OpenAI's first Category 5 op hired unwitting Latin Americans

According to a new OpenAI threat report, Russian operators say they used a fake email in the name of Lima's regional education directorate to get schools in Peru to hold Ukraine-themed events that referenced Stepan Bandera, and the story then reached the Polish press and a Polish MEP. OpenAI calls the operation "Dark Clark" and rates it Category 5 on the IO Breakout Scale, which runs from 1 to 6. It is the first Category 5 operation OpenAI has disrupted since it began reporting.
The same report covers an Iranian operation, nicknamed "Bogus Bylines", that reached Category 4. OpenAI banned the ChatGPT accounts behind both. In the company's account, both closely resembled influence operations from before AI, and AI made some of the work easier.
At a glance
- Russian operators ran a Latin American "research platform", the Social Research Center, through a fake persona called Mia Clark, and its local staff apparently never knew who they worked for.
- Seven fake Western journalist personas run from Iran placed almost 100 articles across roughly a dozen outlets, while the operation's batches of social media comments drew little engagement and rated only Category 2.
- Both teams leaned on ChatGPT for internal reports, and both inflated results: the Russians took credit for events they had no part in, the Iranians counted views on other people's posts.
If you have not been following, OpenAI has published threat reports for about two and a half years and says it has exposed 30 covert influence operations since early 2024. According to TrendFlash.net, its October 2025 report described threat actors who "bolt AI onto old playbooks to move faster, not gain novel offensive capability from our models".
Dark Clark ran a Latin American think tank through a persona named Mia Clark
The Russian operators reached ChatGPT through VPNs and mostly prompted in Russian. Their main use was drafting reports to an unknown superior. The reports covered three workstreams: denigrating Ukraine and undermining recruitment for its army, interfering in domestic politics in Bolivia and Argentina, and managing the Social Research Center, which presents itself as a research platform on the Indian diaspora in Latin America.
The reports discussed pay scales, hiring, firing and staffing plans, so OpenAI concludes that the operators controlled the SRC rather than worked alongside it. Local staff interviewed experts and wrote papers on topics ranging from public opinion on BRICS to Brazil's economy under Bolsonaro and Lula. OpenAI found well over 60 articles on the site, most of them original. It compares the setup to PeaceData, a 2020 front that co-opted unwitting journalists.
The SRC's social media presence was weaker. As of August 17, an SRC-branded LinkedIn account had 961 followers and claimed 200–500 staff, yet listed only two employees. The operators reported creating fake accounts to follow it so it would look more convincing. The main X account showed a German location but a connection through the Russian Federation App Store.
Fake school emails in Peru and Ecuador drew a minister's rebuttal
The operators claimed that in May 2026 they set up a fake address posing as Lima's Regional Directorate of Education. From it, they told schools to mark the Day of Cultural and Linguistic Diversity on May 21 with Ukraine events that referenced Bandera. According to the operators, some schools replied with photos. Matching stories ran in Peruvian and Polish media and in an English-language publication in Hungary, and one Polish MEP proposed declaring people who showed "anti-Polishness" persona non grata.
In June, the operators claimed, another fake email got schools in Ecuador to pledge allegiance to President Daniel Noboa and to Erik Prince, former head of Blackwater. Ecuador's Minister for Education published a detailed rebuttal. In Bolivia, during the late-May protests, a fake audio clip of a worker at the water company EPSAS warned that water to La Paz would be shut off. EPSAS issued a denial.
ChatGPT played a smaller part in making the content. The Spanish-speaking operator, based in Russia, had it proofread a fake contract from "International Security Solutions FZE". A picture of the contract later circulated online. In early April, Ecuadorian fact checkers found that the company was not in the national companies registry.
Seven Iranian bylines placed almost 100 articles in roughly a dozen outlets
The Bogus Bylines operators prompted in Persian. They asked ChatGPT to check English drafts on the US-Iran conflict against a specific outlet's submission criteria, then to write the pitch email to its editor. The bylines were Ervin B. Hoskins, Noah Lamington, Sophia Gonzalez, Michael Harrison, Ericka Feusier, Jenny Williams and Alice Johnson, mostly presented as American journalists. OpenAI compares them to "Alice Donovan", a front for Russian military intelligence whose articles Western outlets published in 2016–17.
The articles ran from July 2025 to October 2026, and their pace picked up sharply after the US-Iran war began. As of August 2026, one outlet that published them had almost 2 million followers on Facebook, almost 355,000 on X and over 544,000 on Instagram. The comment batches got likes, views and replies in the single or double digits, and many of their likes came from the operation's own accounts.
Why did both operations look so successful in their own reports?
They wrote their own scorecards. The Iranian team's main metric was the number of views on the posts it replied to, counted before its replies went up and again some unspecified time later, rather than views on the replies themselves. Growth from the original post's popularity or from other comments went to the operation's credit.
It is like a street vendor counting every tourist who walked past the cathedral next door as a customer. The Russian operators asked ChatGPT to find events they could claim, such as Falklands arguments Argentina's Foreign Minister made at a UN committee, which had been official Argentine policy for years. OpenAI says this suggests an influence operation targeting the operators' own employers.
The ratings rest on what OpenAI could see from outside. It says the Russian operators' impact claims cannot be taken at face value, some fakes could not be corroborated, not all placed content came from its models, and the Iranian activity appeared consistent with an unidentified for-hire actor. In our view, the telling contrast sits inside Bogus Bylines: comments rated Category 2, articles placed through real editors Category 4.
Whether Mia Clark goes quiet
Both Alice Donovan and PeaceData stopped after they were exposed, and OpenAI says it publishes these reports to make such operations harder to continue. The thing to watch is whether the SRC website, its LinkedIn page and the seven bylines stop publishing. OpenAI has shared both cases with the relevant authorities and the Iranian case with industry partners. The report does not say what any of them will do next.
Related stories
- OpenAI ties a reasoning-extraction campaign to Moonshot AI
- OpenAI will report misbehaving models before it fixes them
- Blocked from the web, an OpenAI agent tunneled out via DNS
- OpenAI wants a safety case before every frontier RL run
- OpenAI's swarm spent days fighting a check it only inferred
- OpenAI's newest model found a way out of its RL sandbox
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
