top of page

Cyber based influence campaigns 20th - 26th July 2026 Report

  • Writer: CRC
    CRC
  • 4 hours ago
  • 16 min read
Cover Image- Text: Weekly Media Update: Information Operations


[Introduction]


Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW).

Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. 

Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. 

We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc.

During the 20th to the 26th of July 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities.



[Contents]





Tiktok


Russia 

Ukraine


China





[ Report Highlights]


  • Russia launched a coordinated cognitive warfare campaign against the Poland-Ukraine alliance, deploying GRU-linked operations to pay Ukrainian refugees to hold destabilising protests in Poland, FSB-released purported archival documents amplifying historical grievances, and coordinated Google Maps vandalism, prompting Poland's Foreign Minister to state Moscow was waging a full-scale cognitive war against Poland.

  • A Russian influence operation spread a fabricated Human Rights Watch report falsely claiming President Zelensky ordered the torture and killing of 43 anti-draft protesters in Lviv, with the disinformation originating from the Foundation to Battle Injustice, an organisation assessed to be controlled by Russian intelligence.

  • Russian propaganda falsely claimed US Senator Lindsey Graham was killed in Kyiv by a Russian Iskander missile strike; he died in Washington DC on July 11th from aortic dissection. The campaign deployed a fabricated CNN article and digitally manipulated imagery to signal Russia's capacity to target Western politicians and deter allied support for Ukraine.

  • In the five days following President Trump's July 16th national address revisiting 2020 election fraud claims, posts on X claiming the 2020 election was rigged or stolen surged by 214 per cent, accumulating 77.7 million views, and the number of individual accounts actively disseminating the narrative increased by 295 per cent to 218,000.

  • Beijing is systematically weaponising Taiwan's political divisions through Mazu religious temple networks, subsidised mainland visits, and targeted digital campaigns to erode Taiwanese trust in the United States, with electoral data confirming CCP influence operations have already shifted voting patterns in key districts.

  • A NewsGuard audit found that leading AI chatbots reproduce pro-China false claims at significantly higher rates when prompted in Mandarin than in English, creating a language-dependent vulnerability that exposes Chinese-language users to disproportionate levels of CCP-aligned disinformation through mainstream AI tools.

  • A Graphika investigation documented over 300 accounts across YouTube, Facebook, TikTok, and X deploying AI-generated personas to spread anti-Western and pro-China commentary on geopolitics and world affairs, with more than 140 YouTube channels hosting deepfakes impersonating journalists and academics including Rachel Maddow.

  • The European Commission published binding AI Act transparency guidelines requiring disclosure of AI-generated content and deepfakes from August 2nd 2026, and issued preliminary DSA findings that TikTok violated platform safety obligations by setting minor accounts to publicly visible by default and recommending minor-generated content to a global audience.

[ Report Summary]

  • A Russian influence campaign spread a fabricated Human Rights Watch report claiming Zelensky ordered the torture of 43 anti-draft protesters in Lviv. The false narrative originated from the Foundation to Battle Injustice, an organisation assessed to be controlled by Russian intelligence.

  • Russia exploited the Poland-Ukraine dispute over the OUN and UPA historical legacy through a GRU-linked campaign paying Ukrainian refugees to hold destabilising protests, FSB releases of purported archival documents, and coordinated Google Maps vandalism. Poland's Foreign Minister stated Moscow was waging a full-scale cognitive war against Poland.

  • Russian propaganda falsely claimed Senator Graham was killed in Kyiv by a Russian Iskander missile strike, when he died in Washington DC on July 11th from aortic dissection. The campaign used a fabricated CNN article and digitally manipulated photographs, aimed at deterring allied support for Ukraine.

  • Russian propaganda outlets shared an AI-generated image falsely depicting a protest rally in Lviv in which participants wearing balaclavas hold a cardboard sign reading 'Cut down TRCs like cardboard', a reference to draft recruitment centres. AI detection service AI or Not assessed the image as artificially generated with 93 per cent probability.

