October 8, 2026, (Inside AI) — A sophisticated Russian influence operation successfully co-opted unwitting Latin American researchers to produce original content for a fake think tank, marking the first time a covert AI-enabled campaign has reached Category 5 on the IO Breakout Scale, according to a new threat report published today. The operation, nicknamed "Dark Clark," represents the most complex front identity disruption in over two years of tracking, with evidence suggesting its fabricated stories penetrated mainstream media across Peru, Poland, Ecuador, and Bolivia.
The Russian campaign ran from at least early 2024 through mid-2026, using ChatGPT to draft internal reports, create fake documents, and manage a network of unwitting staff. Unlike previous operations that relied primarily on social media distribution, Dark Clark successfully planted content in established news outlets, triggering official government denials and fact checks in multiple countries. The operation also fed into historical tensions between Ukraine and Poland through a fabricated story about Ukrainian nationalist Stepan Bandera being promoted in Peruvian schools.
Unwitting Researchers Built Fake Think Tank's Credibility
At the center of the operation stood the Social Research Center (SRC), a self-described research platform focusing on Indian diaspora issues in Latin America. According to internal reports obtained during the investigation, Russian operators controlled the SRC through a fake persona named "Mia Clark" and made hiring, firing, and payment decisions while their Latin American employees conducted research in good faith, unaware they were working for a Russian intelligence-linked group.
The evidence indicates that SRC employees were not aware they were working for a Russian group. They conducted interviews with experts across the region and drafted research papers on topics ranging from BRICS public opinion to comparative economic analysis of Brazilian presidents. Investigators identified over 60 original articles on the SRC website, distinguishing this operation from previous Russian front think tanks that relied heavily on plagiarized content.
This approach mirrors the 2020 "PeaceData" operation, which Meta exposed for co-opting unwitting journalists. Both operations share connections to entities founded by Yevgeniy Prigozhin, the late Russian oligarch whose Wagner Group successor "Politology" or "La Compania" has been linked to several fakes claimed by Dark Clark.
The operators used VPNs to access ChatGPT from Russia, where the service is unavailable. They prompted primarily in Russian, with one operator using Spanish while apparently located in Russia. Their internal reports described three main workstreams: denigrating Ukraine and undermining military recruitment, interfering in Bolivian and Argentine politics, and managing the SRC.
Open-source evidence corroborated several claimed operations. In May 2026, the operators allegedly created a fake email address impersonating Peru's Regional Directorate of Education, instructing schools to hold events honoring Bandera on the national Day of Cultural and Linguistic Diversity. Some schools reportedly complied and sent photographs. Stories about these events subsequently appeared in Peruvian, Polish, and Hungarian media, with one Polish Member of the European Parliament proposing that people showing "anti-Polishness" be declared persona non grata.
In Ecuador, the operators claimed to have tricked schools into holding ceremonies pledging allegiance to President Daniel Noboa and Erik Prince, former head of Blackwater. The incident provoked enough outrage that Ecuador's Minister for Education issued a detailed rebuttal. Fact checkers also debunked a fake contract purportedly between "International Security Solutions FZE" and an Ecuadorian individual, which the operators had asked ChatGPT to proofread and format.
Other operations targeted Bolivia during anti-government protests in May 2026, spreading fake audio claiming the government would shut off water to La Paz. The state water company EPSAS issued an official denial. The operators explicitly described their goal as exacerbating the crisis around the protests.
However, the report cautions that the operators' own claims of impact cannot be taken at face value. They frequently took credit for incidents they had nothing to do with, including claiming responsibility for Argentina's long-standing official position on the Falkland Islands and a Brazilian media report about a citizen captured in Ukraine. This suggests an attempt to run an influence operation targeting their own employers rather than external audiences.
The operation's social media efforts encountered significant obstacles. According to internal reports, operators in different locations struggled to access the same accounts, triggering platform restrictions. A LinkedIn account for the SRC counted 961 followers by August 2026 but listed only two employees despite claiming 200-500 staff. The main X account showed a German location but connected via the Russian Federation App Store, while an Instagram account displayed an admin location in Venezuela.
The Iranian operation, dubbed "Bogus Bylines," took a different approach. Seven fake journalist personas pitched long-form articles to small and medium online outlets worldwide, with nearly 100 articles published or syndicated across roughly a dozen publications. The personas, including Ervin B. Hoskins, Noah Lamington, and Sophia Gonzalez, purported to be Western journalists focused on international politics and Middle East affairs. Some were backstopped by social media accounts that transparency settings located in Iran.
The earliest identified article appeared in July 2025, with publication frequency increasing sharply after the US-Iran conflict erupted. One outlet that published the operation's articles had almost 2 million Facebook followers as of August 2026. The operation also generated batches of social media comments, though these received minimal engagement. Internal reports used a deceptive calculation measuring views on posts they replied to rather than views on their actual replies, inflating apparent effectiveness.
Both operations demonstrate how AI can enhance traditional influence techniques with greater scale, efficiency, and linguistic fluency. The report notes that understanding these vulnerabilities will be essential for maintaining robust defenses across organizations. The covert nature of false-front operations also makes them vulnerable to responsible disclosure, as demonstrated by the shutdown of "Alice Donovan" and "PeaceData" after exposure.
Read: Stanford Study: Users Trust Sycophantic AI Chatbots Despite Knowing They Lie
The findings underscore a pattern observed across 30 covert influence operations exposed since early 2024: campaigns that land content in real media outlets rather than relying on fake social media distribution tend to achieve the highest potential reach and impact. Both operations have been reported to relevant authorities, with information shared to enable further research and disruption.