OpenAI says two covert influence operations it banned succeeded in placing material in established media outlets. One allegedly used fake journalist identities to pitch articles. The other appears to have recruited unwitting people in Latin America to work for an ostensibly local think tank.
The company describes the Russia-origin campaign as the first Category 5 influence operation it has disrupted since it began publishing these reports. That designation concerns how far an operation spread and who amplified it, not whether it persuaded readers or changed political outcomes.
OpenAI’s October 8, 2026 announcement attributes the operations to Russia and Iran. Those origins, the relationships between operators and their fronts, and the impact ratings are company assessments, not independently established conclusions. A detailed account from CellCog provides additional particulars from the report, including campaign names and examples discussed below.
The important distinction is between producing content and obtaining credibility. According to OpenAI, these campaigns combined AI assistance with conventional deception, including invented identities, article pitches, fabricated material, and internal performance reports. Their access to legitimate publications mattered more than their largely unsuccessful attempts to attract attention through social comments.
The Russian Front Apparently Had Real, Unwitting Staff
OpenAI calls the Russia-origin operation Dark Clark. According to CellCog’s account of the findings, the operators controlled a Latin American organization called the Social Research Center, using a fake persona named Mia Clark to communicate with local staff.
OpenAI’s assessment is that those people appeared not to know they were working for a Russian group. That qualification matters. The report should not be read as accusing everyone associated with the center of knowingly participating in a covert operation.
The evidence described in the summary includes internal reporting about hiring, firing, pay scales, and staffing plans. OpenAI interprets those records as evidence of operational control, rather than a loose relationship between outside actors and an independent research organization.
The center reportedly published more than 60 articles, most of them original. Publication volume alone does not establish deception or influence. The central allegation concerns concealed control: an organization presenting itself as a local research institution while operators elsewhere allegedly directed its activities.
That structure could make scrutiny harder than it would be for an obvious collection of fake accounts. A front with real workers can produce genuine correspondence and ordinary institutional activity. Checking that a staff member exists would not necessarily reveal who controls the organization or sets its agenda.
OpenAI also describes fabricated material associated with the campaign. CellCog’s summary recounts a fake audio clip presented as coming from an employee of Bolivia’s state water company, claiming that La Paz was about to lose water during protests. OpenAI says it found both a debunk and an official denial from the company.
The alleged mechanism differs from simply publishing an opinion under a false name. Fabricated audio or letters can function as synthetic leaks: purported evidence that invites journalists or officials to investigate and respond. But the existence of such material does not establish that ChatGPT generated it, and OpenAI explicitly cautions against treating all campaign content as model-produced.
Seven Journalist Personas Offered Another Route Into Newsrooms
OpenAI calls the Iran-origin operation Bogus Bylines. It says the group used seven journalist personas to submit and pitch articles, alongside a separate effort to generate social-media comments.
The reported AI workflow was practical and editorial. Operators asked ChatGPT to assess English-language drafts against particular outlets’ submission requirements, suggest changes, and write pitch emails.

That use of AI could help a deceptive contributor navigate a publication’s ordinary commissioning process. An editor might receive a plausible submission, correctly formatted and accompanied by a professional email, while the identity and affiliation behind it remained false.
According to CellCog’s summary, OpenAI found almost 100 articles associated with the personas across roughly a dozen outlets, published between July 2025 and October 2026. Those are OpenAI’s reported findings, not an independently verified count for this article.
Nor does an article placement demonstrate how many people read it, believed it, or changed their views. Its immediate significance is that material attributed to invented contributors passed into real publishing environments.
The comment campaign performed differently. OpenAI says it did not observe substantial engagement with the comments. The operators also reportedly measured impact using views on the posts they replied to, rather than views on their own replies.
That is a consequential measurement problem. A comment beneath a widely viewed post cannot claim the parent post’s audience as its own. Combining those figures would make a weak distribution effort look much more successful than the available evidence supports.
Category 5 Measures Amplification, Not Persuasion
The Breakout Scale developed by Ben Nimmo classifies influence operations using observable patterns of spread across platforms, communities, media, and public figures.
Category 4 covers operations amplified by mainstream media. Category 5 involves amplification by high-profile individuals, such as celebrities or political candidates. Category 6 reaches further, covering a policy response, other concrete action, or a call for violence.
OpenAI rates Dark Clark at Category 5 and Bogus Bylines’ article-placement activity at Category 4. It reportedly rates the Iranian operation’s social-comment activity at Category 2.
The distinction explains why established publications feature prominently in the announcement. Publishing material under a fabricated identity can carry an operation beyond its own accounts and introduce it to an outlet’s audience. Attention from a prominent political figure can extend that spread again.
CellCog’s account connects Dark Clark’s rating to coverage of fabricated material and apparent comment from at least one Polish member of the European Parliament. That is OpenAI’s assessment of the observed chain of attention, not proof of a political outcome.
The scale also requires careful interpretation when material attracts denials or fact-checks. A public response can demonstrate that an operation escaped its original distribution channels without showing that its claims were accepted. Debunking and endorsement are different forms of attention.
Likewise, OpenAI’s description of its first Category 5 disruption is a statement about its own reporting record. It does not establish that this was the first AI-assisted influence operation to reach that level anywhere.
AI Often Worked Behind the Scenes
OpenAI says both operations used AI heavily for internal reports. In the Russian campaign, the company reportedly observed model use mainly for reporting on activities, with more limited use involving fake letters, audio scripts, and translations.
Sources
- detailed account from CellCogcellcog.ai
- Breakout Scale developed by Ben Nimmobrookings.edu





