← All posts post

Exposed by Their Paperwork

Threat InvestigationOctober 2026 · 1 min read

The most interesting detail in OpenAI's new report isn't that state actors used ChatGPT to write propaganda. It's that Russian operatives used it to write status updates to their own bosses.

And that's what exposed their campaigns.

Those internal updates gave OpenAI a window into influence campaigns that hadn't previously been attributed to Russia at all. The operatives didn't get exposed by their payloads. They got exposed by their paperwork.

From a threat investigation standpoint, that's the whole lesson in one story: adversaries leave their clearest traces in the tools they use for convenience, not in the attacks they plan carefully. Operational metadata, who is updating whom, in what language, about what, is often more revealing than the malicious output itself.

The signal is rarely where the noise is loudest. It's in the part nobody thought to hide.

Sources

  1. OpenAI caught Russians and Iranians using ChatGPT for influence campaigns, NPR (October 8, 2026)
  2. Disrupting AI-enabled “false front” operations, OpenAI