Full Report
A Latin American propaganda operation run by Russians and a cluster of Iranian fake journalist identities each had help from now-closed ChatGPT accounts, OpenAI's safety team said.
Analysis Summary
# Incident Report: Disruption of Russian and Iranian AI-Augmented Influence Operations
## Executive Summary
OpenAI identified and terminated multiple accounts linked to Russian and Iranian state-sponsored influence operations that utilized ChatGPT to automate and enhance propaganda workflows. These campaigns focused on damaging Ukraine’s reputation in Latin America and influencing U.S. political discourse via fake journalist personas. While the AI was used to streamline content creation, the operations were ultimately unsuccessful in gaining significant organic social media traction.
## Incident Details
- **Discovery Date:** October 2026 (Publicly reported)
- **Incident Date:** July 2025 – October 2026
- **Affected Organization:** OpenAI (Platform misuse); Various mid-size news publications
- **Sector:** Technology / Social Media / Journalism
- **Geography:** Russia and Iran (Origin); Latin America and USA (Targets)
## Timeline of Events
### Initial Access
- **Date/Time:** July 2025
- **Vector:** VPN-facilitated Account Creation
- **Details:** Operators in Russia and Iran bypassed geographic restrictions using VPNs to create ChatGPT accounts to support influence operations (IO).
### Lateral Movement
- **Details:** N/A. The attackers did not move through OpenAI's internal network; rather, they moved across the information ecosystem by recruiting unwitting human researchers in Latin America and pitching content to legitimate news outlets.
### Data Exfiltration/Impact
- **Details:** No internal data was stolen. The impact involved the generation of:
- Fake leaked documents and audio scripts.
- Nearly 100 articles published across a dozen news outlets.
- Social media commentary in English and Persian.
### Detection & Response
- **How it was discovered:** Internal safety monitoring by OpenAI’s safety team.
- **Response actions taken:** Permanent banning of associated accounts and public disclosure of the IO clusters.
## Attack Methodology
- **Initial Access:** Use of VPNs to circumvent geographic blocks on Russia and Iran.
- **Persistence:** Creation of a fake research organization, the Social Research Center (SRC), to provide a veneer of legitimacy.
- **Privilege Escalation:** N/A (Platform misuse).
- **Defense Evasion:** Use of "good faith" local employees in Latin America to generate original content, masking the Russian origin of the operation.
- **Credential Access:** N/A.
- **Discovery:** AI used to research Indian diaspora and regional politics in Latin America.
- **Lateral Movement:** Pitching to editors of mid-size news publications using seven fake journalist identities.
- **Collection:** AI used to draft internal reports and summarize geopolitical trends.
- **Exfiltration:** N/A.
- **Impact:** Strategic propagation of political propaganda and reputation damage targeting Ukraine and U.S. interests.
## Impact Assessment
- **Financial:** Minimal direct cost; costs associated with OpenAI's safety investigations.
- **Data Breach:** None.
- **Operational:** Disruption of OpenAI service terms; misuse of AI resources.
- **Reputational:** High for affected news outlets (one with 2 million Facebook followers) that unknowingly published state-sponsored propaganda.
## Indicators of Compromise
- **Network indicators:** Connections to ChatGPT originating from VPN nodes linked to Russian and Iranian clusters.
- **File indicators:** AI-generated scripts for audio recordings and fabricated "leaked" documents.
- **Behavioral indicators:** Large-scale generation of social media comments in Persian/English; prompts primarily authored in Russian/Persian; repetitive pitching patterns to international news outlets.
## Response Actions
- **Containment measures:** Account suspension and API access revocation for identified actors.
- **Eradication steps:** Removal of content where possible and blacklisting of associated payment/identity methods.
- **Recovery actions:** Collaboration with fact-checking organizations to address widely circulated false claims.
## Lessons Learned
- **AI as an Accelerator:** Threat actors are not necessarily using AI to create entirely new types of attacks, but rather to make traditional, complex influence operations more efficient and professional-sounding.
- **Human-in-the-loop Propaganda:** The use of unwitting local researchers shows a sophisticated hybrid approach where AI complements human labor to evade detection.
- **Platform Resilience:** Detection based on linguistic patterns (prompt languages) and connection methods (VPNs) remains critical for AI providers.
## Recommendations
- **Geographic Fencing:** Enhance detection of VPN and proxy usage from high-risk jurisdictions.
- **Behavioral Analytics:** Monitor for "persona-based" prompting where accounts simulate journalist or researcher workflows across multiple sessions.
- **Cross-Platform Collaboration:** Sharing IO indicators between AI companies and social media platforms to identify multi-stage campaigns.