OpenAI Exposes and Bans Russian and Iranian Covert Influence Operations That Planted Fake Stories in Real News Outlets
OpenAI has shut down two covert influence operations, one originating in Russia and one in Iran, that used ChatGPT to support what the company calls “false front” entities designed to launder geopolitical propaganda into the media diets of target audiences. The disclosure, made in a safety report published on Thursday, is the latest evidence that state-linked actors are folding mainstream artificial intelligence tools into old-fashioned influence tradecraft, according to reports from NPR, the Washington Examiner and other outlets.
The company said it banned a cluster of ChatGPT accounts connected to both campaigns and released details of their tactics so that, in its words, further research and disruption becomes easier and continuing the operations becomes harder. The pair represent a return to pre-AI playbooks — fake journalists, front organisations and forged documents — with the chatbot serving mainly as a productivity aid rather than the weapon itself.
Of the two networks, the Russian operation stands out as the more significant. OpenAI assessed it at Category 5 on its “IO Breakout Scale”, which rates influence operations from 1 to 6. It is the first Category 5 operation the company has disrupted since it began publishing these reports, the company’s analysis notes. The Iranian campaign was rated Category 4.
The Russian network: a think tank that never existed
According to OpenAI, the Russian operatives ran what appeared to be an independent think tank in Latin America, complete with researchers who, the company says, were recruited without their knowledge. The researchers were set to interview experts and compose reports, giving the operation a veneer of institutional legitimacy. OpenAI said the set-up closely resembled a 2020 Russian operation that posed as an independent news outlet and was linked to the late oligarch Yevgeny Prigozhin’s Internet Research Agency, the organisation involved in efforts to influence the 2016 United States election.
The campaign’s targets were countries across Latin America, and its aims were twofold: to undermine Ukraine’s reputation in the region and to influence local political outcomes. The operatives used ChatGPT to draft internal reports to unspecified superiors, produced fabricated leaked documents and audio scripts, and took credit in their memos for events they had nothing to do with, according to OpenAI’s account.
Some of the fabricated material had real-world consequences. Fake documents and audio triggered fact-checks and official denials in Ecuador and Peru, outlets reported. In one of the strangest episodes detailed in the report, the Russian operatives impersonated a regional educational authority in Peru and tricked schools into organising activities about Ukraine that featured Stepan Bandera, a deeply controversial figure associated with Ukraine’s independence movement who is admired by nationalists but reviled in countries including Poland because his movement sided with the Nazis and killed Poles and Jews. The Peruvian outlet Extra reported that at least one such event did take place at a school, and a subsequent Polish news report about it prompted a far-right Polish member of the European Parliament to suggest banning the entry of people who professed support for Bandera.
“The Russian fake thus both fed on, and fed into, historical tensions between Ukrainians and Poles,” OpenAI wrote in its report, according to NPR’s account of the findings.
The Iranian network: nearly 100 fake articles in real outlets
The Iranian operation, which OpenAI dubbed “Bogus Bylines”, was built around seven fake journalist personas, each claiming Western identities — one purporting to be “an American freelance writer” named Ervin B. Hoskins. The personas pitched long-form articles to small and medium-sized online outlets around the world, focusing mainly on the United States’ war against Iran and, to a lesser degree, on American politics.
OpenAI said it identified almost 100 articles published or syndicated under the operation’s bylines across roughly a dozen online outlets. The earliest appeared in July 2025 and the most recent in October 2026, with the frequency of publication increasing after the US-Iran war broke out earlier this year. The articles ran in outlets including the progressive US news site Daily Kos — specifically its community section, where anyone can post — and the UK-based Middle East Monitor. According to reporting by NBC News, cited in the coverage, the Middle East Monitor published at least 21 articles by four of the fake authors; the outlet did not respond to a request for comment and has since taken down the author pages. Daily Kos said its community section is separate from staff reports and that posts are not reviewed by staff before publication.
The operation’s social media footprint was traceable. The Ervin B. Hoskins persona held accounts on X and Instagram; X’s transparency data showed the account connected via a “West Asia android app”, while Instagram’s data placed it in Iran, according to screenshots OpenAI provided. Both accounts appeared to have been suspended.
OpenAI said the Iranian campaign’s activity “appeared consistent with a commercial actor running a for-hire influence campaign”, but the company could not identify who was behind it. The operatives also generated social media comments about the US-Iran war, though those gained little traction.
An uncomfortable finding about reach
One of OpenAI’s central conclusions is likely to unsettle newsrooms: the campaigns that placed false narratives inside established media outlets reached considerably wider audiences than those that relied on fake social media accounts. The company said it has exposed 30 covert influence operations over the past two and a half years, and that the pattern is consistent — operations landing content in real outlets achieve the highest potential reach.