  • Taiwanese officials and researchers warn that Beijing weaponises Taiwan's political divisions through Mazu religious temple networks, subsidised trips to mainland China, and targeted digital campaigns to erode Taiwanese trust in the United States. Electoral data found that neighborhoods near urban temples showed greater shifts toward opposition candidates in 2018-2020.

  • The European Commission issued preliminary DSA findings that TikTok violated platform safety obligations by allowing minor users to set accounts as publicly visible by default and by recommending content from users aged 16-17 to all platform users globally through the For You Feed. TikTok is required to restrict default account visibility for minors and cease global distribution of minor-generated content.

  • The European Commission published guidelines on AI Act Article 50 transparency obligations, effective August 2nd 2026, requiring providers to inform users during direct AI interaction and add machine-readable marks to AI-generated content, with deployers required to disclose deepfakes, AI-generated public interest content, and emotion recognition systems.

  • A NewsGuard audit found that leading AI chatbots reproduce pro-China false claims at significantly higher rates when queries are submitted in Mandarin than when identical topics are raised in English, indicating a language-dependent vulnerability in AI models' handling of politically sensitive content.

  • A Graphika investigation documented over 300 assets across YouTube, Facebook, TikTok, and X deploying AI-generated personas to distribute commentary on geopolitics and world affairs. More than 140 YouTube channels hosted deepfakes impersonating journalists and academics, including Rachel Maddow and Col. Douglas Macgregor, with anti-Western and pro-China narratives recurring across discussions of the Russia-Ukraine conflict, Iran tensions, and the South China Sea.

  • Multiple US election races in the 2026 midterm cycle feature AI-generated attack ads depicting candidates in fabricated scenarios, ranging from deepfake hotel footage to exaggerated cartoon villains. The trend raises concerns about voter manipulation through synthetic media, particularly among older demographics unfamiliar with AI generation technology.

  • A NewsGuard analysis found that in the five days following US President Trump's July 16 address revisiting 2020 election fraud claims, posts on X claiming the 2020 election was rigged surged by 214 per cent, accumulating 77.7 million views. The number of individual accounts advancing stolen-election claims increased by 295 per cent to 218,000 accounts within the five-day window.

  • Following Spain's defeat of Argentina in the 2026 FIFA World Cup final on July 19th, a fresh wave of viral false claims emerged. NewsGuard tracked at least 14 provably false claims circulating since the tournament began in June 2026, illustrating how major sporting events are routinely exploited as disinformation vectors.

  • France became the first European Union country to approve a blanket social media ban for children under 15, with the law taking effect September 1st, 2026 for new account creation and enforcement on existing accounts beginning January 2027. All users must verify their age using privacy regulator-approved methods, and cell phones are also banned from high schools.

  • NewsGuard debunked the viral claim that Coca-Cola and General Motors pulled advertising from NBC and ABC after the networks did not broadcast President Trump's July 16 election security address. NewsGuard identified Chevrolet commercials airing on both networks on July 19th, and both General Motors and Coca-Cola confirmed to NewsGuard on July 20th that no advertising withdrawal had occurred.

[State Actors]


Tiktok

Commission Preliminary Finds TikTok in Breach of DSA for Failing to Ensure Safe Accounts for Minors

A finding published by the European Commission states that preliminary findings under the Digital Services Act determined that TikTok violated platform safety obligations by allowing minor users to set their accounts as publicly visible by default and by recommending content from users aged 16 to 17 to all platform users globally through the For You Feed, with TikTok required to restrict minor account defaults so that content is visible only to accepted followers and to cease recommending minor-generated content to a global audience.


The preliminary finding represents the most significant DSA enforcement action against TikTok since it was designated a Very Large Online Platform in 2023. If confirmed following TikTok's response period, the platform faces financial penalties of up to six per cent of its global annual turnover under DSA enforcement provisions. The European Commission separately opened formal DSA proceedings against TikTok in 2024 over its recommendation algorithms and alleged addictive design features; those proceedings remain ongoing and are independent of the current preliminary finding on minor account safety.


