Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
OpenAI Bans Russia-Linked ChatGPT Accounts for Covert Influence Operations
August 26, 2026
Attackers Abuse RMM Tools in 46-Country Phishing Campaign for Remote Access
August 26, 2026
New npm Malware Hosts ClickFix Phishing Pages via Trusted Mirrors
August 26, 2026
Home/Threats/OpenAI Bans Russia-Linked ChatGPT Accounts for Covert Influence Operations
Threats

OpenAI Bans Russia-Linked ChatGPT Accounts for Covert Influence Operations

Key Takeaways OpenAI has identified and terminated several ChatGPT accounts linked to a covert Russian influence operation. The operation leveraged generative AI to create social media content...

Jennifer sherman
Jennifer sherman
August 26, 2026 5 Min Read
3 0

Key Takeaways

  • OpenAI has identified and terminated several ChatGPT accounts linked to a covert Russian influence operation.
  • The operation leveraged generative AI to create social media content promoting a fictitious Israeli think tank, the International Burke Institute (IBI).
  • Content, including copied academic articles and a “sovereignty index,” aimed to praise Russia while criticizing Western nations supporting Ukraine.
  • While the campaign’s immediate audience reach was limited, it established a foundation for potential future expansion.
  • Defenders should verify unfamiliar sources, scrutinize author credentials, and report suspicious accounts to mitigate similar AI-driven influence activities.

OpenAI Disrupts Russian AI-Powered Influence Campaign

OpenAI has taken action against a network of ChatGPT accounts associated with a clandestine Russian influence operation. These accounts were instrumental in generating social media posts and replies designed to promote the International Burke Institute (IBI), a fabricated Israeli expert community. The content aimed to subtly guide public opinion towards the IBI’s narratives.

Table Of Content

  • Key Takeaways
  • OpenAI Disrupts Russian AI-Powered Influence Campaign
  • Operational Tactics Revealed
  • Credibility Fabricated from Plagiarized Works
  • What You Should Do

This particular influence campaign did not rely on traditional cyberattack methods like malware or exploits. Instead, it strategically employed generative AI to produce and disseminate material across major social media platforms, including X, LinkedIn, Facebook, Substack, and Telegram. The primary goal was to obscure the true identities and origins of the operators while spreading their messaging.

OpenAI’s analytical team detected this activity by identifying AI-generated posts and subsequently tracing them back to a broader network. This network was characterized by the dissemination of plagiarized academic articles, the fabrication of author credentials, and the promotion of a “sovereignty index.” This index consistently lauded Russia while simultaneously denigrating Western countries that support Ukraine.

In a report shared with Cyber Security News (CSN), OpenAI said in a report that while the operation’s initial audience reach was modest, it successfully established a foundational infrastructure with the potential for significant future growth. This incident underscores how sophisticated deceptive operations can blend authentic published works with misleading branding and routine social media engagement to effectively mask their true origins.

Operational Tactics Revealed

The now-banned ChatGPT accounts were observed receiving prompts in Russian but were instructed to generate posts in English, with specific requests to avoid any linguistic markers that might betray Russian authorship. To circumvent OpenAI’s geographical restrictions, which prohibit access from Russia, the operators utilized virtual private networks (VPNs).

LinkedIn post generated by this operation and posted on the platform (Source - OpenAI)
LinkedIn post generated by this operation and posted on the platform (Source – OpenAI)

OpenAI swiftly moved to ban the cluster of accounts once it established a connection between the AI-generated content and the broader influence campaign. The content consistently promoted articles from the IBI through both ostensibly legitimate and clearly inauthentic social media profiles.

Further investigation revealed that the group also used ChatGPT to generate replies on Substack, encouraging users to follow the IBI. One operator was found creating German-language content for a Telegram channel named “Lahme Ente” (Lame Duck), which disseminated critiques of Ukraine, the European Union, and Germany, advocating for stronger ties with Russia.

A second operator was responsible for designing logos for approximately a dozen Telegram channels targeting audiences in Germany, the United States, France, Poland, and Türkiye. This pattern of localized content creation mirrors tactics observed in the expansion of other Russian fake-news networks, where AI-generated content supports a wider ecosystem of deceptive media outlets.

Profile of the Telegram account 'American Observer' (Source - OpenAI)
Profile of the Telegram account ‘American Observer’ (Source – OpenAI)

While OpenAI’s intervention successfully halted the identified use of ChatGPT, the company noted that its platform represented only one component of the larger influence operation. Significantly, the website content itself was not generated using OpenAI’s models, an important distinction in understanding the scope of the AI’s involvement.

Credibility Fabricated from Plagiarized Works

The International Burke Institute’s website, registered in February 2025, falsely claimed to be an Israeli-based expert community boasting contributions from prominent scholars. However, an in-depth review by OpenAI of 36 articles attributed to these “experts” and published between September 2025 and May 2026 revealed that 34 of them were direct copies from other online sources.

Many of these plagiarized articles were outdated, and some were erroneously attributed to incorrect authors. For instance, an article concerning the China-Pakistan Economic Corridor, evidently copied from Cambridge University Press, was falsely credited to a University of Nottingham professor whose actual expertise lay in a different field. Similarly, an article on migration, lifted from the Migration Policy Institute, was attributed to an Australian food-science professor.

The campaign strategically utilized its “sovereignty index” to portray nations such as France, Germany, the European Union, and the United States as weakened or dependent entities, while simultaneously presenting Russia in a positive light. The fluent and professionally crafted posts across popular platforms made it challenging for users to immediately discern the deception.

OpenAI assessed this influence effort as being at the lower end of the spectrum for multi-platform operations targeting real audiences. While typical posts garnered minimal views, some individual Telegram channels managed to attract a substantial following of approximately 10,000 to 20,000 subscribers.

The true significance of this operation lies in its creation of a ready-made brand, a network of channels, and a content base that could be scaled up in the future. This incident highlights the evolving landscape of online influence campaigns and the critical role AI can play in their execution.

What You Should Do

  • Verify Sources: Always cross-reference information from unfamiliar research sites or social media accounts with established, reputable news organizations and academic institutions.
  • Scrutinize Authorship: Check the credentials and publication history of any quoted experts or authors. A quick search can often reveal discrepancies in expertise or affiliations.
  • Look for Inconsistencies: Be wary of accounts that consistently link to a single, obscure outlet, make vague claims about institutional backing, or offer highly polished commentary without clear, verifiable sourcing.
  • Report Suspicious Activity: If you encounter accounts or content that you suspect are part of an influence operation, report them to the platform administrators. Your vigilance helps limit the amplification of deceptive narratives.
  • Employ Critical Thinking: Understand that influence campaigns are not always immediately obvious or viral. Subtle, consistent messaging can be highly effective over time.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitSecurity

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Attackers Abuse RMM Tools in 46-Country Phishing Campaign for Remote Access

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical WordPress Plugin Vulnerability Exposes 400,000 Sites
August 26, 2026
Iran-Linked Hackers Exploit Legitimate Dev Tool to Conceal Didoor Backdoor
August 26, 2026
Mirage2FA Phishing Kit Bypasses MFA, Hijacks Microsoft 365 Sessions
August 26, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us