← All Incident Reports
Incident report · TESSOC: Subversion / Cyber
Information operation - manufactured expertise

The Burke Institute: a Russian influence operation run with ChatGPT

OpenAI has banned a cluster of accounts it assesses were run from Russia through virtual private networks, used to promote an outfit calling itself the International Burke Institute - an expert community with a Tel Aviv address, a roster of distinguished names, and a sovereignty index that happened to rank Russia well.

Of thirty-six articles sampled, thirty-four had been copied from elsewhere, some years old and some attributed to the wrong authors. The institute rejects the characterisation and its website remains online.

↓  Download one-page brief (PDF)
Who
Disclosing party: OpenAI, which banned the accounts and published its findings. Operators: assessed by OpenAI as Russia-origin, using virtual private networks to reach a service not available in Russia, prompting in Russian to produce English output. The International Burke Institute has publicly rejected the characterisation and says it operates in Israel and publishes original research with full source attribution.
What
A covert influence operation built around a fabricated research institute. ChatGPT was used to write social media posts promoting the institute, with instructions to remove any linguistic trace of Russian origin. OpenAI states the articles on the website itself were not generated by its models: most were copied from real academic writing, some apparently drafted by a Slavic speaker and machine translated.
Where
Content was seeded across Substack, Telegram, X, Facebook and LinkedIn. The website presented a street address in Israel. Narratives targeted Western states opposing Russia's war in Ukraine.
When
The website was registered in February 2025; the sampled articles were published between September 2025 and May 2026. OpenAI published on Tuesday 25 August 2026.
Why
To manufacture the appearance of independent expertise and launder pro-Moscow argument through it. The point was not reach but credibility - an ostensibly academic source that a reader, or another outlet, might cite.
How
A fabricated institute with a real-looking address and prominent names on its roster; copied and misattributed scholarship to fill it; a proprietary index to give it a signature product; and machine-generated promotion to push traffic toward it.
What happened
1

February 2025 - a website is registered

A site appears presenting the International Burke Institute as an expert community with a street address in Israel.

2

It is filled with other people's work

OpenAI sampled thirty-six articles linked to experts on the site and published between September 2025 and May 2026. Thirty-four had been copied from elsewhere on the internet. Some were years old. Some were attributed to the wrong authors: one piece originally published by Cambridge University Press was credited to a professor at a different university.

3

Distinguished names are added to the roster

By July the site claimed a range of world-class experts, listing figures including Francis Fukuyama and Noam Chomsky. The credibility is borrowed twice over - once from the scholarship and once from the scholars.

4

A signature product: the sovereignty index

The institute published an index ranking states by sovereignty, on which Russia scored well and Western countries were presented as increasingly dependent. Reporting notes Russia's military was scored half a point above that of the United States. An index is the ideal vehicle for this: it looks like methodology and it produces a headline.

5

The promotion is machine-written

Operators reach ChatGPT through virtual private networks, prompt in Russian and ask for English social media comments, with explicit instruction to strip out linguistic markers of Russian origin. The posts are seeded across five platforms.

6

25 August 2026 - the ban and the report

OpenAI bans the account cluster and publishes. It rates the operation category three on a six-point scale, meaning present across multiple platforms with early signs of reaching real people. Official institute accounts drew little engagement; associated Telegram channels each carried roughly ten to twenty thousand followers.

7

The institute answers

The institute publicly rejects the characterisation, referring to a Le Monde report based on OpenAI's findings, and states that it operates in Israel, publishes original research and maintains an open-access library with full source attribution. Its website remains online.

Impact
Reach
Limited, and OpenAI says so plainly. Individual posts drew few views and the institute's own accounts had low followings, though linked Telegram channels each ran to five figures.
Scholars
Academics were listed as affiliates without their involvement and work was republished under the wrong names. The people whose reputations were used are third parties with no way of knowing it was happening and limited means of correcting it.
Credibility
The substantive risk is not the audience but the citation. A fabricated institute with a real-looking address, a named roster and an index is built to be quoted by somebody else, at which point the reach becomes the citing outlet's.
Tradecraft
The exposure is useful defensively: hiding linguistic markers on request, laundering copied scholarship, and building a proprietary index as a credibility product are all now documented and can be looked for.
The technique, and what is actually new
The front

Why a think tank

A research institute is the cheapest convincing object to fabricate. It needs a website, an address, a list of names and a body of published work, none of which is verified by anyone before a reader encounters it, and all of which signals independence.

