OpenAI blocks Russian influence campaign using ChatGPT
OpenAI has disrupted a covert Russian campaign that used ChatGPT to generate fake think-tank articles, highlighting the persistent threat of state-sponsored actors weaponizing generative AI.
OpenAI recently exposed and disrupted a covert Russian influence operation that leveraged ChatGPT to generate deceptive social media content. The operators accessed the AI platform from Russia using virtual private networks (VPNs) and specifically instructed ChatGPT to strip out any linguistic markers that could reveal their Russian origin. The primary objective of the campaign was to promote a fraudulent, supposedly Israel-based think tank called the International Burke Institute (IBI). This fake organization published a 'sovereignty index' that ranked Russia's military 0.5 points higher than the military of the United States.
The operation relied heavily on plagiarized material to build credibility. OpenAI revealed that 34 out of 36 expert-linked articles published by IBI between September 2025 and May 2026 were stolen from legitimate sources. For instance, the campaign falsely attributed a Cambridge University Press article to a University of Nottingham professor, and assigned a Migration Policy Institute piece to an Australian food chemistry professor. The content was distributed across X, LinkedIn, Facebook, Substack, and Telegram. A German-language Telegram channel named 'Lahme Ente' targeted European politics, while another operator generated logos for approximately a dozen Telegram channels focused on the United States, Germany, France, Poland, and Turkey.
While individual posts received minimal engagement, the associated Telegram channels managed to attract between 10,000 and 20,000 followers each. On the Brookings Breakout Scale, OpenAI rated the campaign at category three out of six, indicating it successfully spanned multiple platforms and showed early signs of reaching real audiences. This is not the first time OpenAI has intervened; the company previously shut down the 'Bad Grammar' network in June 2024 and 'Operation Helgoland Bite' prior to Germany's 2025 federal election.
For AI safety practitioners and platform security teams, this development underscores the critical need for robust behavioral monitoring and multi-layered threat detection. Because bad actors actively instruct models to mask their geographical and linguistic origins, relying solely on simple text-pattern analysis is insufficient. Security teams must combine API access telemetry, such as VPN usage patterns, with cross-platform threat intelligence to identify coordinated inauthentic behavior. Furthermore, as open-weight models and alternative AI providers proliferate globally, practitioners must prepare for a threat landscape where centralized API bans are no longer a complete solution to automated disinformation.
This is our own summary of reporting by The Decoder



