OpenAI blocked two influential operations that used ChatGPT alongside conventional techniques to give a credible appearance to false structures and professionals. One, attributed to actors operating from Russia, reportedly recruited people in Latin America without their knowledge to operate an alleged research centre. The other, operating from Iran, used seven journalists' identities to offer articles to international media.
For creators, freelancers, consultants and small editors, the lesson is very concrete: a well-written proposal, a careful contract, a professional site and several social profiles are no longer sufficient to prove that collaboration is legitimate. Artificial intelligence reduces the cost of building a coherent facade. It does not create manipulation alone, but it allows for faster production of biographies, presentations, messages, documents and reports that give confidence.
Information verified on 9 October 2026. OpenAI released its analysis on October 8 and reported that it had banned the relevant account groups. This is not a product launch or deployment for the public. The operations described came from Russia and Iran, with targets or relays especially in Latin America and in international media.
What OpenAI really discovered
OpenAI describes these devices as false fronts, which can be translated into organizations or facade identities. Their role is to hide the true sponsor of a content, mission or campaign behind a structure that seems independent and legitimate.
The first operation, nicknamed "Dark Clark", used ChatGPT accounts from Russia. It targeted several Latin American countries, including efforts to degrade the image of Ukraine or to intervene in local political debates. Operators seemed to control an alleged research platform called Social Research Center through a false identity. According to the evidence examined by OpenAI, local collaborators did not know that they were working for a Russian group.
ChatGPT was primarily used to prepare internal reports, prepare content and improve documents. OpenAI also explained that it had observed the language preparation of a false contract then used to support a false story. Open research by journalists and verification organizations had already linked several such operations to a network of Russian influence active on several continents.
The second operation, nicknamed "Bogus Bylines", came from Iran. Its operators used seven identities of supposedly Western journalists to improve articles in English, adapt their proposals to different media criteria and write emails sent to publishers. OpenAI claims to have identified nearly a hundred articles published or reproduced under these signatures by about a dozen sites.
The same actors also produced series of comments supporting their stories. But this social activity seems to have achieved little commitment. The most effective strategy was therefore not to create a huge volume of false comments: it consisted of having content published by real media and borrowing its credibility.
The real risk: lend its reputation to an invisible sponsor
The common thread between the two operations is not just the use of ChatGPT. Influence campaigns existed well before the generative models. The novelty lies in the ease with which a group can now maintain several characters, harmonize their biographies, translate documents, adapt messages to each contact and produce a large amount of professional content.
VIFLY’s perspective: as professional appearances become easy to make, trust must move from rendering to verifiability. A beautiful site, a perfectly written email or an elegant contract are presentation signals, not proof of identity.
A creator can be asked to produce a video, participate in a study, sign a forum, relay a campaign or represent an organization at an event. Even if he does not know the real sponsor, his name, face and community can then serve as social validation.
The injury is not limited to an unpaid invoice. A person may discover after publication that he or she worked for a facade structure, contributed to a hidden political campaign or transmitted personal information to a fictitious interlocutor. The hearing may then consider that she voluntarily endorsed the operation.
This news complements the VIFLY guide on how to find and qualify brands for collaborations. Identifying an active enterprise is not enough: it is still necessary to check who actually formulates the proposal, for what purpose and with what responsibilities.
Two concrete scenarios for the VIFLY audience
A designer receives a mission from a research organisation
A designer specializing in media education receives a very professional email. An "international research centre" offers a paid mission: interviewing several people, producing a short video and publishing the results. The site presents a team, reports and some LinkedIn profiles. The contract uses a credible legal vocabulary.
Before accepting, she looks for the structure in the official registers, checks the seniority of the domain, independently contacts two supposed members of the team and asks for a video conference with the signatory. She discovers that the legal address does not correspond to any registered organization and that one of the researchers mentioned does not know the project.
The right reflex is not to conclude that any young structure is fraudulent. The commitment should be suspended until the sponsor's identity, funding, end use of content and validation chain are explained.
Freelance approached by fake journalist
A consultant receives an interview request from a person who presents himself as an independent journalist. His profile contains publications, several photos, a consistent biography and links to articles with his signature. She wants a quick reaction on a sensitive subject and also asks for internal documents to "contraxtualize" the exchange.
The consultant checks directly with the editors hosting the articles, reviews the accounts history and offers a video call. The interlocutor refuses any synchronous verification and cannot provide an editorial mission letter. The consultant does not transmit the documents.
In this scenario, the publication of articles under a name does not guarantee that identity is authentic. The OpenAI report shows precisely that a false signature can succeed in publishing texts and gradually build a digital footprint.