The index

Methodology as a costume

A ranking product gives an outlet something to cite and a number to argue with. It implies data collection, a method and a team, and it generates recurring content without requiring original research.

2022 - 2026

The documented Russian pattern

This continues a line of Russian information operations running through the war, including the networks known as Doppelganger and Matryoshka. OpenAI separately disrupted a Russia-origin operation earlier in 2026 that used ChatGPT to generate German-language political content ahead of Germany's federal election.

What is new

Not the AI, the assembly

OpenAI is explicit that the institute's articles were not model-generated and that the campaign reached small audiences. What distinguishes it from earlier operations is the elaborate construction rather than the volume of output or the use of a language model.

The most quotable fact is the one to handle carefully. Thirty-four copied articles out of thirty-six is a striking figure, and it describes plagiarism rather than generation. The machine wrote the advertising; human beings assembled the fraud, and reading this as an AI story misplaces where the effort went.

Assessment
1

The product is not reach, it is a citable source

OpenAI rates this category three of six and says the audience was small. Judged as propaganda that is a failure. Judged as infrastructure it is not, because a fabricated institute exists to be quoted rather than to be read: one citation by a genuine outlet, one researcher who takes the index at face value, one journalist who needs a source, and the operation acquires an audience it could never build itself.

2

The AI did the least interesting part of this

The language model wrote promotional comments and was asked to hide Russian linguistic markers. It did not write the articles, invent the index or build the roster. Those required a person to select real scholarship, strip its attribution and put a respectable name on it. An assessment that treats this as evidence of AI-driven influence operations overstates the tooling and understates the deliberate human construction, which is the part that took eighteen months.

3

Borrowed names are the cheapest credibility available and the hardest to police

Listing prominent academics as affiliates costs nothing, is not verified by any authority, and is discovered only if someone checks. The scholars concerned have no practical remedy and frequently no knowledge. Any organisation citing a research body should be able to confirm at least one listed expert directly, because the roster is where these operations are thinnest.

4

The denial is part of the record and does not resolve it

The institute rejects the characterisation and says it publishes original research with full source attribution. That sits directly against OpenAI's finding that thirty-four of thirty-six sampled articles were copied and some misattributed. Both positions belong in the entry; the site remains online, and no authority has adjudicated between them.

5

The pseudo-academic front will be reused

It is cheap, it is durable, it survives the loss of the accounts promoting it, and its value rises the moment anyone legitimate cites it. It is likely that further influence operations fronted by fabricated research bodies are identified against European audiences, and likely that they are found through the provenance of their content rather than through the volume of their posting.

The comparison worth making

Set this beside the Sandworm recruitment campaign, where Ukrainian system administrators were taken through a fake but entirely ordinary-looking hiring process. Both build an elaborate legitimate-seeming structure and let the target walk into it, and in both cases nothing was hacked: a real platform, a real-looking organisation and an ordinary reason to trust it did all the work.

What should carry
  • Verify a research body before citing it, and start with the roster. Contact one named expert directly. Fabricated institutes are thinnest exactly there, and a single email settles it.
  • Check provenance on anything you are about to quote. Thirty-four of thirty-six articles here were copied. A search on a distinctive sentence would have exposed the whole operation, and that check costs a minute.
  • Treat an unfamiliar index with the scepticism you would apply to a claim. A ranking implies a method. If the method is not published, or the team behind it cannot be identified, the number is an assertion dressed as research.
  • Watch for your own organisation being listed without consent. Academics and practitioners should periodically search their own name alongside terms like institute, fellow and affiliate, because this is discovered by the person named or not at all.
  • Do not judge an information operation by its follower count. This one had small direct reach and was built to be borrowed. The measure that matters is whether anyone legitimate has cited it.
  • Record what the platform actually said. OpenAI was explicit that the articles were not model-generated. Repeating this as an AI-written campaign would misdescribe it and would point defensive effort at the wrong stage.
Sources

Compiled from open-source reporting for professional security discussion. The assessment that this operation originated in Russia is OpenAI's, published in its own report; no government has attributed the activity and OpenAI states it could not establish what relationship, if any, real individuals in Israel linked to the institute's activity had with the operators. The International Burke Institute has publicly rejected the characterisation, stating that it operates in Israel and publishes original research with full source attribution, and its website remains online. The academics named on the institute's roster are not implicated and reporting indicates work was republished without their involvement and in some cases under the wrong names. Figures for the sampled articles, the audience reach and the Breakout Scale rating are OpenAI's. Details may be revised. This is a protective-security lessons-learned assessment, not an operational account.