CiberLATAMbywhalemate

OpenAI flags Russian ops in Latin America

OpenAI suspended accounts used in covert influence campaigns in Argentina, Bolivia, Peru and Ecuador, with AI-assisted ransomware reported in Mexico.

Whalemate Labs · AI-assisted researchPublished:3 min read

OpenAI said it suspended ChatGPT accounts traced to Russia for supporting covert influence operations aimed at Latin American countries, with a particular focus on Argentina and Bolivia. The company also said one campaign used fake email addresses to deceive schools in Peru and Ecuador, while another spread content on local political issues.

OpenAI said it suspended ChatGPT accounts traced to Russia after they were used to support covert influence operations aimed at Latin American countries, with a particular focus on Argentina and Bolivia. The company also said one of those campaigns used fake email addresses to deceive schools in Peru and Ecuador, while another spread content about local political issues.

What did OpenAI detect in these operations?

OpenAI said it identified and blocked two covert influence operations that used ChatGPT to draft and update internal reports. According to the company, the activity included messages designed to interfere in domestic politics in Bolivia and Argentina, along with pieces aimed at Latin American schools that included local references.

NBC News reported that the Russian operation was not limited to generating content. It allegedly deceived Latin American schools and used a fake regional education authority in Peru to promote activities about Ukraine with references to Stepan Bandera. CyberScoop, for its part, identified the operation as Dark Clark and said it used fictitious journalist personas and a covert think tank to place narratives in the media.

What other offensive uses of AI were reported in the region?

In Mexico, The Economist reported that cybercriminals used AI in a ransomware attack against a Mexican organization, within a campaign that reached more than two dozen organizations across six countries. Mexico Business added that a ransomware affiliate used an AI coding assistant through MCP to carry out actions inside compromised systems, as part of the same regional campaign.

El Economista also reported that SCILabs recorded 290 attacks in Latin America during the first half of 2026, up 25.5% from the previous half. Mexico accounted for 17.93% of those cases, or about 52 attacks, according to that coverage.

What did other coverage say about the regional scope?

Unite.AI, in secondary coverage of OpenAI's alert, said one of the operations also used a fake email to deceive schools in Lima, Peru, and that another campaign claimed to have spread fabricated audio about a water crisis in Bolivia. CyberScoop added that the fake audio about possible water cuts in La Paz prompted an official denial from the Bolivian government.

The Decoder reported, without official confirmation, that falsified content, including audio and documents, may have triggered official checks and denials in Ecuador and Peru, and that the network had incorporated local personnel without knowledge of the operation.

How does this connect to the broader regional debate?

The United Nations, according to press coverage of a UNODC report, warned that AI is increasing the scale and efficiency of criminal operations, including phishing campaigns and deepfake-based impersonation. In Colombia, a study cited by El Espectador found that 71% of respondents received at least one digital fraud attempt in the last year, and that 53% would let an AI tool analyze their personal information to detect it.

At the same time, Latin American media reported an investigation into cybercrime-as-a-service platforms using AI to sell phishing and fraud tailored to Latin America, with Argentina accounting for part of the tracked operations.

Sources

View all