Source: European Commission. Commission preliminary finds TikTok in breach of Digital Services Act for failing to ensure safe accounts for minors. [online] Published 24 July 2026. Available at: https://digital-strategy.ec.europa.eu/en/news/commission-preliminary-finds-tiktok-breach-digital-services-act-failing-ensure-safe-accounts-minors


Russia

Russia Concocts Ukrainian Torture

A report published by NewsGuard states that a Russian influence campaign is spreading a fabricated Human Rights Watch report claiming that 43 anti-draft protesters in Lviv were tortured to death on the orders of President Zelensky, with the false claim originating from the Foundation to Battle Injustice, an organisation assessed to be controlled by Russian intelligence.


The Foundation to Battle Injustice has been linked to multiple previous Russian-backed disinformation operations targeting Western audiences. By attributing the fabricated narrative to an entity designed to mimic the name and format of a legitimate international human rights body, the operation sought to exploit the credibility typically associated with organisations such as Human Rights Watch, enabling initial amplification through pro-Kremlin media ecosystems before independent fact-checkers could issue rebuttals.


Source: NewsGuard. Russia Concocts Ukrainian Torture Footage to Feed Kremlin Narrative. [online] Published 22 July 2025. Available at: https://www.newsguardrealitycheck.com/p/russia-concocts-ukrainian-torture


Moscow Exploits Poland-Ukraine Dispute Over OUN and UPA Legacy

An analysis published by The Jamestown Foundation states that Russia exploited the Poland-Ukraine diplomatic dispute over the contested legacy of the Organisation of Ukrainian Nationalists and the Ukrainian Insurgent Army to conduct a coordinated cognitive warfare campaign, including GRU-linked operations paying Ukrainian refugees $100-$200 to hold destabilising protests in Poland, FSB-released purported archival documents amplifying the historical dispute, and coordinated digital vandalism of Google Maps across Poland, with Polish Foreign Minister Sikorski explicitly stating that Moscow was waging a full-scale cognitive war against Poland.


The operation marks an escalation in Russia's use of pre-existing historical fault lines as cognitive warfare instruments against NATO-adjacent states. The OUN and UPA legacy represents one of the deepest points of tension in Polish-Ukrainian relations, making it a high-yield target for operations designed simultaneously to destabilise Polish domestic support for Ukrainian refugees, undermine Warsaw's backing for Kyiv, and fracture a strategically critical alliance on Russia's western flank at a moment when both countries are cooperating closely on defence and border security.


Source: Jamestown Foundation. Moscow Exploits Poland–Ukraine Dispute Over OUN and UPA Legacy. [online] Published 22 July 2026. Available at: https://jamestown.org/moscow-exploits-poland-ukraine-dispute-over-oun-and-upa-legacy/


Ukraine

Russian Propaganda Spreading Fakes About Death of US Senator Lindsey Graham

A fact-check published by Ukrinform states that Russian propaganda outlets spread fabricated claims that US Senator Lindsey Graham was killed in Kyiv by a Russian Iskander missile strike targeting a drone facility, when in fact he died in Washington DC on July 11th from aortic dissection, with the campaign including a fabricated CNN article and digitally manipulated photographs of a Kyiv library renamed in his honour, designed to create the impression that Russia can target Western politicians and deter allied support for Ukraine.


Senator Graham had been among the most prominent voices in the United States Senate advocating for continued military and financial assistance to Ukraine. The campaign's use of a fabricated CNN article, a format that presents false claims in the visual style of breaking news, and digitally altered imagery was designed to circulate rapidly on social media before platform moderation or journalistic verification could intervene, compressing the available window for correction and maximising exposure of the deterrence narrative to Western political audiences.


