Safety & Security

OpenAI Bans China-Linked ChatGPT Accounts in 'Silver Lining Playbook' Op

OpenAI banned China-linked ChatGPT accounts that drafted fake consulting-firm emails targeting US officials and researched federal offices and US persons, per its February 2026 report.

Silver lining playbook: Likely China-origin activity targeting US persons
Silver lining playbook: Likely China-origin activity targeting US personsjurvetson / Openverse
By Rebecca Stone4 min read

Updated

Why it matters

  • OpenAI banned ChatGPT accounts likely from mainland China that used its models to draft social-engineering emails posing as Hong Kong-based 'Nimbus Hub Consulting', disclosed in its February 2026 report.
  • The accounts researched US federal office locations, personnel distribution by state, Voice of America hosts, and industry forums, and one sought novice-level installation help for the FaceFusion live face-swapping tool.
  • OpenAI found no evidence targets replied to the invitations and could not confirm the emails were sent; the US, UK, and Australia have warned that foreign intelligence services pose as consulting firms to recruit government employees.

OpenAI has banned a small set of ChatGPT accounts, likely operated from mainland China, that used its models to research US persons, federal office locations, and professional forums, and to draft English-language social-engineering emails aimed at US officials and policy analysts. The company disclosed the operation, which it named "Silver Lining Playbook," in its February 2026 report on disrupting malicious uses of AI.

The accounts prompted OpenAI's models in Chinese, operated mostly during mainland Chinese business hours, and connected through VPNs. Their email drafts claimed to come from employees of a Hong Kong-based company called "Nimbus Hub Consulting." But the operators wrote in Simplified Chinese characters, typically used in mainland China, rather than the Traditional characters typical of Hong Kong — a detail OpenAI said suggests the actors were actually based on the mainland. One account also drafted an email purporting to come from a representative of a Shanghai-based public relations organization that promotes US-Shanghai economic and cultural exchanges.

OpenAI named the operation "Silver Lining Playbook" because "Nimbus" means a rain cloud or halo, according to the report. Screenshots included in the disclosure show LinkedIn profiles affiliated with Nimbus Hub Consulting; OpenAI said some matched individuals listed on the firm's "Our Team" page. The company's website, which presented Nimbus Hub as a professional strategic consulting firm, is no longer online but has been archived.

How the operation worked

The emails targeted state-level US officials and policy analysts working in business and finance. They invited recipients to paid consultations described as interpreting policy and providing strategic advice for clients. The operators instructed the models to keep drafts concise, clear, and professional, with subject lines that created urgency and used subtle psychological cues.

Beyond email drafting, the accounts used ChatGPT for general information retrieval, answered by the model from publicly available sources. Queries included:

  • Locations of US federal government offices, including a ranked list of states with large concentrations of federal agencies and officials
  • US federal personnel distribution by state
  • US persons, such as Voice of America hosts, including their past interviews and topics of interest
  • Online forums and websites commonly used by professionals and job seekers in the US economics and finance industry

One account requested step-by-step, non-technical guidance on installing FaceFusion, a face-manipulation platform for face-swapping and media enhancement. The user stated they intended to use its live face-swap functionality specifically, claimed to be a novice programmer, and uploaded a screenshot of their computer's hardware specifications to help with installation. The model responded with information drawn from FaceFusion's public website and documentation.

A recruitment playbook

OpenAI assessed that the email-drafting instructions resembled a social-engineering playbook for a foreign intelligence service approach rather than ordinary hiring messages. For each draft, the operators requested a consistent structure:

Establish legitimacy: Present "Nimbus Hub" as a professional strategic consulting firm with authoritative expertise in geopolitics and transnational policy, including a link to its website.

Personalize and flatter the target: Explicitly cite the recipient's public-sector background as proof they were the exact fit for the role. In one case, an account uploaded screenshots of a US person's LinkedIn profile — an individual based in Shanghai — and instructed the model to personalize the draft using details about that person's experiences and background.

Stack incentives: Frame the consulting offer as a lucrative online opportunity with performance bonuses and referral rewards, while staying vague about the actual work.

Reassure and reduce perceived risk: Claim the work was relaxing, had timely payments, and was confidential.

Move off-platform quickly: Push recipients off email and toward an initial video-conference call via WhatsApp, Zoom, or Teams.

Impact and assessment

The operation was not technically sophisticated. OpenAI noted that individual requests sometimes resembled plausible recruitment-drafting tasks or legitimate software installation help. But the combination of a fake corporate identity and sustained interest in geopolitical topics indicates a possible intention for adversarial recruitment, the company wrote.

OpenAI found no evidence from the accounts' ChatGPT usage that targets replied to the invitations. The company said it could not independently determine whether the emails were actually sent or whether any recipient responded.

The case matters because it shows how commercial AI tools lower the cost of running tailored influence and recruitment operations at scale — and how the traces those tools leave behind now give platform security teams visibility into campaigns that once would have stayed hidden in email inboxes. Multiple democratic governments, including the United States, the United Kingdom, and Australia, have warned that foreign intelligence services target current and former government employees by posing as consulting firms and other entities on social and professional networking platforms.

OpenAI acknowledged that these approaches can be hard to distinguish from ordinary hiring messages because they share similar traits. Legitimate outreach, the company wrote, is usually optimized for slower screening processes and includes verifiable role titles, credible employer details, reasonable market compensation ranges, and links to real job postings.

"In short," the report concludes, "if it's too good to be true, then it probably is."

Original: cdn.openai.com

Share this article:

More from Rebecca Stone

Rebecca Stone

Show full bio

Correspondent covering consumer brands and retail at AI In Context.

135 articles

Related articles

  1. OpenAI Maps the Anatomy of AI-Enabled Romance Scams
  2. How an OpenAI Investigator's Own Phone Helped Bust an AI Task Scam
  3. OpenAI Bans Accounts Reviving Russia's 'Stop News' Influence Operation
  4. OpenAI Bans Korean-Language Accounts Tied to Malware Development
  5. OpenAI Bans PRC-Linked Accounts Running Covert AI Influence Ops

« Previous articleNext article »