is most striking about these operations is that they closely resembled complex influence operations of the pre-AI age, but used AI to make some of the workflows easier," OpenAI wrote in the report. OpenAI noted that the Iranian fake journalists resembled "Alice Donovan," a fake journalist run by Russian military intelligence whose articles appeared in Western outlets in 2016-17, and that the SRC resembled "PeaceData," a fake outlet that Meta exposed in 2020. According to a chart in the report that METAL reviewed, of the 30 operations exposed since early 2024, the 18 centered on social media and the 8 centered on their own websites all stayed at Category 3 or below; the only ones at Category 4 or above were the 4 that placed content in external publications.

METAL has previously reported on OpenAI banning a batch of Russia-origin ChatGPT influence accounts in August and on Anthropic's report disclosing eight months of Claude misuse cases. OpenAI said it shared information on both cases with the relevant authorities. It added that the Iranian operation looked consistent with a commercial actor running a for-hire campaign, but that it could not identify the specific actor.

오픈AI가 2024년 초 이후 공개한 영향력 공작 30건을 주된 유포 경로와 확산 등급으로 나눈 표 — 외부 매체에 글을 실은 공작만 4·5등급에 올랐다

From a sociological perspective, the vulnerability this report exposes is not technology but the pathways of trust. The operations targeted not algorithms but editors who accept submissions, school staff who trust official letters and local researchers working for a salary. "The covert nature of these false-front operations also makes them particularly vulnerable to responsible disclosure," OpenAI said, noting that both "Alice Donovan" and "PeaceData" ceased activity after they were exposed. According to reports, OpenAI hopes the disclosure will make further research and disruption easier.

Comments