Cyber based influence campaigns 21st - 27th September 2026 Report

[Introduction]
Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW).
Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns.
Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media.
We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc.
During the 21st to the 27th September 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities.
[Contents]
X
Tiktok
Russia
China
Iran
Cyflunce Attack
[ Report Highlights]
Swiss authorities confirmed covert and open Russian interference before Switzerland's neutrality initiative vote, though the security secretariat doubts it was decisive.
The Insider estimates that Russian propagandists posing as 'angry Latvians' control about one-third of Latvia's socio-political Telegram channels.
Russian actors paired an AI-faked anti-corruption raid with a cloned NV news site to portray Ukraine as corrupt during US-Russia talks.
Golden Owl assessed a network of personas posing as Israelis as linked to Iran's regime, carrying fraud and decline themes into the debate before Israel's 27-10-2026 election.
The EU sanctioned former RT France chief Xenia Fedorova for spreading Kremlin-aligned narratives through French media after RT's EU broadcasting suspension.
The UK ordered work on a National Centre for Information Defence to disrupt hostile state disinformation, though its powers remain unclear.
Preliminary research in the run-up to the Victorian election found almost half of participants could not confidently recognise genuine political video as real.
Hackers leaked alleged messages between Putin's press secretary Dmitry Peskov and official Mikhail Babich, including one predicting Prigozhin would be remembered as a 'hero'.
[ Report Summary]
Meta says information from Singapore police helped it act on 3.7 million scam-linked accounts, pages and content in 2026, mostly seemingly empty 'shell pages'.
The US Justice Department filed to support Elon Musk's court challenge against the EU's first Digital Services Act fine, imposed on X.
Euronews fact-checkers found AI-generated TikTok videos of non-existent anti-immigration and nationalist protests targeting users in six European countries, some exceeding 300,000 views.
EUvsDisinfo finds Russia promoting Baltic narratives resembling those it used against Ukraine, stoking fear of war as an instrument of coercion.
The Insider estimates that about a third of Latvia's socio-political Telegram channels are run by Russian propagandists posing as disgruntled locals.
The EU imposed an asset freeze on former RT France head Xenia Fedorova for spreading Kremlin-aligned narratives in French media after RT's EU broadcasting suspension.
Swiss authorities confirmed covert as well as open Russian interference before Switzerland's neutrality initiative vote, though the security secretariat doubts it had decisive impact.
Seznam Zprávy journalists lured a film crew working for Russian propaganda project Rybar, whose founder is EU-sanctioned, to Prague, exposing a wider European filming operation.
Russian actors circulated an AI-generated video of a fictitious anti-corruption raid and a cloned NV website to portray Ukraine as corrupt during US-Russia talks.
StopFake found that screenshots of BBC, Guardian, Independent and Al Jazeera reports blaming Ukraine for the 13-09-2026 train strike near Poland were doctored.
Ukraine's disinformation center says Russia-controlled TikTok networks spread AI videos of fake Jewish pilgrims claiming state-paid resettlement in Ukraine to stoke antisemitism.
RSF's second Propaganda Monitor report details how Beijing uses content deals, funded trips, influencers and pressure on journalists to pursue its 'new world media order'.
Doublethink Lab concludes Chinese influence in Zambia's 2026 election worked through institutional and media ties rather than covert manipulation campaigns.
Golden Owl assessed a network of personas posing as Israelis as linked to Iran's regime, carrying fraud and decline themes into Israel's election debate.
NewsGuard found pro-Iran accounts using months-old footage to claim, without evidence, that the US had withdrawn thousands of troops from its Gulf bases.
Black8Mirror hackers published fragments of alleged correspondence between Russian official Mikhail Babich and Putin's press secretary Dmitry Peskov from an archive they claim to hold.
Democrat Vikki Goodwin filed a police report accusing Texas Lieutenant Governor Dan Patrick of breaking a 2019 deepfake law with AI-generated ads.
An AI-generated art therapist persona, quoted more than 30 times by outlets including Forbes and Vice, was banned from the expert-sourcing platform Qwoted.
Preliminary research before Victoria's election found about three in four participants identified deepfakes, but almost half could not confidently recognise genuine political footage.
NewsGuard found US and Chinese chatbots broadly agreed on AI risks, but Chinese bots often evaded questions on AI-enabled repression or avoided naming China.
NewsGuard debunked viral claims that the UN barred Putin from addressing the 2026 General Assembly over his ICC warrant while letting Netanyahu speak.
Euronews found fabricated videos claiming AfD ballots were destroyed in Berlin or the party left off ballots in Mecklenburg-Western Pomerania, echoing tactics previously used by Storm-1516.
PolitiFact reports that Chinese influence campaigns on US data centers showed little reach and that politicians exaggerate their role in largely organic opposition.
CISA published an Election Infrastructure Security Plan on 24-09-2026, noting that attackers have tried to breach voter registration databases in all 50 states.
An ASPI analysis argues that disputes over who has authority to establish truth may become Australia's key divide, creating openings for foreign interference.
UK Prime Minister Andy Burnham told the UN General Assembly he has ordered work on a National Centre for Information Defence against hostile state disinformation.
An Atlantic Council report proposes a US-supported cognitive warfare defense network across the first island chain to counter China's AI-enabled influence campaigns.
GPTZero released its 4o detection model, designed to catch paraphrased and mixed AI text, reporting one false positive in 10,402 student essays.
[State Actors]
Singapore Police Data Helps Meta Disrupt Scam Networks
An announcement published by Meta states that information shared by the Singapore Police Force (SPF) led the company to act against more than 113,000 fraud-linked entities and pages on Facebook and Instagram between January and June 2026, more than 33,600 entities in a June operation against seasonal e-commerce scams, and over 3.6 million 'shell pages' in July, actions it presents as totalling 3.7 million accounts, pages and content. It says the shell pages looked empty and harmless, with no ads or violating content, but formed pre-built infrastructure that scammers could activate at a moment's notice, and that for the January-June actions SPF's information led it to act on more than five times the number of assets flagged.
