Close Menu
Web StatWeb Stat
  • Home
  • News
  • United Kingdom
  • Misinformation
  • Disinformation
  • AI Fake News
  • False News
  • Guides
Trending

GAHA: The corporate-created “healthier America” movement challenging what it claims is MAHA misinformation about modern farming, chemicals, and food

October 9, 2026

Ukraine’s Disinformation Center Says Russia Is Expanding Surveillance of Schoolchildren

October 9, 2026

Posts share false key dates for November state poll in Malaysia

October 9, 2026
Facebook X (Twitter) Instagram
Web StatWeb Stat
  • Home
  • News
  • United Kingdom
  • Misinformation
  • Disinformation
  • AI Fake News
  • False News
  • Guides
Subscribe
Web StatWeb Stat
Home»AI Fake News
AI Fake News

Disrupting AI-enabled “false front” operations

News RoomBy News RoomOctober 8, 2026Updated:October 9, 202610 Mins Read
Facebook Twitter Pinterest WhatsApp Telegram Email LinkedIn Tumblr

Over the past two and a half years, we’ve watched threat actors try to bend AI to their will in dozens of ways—running cyber attacks, spreading scams, and trying to manipulate public opinion. We publish these stories because regulators, industry peers, and the public need to see how these people are actually working. Recently, we had to ban two influence operations that felt different from the usual sloppy junk we see—one tied to Russia, one tied to Iran. They were patient, polished, and built to look like legitimate media efforts. The Russian operation created a fake “think tank” in Latin America, run partly by real but unwitting local staff, while the Iranian operation invented seven fake journalists and used them to pitch long-form articles to online outlets around the world. Both used our models as a writing, editing, and translation assistant, but they also leaned heavily on old-fashioned tricks: fake letterheads, “leaked” documents, planted audio clips, and fake social media personas. In many ways, these were classic false-front operations—the kind of espionage that long predates the internet—but AI made them easier to scale and harder to catch. The Iranian operation looked a lot like the fake journalist personas we’ve seen from Russian military intelligence in the past; the Russian operation echoed an earlier fake news outlet that recruited unwitting writers. What made them stand out was their reach. On the breakout scale we use to rate influence operations from 1 to 6, the Russian operation hit Category 5—the first time we’ve disrupted one that high—and the Iranian operation reached Category 4. Both managed to get their content into real media outlets, not just fringe social media pages. That, we’ve learned, is the difference between a nuisance and a genuine threat.

The Russian operation, which we nicknamed “Dark Clark,” was aimed at Latin America. The operators were based in Russia, prompted mostly in Russian, and used VPNs to hide their location. Their goals were to undermine Ukraine’s reputation in the region, especially around its resistance to Russia’s invasion, and to interfere in local politics, particularly in Argentina, Bolivia, and Ecuador. Their main use of ChatGPT was not to write propaganda for public consumption—though they did some of that—but to write internal reports to an unknown superior. These reports were filled with tactical detail: they described fake stories they had spread, the reactions they had hoped to provoke, and the management of their front company. Some of their claims matched public reporting about a Russian entity called “Politology” or “La Compania,” a reported successor to Wagner and other Prigozhin-linked operations. For example, they claimed to have spread a false story that Argentina’s President Javier Milei had bought jeweled collars for his dogs, and that they paid locals to paint anti-Milei graffiti in Buenos Aires. Both claims have been publicly attributed to Politology. But they also invented many fakes that had never been tied to Russian influence operations. In Peru, they created a fake email from a regional education department, ordering schools to hold events dedicated to Ukraine on a national cultural day, with instructions to mention Stepan Bandera, a historically divisive figure. Some schools actually replied and sent photos, and the operators then planted media stories about it in Peru, Poland, and Hungary, provoking outrage and even a Polish MEP calling for “anti-Polishness” to be declared unacceptable. In Ecuador, they used a similar fake email to trick schools into holding a ceremony pledging allegiance to President Daniel Noboa and Erik Prince, the former head of Blackwater. That one triggered official denials and nationwide coverage. They also used fake audio clips—one attributed to Ukraine’s consul in Ecuador, another to a Bolivian water company employee—hoping to inflame tensions. Some worked; some flopped. But the pattern was clear: this was not a lone troll. It was an organized, funded operation trying to exploit real institutions and real people.

The most unusual part of Dark Clark was the “Social Research Center,” a think tank the operators controlled through a fake persona named “Mia Clark.” According to their internal reports, they hired real people in Latin America to run research projects, conduct interviews, and write papers—without those people knowing they were working for a Russian operation. The staff interviewed experts across the region and produced dozens of original articles on topics like BRICS and the Brazilian economy. The operators made decisions about hiring, firing, and pay scales, all while pretending to be a legitimate research platform. This was a serious attempt to build a durable, credible front entity, not just a fake Facebook page. It resembled a 2020 operation called PeaceData, but it was more sophisticated because the staff were unwitting and the content was mostly original. The operators also tried to build a social media presence for the SRC, but they kept running into technical problems—accounts locked because different operators in different time zones tried to access them, transparency settings that revealed Russian app stores, and Instagram accounts with admin locations in Venezuela. Their LinkedIn strategy was almost comical: they created a fake account to represent the SRC, then created more fake accounts to follow it and make it look more convincing. They occasionally used ChatGPT to help with content, such as translating a Russian-language script about Noboa insulting poor people into Ecuadorian Spanish, or proofreading a fake contract between a company and an individual in Ecuador that was later circulated online to support a false claim about government recruiting. When we assessed the actual impact, we had to be careful: the operators often took credit for events that had nothing to do with them, and some of their claimed fakes never appeared in open-source searches. But enough were verified—by fact-checkers, official denials, and media coverage—to place this operation at Category 5, the highest we’ve ever disrupted.

