“Cyber Special Operations”: China-linked influence planning
OpenAI banned an account linked to an individual associated with Chinese law enforcement, using AI to plan influence activity, harassment, and online operations.
This case study was originally published in OpenAI’s February 2026(opens in a new window) report on disrupting malicious uses of AI.
Actor
We banned a ChatGPT account linked to an individual associated with Chinese law enforcement. They tried to use our model to plan a covert influence operation (IO) targeting the Japanese prime minister. Our model refused to assist in such planning. They also asked our model to edit and polish periodic status reports on the conduct of what they termed “cyber special operations” (网络特战) - covert influence operations against domestic and foreign adversaries. The broad range of activities they described illustrates the scope and the scale of these operations, including the range of countries, issues and people they target. Using open-source investigative techniques, we were able to identify activity across the internet that matched some of the activity referenced in the user’s engagement with ChatGPT.
The available evidence suggests that Chinese law enforcement is implementing a strategy of “cyber special operations” to suppress dissent and silence critics both online and offline, at home and abroad. This effort appears to be large-scale, resource-intensive and sustained, counting at least hundreds of staff, thousands of fake accounts across scores of platforms, the use of locally deployed AI models, and a playbook of dozens of tactics. These range from abusive reporting of dissidents’ social media accounts, through mass online posting, to forging documents and impersonating US officials. The targets are not just people in China, but also dissidents around the world and representatives of foreign countries, up to and including the prime minister of Japan.
The effects of this strategy vary, from visibly low-impact social media posts, to allegedly high- impact outreach to the targets themselves. But they are all presented as part of a well-resourced and meticulously orchestrated strategy for covert influence operations targeting the United States, Japan, their allies, and critics of the CCP around the world.
Behavior
The user’s main activity consisted of asking the model to edit and polish periodic status reports on “cyber special operations” conducted against domestic and foreign targets, especially Chinese dissidents and critics of the Chinese Communist Party (CCP) around the world. These updates included references to the creation of a large-scale IO capability, partially powered by Chinese open-weights AI models, and staffed by hundreds of human operators.
The user also asked our model to help design and refine a campaign targeting the Japanese prime minister. Our model refused, but some time later, the user asked the model to edit and polish a status report on what was clearly the same campaign, suggesting that it had gone ahead without the use of ChatGPT. The user’s engagement with ChatGPT included indications of much wider cross-internet activity, such as references to hashtags and fake accounts on social media. It also led to a website called revealscum.com, that we had already identified as part of the China-origin IO known as “Spamouflage(opens in a new window)” in early 2024. Meta attributed(opens in a new window) Spamouflage to individuals associated with Chinese law enforcement in August 2023. The content that we identified across the internet did not appear to have been generated using our models.
Completion
The user’s activity spanned both operational planning and tactical reporting, and provided insights into the scale and scope of “cyber special operations” more broadly, including the use of locally-deployed AI models such as DeepSeek and Qwen. This section discusses each type of activity in turn.
Operational Planning and Reporting
In mid-October, the user asked ChatGPT to help plan an operation to discredit Japanese politician Sanae Takaichi - now Japan’s first female prime minister - after she publicly criticized the state of human rights in Inner Mongolia.
The user asked the model to help craft a plan based on six main elements. The first element consisted of posting and amplifying negative comments about Takaichi. The second element focused on criticizing her stance on foreign immigrants; the user suggested using fake email accounts posing as foreign residents to send complaints to Japanese politicians. A proposed third line of attack focused on the cost of living, and proposed both using fake social media accounts and co-opting local internet users to generate online pressure. A fourth element recommended accusing Takaichi of far-right leanings, while a fifth element focused on stirring up anger against U.S. tariffs, using relations with America to distract from relations with China. Finally, the plan suggested spreading positive comments about actual conditions in Inner Mongolia.
Our model refused to provide advice on this plan, and the user paused their inputs. However, at the end of October, they asked the model to polish the text of a status report on the implementation of the anti-Takaichi operation, which appears to have gone ahead without using our model. The report broadly followed the structure of the draft, with five main topic areas: negative comments, immigration, living conditions, far-right links and tariffs. (It did not mention Inner Mongolia.) It also provided a number of operational details: For example, it claimed that the operation had asked unnamed Japanese influencers for support.
Crucially, the report claimed that the operation had launched a set of hashtags, including \#右翼共 生者 (“right-wing symbiont”). Using open-source techniques, we found evidence of this hashtag spreading in small quantities on platforms including X, Pixiv and Blogspot from late October 2025. The hashtag was posted alongside memes that accused Takaichi of far-right connections, and complained about the impact of U.S. tariffs on Japanese agriculture.
Two memes posted on Blogspot by an account registered in October 2025. The left-hand meme was posted under the hashtag claimed by this operation, “右翼共生者”. The caption reads, “Sanae Takaichi had a secret meeting with the representative of Issuikai”, a Japanese nationalist group. The meme photoshops Takaichi onto a picture of Issuikai representative Mitsuhiro Kimura. The right-hand title, in Chinese, reads, “50% tariff shock\! American beef has swallowed half of Japan’s market”. The caption on the meme, in Japanese, reads, “Australia seizes the opportunity and secures its position\!” Four of the user’s five cartoons were listed as being AI-generated. These do not appear to have been generated using our models.

