Skip to main content
OpenAI

June 1, 2025

Operation “VAGue Focus”: Social engineering and influence activity

OpenAI banned accounts using AI for social engineering, surveillance-themed research, and influence activity targeting critics.

Loading…

This case study was originally published in OpenAI’s June 2025(opens in a new window) report.

Actor

We banned a small network of ChatGPT accounts that used our models to generate social media posts, analyze datasets, and translate emails and messages that resembled attempts at social engineering from Chinese to English. The accounts prompted our models in Chinese and were mostly active during mainland Chinese business hours.

They generated messages that purported to come from employees of three geopolitically focused entities: “Focus Lens News”, “BrightWave Media Europe,” and “Visionary Advisory Group” (VAG). In addition, the ChatGPT accounts generated text that matched the posts and bios of X accounts associated with these three entities. The threat actors separately described these entities as fronts for intelligence collection and analysis. Based on these names, we have dubbed this operation “VAGue Focus.”

Behavior

The operation used ChatGPT to support four main workstreams. First, the accounts mostly used our models to generate social media posts and biographies for online personas that appeared to be part of a covert influence operation. The posts were distributed by X accounts that posed as journalists and geopolitical analysts.

Tweet generated by this threat actor using ChatGPT and posted from an X account that consistently posted this actor’s content.

Tweet generated by this threat actor using ChatGPT and posted from an X account that consistently posted this actor’s content.

Second, the accounts polished and translated correspondence addressed to a US Senator regarding the nomination of an Administration official. We are not able to independently confirm whether any of the correspondence was sent.

Third, the accounts asked a series of basic questions about computer network attack and exploitation tools, to which our models only provided general explanations about their use and capabilities. These questions lacked the sophistication of the cyber actors we describe later in this report, and suggest a low level of expertise.

Lastly, the users regularly requested translations from Chinese into English of messages that appeared designed to engage with, and ultimately extract information from, unknown interlocutors. Some of these messages were posted on social media as replies to journalists and researchers. Others resembled direct messages that did not show up in online searches.

Cold outreach from an X account associated with this operation, publicly messaging a researcher on X.

Cold outreach from an X account associated with this operation, publicly messaging a researcher on X.

Completions

The primary objective of this network appeared to be collecting intelligence by posing as professionals based in Europe or Turkey. In the content that they generated and posted online, the operators described “Focus Lens News” as an independent European-based entity specializing in analysis and reporting. However, the operators also claimed this branding actually served as a cover to facilitate intelligence collection, analysis, and dissemination.

According to the website linked in social media biographies, Visionary Advisory Group is located in Turkey and specializes in professional geopolitical consulting services. The operators used our models to translate instructions from Chinese into English claiming VAG Group was seeking information about U.S. economic and financial policies and were willing to compensate $2,000 per hour for an interview. They also translated offers to pay for classified documents.

VAG Group’s website has Turkish and English versions, and on the Contact Us page of the English version of the website, the Chinese characters for “contact us” (聯絡) are visible in the menu. This was the only Chinese text on the entire domain.

Screenshot of VAG Group’s Contact Us page where the Chinese characters for “contact us” (聯絡) are visible in the drop-down menu.

Screenshot of VAG Group’s Contact Us page where the Chinese characters for “contact us” (聯絡) are visible in the drop-down menu.

Some of this network’s content resembled marketing materials for broader influence operations. According to the claims, which we cannot independently verify, the operation used machine learning, natural language processing, and automated data scraping to identify influential voices and topics on social media.

Impact

The social media accounts affiliated with this activity did not gain significant authentic engagement online. Only the Focus Lens News X account had a substantial follower count, at 17,000 followers; however, the account was created in November 2014 with a different name, tweeted for three days, and then fell silent until mid-2024. This is typical of accounts that have been compromised and repurposed, and its follower numbers should be treated with caution.

Using the IO impact Breakout Scale(opens in a new window), we would assess the public-facing part of this operation as being at the low end of Category 2: activity on multiple platforms, but little evidence that real people picked up or widely shared their content. There is insufficient evidence available to assess the impact of the operation’s social engineering and other covert activity.

Author

OpenAI