Source: Ukrinform. Russian propaganda spreading fakes about death of U.S. Senator Lindsey Graham. [online] Published 19 July 2026. Available at: https://www.ukrinform.net/rubric-factcheck/4145861-russian-propaganda-spreading-fakes-about-death-of-us-senator-lindsey-graham.html


Russian Propaganda Uses AI to Spread Fake Cardboard Protest Images

A fact-check published by Ukrinform states that Russian propaganda outlets spread an AI-generated image falsely depicting a protest rally in Lviv in which participants wearing balaclavas hold a cardboard sign reading 'Cut down TRCs like cardboard', a reference to draft recruitment centers, with AI detection service AI or Not assessing the image as artificially generated with 93 percent probability, exploiting ongoing tensions surrounding Ukraine's military mobilisation.


The fabricated image forms part of a recurring Russian information operation aimed at manufacturing visual evidence of anti-conscription sentiment within Ukraine for consumption by both domestic Ukrainian audiences and Western observers, intended to convey that opposition to mobilisation is broader than official reporting reflects. The use of AI generation enables low-cost, scalable production of synthetic protest imagery with sufficient visual plausibility to circulate on social media platforms before detection tools can flag it, exploiting the speed asymmetry between disinformation production and fact-checking response that characterises the current information environment.


Source: Ukrinform. Russian propaganda uses AI to spread fake “cardboard protest” images. [online] Published 23 July 2026. Available at: https://www.ukrinform.net/rubric-factcheck/4147206-russian-propaganda-uses-ai-to-spread-fake-cardboard-protest-images.html


China

Taiwan Officials Warn Beijing Is Turning Taiwan's Political Divisions into Distrust

A report published by The Epoch Times states that Taiwanese officials and researchers warn that Beijing is weaponising Taiwan's political divisions through religious networks, subsidised visits to mainland China, and digital campaigns to erode Taiwanese trust in the United States rather than build affinity toward China, with electoral data showing CCP influence operations have already shifted voting patterns in Kaohsiung and research finding that frequent users of China-based social media show elevated distrust of the US and increased identification with mainland China.


Unlike earlier CCP influence operations in Taiwan that sought to build affirmative pro-mainland sentiment, the strategy identified by officials focuses primarily on eroding Taiwanese confidence in the United States as a credible and reliable security guarantor. Research cited in the report found that Taiwanese social media users with higher exposure to mainland Chinese platforms exhibited measurably lower trust in the US-Taiwan security relationship, indicating the operation is reshaping Taiwan's strategic calculus without requiring any positive identification with the mainland, a more operationally efficient objective that is also harder for Taiwanese authorities to counter through straightforward pro-democracy messaging.


Source: The Epoch Times. Taiwan Officials Warn Beijing Is Turning Taiwan’s Political Divisions Into Distrust. [online] Published 28 July 2026. Available at: https://www.theepochtimes.com/china/taiwan-officials-warn-beijing-is-turning-taiwans-political-divisions-into-distrust-6067510


[AI Related Articles]


Commission Publishes Guidelines on Transparency Obligations for AI Systems

A guidelines published by the European Commission state that Article 50 transparency obligations under the EU AI Act take effect on August 2nd, 2026, requiring providers to design AI systems that inform users when they are interacting with AI and to add machine-readable marks to AI-generated or manipulated content, with deployers required to disclose deepfakes, AI-generated public interest content lacking human editorial control, and emotion recognition systems, a framework the Commission states will reduce the risk of deception and manipulation through synthetic media.


The transparency obligation applies to any AI system generating or manipulating audio, image, video, or text content where the output could reasonably be mistaken for human-produced material, with specific exemptions for authorised law enforcement and national security applications. The machine-readable marking requirement is intended to work alongside automated platform detection tools, enabling social media and news distribution systems to flag synthetic content at scale, a mechanism the Commission characterises as necessary given the volume of AI-generated material that makes manual disclosure verification impractical across contemporary digital information ecosystems.


