The first category 5

OpenAI published a threat report on 8 October describing two banned clusters of accounts, one from Russia and one from Iran, both built around “false front” entities rather than fake social media crowds.

Using the IO Breakout Scale, which runs from 1 to 6, OpenAI assesses the Russia-origin operation as Category 5. It says this is the first Category 5 operation it has disrupted since it began reporting. The Iranian operation reached Category 4. Across the 30 covert influence operations OpenAI says it has exposed in the past two and a half years, the pattern it draws is that the ones which land content in real media outlets, rather than posting on social media, reach furthest.

A think tank whose staff did not know

The Russian cluster, which OpenAI nicknames “Dark Clark”, targeted Latin America. Most operators prompted in Russian; one prompted in Spanish but appeared to be in Russia. Because OpenAI does not serve Russia, they connected over VPNs.

They controlled a self-described research platform called the Social Research Center through a fake persona named “Mia Clark”. OpenAI says the internal reports referenced hiring and firing decisions, pay scales and staffing plans — the markers of control rather than cooperation — and that the available evidence indicates the SRC’s employees in Latin America were not aware they were working for a Russian group. OpenAI identified well over 60 articles on the site, most of them apparently original compositions by those staff. It calls this the most complex attempt to run a front identity it has disrupted.

A person reading a printed newspaper at a table
OpenAI found matching stories in the Peruvian and Polish press, some since deleted. Illustrative image. Mike van Schoonderwalt · pexels · Pexels License

Fake emails to schools

The tactics described are old-fashioned. In May 2026 the operators claimed to have created a fake email address purporting to come from the Regional Directorate of Education in Lima, instructing schools to hold events dedicated to Ukraine on 21 May and to reference the twentieth-century Ukrainian nationalist Stepan Bandera. According to the operators, some schools replied confirming they had held the events, and sent pictures.

They then claimed to have planted stories about those events in the Peruvian and Polish press. OpenAI’s own open-source searches found matching stories in both, and in an English-language publication in Hungary, some since deleted. Some carried a reaction from a Polish Member of the European Parliament proposing that people showing “anti-Polishness” be declared persona non grata. A similar scheme in June tricked schools in Ecuador into a ceremony pledging allegiance to President Daniel Noboa and to Erik Prince, drawing a detailed rebuttal from Ecuador’s education minister.

Older fakes line up with existing reporting: the operators claimed credit for a false story that Argentina’s president Javier Milei bought Cartier jewelled collars for his dogs, and for paying local actors to post anti-Milei graffiti in Buenos Aires. Open-source researchers have attributed both to a Russian entity known as “Politology” or “La Compania”, a reported successor to the Wagner Group.

They used the model to flatter themselves

The most striking finding is what the operators actually did with ChatGPT. In the majority of cases, OpenAI says, they were not generating campaign content at all — they were drafting and updating internal reports to an unknown superior.

And they inflated them. The operators asked the model to help identify incidents they could claim credit for even where they had not been involved, including arguments Argentina’s foreign ministry has made about the Falklands for decades, and a Brazilian captive’s own televised statement. OpenAI’s dry conclusion is that this “suggests an attempt by the operators to run an influence operation targeting their own employers”.

Stacked paper files and folders on an office shelf
The operators mostly used ChatGPT to draft internal reports to an unknown superior. Illustrative image. Zulfugar Karimov · pexels · Pexels License

Iran: seven journalists who do not exist

The Iranian cluster, nicknamed “Bogus Bylines”, pitched long-form articles under seven fake Western journalist personas. OpenAI identified almost 100 published or syndicated articles across more than a dozen outlets, the earliest from July 2025 and the latest from October 2026, with the rate rising after the outbreak of the US-Iran conflict. The accompanying batches of social media comments got almost no engagement, and OpenAI notes the operators used a deceptive calculation in their own reporting to make the numbers look better.

One persona, “Michael Harrison”, matches a name Meta disrupted in a separate Iranian operation in March.

What to watch

OpenAI’s argument for publishing is that false fronts are unusually vulnerable to exposure — it notes that both “Alice Donovan” and “PeaceData”, earlier Russian fronts, stopped once named. The test is whether the Social Research Center’s co-opted staff in Latin America, who appear to have been doing real research in good faith, now walk away from it.