Skip to main content
isrl.com

How Iran Turned Chatbots Into a Weapon Against Israel

Israeli researchers say Tehran is using artificial intelligence to fake crowds, forge personas and speed up hacking, and that nobody can reliably detect it.

The Israel.com Newsroom··4 min read·
Share
Illustration of a dim cyber-operations room with dark unlit monitors, glowing server racks and a lone analyst seen from behind in silhouette, representing Iran's AI-driven influence campaigns.

Illustration

Illustration, generated by an image model, not a photograph: a dim cyber-operations room with dark unlit monitors, glowing server racks and a lone analyst seen from behind in silhouette, representing Iran's AI-driven influence campaigns. It shows a setting of the kind this report describes. It is not a picture of the events reported, and no photograph of them is published here.

Iran is pushing artificial intelligence into its covert influence work against Israel and Western societies, according to specialists who spoke to The Press Service of Israel (TPS-IL), the Israeli news agency whose report this account is drawn from. The shift, they said, is less about new goals than about new tools: fake personas that read as real people, fluent output in several languages at once, and a volume of material that human operators alone could not sustain.

What makes the change consequential, the analysts told TPS-IL, is what surrounds it. Tehran has been suppressing widespread anti-government protests at home while simultaneously writing artificial intelligence into national policy. “There is no ability today to systematically identify AI-driven influence campaigns,” said Danny Citrinowicz, a senior researcher in the Iran and Shi’ite Axis Programme at the Institute for National Security Studies (INSS) in Tel Aviv, who spent 25 years in Israeli defence intelligence, including as head of its Iran branch. He said the regime uses the technology to manufacture an impression of broad public support, inflating the apparent size of crowds in photographs and casting protesters as rogue actors. “People are being killed in the streets,” he told TPS-IL. “But when everything is shut down inside Iran, AI makes it easier to convince outside audiences.”

Why Tehran wrote AI into state policy

The interest is not confined to freelance hackers. An analysis published in December 2025 by the Jerusalem Institute for Strategy and Security (JISS), written by Dr Avi Davidi and cited throughout the TPS-IL report, traces the drive to the top of the Iranian system. It records that Supreme Leader Ayatollah Ali Khamenei called artificial intelligence a national strategic priority in April 2025, warning that Iran must become a developer rather than a consumer of the technology. JISS dates parliament’s approval of a National Artificial Intelligence Document to June 2024 and the creation of a National AI Organisation under the president’s office to October 2025, and notes that Islamic Revolutionary Guard Corps (IRGC) commanders have spoken publicly about folding AI into weapons and targeting systems.

The Iranian operations Western companies have already named

Some of the activity is documented by the companies whose products are being used. An Iranian influence network tracked as Storm-2035 was shut out of ChatGPT by OpenAI in August 2024 after it used the tool to generate articles and social-media comments in English and Spanish, spread across a dozen accounts on X, one Instagram account and five websites dressed up as ordinary news outlets. The material covered the Gaza war, the United States presidential race, Venezuelan politics and Scottish independence, padded out with fashion and beauty posts to look authentic. OpenAI said at the time it had seen no sign the content reached a meaningful audience.

A second cluster, tracked by Google as APT42 and assessed by Mandiant in May 2024 to work on behalf of the IRGC Intelligence Organisation, specialises in impersonation rather than volume. Google’s researchers describe weeks of patient correspondence with targets in journalism, academia and human-rights work, typo-squatted domains imitating outlets including The Washington Post and The Jerusalem Post, fake Google and Microsoft login pages, and techniques for defeating two-factor authentication. Davidi’s analysis adds a third group, the IRGC-linked CyberAv3ngers persona, which he reports has used generative tools to research vulnerabilities and speed up reconnaissance against industrial control systems rather than to invent new attack methods.

OpenAI and Google Cloud did not respond to queries from TPS-IL.

An Israeli election year raises the stakes

Citrinowicz said Iranian influence work intensified after the Hamas attack of 7 October 2023, and that AI has closed the language and cultural gaps that once made such campaigns easy to spot. “Everything we’ve seen, from phone hacking to covert social media campaigns, follows the same logic,” he said. “The goal is to weaken Israeli society internally.” Israel is due to vote in a general election by the end of October; the ballot is scheduled for 27 October 2026, at the end of the first Knesset since 1988 to serve a full four-year term. State Comptroller Matanyahu Englman has already described Israel’s preparations against foreign interference in that vote as deficient.

Not everyone in the TPS-IL report was equally alarmed. Alex Grinberg, an Iran researcher at JISS, argued that ideological blind spots keep exposing Iranian operations: “Their demonisation of Israel prevents them from fully understanding Israeli society, often exposing their influence campaigns.” Moran Alaluf, an independent researcher on Iran, called AI a force-multiplier and said Tehran is likely pursuing independent capabilities with China and Russia while exploiting Western tools in the meantime. Dr Daniel Cohen of the Abba Eban Institute at Reichman University framed the next phase differently again: “This is going to be a war over knowledge itself. The Iranians will try to plant messages inside the sources that train AI models.”

Israel’s National Cyber Directorate told TPS-IL it works “around the clock” on cyber threats, and that “ultimately, public awareness is the first line of defence against influence operations, with or without AI.”

What is still unclear

The report gives no estimate of how many Iranian AI-assisted accounts or campaigns are currently running against Israel, and no figure for how much of the online material aimed at Israeli audiences is machine-generated. It does not say whether any specific Israeli election-related operation has been detected, only that experts consider one likely. Nor does it quantify the claim, repeated by several of the researchers, that the scale of Iranian activity inside Israel is far greater than abroad.

Topicsirancyberdisinformationartificial-intelligence

Sources and further reading

Every link below was opened and checked when this page was written. Official statements are marked as such: they are the subject's own account, not an independent one.

  1. OfficialInstitute for National Security Studiesinss.org.il
    Danny Citrinowicz

    Confirms the researcher's role and intelligence background

  2. ReportingThe Hacker Newsthehackernews.com
    OpenAI Blocks Iranian Influence Operation Using ChatGPT

    Details of the Storm-2035 account takedown, languages and topics

  3. ReportingGoogle Cloud / Mandiantcloud.google.com
    Uncharmed: Untangling Iran's APT42 Operations

    APT42 attribution to the IRGC and its credential-phishing tradecraft

  4. ReferenceJerusalem Institute for Strategy and Securityjiss.org.il
    Iran and the Artificial Intelligence Revolution

    Dr Avi Davidi's December 2025 analysis, the basis for the AI-policy and threat-group claims

  5. ReferenceWikipediaen.wikipedia.org
    2026 Israeli legislative election

    Date of the coming Knesset election

How we checked this

The expert quotes and assessments are as published by The Press Service of Israel on 19 January 2026. The Iranian AI policy timeline comes from the Jerusalem Institute for Strategy and Security analysis of December 2025; the Storm-2035 and APT42 details were checked against reporting on OpenAI's takedown and Google Cloud's own threat-intelligence write-up.

Our sourcing and corrections policy →

The week from Israel, in one email

The stories that mattered, sourced and checked by the Israel.com newsroom. Free, weekly, one-click unsubscribe.

One list, unsubscribe in a click. See our privacy policy.

More in Security

All security

Latest

← All news