The Singapore partnership sits within a wider ecosystem of anti-scam work, Meta says, citing a two-week US Department of Justice Scam Center Strike Force operation in May and June 2026 that disrupted 1.4 million accounts, pages and groups on Facebook and Instagram, 20,000 Microsoft accounts and thousands of Starlink kits, and led the Royal Thai Police to arrest 63 people. The company says it has removed 65 million scam ads from Facebook and Instagram so far this year, 94% of them before anyone reported them, and that it backs a shared defence in which platforms, banks, telecoms providers and governments exchange signals.
Source: CyberScoop. The FTC Wants to Regulate AI for Ideological Bias. [online] Published 10 August 2026. Available at: https://cyberscoop.com/ftc-regulating-ai-ideological-bias/
X
US Backs Musk's Challenge to EU's First DSA Fine
An article published by Wired states that the US Department of Justice, with the help of the State Department, has filed an application to support Elon Musk's challenge to annul the European Union's €120 million fine against X at the EU General Court, arguing that it should be involved in the case to protect American companies. It adds that Assistant Attorney General Brett A. Shumate said 'we will not tolerate' what he called regulatory overreach by the European Commission, that President Trump has called such penalties 'overseas extortion', and that Vice President JD Vance has described the Digital Services Act's content moderation rules as 'authoritarian censorship'.
The penalty, the first sanction under the Digital Services Act, followed a two-year Commission investigation which found that X's paid blue checkmarks deceptively presented users as 'verified accounts', and that its inaccessible advertising repository and failure to give researchers access to public data hinder research into the platform's risks. According to Wired, the Commission accepted X's plan in July to fix the data-access problems within six months, while Musk and X, who appealed in February, call the investigation 'incomplete and superficial' and allege prosecutorial bias.
Source: WIRED. The Trump Administration Is Trying to Get Musk and X Out of a $137 Million EU Fine. [online] Published 25 September 2026. Available at: https://www.wired.com/story/trump-administration-is-trying-to-get-musk-and-x-out-of-a-dollar137-million-eu-fine/
TikTok
AI-Fabricated Anti-Immigration Rallies Circulate on TikTok
An article published by Euronews states that its fact-checking team, The Cube, identified AI-generated videos on TikTok depicting thousands of people in a range of European cities protesting against immigration, the government or 'the state of the country', or for nationalist values, none of which took place, with the content targeting users in Portugal, France, Germany, Ireland, Italy and the UK. It adds that the videos were published over the past four months, some exceeding 300,000 views, and that many pose as legitimate news outlets, including one showing a supposed journalist with a microphone bearing the logo of Portuguese state broadcaster RTP, which told The Cube she does not work for it, and that some German videos carry captions supporting the AfD.
TikTok itself had labelled the videos as AI-generated and claims it bans AI content that is 'misleading about matters of public importance', yet some videos seem to slip through. Bruna Martins dos Santos of WITNESS said their continued presence does not automatically establish a policy breach but 'raises critical questions' about TikTok's detection mechanisms, labelling standards and recommender algorithms, and the article notes that the Digital Services Act requires effective measures against content that could harm civic discourse and electoral processes; TikTok did not immediately respond to a request for comment.
Source: Euronews. Wave of AI Videos Showing Far-Right Protests in Europe Spreads Online. [online] Published 24 September 2026. Available at: https://www.euronews.com/2026/09/24/wave-of-ai-videos-showing-far-right-protests-in-europe-spreads-online
Russia
Russia Weaponises Fear of War Against the Baltic States
An analysis published by EUvsDisinfo states that Russia is promoting a picture of the Baltic region in which NATO is preparing to attack Russia, the Baltic states are rapidly militarising, Russian speakers face imminent persecution and local authorities glorify Nazism, narratives that closely resemble those previously used against Ukraine. It cites Russian Foreign Ministry official Grigory Lukyantsev's unevidenced claim that the Baltic states were preparing mass deportations of Russian speakers, which Russian state-aligned media widely amplified while Russian embassies in all three countries publicised a joint Russian-Belarusian report on alleged rights violations, and the ministry's announced plan to take the alleged 'systematic violation' of ethnic Russians' rights to the International Court of Justice.
EUvsDisinfo argues that these narratives serve Moscow regardless of its current intent or timetable, because stoking fears of imminent war can weaken confidence in NATO, encourage risk-averse Western decisions and frame defensive preparations as escalation, so that the possibility of conflict itself becomes an instrument of coercion. It warns that capability, rhetoric and evidence of imminent intent should not be treated as interchangeable, noting that Estonian and Latvian officials signalled no change in their threat assessments after anonymously sourced US reports about the CIA director's Moscow visit, and concludes that preparations should rest on a rational assessment of Russian capabilities rather than on the fear the Kremlin seeks to spread.
Source: EUvsDisinfo. Russia’s Baltic Escalation Playbook: Fear Is Part of the Strategy. [online] Published 24 September 2026. Available at: https://euvsdisinfo.eu/russias-baltic-escalation-playbook-fear-is-part-of-the-strategy/
Russian Propagandists Pose as 'Angry Latvians' on Telegram
An investigation published by The Insider states that the outlet estimates around one-third of the socio-political channels in Latvia's Telegram ecosystem, and upwards of 65% of the Russian-language ones, are controlled by Russian propagandists posing as 'angry Latvians'. It adds that its analysis covered 72 socio-political channels and 353,000 posts published since 01-01-2025, finding that of 93,000 shares, 30.3% were reposts between the channels themselves and 43.7% came from Russian state media, official government channels, military bloggers and pro-war 'Z-channels', and that the largest channels are linked to the state media group Rossiya Segodnya, which includes RT.
