OpenAI Operation “Fish Food” Russia-origin Content Farm Disrupted
TL;DR
OpenAI disabled a set of ChatGPT accounts tied to the Russian‑origin “Rybar” network—dubbed Operation “Fish Food”—because the actors used the model to mass‑produce multilingual propaganda, commercial plans for covert campaigns in Africa, and promotional material for allied media outlets. The disruption demonstrates how generative AI can be weaponized as a content farm for influence operations.
Actor and Attribution
- Network: The “Rybar” (Russian: "Рыбарь", meaning “fisherman”) network operated on Telegram and X (formerly Twitter).
- Origin: At least some accounts were traced to Russia.
- OpenAI Action: A group of ChatGPT accounts linked to this network were permanently banned.
- Naming: OpenAI labeled the activity “Operation Fish Food” to reflect the role of ChatGPT as feed for the content farm.
Core Behaviors
Multilingual Content Generation
- Prompts were primarily in Russian, but the generated output spanned Russian, English, and Spanish.
- Content was posted by both “Rybar”-branded accounts and unrelated social‑media profiles.
- One user also generated Sora video assets promoting the Rybar brand.
Content Farm Mechanics
- OpenAI identified exact text matches between AI‑generated comments and posts on multiple Telegram channels and X accounts.
- A single prompt produced a batch of seven tweets; six were posted by distinct X accounts with follower counts ranging from 827 to over 600 000. The tweet from the high‑follower account received >150 000 views, indicating that audience size, not AI content, drove reach.
- Similar batch generation was observed for Telegram posts, where identical text appeared across four separate channels.
Strategic Planning via AI
- The main user asked ChatGPT to translate a list of services Rybar could sell, including:
- Operating X and Telegram accounts.
- Running a bilingual investigative‑journalism website focused on Africa.
- Publishing paid pieces in French‑language media.
- Coordinating a network of amplifiers.
- Separate prompts requested edits to a proposal for a deployed election‑interference team in Africa, outlining on‑the‑ground activities, local agent recruitment, and large‑scale event organization.
- Additional prompts outlined information campaigns targeting the Democratic Republic of Congo, Burundi, Cameroon, and Madagascar, with suggestions to incite protests.
- The most ambitious plan estimated an annual budget of up to $600 000.
Promotion of Allied Media
- The actor generated promotional copy for “REST Media,” a outlet previously linked by open‑source researchers to Rybar.
- After feeding an article accusing Germany of influence operations in Moldova into ChatGPT, the model produced three comments that were later posted on separate Telegram channels, each linking back to the REST Media article.
Content Themes and Impact
- The generated material echoed classic Russian covert influence motifs: praising Russia and Belarus, criticizing Ukraine, and accusing Western nations of interference.
- Audience Reach: Rybar’s primary Russian‑language Telegram channel amassed ~1.4 million subscribers. Numerous X and Telegram accounts that disseminated the AI‑generated content had tens of thousands of followers.
- Amplification: No evidence was found of mainstream news outlets amplifying the content, nor of on‑the‑ground activities in Africa matching the sales pitches.
- Influence‑Operation Rating: Using the Brookings IO Impact Breakout Scale (1 = lowest, 6 = highest), OpenAI assessed the operation at the top of Category 3 (multiple communities on multiple platforms), reflecting its broad distribution across social media.
Implications for AI Governance
- Weaponization of LLMs: The case illustrates how large language models can be leveraged as low‑cost, high‑volume content farms for state‑aligned disinformation.
- Detection Challenges: While OpenAI could trace text matches across platforms, the exact posting mechanisms (e.g., automated bots vs. manual operators) remain unclear.
- Policy Response: Banning the offending accounts demonstrates a proactive enforcement stance, but the persistence of similar networks suggests a need for broader industry collaboration on detection, attribution, and mitigation of AI‑driven influence operations.
Conclusion
OpenAI’s disruption of the Rybar‑linked “Fish Food” operation underscores the real‑world risk that generative AI models pose when co‑opted for coordinated propaganda. The incident provides concrete evidence of AI‑assisted content farms operating across languages and platforms, and it highlights the importance of robust monitoring and rapid response mechanisms to safeguard the information ecosystem.