Two memes posted on Blogspot by an account registered in October 2025. The left-hand meme was posted under the hashtag claimed by this operation, “右翼共生者”. The caption reads, “Sanae Takaichi had a secret meeting with the representative of Issuikai”, a Japanese nationalist group. The meme photoshops Takaichi onto a picture of Issuikai representative Mitsuhiro Kimura. The right-hand title, in Chinese, reads, “50% tariff shock! American beef has swallowed half of Japan’s market”. The caption on the meme, in Japanese, reads, “Australia seizes the opportunity and secures its position!”

Two memes mocking Takaichi posted on Pixiv by an account whose posts were all made on October 27, 2025, using the operation’s hashtag. Four of the user’s five cartoons were listed as being AI-generated. These do not appear to have been generated using our models.
In November, we identified accounts across the internet posting a very similar hashtag, “右翼の共 生者”, which has the same meaning, but a more idiomatic Japanese construction. These accounts posted the same memes; they also posted English-language criticisms of Takaichi after she suggested that Japan could offer military assistance if China attacked Taiwan. These comments do not appear to have been generated using our model. One YouTube channel used both the earlier hashtag and the later one, under different versions of the same video, suggesting that the second hashtag was an update of the first one by the same operators.

Three tweets posted by the same X account in November. Left, the anti-Takaichi meme, with the later variant of the hashtag. Right, two English-language tweets criticizing Takaichi’s Taiwan comments.