The people behind the five largest channels criticise Latvian policy from abroad after moving to Russia or Belarus while presenting themselves as voices of the country's 'outraged citizens', according to the investigation, which names former Saeima member Aleksejs Rosļikovs, who left for Belarus in spring 2026 and runs a roughly 30,000-subscriber channel, and the 24,000-subscriber Baltnews, run by the editorial staff of the Russia Today news agency. The Insider says the network repeats Kremlin narratives about persecuted Russian speakers, rising Nazism and impoverishment blamed on Riga's support for Ukraine, and that one small Wagner-branded channel, 'Zloi Pribalt', has published about 66,000 posts since January 2025.
Source: The Insider. “Pashinyan’s illness,” “looming war with Russia,” and “gas chambers on Mount Ararat”: Moscow floods Armenia with disinfo ahead of elections. [online] Published 29 May 2026. Available at: https://theins.press/en/inv/297571
EU Sanctions Ex-RT France Chief Xenia Fedorova
An announcement published by the Council of the EU states that the Council adopted restrictive measures against Xenia Fedorova, a Russian media figure and former President and Director of Information of RT France, for engaging in foreign information manipulation and interference (FIMI) as part of Russia's hybrid activities. It says that after RT's broadcasting activities were suspended in the EU, Fedorova continued to disseminate narratives aligned with those promoted by the Russian authorities on the war against Ukraine, European support for Ukraine, NATO and EU-Russia relations through French outlets including CNews, Europe 1 and Le JDNews.
The listing brings the number of individuals and entities covered by the EU's framework for restrictive measures over Russia's destabilising activities to 81 and 20 respectively, and those listed that day are subject to an asset freeze, with EU citizens and companies barred from making funds or economic resources available to them. The framework, set up on 08-10-2024, also targets those responsible for Russia's hybrid activities against third countries and international organisations, and the Council notes that the European Council in June 2026 called for urgent efforts to prevent, deter and respond to hybrid attacks by hostile actors, notably Russia and Belarus.
Source: Council of the European Union. Russian hybrid threats: EU lists Xenia Fedorova over information manipulation activities. [online] Published 24 September 2026. Available at: https://www.consilium.europa.eu/en/press/press-releases/2026/09/24/russian-hybrid-threats-eu-lists-xenia-fedorova-over-information-manipulation-activities/
Swiss Detect Covert Russian Operations Before Neutrality Vote
An article published by SWI swissinfo.ch states that Swiss authorities confirm Russian actors interfered both openly and covertly in the campaign ahead of the neutrality initiative vote, which, if accepted, would have barred Switzerland from following EU sanctions against Moscow, with the State Secretariat for Security Policy (SEPOS) writing that 'coordinated, covert disinformation operations' were observed but that it did not believe foreign actors had a decisive impact. It adds that, in the open interference, Russian state platform RT DE published many articles about the initiative, and during the campaign RT published an error-laden article in Swiss dialect, while Russian foreign ministry spokeswoman Maria Zakharova claimed the Swiss financial system had served the German war machine during the Second World War.
Citing British historian Ian Garner, the article says the Kremlin cares less about winning a vote than about getting an argument across, which Garner calls 'a kind of victory' when it succeeds, while DFRLab expert Ruslan Trad called an earlier RT move, publishing opposing opinion pieces under the same byline on a Swiss licence-fee initiative, 'a textbook influence-operation tell'. Russian state media are sanctioned in the EU, where sharing their content is banned, but not in Switzerland, where cable operators have voluntarily stopped carrying such channels while RT remains accessible online, and parliament has tasked the government with laying foundations for 'an effective analysis' of foreign influence attempts.
Source: SWI swissinfo.ch. Swiss Democracy in the Crosshairs of Russian Propaganda. [online] Published 27 September 2026. Available at: https://www.swissinfo.ch/eng/information-wars/swiss-democracy-in-the-crosshairs-of-russian-propaganda/92127460
Czech Sting Exposes Rybar Film Crew Operating in Europe
An article published by The Insider states that journalists from the Czech outlet Seznam Zprávy used the Russian propaganda project Rybar's interview request to media literacy expert Bohumil Kartous to lure a film crew from Berlin to Prague, where correspondent Vitaliy Chashchukhin confirmed on hidden camera that the filming was for Rybar before he and cameraman Igor Dolmatov fled when confronted. It adds that the investigation linked the organiser, Moscow-based filmmaker Boris Dvorkin, to the History of the Fatherland Foundation chaired by foreign intelligence chief Sergei Naryshkin, and found that the project's list of potential or completed interview subjects included an MEP and several Czech experts, with a former military intelligence chief and an energy expert confirming they had been filmed and Dvorkin's own messages referring to a crew delayed in Slovakia.
Dvorkin's planned questions included whether right-wing and Euroskeptic ideas were becoming more popular in Czechia and how relations with Russia could be normalised, and he was particularly interested in disinformation, with Kartous saying the questions appeared designed to portray disinformation as a phenomenon 'on both sides of the border' and to cast doubt on Czech sovereignty within the EU. Rybar, whose founder Mikhail Zvinchuk is under EU sanctions, openly describes its work as participation in an information war, and a Czech Finance Ministry spokesperson said providing services to an organisation controlled by a sanctioned person can count as indirect provision of economic resources to that person, with the article noting that sanctions violations in Czechia can carry criminal liability and fines of up to 50 million koruna.
Source: The Insider. Czech journalists lure Russian propaganda project Rybar’s film crew to Prague to expose influence operation across Europe. [online] Available at: https://theins.press/en/news/297421
Russians Clone NV Site to Push AI-Faked Ukraine Graft Story
An article published by The New Voice of Ukraine (NV) states that Russians created and spread an AI-generated video, circulating from 23-09-2026, a day before US envoys Steve Witkoff and Jared Kushner met Putin envoy Kirill Dmitriev in New York, that purported to show Ukraine's National Anti-Corruption Bureau (NABU) finding $140 million in cartons labelled 'for Servant of the People' while searching Arsen Zhumadilov, former head of the Defense Procurement Agency, a search NABU says never took place, in an effort to portray Ukraine to the West as corrupt. It adds that, to make the fabrication look like genuine news, the perpetrators registered the domain nvukraine.com, copied NV's design, and posted a fake article dated 23-09-2026 in Ukrainian and English.
