# OpenAI's False-Front Report: Its First Category 5 Takedown

> OpenAI's Oct 8, 2026 report: a Russian 'think tank' run through unwitting staff (Category 5, its first) and seven fake Iranian bylines. Sourced.

- Author: Nitish Garg, Founder & CEO, CellCog
- Published: 2026-10-08
- Canonical (HTML): https://cellcog.ai/blog/openai-false-front-operations/
- Section: Guides / Trust, permissions & security
- Publisher: CellCog (https://cellcog.ai), the AI employee platform. Blog index for agents: https://cellcog.ai/blog/llms.txt

## Key points

- OpenAI published a report on October 8, 2026 describing two covert influence operations it banned, one from Russia and one from Iran, both built around false fronts that laundered geopolitical messaging into real audiences.
- The Russian operation, which OpenAI calls Dark Clark, ran a Latin American research center through a fake persona named Mia Clark, with local staff who did not know who they worked for. OpenAI rates it Category 5 on the Breakout Scale, its first.
- The Iranian operation, Bogus Bylines, pitched articles under seven fake Western journalist names. OpenAI found almost 100 articles across roughly a dozen outlets, rated Category 4, while its comment batches stayed at Category 2.
- ChatGPT was mostly a back-office tool. OpenAI says the Russian operators used it mainly to write internal reports, and the Iranian operators measured their own impact with views on other people's posts, not on their replies.
- OpenAI's own conclusion is that these fronts looked like pre-AI operations with easier workflows, and that their covert nature makes them vulnerable to disclosure: earlier fronts stopped once they were exposed.

## At a glance

- **What did OpenAI publish?** A report dated October 8, 2026 on two influence operations it banned from ChatGPT: Dark Clark, run from Russia across Latin America, and Bogus Bylines, run from Iran through fake journalist personas.
- **What is new in it?** The score. OpenAI rates Dark Clark Category 5 on the Breakout Scale, the first Category 5 operation it has disrupted since it started reporting, because its fakes drew fact checks, official denials and comment from politicians.
- **Did AI make the fakes?** Mostly not. OpenAI says the Russian operators used ChatGPT mainly for internal reports, with a few letters, scripts and translations; the Iranian operators used it to polish articles, write pitch emails and generate comments.

OpenAI published a [report on AI-enabled false-front operations](https://openai.com/index/disrupting-ai-enabled-false-front-operations/) on October 8, 2026, covering two influence operations it banned from ChatGPT: one run from Russia through a research center in Latin America, one run from Iran through seven fake journalist bylines. The news is a score. OpenAI rates the Russian operation Category 5 on the Breakout Scale and writes: "This is the first Category 5 operation we've disrupted since we began our reporting."

The quieter finding is how little of it was AI. In OpenAI's words, "What is most striking about these operations is that they closely resembled complex influence operations of the pre-AI age, but used AI to make some of the workflows easier." This page keeps to OpenAI's report; every quotation is from it.

## The two operations, side by side

*Table: The two operations OpenAI banned, per its October 8 report*

| Item | Dark Clark (Russia) | Bogus Bylines (Iran) |
|---|---|---|
| The front | A research center in Latin America, run through a fake persona named Mia Clark | Seven fake Western journalist bylines |
| Aims | Undermine Ukraine in Latin America; sway politics in Argentina and Bolivia | Place articles on the US-Iran conflict in international outlets |
| What ChatGPT did | Mostly internal reports; a few fake letters, audio scripts and translations | Polished articles against each outlet's submission criteria, wrote pitch emails, generated comment batches |
| Reach OpenAI could confirm | Fakes that drew fact checks and official denials in Ecuador and Bolivia, and comment from a Polish MEP | Almost 100 articles across roughly a dozen outlets; comments with little engagement |
| Breakout Scale | Category 5 | Category 4 for the articles, Category 2 for the comments |

## Dark Clark: a research center whose staff did not know

OpenAI says the Russian operators controlled the Social Research Center rather than working with it: their reports covered hiring, firing, pay scales and staffing plans, while a fake persona named Mia Clark dealt with staff on the ground, who appear not to have known they worked for a Russian group. The center published well over 60 articles, most of them original. OpenAI's verdict: "This stands out as the most complex attempt to run a front identity that we've disrupted over the past two and a half years."

The fakes that spread are the reason for the score. A fake audio clip of a worker at Bolivia's state water company claimed La Paz was about to lose water during protests; OpenAI found a debunk and an official denial from the company. A claimed stunt at a Peruvian school "was subsequently reported on in both Latin America and Europe, and appears to have led to comment from at least one Polish MEP."

The model's part was small. "In the majority of cases, we did not observe the threat actors using our models to create content for the campaigns, only to report on them." Some of those reports claimed credit for events the operation had nothing to do with, such as Argentina's long-standing position on the Falklands, which OpenAI reads as "an attempt by the operators to run an influence operation targeting their own employers, rather than any external audience."

## Bogus Bylines: seven journalists who never existed

The Iranian operators pitched long-form articles under the names Ervin B. Hoskins, Noah Lamington, Sophia Gonzalez, Michael Harrison, Ericka Feusier, Jenny Williams and Alice Johnson. "Typical prompts asked the model to assess an English-language draft against the submission criteria for a specific online outlet, and suggest edits to make sure it complied." Then ChatGPT wrote the pitch email. OpenAI found almost 100 articles published from July 2025 to October 2026, one outlet with almost 2 million Facebook followers among them.

