OpenAI bans Chinese network using ChatGPT to pose as journalists, offer $2,000/hr for intel
Curated by the Inblix editorial team
OpenAI has banned a network of accounts it says used ChatGPT to fuel a multi-pronged intelligence collection operation, a campaign the company has dubbed “VAGue Focus.” The threat actors, operating primarily during mainland Chinese business hours, didn’t deploy sophisticated malware. Instead, they used the AI to lubricate the mundane machinery of social engineering: generating fake journalist personas, translating honey-trap messages, and polishing correspondence meant to hook a U.S. Senator’s office.
The operation revolved around three fictitious entities—Focus Lens News, BrightWave Media Europe, and Visionary Advisory Group (VAG). OpenAI’s models were prompted to craft social media posts and bios for X accounts posing as geopolitical analysts. The most successful of these, Focus Lens News, amassed 17,000 followers. But before you picture a viral disinformation juggernaut, that number is likely smoke and mirrors. The account was originally created in 2014 under a different name, tweeted for three days, and then went dark until mid-2024. That’s a classic signature of a compromised account bought for a quick credibility boost, not a groundswell of organic support.
The financial bait was startlingly direct. The operators translated instructions claiming VAG was willing to pay $2,000 per hour for interviews on U.S. economic policy and even floating offers to buy classified documents. They also generated a message targeting a U.S. Senator regarding an Administration official’s nomination, though OpenAI can’t confirm it was ever sent. Elsewhere, the accounts translated messages from Chinese to English designed to engage researchers and journalists online, some of which appeared to be private direct messages that never surfaced in public searches.
A telling slip-up sat in plain sight on VAG’s supposed Turkish consulting website: the only Chinese characters on the entire domain appeared in the “Contact Us” menu. It’s a small but damning detail that underscores how even AI-assisted influence ops can be betrayed by basic operational security failures. While the public-facing influence effort barely registered on the IO Impact Breakout Scale—flailing at the low end of Category 2 with little real engagement—the covert social engineering remains the bigger unknown. OpenAI admits there simply isn’t enough evidence to assess how many private targets might have taken the bait. In a threat landscape obsessed with generative AI’s potential for deepfakes and malware, VAGue Focus is a reminder that the technology’s most immediate espionage value is far duller: perfecting the grammar on a bribe.
💡 Key Takeaways
- The operation’s public-facing X accounts saw little authentic engagement, with the largest account's follower count inflated by a compromised, dormant handle created in 2014.
- OpenAI assessed the network's technical sophistication as low, noting their questions about cyber attack tools only yielded basic, general explanations from the models.
- The operators translated direct offers to pay $2,000 per hour for interviews and to purchase classified documents, showing a clear financial inducement strategy for intelligence gathering.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.