According to Ukraine's Center for Strategic Communications and Information Security (SPRAVDI), the fake was picked up on 24-09-2026 by the pro-war Russian Telegram channels Golos Mordora and Militarist, with about 149,000 and 277,000 subscribers, spread in English-language communities on Lemmy and, on X, by RT author Chay Bowes, shared by Dmitriev himself on 25-09-2026 and then carried by RIA Novosti, Life, Vesti, Ukraina.ru and Mail.ru sites. SPRAVDI concluded that the operation made the story appear to originate within Ukraine's own information space, promoting a narrative of large-scale defence-sector corruption to Western audiences against the backdrop of Russia's contacts with the United States.
Source: The New Voice of Ukraine. Russia Spreads Fake $140 Million Ukraine Corruption Story During U.S. Talks. [online] Published 25 September 2026. Available at: https://english.nv.ua/nation/russia-spreads-fake-140-million-ukraine-corruption-story-during-dmitriev-u-s-talks-50644647.html
Doctored Media Screenshots Blame Ukraine for Russian Train Strike
An article published by StopFake states that screenshots circulating online, styled as BBC, Guardian, Independent and Al Jazeera reports, falsely claim that Ukrainian intelligence orchestrated the 13-09-2026 attack on a railway near the Ukrainian-Polish border to drag European countries into the war, citing former MI6 chief Alex Younger as the source. It says the headlines were doctored and the claims fabricated, noting that Younger died more than three months before the strike, with the UK government publishing a tribute on 03-06-2026, and that the genuine BBC report describes a Russian drone hitting a locomotive in Yahodyn shortly after Boris Johnson and senior European officials had left the station.
Beyond the doctored headlines, the Guardian and Independent images carried fabricated subheadings and, in the Al Jazeera case, the headline and description of a genuine 14-09-2026 video report were altered so that the headline opened with the words 'Ukrainian hoax', while the original Guardian and Independent articles say the Russian strike may also have been aimed at trains carrying Johnson and the former CIA director. StopFake adds that passengers were evacuated and no injuries were reported, that former CIA director David Petraeus was on another train at Yahodyn station at the time, and that it previously examined disinformation claiming Ukraine may have staged a false-flag operation at Leipzig airport to discredit Russia.
Source: StopFake. Fake: Western Media Report that Ukrainian Intelligence Orchestrated the Attack on Boris Johnson’s Train. [online] Published 24 September 2026. Available at: https://www.stopfake.org/en/fake-western-media-report-that-ukrainian-intelligence-orchestrated-the-attack-on-boris-johnson-s-train/
AI Videos of Fake Pilgrims Spread Uman Resettlement Myth
An article published by The Jerusalem Post states that Ukraine's Center for Countering Disinformation (CCD) said that, during and after Rosh Hashanah, Russia-controlled TikTok account networks circulated AI-generated interview videos in which fake Jewish pilgrims to Uman claimed they were moving to Ukraine permanently, citing fabricated 'payments from the Ukrainian government of 200,000 hryvnias', special benefits and plans to make Uman an independent entity. It adds that the CCD called the campaign 'entirely disinformation', stressing that the pilgrimage is temporary and that Ukraine has no programme paying foreigners to relocate, while local health authorities counted a record of more than 49,000 pilgrims in the city by the morning of 11-09-2026.
The Israel-based media site Nikk traced the narrative back to a 2019 text by then-Kremlin adviser Sergey Glazyev; researchers documented Matryoshka-network fakes in April 2026 claiming Ukraine planned to bar Israeli pilgrims; and the narrative's trajectory ran to an AI-generated pilgrim supposedly 'confessing' on 14-09-2026 to receiving money. Nikk argued the campaign works by slightly altering the relationships between real elements rather than inventing one large fake, such as joint patrols by Israeli and Ukrainian police and an unrelated Ukrainian state payment of exactly 200,000 hryvnias, while the CCD said the aim is to destabilise Ukrainian society and artificially provoke antisemitic sentiment.
Source: The Jerusalem Post. Russia spreads AI fakes claiming Jews are being paid to settle in Ukraine. [online] Published 22 September 2026. Available at: https://www.jpost.com/international/internationalrussia-ukraine-war/article-909326
China
RSF Details Ten Tactics Beijing Uses to Export Propaganda
A report published by Reporters Without Borders (RSF) states that its second Propaganda Monitor report traces the Chinese regime's global propaganda apparatus across five continents and concludes that no country is immune, as Beijing pursues the 'new world media order' Xi Jinping has promoted since 2012. It identifies ten tactics, including content-sharing deals that let Chinese state content be republished as seemingly independent journalism in Germany, funding and equipment in exchange for editorial alignment in the Solomon Islands, embassy pressure and doxxing of journalists in the Philippines and Denmark, and sponsored trips for foreign YouTubers and TikTok creators.
According to RSF, the apparatus runs from the Central Propaganda Department, which controls the content of state media such as CGTN and Xinhua, operating in 160 countries, to diaspora media in the US, Australia and New Zealand, and China, ranked 178th of 180 in RSF's 2026 World Press Freedom Index, is the world's leading jailer of journalists with 120 detained. The report adds that the China-based company Wubianjie has invested heavily in promoting disinformation in Taiwanese Facebook lifestyle groups and Threads accounts, particularly during politically sensitive and fragile periods, and that CGTN amplifies Russian state outlets Sputnik and RT, with RSF warning that China works hand in hand with authoritarian regimes such as Putin's Russia to strengthen their grip on the global information space.