The Iranian operation, which we called “Bogus Bylines,” was smaller in geographic scope but still ambitious. The operators were based in Iran, used VPNs, and prompted in Persian, while generating content in both Persian and English. Their main workstream was to refine long-form articles about the US-Iran conflict and pitch them to small and medium online outlets under fake Western journalist names. They created seven personas—Ervin B. Hoskins, Noah Lamington, Sophia Gonzalez, Michael Harrison, Ericka Feusier, Jenny Williams, and Alice Johnson—each with a backstory and, in some cases, social media accounts to make them look real. They would ask ChatGPT to review an English-language draft against a specific outlet’s submission guidelines, suggest edits, and then generate a pitching email to the editor. This worked surprisingly well. We identified almost 100 articles published or syndicated under these bylines across more than a dozen outlets, mostly focused on international affairs, geopolitics, and the Middle East. The earliest appeared in July 2025, and the frequency jumped dramatically after the US-Iran conflict escalated. At least one outlet had nearly two million Facebook followers, giving the operation a potential audience far beyond what a fake social media account could ever reach. The articles themselves were not overtly crazy; they were opinion pieces that framed the US as aggressive, Israel as an unreliable ally, and Iran as a defiant but resilient victim. That made them harder to spot as propaganda. The operation also generated batches of social media comments, often replying to posts about missile strikes, ceasefires, or diplomacy, with instructions to portray the US as the aggressor and Iran as a victim. They even replied to posts about their own articles with praise, trying to make the articles look more popular than they were. Some of those comments were posted by accounts with Western-sounding names but transparency settings showing they were located in Iran. But by and large, the comments did not take off—they got very few likes or replies, and they usually made up a small minority of the discussion on any given post.

When we measured the impact of the two halves of the Iranian operation, the contrast was stark. The social media commenting workstream was, on the breakout scale, a Category 2: it appeared on multiple platforms, but it never broke out, never dominated the conversation, and showed little sign of real influence. The operators’ own internal reports tried to claim otherwise, using a deceptive metric that counted views on the original posts they replied to rather than views on their actual comments. That inflated their numbers and made their work look much more successful than it was. But the article-pitching workstream was a different story. By getting those long-form articles published in real outlets, some with significant followings, the operation achieved Category 4, because it consistently broke out into media that people actually read and trusted. This is the same pattern we’ve seen across the thirty influence operations we’ve exposed over the past two and a half years: operations that focus on landing content in real media outlets have far more potential impact than those that rely on fake social media accounts alone. Social media still matters, but it’s often used as a supporting tool—to amplify the articles, to seed comments, to make a fake persona look real. The real prize is editorial acceptance. If a fake journalist can convince an editor to publish an article, that article carries an authority no anonymous tweet can match. And that’s exactly what these operations were after. They were not trying to go viral; they were trying to pass as part of the legitimate information ecosystem.

The bigger lesson here is that AI is not making influence operations radically new; it’s making them easier, faster, and more plausible. It helps operators write fluent English and Spanish, refine articles to match submission guidelines, translate scripts with the right regional accent, and generate an endless stream of comments. It also helps them write internal reports that make their work look successful—to themselves, or to whoever is funding them. That last point is important: both operations used AI to exaggerate their own effectiveness, which suggests that the people running them were more concerned with justifying their budget than with actually changing minds. But the core vulnerabilities they exploited are human. Editors at small media outlets thought they were publishing a freelance journalist. Staff at the “think tank” thought they were doing legitimate research. Schools in Peru and Ecuador thought they were receiving official government emails. The best defense, then, is not just better AI detection; it’s human awareness, media literacy, and institutional verification. We know that disclosure works: both the Alice Donovan and PeaceData operations stopped after they were exposed. That’s why we publish these reports—to make it harder for these operations to continue, and easier for researchers, journalists, and the public to recognize the patterns. We’re not naive enough to think this will stop all influence operations. But every time one is exposed, it raises the cost for the people running it. They have to abandon personas, delete accounts, re-establish credibility, and explain to their sponsors why they got caught. In the long run, that is a fight worth having. The goal is not to silence speech; it’s to expose deception. And the more we can shine a light on these false fronts, the less power they have.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
News Room
  • Website

Keep Reading

Iranian operatives used AI to plant fake stories in multiple US media outlets

How are AI photos trying to manipulate opinion and create “fake news”?

AI Misuse: Runsewe Warns Against Fake Content, Social Media Manipulation – Independent Newspaper Nigeria

AI: Runsewe warns against fake content, social media manipulation

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

INEC creates AI division to verify results, curb fake news

Editors Picks

Ukraine’s Disinformation Center Says Russia Is Expanding Surveillance of Schoolchildren

October 9, 2026

Posts share false key dates for November state poll in Malaysia

October 9, 2026

FIGHTING AGAINST MISINFORMATION ABOUT UNIVERSAL HEALTHCARE (Part 3

October 9, 2026

US pressured EU to withdraw sponsorship of disinformation conference

October 9, 2026

Niger warns content creators over misinformation

October 9, 2026

Latest Articles

Fort Hare VC accused of lying under oath to keep forensic lawyer’s assets frozen

October 9, 2026

Lithuania Refuses to Participate in Disinformation Conference as It Criticizes the U.S.

October 9, 2026

Automated ultrasound had fewer false positives in US study — News-Medical

October 9, 2026

Subscribe to News

Get the latest news and updates directly to your inbox.

Facebook X (Twitter) Pinterest TikTok Instagram
Copyright © 2026 Web Stat. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Contact

Type above and press Enter to search. Press Esc to cancel.