YouTube channel created on October 27, 2025. Note that the same video of Takaichi shows up three times, once under the English title “Right-wing Symbiotes” (October 27, 2025), once with the original form of the hashtag (November 6), and once with the updated form (November 18). As of November 28, the maximum number of views on any of these videos was four.
This open-source evidence closely resembled the user’s description of the anti-Takaichi operation. Account creation dates clustered around late October. The use of Blogspot and Pixiv resembled “Spamouflage” activity reported(opens in a new window) by Meta(opens in a new window) in 2023. Of note, none of the social media posts we identified had a significant degree of engagement: the YouTube videos had single-digit views, while the tweets and Pixiv posts typically showed zero engagements. The highest number of views recorded for a meme on Pixiv was 108. The evidence that we were able to identify was likely incomplete: According to the user’s own assessment, almost 200 social media accounts run by the operation were taken down by the platforms in the first few days. Nevertheless, while this activity does illustrate apparent operational planning and implementation across the internet, it does not appear to have achieved much impact.
Tactical Range
In parallel to this work on one specific target, the user’s activity referenced a much wider range of tactics that they claimed to have deployed across broader “cyber special operations”. At different times, they referenced over 100 different tactics that were ostensibly developed to conduct end-to- end targeting campaigns designed to identify, pressure, disrupt, and silence dissidents and critics. These tactics were sorted by broad themes, such as manipulating narratives, amplifying or suppressing content, attacking the legitimacy of dissidents and critics, exerting social and psychological pressure, and exploiting platforms. Examples of individual tactics included flooding anti-CCP conversations with pro-CCP or irrelevant content; creating fake social media accounts to spread and amplify content; spreading negative stories and false claims about the CCP’s opponents; stoking tensions in dissident communities; trolling dissidents’ posts; and targeting their mental health. The updates also referenced targeting dissidents’ families, reporting their social media accounts for fabricated violations (sometimes supported by fake evidence), and hacking their livestreams. Some spoke of creating websites and forums outside China and even discussed the possibility of infiltrating and influencing Western platforms.
Some of these tactics have already been publicly linked to Chinese law enforcement. For example, in 2023, the US Department of Justice accused(opens in a new window) Chinese officers(opens in a new window) of running a campaign aimed at “silencing, harassing and threatening dissidents and activists living abroad in the United States and other countries”. This included detailed allegations of how the officers used fake social media accounts to harass CCP critics; hacked into livestreams; attempted to recruit potentially sympathetic influencers; recruited(opens in a new window) a security engineer from at least one Western communications company; attempted to “strengthen positive publicity and suppress negative public opinion”; and doxxed a dissident.
For other tactics, we were able to identify online activity that closely resembled the activity described by the ChatGPT user and tie it to earlier IO. In particular, one prompt claimed that “cyber special operations” teams had created a website that published sensitive personal information about over 20 dissidents as a way of putting psychological pressure on them. The site was described as a “pro- Japan exhibition hall” (“精日展览馆”). That precise term linked to Spamouflage in May 2024.
The ChatGPT user described efforts to harass the X account @whyyoutouzhele, better known as “Teacher Li is not your teacher” (李老师不是你老师), a Chinese dissident, real name Li Ying. They also described attacks on the human-rights group “Safeguard Defenders”. Chinese public security forces have been publicly tied to previous campaigns against both.
One account that we identified on X allowed us to connect the anti-Takaichi hashtag campaign, described above, with attacks on both Teacher Li and the Safeguard Defenders. On November 19, this X account posted five tweets featuring the original anti-Takaichi hashtag, accusing her of far-right connections and warmongering. A sixth tweet used the same style of messaging, but without the hashtag. Before those tweets, the account’s only activity came between January 13 and January 17, 2025, when it made nine different replies to a tweet by Teacher Li quoting a study by the Safeguard Defenders. The nine replies included insults against Li and the Safeguard Defenders and accusations of being foreign spies.
![Logo from the website revealscum\[.\]com, which OpenAI first linked to Chinese IO in May 2024. The calligraphy reads “pro-Japan exhibition hall” (“精日展览馆”).](https://images.ctfassets.net/kftzwdyauwt9/4xzk3TRdZpvPnXcPZkkUL2/0e84f1bb75a5dc928c5f800aafdfd943/image32.png?w=3840&q=90&fm=webp)
Logo from the website revealscumcom, which OpenAI first linked to Chinese IO in May 2024\. The calligraphy reads “pro-Japan exhibition hall” (“精日展览馆”).