Source: Reporters Without Borders (RSF). The Propaganda Monitor: RSF exposes China’s global campaign to distort journalism worldwide. [online] Published 21 September 2026. Available at: https://rsf.org/en/propaganda-monitor-rsf-exposes-china-s-global-campaign-distort-journalism-worldwide
PRC Sway in Zambia's Election Was Structural, Not Covert
A report published by Doublethink Lab states that its investigation into the 2026 Zambian general election, conducted from May to August 2026, found the People's Republic of China's influence to be 'structural, not covert', operating through decades of institutional ties across Zambia's economy, media, education and digital infrastructure rather than through covert directives or foreign information manipulation and interference (FIMI) campaigns. It found that development narratives, such as solar power deals and PRC donations of 'election security' vehicles, were absorbed into campaign communications without explicit PRC intervention, and that FIMI techniques observed on Facebook, including fake personas, image manipulation and information flooding, could not be definitively attributed to the PRC.
Narratives about the PRC's engagement in Zambia potentially affected the election, the report finds, by legitimising the incumbent UPND and existing institutional actors and by narrowing the public agenda to the delivery of material goods while constraining scrutiny of debt conditions, procurement transparency and surveillance capability. It illustrates the structural position with TopStar, a digital television joint venture in which, according to publicly available records, Chinese firm StarTimes holds 60% and national broadcaster ZNBC 40%, while cautioning that institutional access does not prove editorial control, and recommends public disclosure of foreign relationships, labelling of foreign-supplied content and FIMI analysis that extends beyond bots and fake accounts to funding and framing shifts.
Source: DoubleThink Lab. Structural Ties Over Manipulation: An Analysis of PRC Influence During the 2026 Zambian Election. [online] Available at: https://medium.com/doublethinklab/structural-ties-over-manipulation-an-analysis-of-prc-influence-during-the-2026-zambian-election-6e89711ce2e3
Iran
Golden Owl Assesses Fake Israeli Persona Network as Iran-Linked
A report published by Golden Owl states that it identified a coordinated, foreign-operated influence network targeting Israel's 2026 election debate ahead of the 27-10-2026 vote, documenting an operational core of 35 accounts made up of 32 Israeli-presenting personas and three Hebrew media-style channels, whose personas carry themes of fraud, security, political responsibility and national decline into genuine Israeli debates, and that the combined evidence is most consistent with an operation associated with the Islamic Republic of Iran. It adds that in the measured 30-day window from August 23rd, 2026 to September 22nd, 2026, posts by active network accounts received 947,322 impressions and 9,112 interactions, and that genuine Israeli users helped circulate some of that content without being assessed as participants in the operation.
Golden Owl says the assessment rests on combined evidence rather than political viewpoint, including X's transparency data showing four of the personas connecting through the 'Iran Android App' while geolocated to Germany or Finland, one of them an account that posted only in Persian until April 2026 and re-emerged on 26-08-2026 as 'Alon Strauss' with an Israeli flag as its avatar, and account records showing that 26 of the 32 personas were created in 2025 or 2026. Reach was concentrated, with a single emigration video accounting for 688,434 of the measured views, and the report cautions that the 1,516 flags from its broader election scan are not distinct cases and are not all attributed to the operation, and that the evidence does not establish who personally operated the accounts, which institution directed them, or whether the activity changed any voter's decision or the election outcome.
Source: Golden Owl. The Other Face of War: Iranian Regime–Linked Manipulation of Israel’s 2026 Election Debate. [online] Published 24 September 2026. Available at: https://goldenowl.ai/resources/research/Iranian-Regime-Linked-Manipulation-of-Israel-2026-Election-Debate
Months-Old Footage Used to Claim US Troop Pullout from Gulf
A report published by NewsGuard Reality Check states that pro-Iran social media accounts are claiming, in Farsi, English, Chinese and French on Facebook, X and Instagram, that the US has withdrawn thousands of troops from its bases in Qatar, Bahrain, Kuwait and other Gulf countries, in an apparent effort to present Iran as the victor in its war with the US and Israel. It found no evidence of any such withdrawal, noting that the US has 50,000 troops stationed in the Middle East, according to Reuters, and that Qatar alone hosts 10,000 US troops and Al Udeid Air Base, the largest US military installation in the region.
The two videos used as evidence, one of troops marching in a parking lot at night and one of troops with large packs on a military aircraft, predate the purported withdrawal: NewsGuard found that one first appeared in March 2026, showing heavy winter gear inconsistent with September temperatures and no protective equipment expected amid hostilities, and that the other was first published in June 2026. It notes that real but limited US moves, including a planned withdrawal from Iraq by September 30th and the earlier handover of bases in Syria, do not amount to a mass withdrawal from the region.
Source: NewsGuard. The Troop Withdrawal That Didn’t Happen. [online] Published 25 September 2026. Available at: https://www.newsguardrealitycheck.com/p/the-troop-withdrawal-that-didnt-happen
Cyfluence Attack
Hackers Leak Alleged Peskov Messages from Claimed Babich Archive
An article published by Nasha Niva states that the hacker group Black8Mirror claimed to have obtained an archive of more than 21 GB belonging to Mikhail Babich, former Russian ambassador to Belarus and deputy director of the Federal Service for Military-Technical Cooperation since 2021, covering 2020 to August 2026, and published fragments and screenshots of his alleged correspondence with Vladimir Putin's press secretary Dmitry Peskov. It adds that in the fragments, 'Peskov' calls Kazakh President Kassym-Jomart Tokayev's July 2026 speech, in which he proposed freezing the war, 'pure improvisation', says someone 'asked Tokayev to say this' and that the only question is whether it was 'Ukrainians, Americans, or someone from within', and defends a scaled-down Navy Day event as 'safe'.