Source: European Commission. Commission publishes guidelines on transparency obligations for providers and deployers of certain AI systems. [online] Published 20 July 2026. Available at: https://digital-strategy.ec.europa.eu/en/news/commission-publishes-guidelines-transparency-obligations-providers-and-deployers-certain-ai-systems


In Chinese, AI Speaks Fluent Propaganda

A report published by NewsGuard states that leading AI chatbots reproduce pro-China false claims at significantly higher rates when prompted in Mandarin than in English, indicating a language-dependent vulnerability that exposes Chinese-language users to disproportionate levels of CCP-aligned disinformation through mainstream AI tools.


The audit tested chatbots from multiple providers on a range of politically sensitive topics including the Uyghur detention camps, the Tiananmen Square events of 1989, and Taiwan's political status. The report noted a particularly sharp deterioration in source quality for one audited model, which cited Russian state-affiliated media in every response to queries about the Russia-Ukraine conflict,  a finding NewsGuard described as a significant regression from an earlier audit cycle in which the same model cited Russian state sources in only four per cent of equivalent responses, suggesting a measurable worsening of AI model reliability on contested geopolitical topics.


Source: NewsGuard. In Chinese, AI Speaks Fluent Propaganda. [online] Published 21 July 2026. Available at: https://www.newsguardrealitycheck.com/p/in-chinese-ai-speaks-fluent-propaganda


The Mass Production of AI Personas Weighing In on World Affairs

A report published by Graphika states that an investigation into more than 300 accounts across YouTube, Facebook, TikTok, and X uncovered a network of AI-generated personas producing geopolitical commentary, with over 140 YouTube channels using deepfakes impersonating journalists and academics to spread anti-Western and pro-China narratives on the Russia-Ukraine conflict, Iran tensions, and the South China Sea, and more than 200 identified channels removed for violating platform terms of service.


A single AI-generated persona was identified across 154 channels, predominantly producing finance and investment content, indicating a potential commercial monetisation motive operating alongside the geopolitical commentary function. While Graphika researchers could not definitively attribute the network to a single state or non-state actor, they noted that the consistent anti-Western and pro-China thematic framing across assets spanning multiple countries and languages is consistent with previously documented Chinese state-aligned influence infrastructure, and that YouTube's synthetic content disclosure labels, present on the identified videos, were absent on equivalent content distributed across other platforms in the network.


Source: Graphika. Pundit by Prompt: The Mass Production of AI Personas Weighing In on World Affairs. [online] Published 21 July 2026. Available at: https://www.graphika.com/reports/pundit-by-prompt (Graphika)


Voters Are Being Inundated by a Barrage of AI-Generated Election Ads

A report published by Futurism states that multiple US election races in the 2026 midterm cycle feature AI-generated attack ads depicting candidates in fabricated scenarios, including deepfakes and cartoon-style caricatures, raising concerns about synthetic media manipulation of voters, particularly among older demographics unfamiliar with AI generation technology.


The 2026 midterm cycle is the first US federal election in which AI-generated attack advertising has appeared at scale, with campaigns and affiliated political action committees using commercially available AI video generation tools to produce content that would previously have required professional production budgets. Several of the ads identified by Futurism carried no AI-generated content disclosure labels, and the Federal Election Commission has not issued binding rules on synthetic political advertising, creating a regulatory gap that currently allows AI-generated attack content to circulate in competitive races without mandatory transparency requirements.


Source: Futurism. Voters Are Being Inundated by a Barrage of AI-Generated Conservative “Slop” Ads and Deepfakes. [online] Published 25 July 2026. Available at: https://futurism.com/artificial-intelligence/voters-elections-conservative-generative-ai-slop-ads-deepfakes


[General Reports]


2020 Election Denial Is Back

A report published by NewsGuard states that in the five days following President Trump's 16th July national address, posts on X claiming the 2020 US election was rigged or stolen surged by 214 per cent, reaching 77.7 million views, with the number of accounts advancing the narrative rising by 295 per cent from 55,100 to 218,000, and the content focused on Trump's claims that widespread fraud occurred in 2020 and that China acquired and exploited American voter data.


