OpenAI Silver Lining Playbook: China-origin activity targeting US persons

TL;DR

OpenAI identified and banned a small set of ChatGPT accounts likely operated from mainland China that used the model to gather US‑person data and generate persuasive phishing‑style email drafts, demonstrating a concrete threat of AI‑enabled foreign intelligence recruitment.

Actor Identification

  • Origin: The accounts prompted the model in Simplified Chinese, were active during mainland Chinese business hours, and accessed the platform via VPNs, indicating a mainland China location.
  • Fake Front: Emails were crafted to appear from a Hong‑Kong‑based firm called Nimbus Hub Consulting; however, the use of Simplified Chinese characters rather than Traditional Chinese suggested the operators were not based in Hong Kong.
  • Naming: OpenAI labeled the operation “Silver Lining Playbook” after the company name “Nimbus” (a rain cloud or halo).
  • Evidence: Screenshots of LinkedIn profiles linked to Nimbus Hub Consulting matched individuals listed on the firm’s public “Our Team” page.

Screenshots of LinkedIn profiles affiliated with Nimbus Hub Consulting.

Behaviour Pattern

  • Email Draft Generation: The accounts asked ChatGPT to produce concise, professional English‑language emails addressed to US state‑level officials or policy analysts, framing the outreach as paid consulting on geopolitics and policy.
  • Social‑Engineering Structure:
    1. Establish legitimacy – present “Nimbus Hub” as an authoritative consulting firm with a website link.
    2. Personalize and flatter – cite the target’s public‑sector background, sometimes using uploaded LinkedIn screenshots for bespoke details.
    3. Stack incentives – promise lucrative, performance‑based pay while keeping the actual work vague.
    4. Reduce perceived risk – describe the role as relaxed, confidential, and reliably paid.
    5. Move off‑platform – push the conversation to WhatsApp, Zoom, or Teams for a video call.
  • Information Retrieval: The accounts queried the model for:
    • Locations of US federal offices and a ranked list of states with high concentrations of federal agencies.
    • Distribution of US federal personnel by state.
    • Public profiles of US persons (e.g., Voice of America hosts) and their interview topics.
    • Popular US economics/finance professional forums and job‑seeker sites.
  • Malware‑Tool Guidance: One account requested step‑by‑step, non‑technical installation instructions for the face‑swapping software FaceFusion, providing a screenshot of their hardware specs. The model responded with publicly available documentation.

Completion Details

  • The email drafts followed a known foreign‑intelligence social‑engineering playbook (see FBI reference). Each draft combined legitimacy, personalization, incentive stacking, risk mitigation language, and rapid migration to off‑platform communication.
  • Screenshots of the now‑archived Nimbus Hub Consulting homepage were included as part of the fabricated legitimacy.

Screenshot of Nimbus Hub Consulting’s website homepage, archived.

Impact Assessment

  • Technical Sophistication: The interactions were not highly sophisticated; they resembled ordinary recruitment outreach or basic software‑installation queries.
  • Strategic Intent: The use of a fabricated corporate identity and focus on geopolitical topics suggest an adversarial recruitment motive.
  • Outcome Unclear: OpenAI found no evidence that the drafted emails were actually sent or that any targets responded.
  • Broader Context: US, UK, and Australian intelligence agencies have warned that foreign services frequently masquerade as consulting firms to recruit current or former government employees. Distinguishing genuine hiring from these covert approaches hinges on verifiable employer details, realistic compensation, and transparent job postings.

Lessons for Defenders

  • Treat unsolicited consulting offers that appear overly lucrative, urgent, or vague with suspicion.
  • Verify employer legitimacy through independent sources; legitimate firms provide clear role descriptions, credible websites, and verifiable job listings.
  • Monitor AI platform usage for patterns such as non‑native language prompts, VPN access, and repeated requests for personal data on public officials.
  • Implement automated detection of social‑engineering templates that combine legitimacy, personalization, and incentive stacking.

This case study originates from OpenAI’s February 2026 report “Disrupting Malicious Uses of AI.”

Sources