CyberSecurityNews

OpenAI Bans Russia-Linked ChatGPT Accounts Used in Covert Influence Campaign


OpenAI has removed a cluster of ChatGPT accounts linked to a covert influence operation from Russia. The accounts produced social-media posts and replies designed to steer people toward the International Burke Institute, or IBI, a purported Israeli expert community.

The campaign did not depend on malicious software or an exploit. It used generative AI to spread material through X, LinkedIn, Facebook, Substack and Telegram while hiding its operators.

OpenAI analysts identified the activity through AI-generated posts and traced it to a network mixing copied academic articles, false authorship and a so-called sovereignty index. The index praised Russia while attacking Western countries supporting Ukraine.

OpenAI said in a report shared with Cyber Security News (CSN) that Its audience was limited, but it built infrastructure that could grow.

It shows how deceptive operations can combine real published work, misleading branding and routine social-media engagement to conceal their origins.

OpenAI Bans Russia-Linked ChatGPT Accounts

The banned accounts prompted ChatGPT in Russian, but requested English posts and asked that the writing not reveal Russian linguistic clues. Because OpenAI does not allow access from Russia, the operators used virtual private networks to access it.

LinkedIn post generated by this operation and posted on the platform (Source – OpenAI)

It banned the account cluster after connecting generated posts to the wider operation. The content promoted IBI articles through named accounts and inauthentic profiles.

The group also generated Substack replies urging users to follow IBI. One operator created German-language content for a Telegram channel called Lahme Ente, or “lame duck,” which criticized Ukraine, the European Union and Germany while calling for closer ties with Russia.

A second operator created logos for a dozen Telegram channels aimed at Germany, the United States, France, Poland and Türkiye. That localization resembles patterns reported in a Russian fake-news network expansion, where AI content supports a wider web of deceptive outlets.

Profile of the Telegram account 'American Observer' (Source - OpenAI)
Profile of the Telegram account ‘American Observer’ (Source – OpenAI)

OpenAI’s action stopped the identified ChatGPT use, but said the platform was only one element of the operation. The website content was not generated with its models, an important distinction.

Credibility Built From Copied Work

IBI’s website was registered in February 2025 and claimed to operate from Israel, presenting itself as an expert community with prominent scholars as contributors.

Yet OpenAI’s review of 36 articles linked to experts and published between September 2025 and May 2026 found that 34 were copied from elsewhere online.

Some articles were old, while others carried the names of the wrong authors. An article about the China-Pakistan Economic Corridor appeared copied from Cambridge University Press but was attributed to a University of Nottingham professor with different expertise.

A migration article appeared copied from the Migration Policy Institute and credited to an Australian food-science professor. Readers should check the original source, author history and publication record before treating an unfamiliar research site as authoritative.

The campaign used its sovereignty index to frame France, Germany, the European Union and the United States as weakened or dependent, while placing Russia in a favorable light. Fluent posts across familiar platforms can make the deception hard to spot.

Readers should be cautious of accounts that repeatedly link to one outlet, make vague institutional claims or offer polished commentary without clear sourcing. Similar principles apply to AI connector security controls, where trust in an AI environment must not replace verification.

OpenAI assessed the effort at the lower end of a scale for operations on multiple platforms reaching real audiences. Typical posts drew few views, although individual Telegram channels attracted roughly 10,000 to 20,000 followers.

Its significance lies in a ready-made brand, network and content base that could expand later. Comparing claims with primary sources, checking whether quoted experts wrote the material, and reporting misleading accounts can limit amplification.

These habits support the safe use of AI tools when unfamiliar sources are involved. They also help platforms and users recognize that influence activity is not always loud or viral at first.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC



Source link