Top, tweet using the anti-Takaichi hashtag on November 19, 2025. The tweet reads, “#Right-wing symbiote, Sanae Takaichi is one of the most dangerous women in the world. She has just threatened to start a war with China over the Taiwan issue, breaking a taboo that even Japan’s far-right prime ministers would not touch. She is obsessed with dragging the world into war.” Bottom, two tweets posted by the same account in January 2025, replying to Teacher Li. The replies reference the Safeguard Defenders (“Guardian” in X’s auto-translation on the left), and their founder Peter Dahlin and Research Director Dinah Gardner. In the meme on the left, the two hands are labeled “Defender” and “1450” (Taiwanese slang for paid online commentators), the screen is labeled “classified documents”, the names on the figure’s back are “Spy” and “Dinah Gardner”, and the caption reads, “Alliance of the two ‘agents’”. The meme on the right shows a press photo of Dahlin and an image of the killing of George Floyd, with the caption, “Hey! Darling, you have to believe that America’s human-rights protections are the most perfect.” A few days earlier, Dahlin had been arrested by Chinese police in Beijing.
A separate prompt described attempts to harass dissident Jie Lijian by claiming that he had died. According to the ChatGPT user’s input, “cyber special operations” operators created a fake obituary and photos of a gravestone, and then mass posted them online. Open-source evidence suggests such a campaign was carried out. According to a report by VoA’s Chinese service(opens in a new window) in October 2023, claims that Jie had died did indeed spread on the Chinese internet in August of that year, featuring “mass- produced and widely reposted messages included fake obituaries, memorial photographs, mourning halls, [and] gravestones”. Our investigation also identified an X account calling itself “Jie Lijian Funeral Committee” that tweeted an obituary for the activist on August 24, exactly the time frame identified by VoA. While this does not allow us to directly attribute the X account to any specific operation, it closely resembles the ChatGPT user’s claims.
Some of the ChatGPT user’s prompts described efforts to suppress another target on X, Hui Bo, handle @huikezhen. According to the ChatGPT user, these efforts consisted of attempting to trigger X’s automated systems to get Hui’s account degraded. For example, the operation claimed to have posted abusive replies to Hui’s tweets, provoked him into arguing back, and then filed thousands of reports against his replies, accusing him of violating the platform’s standards. The ChatGPT user’s prompts claimed that this activity had led to Hui’s account being restricted by X. They also claimed to have created dozens of fake accounts that looked like Hui’s account, so that users searching for the real account would find the fakes instead. While we are not able to independently confirm whether and how any such abusive reports were actually sent, as of November 29, 2025, Hui’s X account was indeed restricted, and a number of other X accounts that used his name and profile picture showed up in search results instead.

The first tweet by an X account whose name translates as “Jie Lijian Funeral Committee”, August 2023. The account was created in July 2023 and made its last post in April 2024.

Left, restriction interstitial over Hui’s X account, as of November 29, 2025. Right, clicking through shows Hui’s account with the name “惠波”, blue checkmark, profile picture and count of 11,055 followers.

Top results of an account search on X for the phrase “惠波” (Hui Bo), showing some of the many accounts with Hui’s name and profile picture - none of them the real, verified one. Some of the fake accounts included an email address and phone number not given on the real account’s bio, possibly as a further attempt to harass him.
Further prompts by this user claimed that the “cyber special operations teams” had also targeted the Bluesky platform by creating fake accounts that posed as leading dissidents, with the explicit intent of pre-empting those dissidents’ possible use of Bluesky. Open-source investigation enabled us to identify activity which resembled this claim. For example, a manual search on the platform identified five accounts that appeared to impersonate Hui Bo, all of them created on December 5, 2024, according to a freely available online tool(opens in a new window). Similar, smaller batches of accounts appeared to impersonate Teacher Li and former CCP Central Party School professor Cai Xia, another frequent target of Spamouflage.