The most striking fragment dated May 24th, 2023, a month before the Wagner mutiny, shows 'Peskov' telling 'Babich' that he had argued with Yevgeny Prigozhin for an hour and that 'later we will remember him as a hero', after 'Babich' forwarded a summary of Prigozhin's views on Navalny's imprisonment. An analysis of the publication found the forwarded text, shown on the screenshot as a message from a 'Nikolai Petrov', originated from a since-deleted post on the Telegram channel 'EZh', and the exchange is dated one day after a long interview in which Prigozhin argued Russia had contributed to Ukraine's militarisation and reflected on Navalny's anti-corruption investigations.
Source: Nasha Niva. "Later we will remember Prigozhin as a hero." Hackers published alleged correspondence between Babich and Peskov. [online] Available at: https://nashaniva.com/en/405318
[AI Related Articles]
Texas Candidate Files Police Report Over AI-Generated Campaign Ads
An article published by The Texas Tribune states that Vikki Goodwin, the Democratic candidate for Texas lieutenant governor, filed a police report with the Travis County Sheriff's Office on September 19th, accusing Republican Lt. Gov. Dan Patrick of breaking state law after his campaign released two ads featuring AI-generated videos of her. It adds that the videos have since been deleted from Patrick's X account and that, in an affidavit, Goodwin said the person in the video 'appears to be me' but was not, and alleged that Patrick posted it 'with the intent to deceive Texans, injure a candidate, or influence the result of an election'.
Goodwin invoked a 2019 Texas law, one of the earliest in the US to regulate AI in political campaigns, which bans deepfake videos made with intent to deceive from being published or distributed within 30 days of an election, arguing it applies because early in-person voting begins on October 19th, and mail ballots are about to be sent. Patrick campaign spokesman Allen Blakemore told The New York Times the material was 'an obvious parody produced to entertain' and denied distributing any such content within 30 days of the election, while Goodwin's communications director said removing the posts the day after the complaint looked like an admission of guilt.
Source: The Texas Tribune. In lieutenant governor race, Vikki Goodwin says Dan Patrick ads are illegal AI deepfakes. [online] Published 21 September 2026. Available at: https://www.texastribune.org/2026/09/21/texas-goodwin-patrick-ad-police-complaint/
AI-Generated Persona Quoted 30-Plus Times by Major Outlets
An article published by Cybernews states that 'Dr. Eleni Nicolaou', an art therapist listed as a source on the journalist expert platform Qwoted, was banned from the platform after the journalism news outlet Press Gazette exposed her as an AI-generated persona, finding that much of her profile, from her picture to her 'expert opinions', was AI-generated and that her identity could not be verified. It adds that her comments had appeared more than 30 times in recent months in outlets including Tom's Guide, Forbes, Glamour, Vice, Netmums, AOL and Yahoo, and that the persona was linked to Davincified, an e-commerce site selling paint-by-numbers prints.
The persona had its own LinkedIn profile claiming a PhD in clinical psychology from the University of Cyprus and a Davincified email address, and the Qwoted profile combined with professional profiles on platforms such as LinkedIn raised no alarms on the surface, although Press Gazette found her profile picture scored a perfect 10 on an AI scale and her comments were deemed 100% AI-generated. Cybernews adds that AI detectors such as GPTZero can help but vary in accuracy, citing a case in which Meta's detector misidentified 55% of its own AI images after Reuters edited them, and advises independent verification of sources.
Source: Cybernews. AI-generated expert removed from Qwoted after media quotes. [online] Published 24 September 2026. Available at: https://cybernews.com/ai-news/fake-art-therapist-qwoted-expert-vice-forbes/
Preliminary Study Finds Many People Doubt Genuine Footage
An article published by The Conversation states that AI-generated deepfakes, including a machete attack at a petrol station and floodwater pouring down the steps of parliament, have reportedly appeared as paid advertising months before the Victorian state election, and that in an experiment with 411 Australians, part of the authors' study of political deepfakes in the lead-up to that election, roughly 75% of participants correctly identified deepfakes regardless of quality. It adds that, according to these preliminary findings, almost 29% labelled an authentic political video as fake and a further 18% were unsure, meaning almost half could not confidently identify genuine political content as real.
The authors' yet-to-be-published meta-analysis of 19 studies covering more than 24,000 people from 2018 to 2026 found deepfakes can appear just as persuasive as authentic footage or conventional misinformation and are associated with lower trust in news and democratic institutions, an uncertainty the authors say can contribute to the 'liar's dividend'. In their preliminary experimental findings, people who consumed more news were better at detecting low-quality deepfakes but became less accurate at identifying authentic content, confidence among moderate and higher news consumers became increasingly disconnected from accuracy, and differences linked to political orientation emerged only when the deepfake depicted a political actor aligned with the viewer.
Source: The Conversation. Deepfakes are distorting this year’s Victorian election. We found out who’s most susceptible to them. [online] Published 27 September 2026. Available at: https://theconversation.com/deepfakes-are-distorting-this-years-victorian-election-we-found-out-whos-most-susceptible-to-them-291443
Chinese Chatbots Often Sidestep China-Sensitive AI Questions
A report published by NewsGuard Reality Check states that, ahead of Xi Jinping's 24-09-2026 meeting with President Trump, it tested six Chinese AI chatbots, including DeepSeek, Baidu's Ernie, Alibaba's Qwen and Moonshot AI's Kimi, and US tools including ChatGPT, Grok, Claude and Gemini with six prompts relating to AI, finding far more agreement than disagreement. It adds that all the chatbots identified AI safety as a government's top priority when developing AI and that both sides favoured targeted rather than blanket slowdowns of AI development and described similar scenarios in which AI could spin out of control.
According to NewsGuard, the bots diverged on topics sensitive to China, such as the Chinese government's AI-empowered mass surveillance and its use of AI to suppress dissidents: asked whether AI can be used to suppress political dissent, two Chinese chatbots evaded the question and three of the four that answered avoided mentioning China, while three of the six Chinese bots did not address which countries have been criticised for AI-enabled human rights abuses and those that did cited the US and other Western countries. The US chatbots engaged directly on such misuse, and all cited China, and NewsGuard quotes Tencent's Yuanbao saying it could not 'directly elaborate on examples involving political topics'.