Trump's address included a new allegation that China had acquired and exploited American voter data, a claim for which no supporting evidence was presented and which NewsGuard assessed as false. The 609,000 posts recorded in the five-day window following the address collectively accumulated more than 77.7 million views on X, with the platform's algorithmic amplification of content from high-follower accounts accelerating the narrative's reach beyond what organic sharing alone would have produced, representing, according to NewsGuard's tracking data, the largest single-event surge in 2020 election denial content since the certification of the election result in January 2021.


Source: NewsGuard. 2020 Election Denial Is Back. [online] Published 21 July 2026. Available at: https://www.newsguardrealitycheck.com/p/2020-election-denial-is-back


World Cup Ends, Bogus Claims Don't

A report published by NewsGuard states that Spain's victory over Argentina in the 2026 FIFA World Cup final on July 19th triggered a fresh wave of viral false claims, bringing to 14 the total number of provably false narratives NewsGuard has tracked since the tournament began in June 2026, illustrating how major international sporting events are routinely exploited as vectors for coordinated disinformation.


The pattern reflects a consistent dynamic in which high-profile international sporting events function as disinformation amplification environments: peak audience engagement, intense emotional stakes, and dense social media activity create conditions in which fabricated narratives spread rapidly ahead of correction, and content posted within the first minutes after a major result can accumulate millions of views before fact-checkers can respond. NewsGuard noted that the false claims circulating the 2026 World Cup span a range of categories including fabricated match incidents, invented player conduct, and false reports of off-field events, with the majority achieving initial viral spread on social media before migrating to low-credibility news websites.


Source: NewsGuard. World Cup Ends, Bogus Claims Don't. [online] Published 22 July 2026. Available at: https://www.newsguardrealitycheck.com/p/world-cup-ends-bogus-claims-dont 


French Parliament Greenlights Social Media Ban for Under-15s

A report published by The Record states that France became the first European Union country to approve a blanket social media ban for children under 15, with the law taking effect September 1st, 2026 for new account creation, requiring all users to verify their age using regulator-approved methods, with critics including Amnesty International arguing that governments should instead regulate harmful engagement-based algorithms rather than implement blanket bans.


Research into Australia's analogous ban, introduced in December 2025, found that significant numbers of teenagers remained on social media through circumvention methods including VPN use, accounts created by older contacts, and falsified date-of-birth entries. The French legislation mandates regulator-approved identity verification rather than self-declaration, which proponents argue is more enforceable than the Australian model; privacy advocates have raised concerns that identity-linked verification creates disproportionate data exposure for all users, including adults who must submit to the same process, and the European Commission has indicated it is evaluating a bloc-wide equivalent ban for users under 13.


Source: The Record. French Parliament greenlights social media ban for under-15s. [online] Published 22 July 2026. Available at: https://therecord.media/france-social-media-ban-parliament


The Pro-Trump Ad Boycott that Never Happened

A fact-check published by NewsGuard states that the viral claim that Coca-Cola and General Motors withdrew advertising from NBC and ABC after the networks declined to air President Trump's July 16th election security address is false, with NewsGuard identifying Chevrolet commercials airing on both networks on July 19th and both General Motors and Coca-Cola confirming to NewsGuard on July 20th that no such withdrawal had taken place.


The false boycott narrative followed a documented disinformation template in which a politically charged media event is rapidly followed by fabricated corporate response claims designed to cast the event in binary partisan terms before the named companies can publicly respond. The speed with which the General Motors and Coca-Cola claims circulated illustrates how the disinformation production cycle increasingly outpaces corporate communications, with both companies forced to issue formal denials to NewsGuard several days after the false claim had already achieved substantial social media penetration, a pattern NewsGuard has documented in multiple prior episodes involving major brands and controversial media coverage decisions.


Source: NewsGuard. The Pro-Trump Ad Boycott That Never Happened. [online] Published 24 July 2026. Available at: https://www.newsguardrealitycheck.com/p/the-pro-trump-ad-boycott-that-never


[CRC Glossary]


The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult.


To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence.


As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website.










bottom of page