Minimum verification before collaboration
The first audit concerns the organization. For a French structure, business yearbook allows to consult the public legal information of companies, associations and public services. The presence of a SIREN or a SIRET is not sufficient, however, if the fraudster usurps the presence of a genuine company: the name of the signatory, the email domain and the contact details must also correspond.
The second check is on the channel. A message from a free address or a newly created domain deserves more caution. If an individual claims to represent a known organization, contact that organization from the contact information published on its official website, without answering only the number or address provided in the initial message.
The third audit concerns the mission itself. Ask who funds the project, where the content will be distributed, whether it will be sponsored, translated, modified or used in advertising, and who assumes editorial responsibility. A vague answer about the actual sponsor is an important signal, especially for a political, financial, medical or geopolitical subject.
The fourth concerns contract and payment. The document must identify the parties, deliverables, remuneration, user fees, territory, duration and terms of termination. The VIFLY guide on and within the framework of creative collaborations recalls that a professional mission never boils down to "a publication against an amount".
Finally, keep the evidence: initial proposal, emails, profile used, contract, bank details, invoices and versions of content. Cybermalveillance.gouv.fr recommends the same logic in the face of false recruiters: fraudsters can usurp the name, address, identity of an employee and even the SIRET number of a real company.
Shades and limits to keep in mind
- OpenAI describes what it has observed on its own services. The company does not have full visibility on all the operators' external actions.
- Not all relevant content was generated by ChatGPT. Campaigns combined AI, false profiles, documents, human relations and older influence techniques.
- Some statements of impact came from the operators themselves. OpenAI points out that they sometimes exaggerated their results or attributed events to which they had not contributed.
- A small organization or new media is not automatically suspicious. The lack of seniority calls for enhanced verification, not a public accusation.
- A text assisted by IA is not evidence of fraud. What is problematic is the concealment of the real identity, sponsor or objective.
- Video conferencing is not an absolute guarantee. It complements legal and documentary verification, but does not replace it.
- A coherent social footprint can be made. Accounts on multiple platforms, photos and old publications must be cross-referenced with independent sources.
The witch hunt must also be avoided. Publicizing the name of a person or business by accusing without evidence can cause serious harm. If in doubt, interrupt the collaboration, keep the elements and use the appropriate reporting channels.
What to do now? The method VIFLY in eight stages
- Identify the organisation legally. Check the official country register, address, leaders and activity declared.
- Cross-check the identity of the contact. Look for its history, then confirm its role with the organization through a second channel.
- Examine the domain and coordinates. Compare the email address with the official domain and beware of spelling variants.
- Ask for a real conversation. Organize a call to explain the project, sponsor and end-use of content.
- Clarify the interests involved. Who pays? Who's valid? Who benefits from the message? Is the content editorial, commercial, political or activist?
- Framework the rights. Clearly limit the duration, platforms, countries, changes, advertising and any re-use of your image or voice.
- Protect sensitive information. Please send no full ID, excessive bank data, or customer documents before you have validated the contact person.
- Keep a verifiable trace. Archive the exchanges and reject last minute changes that cannot be attached to the contract.
Creators can also strengthen their own professional identity. Article VIFLY on artificial profiles and trust on Instagram shows why a central, consistent and attributable presence becomes more important when plausible identities can be generated.
A LinkHub VIFLY can collect your identity, media kit, verifiable collaborations, conditions and official contact information. If a brand or media wants to exchange, VIFLY Booking allows you to move the conversation out of a single DM and organize an appointment linked to your career.
The conclusion is not that unexpected collaborations should be refused. Some of the best opportunities start with a message. But the level of completion of the message must never replace the verification of the person sending it.
In the AI era, trust can no longer be based solely on the coherence of a story. It must be based on elements that can be overlapping.
FAQ on fake identities and collaborations
What is a facade organization?
It is a structure that seems independent or legitimate but hides its true controller, its financing or its objective. It can employ real people who themselves ignore the identity of the final sponsor.
Does OpenAI say that AI has created the whole operation?
No. OpenAI explains that the actors combined its models with traditional techniques: recruitment, false profiles, social dissemination, misleading documents and media relations. IA facilitated some workflows.
How to quickly check a French company?
Look for his name, SIREN or SIRET in the Business Directory. Then check that the email domain, address and contact person actually match the official information.
Are an old LinkedIn profile and several articles sufficient?
No. These elements increase plausibility, but they can be manufactured or obtained gradually. Cross-check the identity directly with the organisations and media cited.
What signals should lead to suspension of collaboration?
An unidentified sponsor, a refusal to appeal, excessive time pressure, an unusual request for secrecy, payment from an unexplained third party, inconsistent contact information or a request for sensitive documents are serious warnings.
What if we think we've been manipulated?
Interrupt exchanges, store all evidence, notify platforms or organisations whose identity has been usurped and use official reporting devices. In case of injury, approach the competent authorities.