Source: NewsGuard. U.S. and Chinese AI Tools Are More Alike Than You May Think. [online] Published 24 September 2026. Available at: https://www.newsguardrealitycheck.com/p/us-and-chinese-ai-tools-are-more
[General Reports]
Viral Claim That UN Barred Putin from Speaking Is False
A report published by NewsGuard Reality Check states that anti-Israel and pro-Kremlin social media users falsely claimed on September 22nd, 2026, that the UN barred Vladimir Putin from addressing the 2026 General Assembly because of his International Criminal Court arrest warrant while allowing Benjamin Netanyahu, who also faces an ICC warrant, to speak, presenting this as proof of pro-Israel bias. It adds that the claim emerged in a post by Mohamad Safa, former representative of the Patriotic Vision Association, which drew 1.2 million views and 133,000 likes in one day, and was repeated by the account @Rusia_HD, which garnered 544,100 views.
Putin was not blocked: according to NPR and Deutsche Welle, he chose Foreign Minister Sergei Lavrov to attend in his place; he has not attended the General Assembly since 2015, UN deputy spokesperson Farhan Aziz Haq told NewsGuard the claim was false, and the UN and ICC are separate entities with no prohibition on leaders facing ICC warrants speaking at UN meetings. NewsGuard named the claim its 'False Claim of the Week' because of its spread across platforms, high engagement, and the prominence of those promoting it, and notes that the UN is far more commonly accused of anti-Israel bias.
Source: NewsGuard. The Putin UN Ban That Wasn’t. [online] Published 25 September 2026. Available at: https://www.newsguardrealitycheck.com/p/the-putin-un-ban-that-wasnt
Doctored Ballot Videos Cast AfD as Fraud Victim in Germany
An article published by Euronews states that videos alleging fraud against the Alternative for Germany (AfD), purporting to show AfD postal ballots being destroyed in Berlin or the party missing from ballots in Mecklenburg-Western Pomerania, spread on X ahead of the two elections, garnered hundreds of thousands of views and echoed tactics previously used by the pro-Russian influence network Storm-1516. It adds that one Berlin video was shared by EU-sanctioned pro-Russian blogger Alina Lipp, whose post exceeded 630,000 views, and that Mecklenburg-Western Pomerania's state election chief, Christian Boden, confirmed the AfD appeared on that state's genuine postal ballots and said the forgeries there were closely modelled on official sample ballots with the AfD fields deleted.
Election-monitoring site Wahlrecht.de found the purported Berlin postal packages lacked the polling cards voters must return, had unsealed envelopes and were missing district council ballots. Euronews reports that some videos were amplified by accounts known for pro-Russian theories and closely resembled 2025 federal election fakes that German authorities said appeared to form part of a campaign associated with Storm-1516, a network whose 'central actor', according to Germany's Federal Intelligence Service, is Russia, and notes that the false narrative casts the AfD and its supporters as victims, that the AfD finished first in Mecklenburg-Western Pomerania with 38.2% of the vote, and that there is no evidence the party is behind the campaign.
Source: Euronews. Fake videos spread fraud claims during German elections. [online] Published 23 September 2026. Available at: https://www.euronews.com/2026/09/23/fake-videos-spread-fraud-claims-during-german-elections
Politicians Overstate China's Role in US Data Center Opposition
An analysis published by PolitiFact states that politicians, including President Trump, who told Fox News host Laura Ingraham that 'a lot of people say' data center opposition is 'a China PR thing', exaggerate the effect of Chinese influence campaigns on a movement that spans Americans of all political stripes in nearly every state. It cites OpenAI's report that it found no evidence of meaningful breakout for a China-linked operation that used ChatGPT to argue data centers raise electricity prices, and X's identification of 200 accounts within a bot farm of about 200,000 posting in a manner that could manipulate the debate, noting that Clemson University researcher Darren Linvill's team found 70 accounts common to both sets had no followers or engagement before suspension.
Council on Foreign Relations fellow Jessica Brandt said foreign actors exploit the data center debate rather than manufacture it and that 'evidence of an attempt is not evidence of success', while Linvill said a genuine Chinese priority would involve 'far more than 200 accounts'. PolitiFact points to measures of organic opposition, including an Annenberg survey in which 61% of US adults opposed local data center construction, up 12 points, and 580 local opposition groups with 640,000 members, and notes that TV personality Kevin O'Leary, who called two Utah nonprofits proxies for the Chinese government, was sued for defamation by them and recanted.
Source: PolitiFact. Is US data center opposition a ‘China PR thing,’ as Trump says? Experts say that’s exaggerated. [online] Published 23 September 2026. Available at: https://politifact.com/article/2026/sep/23/china-influence-data-center-opposition/
CISA Election Plan Flags Voter Database Breach Attempts
An article published by Infosecurity Magazine states that the US Cybersecurity and Infrastructure Security Agency (CISA) published an Election Infrastructure Security Plan on September 24th, 2026, ahead of the November 3rd, 2026, midterm elections, setting out guidance for state, local, and federal bodies on mitigating cyber and physical threats to election infrastructure. It adds that the plan notes that threat actors have attempted to breach statewide voter registration databases in all 50 states, with confirmed success in at least 20 over the last decade, and urges multifactor authentication, continuous network monitoring and comprehensive audit trails.
The plan also flags vulnerability exploitation through election systems reachable from general enterprise networks and insider risks from temporary poll workers, contractors and vendors, recommending paper ballots, bipartisan ballot handling and chain-of-custody procedures. Security experts have warned that reported 2025 cuts to CISA impacted its efforts to secure election infrastructure, including the reported termination of federally funded support for the Election Infrastructure Information Sharing and Analysis Center (EI-ISAC), which the new plan does not specifically mention.