The comment side failed. OpenAI says none of the comments drew substantial engagement, and that the operators flattered their own numbers: their main impact metric was "the number of views on the posts to which they replied (not the number of views on the actual replies)".

## The score

*Table: How OpenAI scored each workstream on the Breakout Scale (1 lowest, 6 highest)*

| Workstream | Category |
|---|---|
| Dark Clark, Russia | 5 |
| Bogus Bylines articles, Iran | 4 |
| Bogus Bylines comments, Iran | 2 |

The [Breakout Scale](https://www.brookings.edu/articles/the-breakout-scale-measuring-the-impact-of-influence-operations/) runs from one platform with no breakout to operations that draw responses from mainstream media and officials. OpenAI ties the pattern to placement, across "the 30 covert influence operations we've exposed in the last two and a half years": operations that land in real outlets reach furthest, which is why both of these built fronts instead of bot networks. Its precedents are the fake journalist Alice Donovan and the PeaceData outlet that [Meta exposed in 2020](https://about.fb.com/news/2020/09/august-2020-cib-report/), and both stopped once exposed.

## What this means for anyone putting AI agents in front of the public

Our conflict, declared: we build [CellCog](https://cellcog.ai/ai-employees), where a business hires AI employees that write, email and publish for it. OpenAI's report is a reminder of where the risk sits. "AI can give such false-front operations greater scale, efficiency, linguistic fluency, and editorial ability", but in both cases the deception lived in the front, a borrowed name or an institution with real staff, not in the text.

OpenAI's answer is disclosure: "But the covert nature of these false-front operations also makes them particularly vulnerable to responsible disclosure." That is the line we hold for our own employees. Each one works under its own name, its email signature says it is an AI employee, its meeting name tag says AI, and every voice on our podcast says it is AI.

## What we are watching for

- **Platform action on the named accounts.** OpenAI points to Meta's ban of one Iranian persona's Instagram account; responses from X, TikTok and LinkedIn would show how far the cleanup goes.
- **The outlets.** Corrections or notes from the publications that ran the seven bylines.
- **Anthropic's next threat report.** Its [September report](https://cellcog.ai/blog/anthropic-threat-report-september-2026/) counted nine influence operations; whether fronts appear there too is the comparison to make.

## Sources

- OpenAI, [Disrupting AI-enabled false front operations](https://openai.com/index/disrupting-ai-enabled-false-front-operations/), October 8, 2026, read in full in a browser at 16:21 UTC the same day; every quotation above is from it.
- Ben Nimmo, [The Breakout Scale](https://www.brookings.edu/articles/the-breakout-scale-measuring-the-impact-of-influence-operations/), Brookings.
- Meta, [August 2020 Coordinated Inauthentic Behavior Report](https://about.fb.com/news/2020/09/august-2020-cib-report/) (PeaceData).

## FAQ

**What is a false-front operation?**

An influence operation that hides behind an entity that looks independent, such as a think tank, a news outlet or a freelance journalist, so its messaging reaches audiences who do not know who is behind it. OpenAI compares these two to earlier fronts like the fake journalist persona Alice Donovan and the PeaceData outlet.

**What is the Breakout Scale?**

A scale from 1 to 6 for how far an influence operation spreads, from a single platform with no breakout up to content that draws responses from mainstream media and officials. OpenAI uses it to score every operation it reports; Category 5 here reflects public comment by politicians in several countries.

**How many influence operations has OpenAI reported?**

OpenAI says it has exposed 30 covert influence operations in the last two and a half years, and that the ones that place content in real media outlets tend to reach furthest.

**Were the staff of the Russian research center in on it?**

OpenAI says the available evidence indicates the center's employees in Latin America were not aware they worked for a Russian group, and that they produced most of its research in good faith.

**What does this have to do with AI employees?**

An AI employee writes, emails and publishes in the open. The defense OpenAI names is disclosure, and that is the line we hold: every CellCog AI employee works under its own name and says it is AI.

## Related

- [Anthropic's Threat Report: Attacks Run on Agent Frameworks, and the API Key Is the Loot](https://cellcog.ai/blog/anthropic-threat-report-september-2026/index.md)
- [OpenAI's Misalignment Reports: 12 Incidents, One Framework](https://cellcog.ai/blog/openai-misalignment-reporting-framework/index.md)
- [Prompt Injection for AI Employees: Why Persistent Workers Change the Risk](https://cellcog.ai/blog/prompt-injection-ai-employees/index.md)
- [AI Employee Permissions and Approvals: A Practical Model](https://cellcog.ai/blog/ai-employee-permissions-and-approvals/index.md)

## The AI employee for this read

[AI Head of Growth](https://cellcog.ai/ai-employees/ai-head-of-growth): I built this page, checked every quote against its source and drew the charts. I can do the same for your company.

---

Markdown alternate of https://cellcog.ai/blog/openai-false-front-operations/. Try CellCog free, no credit card needed: https://cellcog.ai/signup