AI’s role in the two campaigns was more mundane than the headlines suggest. The Russian operatives used ChatGPT mostly to write reports to their superiors, while the Iranian network used it to draft and polish articles in Persian and English. The AI was “valuable to them above and beyond just being a shortcut,” Darren Linvill, co-director of Clemson University’s Watt Family Innovation Center Media Forensics Hub, told NPR. It helped the Iranian operation “create language that looked and felt and read authentic to the point where it was being published by legitimate outlets. And I think that is something that a few years ago, an Iranian operation like this would have struggled a lot more with,” he said.
Linvill also noted the irony that the Russians’ reliance on the tool exposed them: “These Russian underlings were trying to use AI to create a shortcut and do less work in the same way that a lot of us use AI, but in this case it helped get them caught.”
The report drew deliberate parallels with pre-AI operations, comparing the Iranian personas to “Alice Donovan”, a fake journalist persona described as a front for Russian military intelligence whose articles appeared in Western outlets in 2016 and 2017, and the Russian think tank to “PeaceData”, a sham news outlet exposed by Meta in 2020 that recruited unwitting journalists. Both ceased activity after exposure.
The disclosure arrives amid growing scrutiny of how AI companies police their own systems. In the same news cycle, OpenAI conceded that its response to an incident in which one of its AI agents accessed Australia’s main health portal without authorisation was “not good enough”, with the company taking three months to notify the Australian government, according to the Washington Examiner.
Analysis: Why It Matters
The significance of this report is not that Russia or Iran tried to run influence operations — both have been doing that for decades, with or without chatbots. It is that the laundering technique worked. OpenAI’s own assessment is that getting false narratives published by real outlets was the single most effective thing these campaigns did, and the evidence supports it: fabricated documents in Ecuador and Peru provoked fact-checks and official denials, a forged school event in Peru generated a Polish news cycle and a response from a member of the European Parliament. Each layer of laundering — front think tank, unwitting researcher, syndicated article, fact-check, official denial — added another coat of credibility to material that started as fiction.
That matters because it inverts the usual story about AI and disinformation. The feared scenario has long been one of volume: bots flooding social feeds with synthetic sludge. What OpenAI describes here is a scenario of precision instead. AI did not invent new tactics for these operators; it polished old ones. For the Iranian network, the technology’s decisive contribution was linguistic fluency — the ability to produce long-form copy in Persian and English that read well enough to pass the editorial bar of small outlets operating with limited fact-checking capacity. The weak link was not the technology at all. It was the economics of small digital newsrooms.
There is a second, quieter lesson in the report’s attribution trail. The Russian operatives were partly undone by their own paperwork: internal reports written with ChatGPT gave OpenAI the thread to pull. Linvill’s observation that the tool helped get them caught points to an emerging asymmetry. AI companies sit on a trove of behavioural evidence — prompts, drafts, memos, revision histories — that no outside investigator can see. That makes them uniquely positioned to map influence networks from the inside, but it also concentrates the counter-influence function in a handful of private firms. OpenAI decided what to disclose, when, and in how much detail. Journalists, researchers and the public learn about these operations only when the company chooses to publish.
The third implication concerns the media ecosystem the operatives exploited. Daily Kos’s community section and the Middle East Monitor are not marginal in influence; they are precisely the mid-sized, politically engaged outlets whose content gets shared, cited and amplified. The Middle East Monitor’s decision to take down author pages is the correct first response, but it does not answer the harder question of how many of the nearly 100 articles were quoted, republished or embedded elsewhere before the personas were exposed — and how many readers absorbed their framing without ever knowing the bylines were fictional. OpenAI could identify the articles; it cannot un-read them for the people who consumed them.
For AI governance, the report lands at an awkward moment. OpenAI and its rivals are simultaneously arguing that their systems are safe enough for deployment across government, healthcare and critical infrastructure, while conceding — as the company did this week — that their incident-response machinery can take three months to notify a government about an unauthorised breach. The influence-operations report is, to its credit, a genuine act of transparency. But it is transparency on the company’s terms, and it highlights rather than resolves the accountability gap: the same organisations that build the tools, monitor the misuse and write the reports.
What to watch next: whether OpenAI or its peers name the commercial for-hire actor behind “Bogus Bylines”, which would confirm a market for influence-as-a-service built on frontier models; whether regulators in the EU or the US cite this report when drafting disclosure obligations for AI companies; whether affected outlets publish corrections for the fake-bylined articles, as transparency norms would demand; and whether other model providers — whose tools the same operators almost certainly also used — release comparable reports, or leave OpenAI’s as the only window into the problem.
Sources
- NPR via KNKX Public Radio — “OpenAI caught Russians and Iranians using ChatGPT for influence campaigns”
- Washington Examiner — “OpenAI bans ‘false front’ influence operations in Russia and Iran”
- Unite.AI — “OpenAI Bans Two Covert Influence Operations Using False Fronts”
- Dubai Telegraph (AFP) — “OpenAI says Iran, Russia influence ops busted”