Source: Infosecurity Magazine. CISA Unveils Election Security Plan Ahead of 2026 Midterms. [online] Published 25 September 2026. Available at: https://www.infosecurity-magazine.com/news/cisa-election-security-midterms/
Fight Over Who Defines Truth May Leave Democracies Exposed
An analysis published by The Strategist (ASPI) states that Australia's next class war may be fought less over wealth than over truth, as the deepest disagreements increasingly concern who has the authority to establish what is true and institutional authority based on credentials and editorial processes competes with networked authority derived from authenticity, affinity, audience and visibility. It cites research indicating that social media can amplify the false-consensus effect, although the effects are generally modest and vary across platforms and users, and argues that with personalised algorithms an online audience can gradually become an assumed majority and political disappointment can be reinterpreted as evidence that institutions no longer represent the people, which creates fertile ground for conspiratorial reasoning.
The analysis argues that foreign interference is most effective where trust has already begun to fracture, and that adversaries need not persuade Australians that their worldviews are correct if they can persuade them that no domestic institution deserves confidence, suggesting the most effective information operation may no longer be 'believe us' but simply 'don't believe them'. It calls for trust proportionate to evidence rather than blind institutional faith or reflexive cynicism, and lists compulsory voting, robust electoral institutions and an independent electoral commission as Australian strengths that should not breed complacency.
Source: Australian Strategic Policy Institute (ASPI). Australia’s next class war may be fought over reality. [online] Published 24 September 2026. Available at: https://www.aspistrategist.org.au/australias-next-class-war-may-be-fought-over-reality/
[Appendix - Frameworks to Counter Disinformation]
UK Orders Work on Information Defence Centre Against Hostile States
An article published by The Record states that British Prime Minister Andy Burnham told the UN General Assembly he has ordered security chiefs to begin work on a National Centre for Information Defence to 'detect, attribute and disrupt' hostile state disinformation, with the Cabinet Office understood to be leading initial work involving intelligence agencies, government departments, law enforcement and social media companies. It adds that Burnham accused Russian agencies of using bots and fake websites, falsifying newspaper articles, copying the branding of 28 British organisations including universities and the BBC, and amplifying far-right narratives, and said the Kremlin spends around £1.3 billion a year on manipulating information.
Experts questioned the centre's form and accountability, with RUSI analyst Sophie Williams-Dunning noting 'a real difference between a centre inside the Cabinet Office and an agency accountable to Parliament' and saying a high evidentiary threshold, particularly on proving foreign orchestration, is one reason the National Security Act 2023 foreign interference offence has been hard to use. She said Burnham's language suggests something closer to 'defending forward' than France's Viginum, which focuses on detection, coordination and public attribution of foreign operations without an explicit disruption mandate, while The Record notes it is not yet clear what powers the new centre would have to carry out disruption.
Source: The Record. Burnham Announces Plan for New UK Center to Fight Disinformation. [online] Published 23 September 2026. Available at: https://therecord.media/uk-disinformation-russia-center
Report Urges US-Backed Cognitive Defense Network for Taiwan and Japan
A report published by the Atlantic Council states that the Chinese Communist Party has upgraded the cognitive domain from the 'Three Warfares' to a contest for 'brain control', running AI-enabled, party-state-wide influence campaigns, including through contracted AI firms exploiting fears of US abandonment, that evolve faster than democratic countermeasures, while most security cooperation among first island chain nations still focuses on physical threats. It adds that the report, by Major Yu-Hao 'Vinson' Shen, uses the DISARM framework to compare China's military cognitive warfare against Taiwan and Japan and finds both democracies constrained in regulating hostile content by free speech norms and public concern about government control of information.
Taiwan and Japan have complementary strengths, the report finds, with Taiwan offering a mature public-private ecosystem, linguistic proximity and frontline experience, and Japan stronger internal official coordination, alliance management and international strategic communication. It recommends integrating them in a US-supported multilateral cognitive warfare defense network across the first island chain, built on a shared framework and common operational picture, which it says would help democracies move from isolated, reactive responses toward coordinated early warning and proactive defence; it separately urges first island chain democracies and the United States to share what they see, build civil society into their own response, and train together, and discloses that the report and the author's fellowship were made possible by support from Taiwan's Ministry of National Defense.
Source: Atlantic Council. Building a Multilateral Cognitive Warfare Defense Network: A Collaborative Framework for the United States, Japan, and Taiwan. [online] Published 23 September 2026. Available at: https://www.atlanticcouncil.org/in-depth-research-reports/report/building-a-multilateral-cognitive-warfare-defense-network/
GPTZero Launches 4o Model to Detect Paraphrased AI Text
An announcement published by GPTZero states that its new GPTZero 4o model, the default for all users since 20-09-2026, deliberately tackles the harder cases of AI-generated text that has been paraphrased or mixed with human writing, and is versatile across model types including Claude, OpenAI, Gemini, Grok and DeepSeek. It adds that the company recorded one false positive out of 10,402 essays on the PERSUADE student-writing dataset and AI recall above 99% on its own benchmark covering GPT-5.6, Gemini 3.6, Grok 4.5 and Claude 5, with a false positive rate below 0.03% on human text.
The release adds interpretability features, including an 'AI Patterns' view that explains recurring stylistic structures such as a 'Phantom Experts' pattern, in which claims are assigned to unnamed authorities instead of identified sources, and 'Masked Detection', which excludes headings from analysis. GPTZero says the model is designed to be indifferent to punctuation changes such as em dashes and that, on the Epoch AI and DetectRL benchmarks 4o matched or outperformed rival detector Pangram 4 on most measures, and it cites a Graphite study which, as Graphite reported, found lower error rates for GPTZero than for Pangram.
Source: GPTZero. Introducing GPTZero 4o. [online] Published 24 September 2026. Available at: https://gptzero.me/news/introducing-gptzero-4o/
[CRC Glossary]
The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult.
To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence.
As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website.
_edited.png)
.png)