Profiles of five Bluesky accounts resembling Hui Bo, all created on December 5, 2024. Dates from Bluesky join date checker.
On at least one occasion, the user reported that the public security services had targeted multiple dissidents in a single smear campaign. One of the three, Wang Dan, had been previously accused of sexual abuse. According to the ChatGPT user, operators created a series of false claims that associated Wang Dan and two other dissidents with the sex scandal. Searching for the three dissidents’ names together revealed multiple open-source pieces of content that closely resembled this claim across blogs, Reddit, YouTube, Tumblr, Behance, and other platforms. This content, which appears to have started around mid-2023, always used this trio of names together, and wrapped them in sensational, often homophobic and pornographic language.
The above examples document occasions where it was possible to map the ChatGPT user’s claims to open-source activity. However, the user’s status updates also referenced many other tactics that were not – and in many cases, could not be – related to visible activity.
For example, one set of prompts detailed ways to abusively trigger automated enforcements on different platforms, as a weapon to get dissidents’ social media accounts taken down. A separate update detailed a harassment campaign leveled at pro-Taiwan X account @xu96175836: the campaign claimed to have used over 50 fake accounts to post hostile (but public) comments about it, send the user terrorist images via direct message, and file fake reports. On one occasion, the ChatGPT user suggested that some of their fake reports were accompanied by AI-generated “screenshots” of “evidence”.
Repeatedly, this user’s activity referred to the importance of combining online and offline operations, especially when it related to government critics within China. In one case the user described the arrest and interrogation of a young woman within China on suspicion of posting a pro-Taiwan tweet. In another case the user described how public security officers might make false accusations against a suspect to their employer or landlord, or put up posters about them in their home towns. In a third case, the user mentioned that plain-clothes officers had put up hostile posters near the homes of one critic’s family members, then photographed the posters and circulated them online as if they were authentic.
This activity also targeted dissidents abroad. According to the user, on one occasion, Chinese operators disguised themselves as US immigration officials to warn a dissident - unnamed, but apparently based in the United States - that their public statements had broken the law. On another occasion, the user quoted a Chinese security official as saying that operators had forged documents from a US county court and presented them to an unnamed social media platform in the hope of triggering a takedown. The official noted that the attempt had not been carried through to its conclusion, but showed potential.
Context and Scale
Taken together, the user’s status updates provide some indications of the scope and scale of China’s “cyber special operations” to counter perceived hostile influence. As described, the operations covered a broad range of activities, such as analyzing and profiling targets; posting and amplifying content; working with online influencers; censoring unfavorable comments; and shaping the information landscape internationally. They used dozens of different tactics, both online and offline. According to the user, the “special operations” ran across Chinese domestic networks such as Weibo and WeChat, and over 300 different “foreign” social media platforms. The user described millions of posts on Chinese networks and tens of thousands of posts on foreign ones, utilizing thousands of accounts, many of which were fake or working under the direction of the operation.
One report that this user asked the model to help draft claimed that 300 operators in their province had been engaged in IO across Chinese and foreign platforms. Other updates referred to equivalent teams in other provinces. All together, the user’s updates and reports implied a staffing allocation of at least hundreds of operators focused on IO across China.
Alongside the human effort, the user’s updates referred to a systematic use of AI for monitoring, profiling, translation, content creation, and internal documentation. This appears to have been focused on locally deployed, open-weights AI models, especially (but not exclusively) Chinese. For example, in one monthly report, the user claimed that teams in their province had experimented with DeepSeek-R1, Qwen2.5, and YOLOv8. We are not able to independently confirm whether this claim is true; however, in earlier threat(opens in a new window) reports(opens in a new window), we exposed China-origin users seeking to use open- weights models to monitor social media and craft phishing emails.
Impact and effects
The impact of these many tactics appears to have varied greatly. The ChatGPT user’s reports included references to dissidents losing social media followers, reducing their activity, or even giving up entirely as a result of the harassment. Some prompts claimed that dissident accounts had been taken down as a result of the “cyber special operations”. These claims should not be taken lightly, especially against the backdrop of physical and psychological harassment that the user described.
In other areas, however, the impact appears to have been less. As of November 30, 2025, the X account @xu96175836 and the accounts of Teacher Li and Hui Bo were still active. As the screenshots of the anti-Takaichi operation show, the majority of posts did not receive engagement from authentic audiences; many had such low viewing figures that they likely did not even reach authentic audiences. Manual investigation showed only a handful of instances of the operation’s hashtags occurring across social media (more may have been deleted already by the platforms). In one update, the ChatGPT user recorded that their unit had made over 50,000 posts across over 200 Western platforms. Of those, under 150 posts received over 300 shares or comments.
This ChatGPT user’s activity paints a clear and consistent picture of Chinese law enforcement’s approach to covert influence operations. We cannot prove or disprove all the user’s claims: some would require evidence which is only available to social media platforms, and others deal with offline activity beyond the scope of open-source investigation. However, some of the behaviors described by this user do closely resemble online activity, up to and including the use of individual rare hashtags, and others align with public reporting.