← All posts post

Teardown: Dark Clark, the Fake Think Tank That Filed Status Reports

Influence OperationsOctober 2026 · 3 min read

On October 8, 2026, OpenAI banned two clusters of ChatGPT accounts running influence operations: one of Russian origin, one of Iranian origin. The Russian one, which OpenAI calls Dark Clark, is the first operation to reach Category 5 on OpenAI's six-level Breakout Scale. Here's how it worked, and what it teaches investigators.

The front

Dark Clark ran a think tank called the Social Research Center. Its public face was Mia Clark, a persona that didn't exist. The operation targeted Latin America, aiming to undermine support for Ukraine and push local politics in its favor.

It hired real people. According to OpenAI, the local staff appear not to have known they were working for a Russian operation. That's the point of a front: real people produce real work, and that lends cover to the fake parts.

The fakes

  • Fabricated stories pushed into Latin American media to undercut Ukraine and local leaders
  • In Peru, operatives impersonated a regional education authority and got schools to organize activities about Ukraine that featured Stepan Bandera, according to NPR
  • Content that drew public reactions from politicians, which is what earned the Category 5 rating

The paperwork

Here's the part that matters most. Generating propaganda was a minority of the workload. Most of the Russian accounts' ChatGPT use went to status write-ups for unnamed superiors, and some of those write-ups inflated the operation's impact.

Those internal reports shed light on influence campaigns that hadn't previously been attributed to Russia. The operators were careful with their payloads and careless with their paperwork.

Attribution

Open-source researchers linked some of the fake stories to a Russian group known as Politologia, or La Compania, a reported successor to organizations tied to Yevgeny Prigozhin. OpenAI's own findings don't tie the operation to a specific government agency. Keep those two layers separate: platform telemetry showed what the accounts did, and outside research suggested who was behind them.

The Iranian side

The Iranian cluster used a different playbook. It invented seven fake authors posing as Western journalists and used ChatGPT to pitch and polish long articles for small and mid-sized outlets. Almost 100 articles ran. Operators wrote their prompts in Persian and had the model produce polished English. OpenAI assessed it as consistent with a commercial, for-hire operator but couldn't identify who.

What investigators should take from this

  • Look at operational metadata, not just output. Who reports to whom, how often, and in what language tells you more than the propaganda does.
  • Origin blocks don't stop motivated operators. Both clusters reached ChatGPT through VPNs.
  • Language is a fingerprint. Prompting in one language and publishing in another is a seam worth checking.
  • Adversaries inflate their own numbers. Their internal reports are evidence of intent and structure, not of actual impact.
  • Fronts mix real and fake. Unwitting staff make an operation look legitimate, so verify the organization, not just the people.

The loudest part of an operation is the content it wants you to see. The most revealing part is the work it does for itself.

Sources

  1. Disrupting AI-enabled “false front” operations, OpenAI
  2. OpenAI caught Russians and Iranians using ChatGPT for influence campaigns, NPR (October 8, 2026)
  3. Iranian operatives used AI to plant fake stories in multiple US media outlets, CNN (October 8, 2026)
  4. OpenAI uncovers Russian and Iranian influence ops that planted fake stories in real news outlets, The Decoder