OpenAI Bans Five ChatGPT Accounts Tied to Iranian Influence Ops
OpenAI banned five ChatGPT accounts used by Iranian influence operations, finding one account that linked IUVM and STORM-2035 and used rewrites to evade detection.

Updated
Why it matters
- OpenAI banned five ChatGPT accounts in its February 2025 report for generating content for Iranian influence operations, its second disruption of the same networks after earlier action last year.
- One banned account generated content for both IUVM and STORM-2035, suggesting a previously unreported operator-level relationship between the two networks.
- The al-Sarira X account had 157 followers as of January 16, 2025; OpenAI rated the operation at the low end of Category 2 on the Brookings Breakout Scale.
OpenAI has banned five ChatGPT accounts that generated content for Iranian influence operations, and in doing so uncovered a previously unreported connection between two networks that analysts had long treated as separate efforts. The company disclosed the disruption in its February 2025 threat intelligence report, marking at least the second time it has moved against these specific operations.
The banned accounts produced a small number of tweets and long-form articles that were then posted on third-party assets publicly linked to known Iranian influence operations. Two of those operations are well documented. One is the International Union of Virtual Media, or IUVM, which Reuters first exposed in 2018 as an Iran-based political influence effort. The other is STORM-2035, a designation used by Microsoft in its own reporting on Iranian threat activity.
A link between two operations
The most consequential finding in OpenAI's case study concerns the relationship between these two networks. STORM-2035 and IUVM have previously been reported as separate campaigns. But OpenAI found that one of the banned accounts was used to generate content for both of them.
"While small in scale, this suggests a potential previously unreported relationship, at least on the operator level," OpenAI wrote. For researchers who track state-aligned influence operations, that single data point matters. It suggests the boundaries between publicly named Iranian campaigns may be blurrier than the existing taxonomy implies, and that operator-level attribution can reveal connections that content analysis alone misses.
What the accounts actually did
The five accounts divided their output across several online entities. Four of the five generated content that analysts connected to STORM-2035. The fifth generated some content published by entities publicly connected to STORM-2035 and some published by a website connected to IUVM.
The workflows were straightforward. One ChatGPT account generated long-form articles that were posted on a website called al-sarira[.]com, which is publicly linked to STORM-2035. Two other accounts generated tweets that were posted by the al-Sarira domain's X account and by two other X accounts.
STORM-2035 is a wide-ranging operation. The open-source community has documented its websites in Arabic, French, Spanish and English. A fourth banned account used OpenAI's models to generate a small number of Spanish-language articles for another website identified through public research by the Foundation for Defense of Democracies: lalineeroja[.]net. FDD identified 19 websites as part of that Iranian global influence operation in September 2024.
The fifth account is where the case gets interesting. It generated occasional French-language texts that appeared on critiquepolitique[.]com, another site publicly linked to STORM-2035. The same account also generated English-language articles published on iuvmpress[.]co, a website linked to IUVM — the organization Reuters exposed in 2018. According to OpenAI, public reporting had not previously identified overlaps between critiquepolitique[.]com and iuvmpress[.]co.
Rewriting to evade detection
The fifth account's operator also appears to have taken deliberate steps to avoid detection. OpenAI's analysis found that the operator generated articles with its models but then rephrased them before publication. When OpenAI used its own models to analyze the semantic similarity between the draft and the published text, the analysis concluded that the published version was highly likely a rewrite of the generated version.
"This suggests that the operator was using multiple rewrites, possibly to evade detection," the company wrote. That detail is significant for platform defenders. It indicates that at least some operators in this space understand that raw model output can be fingerprinted and matched, and are adapting their pipelines accordingly. Detection methods that rely on exact or near-exact matching of generated text will miss content that has passed through additional rewrites.
What the content said
The material these operations published mirrored the output in OpenAI's earlier disruptions of IUVM- and STORM-2035-linked activity. OpenAI described it as typically pro-Palestinian, pro-Hamas and pro-Iran, and opposed to Israel and the United States. During the abrupt collapse of the regime of President Bashar al-Assad in Syria, the operation generated content that praised Assad and denied reports of his unpopularity in the country.
There was also a quieter detail with investigative value. Some of the banned accounts only occasionally used OpenAI's models for influence content. More often, they asked the models to help design materials for teaching English and Spanish as a foreign language. OpenAI flagged this because earlier Iranian threat activity has been publicly attributed to individuals with a background in teaching English as a foreign language.
Negligible reach
For all the operational sophistication on display — multi-language output, cross-network coordination, rewrite-based evasion — the operation failed to find an audience. As with previous Iranian covert influence operations focused on social media and web articles, this network did not build a substantial online following.
The numbers are stark. As of January 16, 2025, the al-Sarira X account had 157 followers while following 895 accounts. Typical tweets received single-digit engagement counts, if any.
OpenAI assessed the operation's impact using the Breakout Scale, a framework developed at Brookings that rates influence operations from 1 (lowest) to 6 (highest). The company placed this activity at the low end of Category 2: activity on multiple platforms, but no evidence that real people picked up or widely shared the content.
Why it matters anyway
Low engagement does not mean low relevance. The case adds to a growing body of evidence that state-linked operators — Iranian ones prominently among them — are integrating commercial AI tools into existing influence pipelines, and that they persist even when earlier iterations of the same networks have already been disrupted and publicly reported. OpenAI disrupted and reported earlier activity by IUVM and STORM-2035 last year; the operators returned.
The case also demonstrates what platform-side visibility can contribute to threat research. OpenAI could see that one account served two networks, that generated text had been rewritten before publication, and that the same accounts were also used for language-teaching materials — threads that external analysts tracing published content alone had not pulled together. As AI companies become the first point of content generation for a growing share of influence operations, their internal detections are increasingly becoming a primary source of intelligence about how those operations are structured. Expect future threat reports to lean harder on that vantage point.
Original: cdn.openai.com
More from Sophie Lindqvist
Show full bio
Staff writer covering marketplaces and e-commerce at AI In Context.
115 articles
Related articles
- OpenAI Bans Accounts Reviving Russia's 'Stop News' Influence Operation
- OpenAI Bans PRC-Linked Accounts Running Covert AI Influence Ops
- OpenAI Bans Accounts Behind AI-Generated Philippine Political Comments
- OpenAI Bans Accounts Linked to DPRK Threat Actors Using AI for Intrusion Research
- OpenAI drops Mixpanel after vendor breach exposed user data