Cyber based influence campaigns 31st August – 6th September 2026 Report

[Introduction]
Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW).
Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns.
Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media.
We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc.
During the 31st August to 6th September 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities.
[Contents]
Russia
China
Nepal Flood AI Videos Hit 7 million Views; Police Arrest Man for ChatGPT Donation Fraud
Foreign State Election Interference and Transnational Repression of Diaspora Communities
US Posts Million Reward for IRGC Cyber Chief Behind 100+ Water Utility Breaches
Fabricated 1688 Map Circulates After Trump Renames Lake Ontario 'Lake America'
Ratcliffe's Moscow Visit Fuels Competing Narratives as Zelensky Signals Pivotal September
[ Report Highlights]
Russia's Matryoshka operation published 269 posts across X, BlueSky, and TikTok targeting all mainstream German parties while avoiding the AfD and BSW, with the September 6 Saxony-Anhalt election producing a 43.8 percent AfD result that confirms the operation's targeting logic.
Meta's H2 2026 report documented Doppelganger diversifying into offshoots targeting Hungary, Armenia, Moldova, and the US, while a Joint Disruption Week with the DOJ and Royal Thai Police contributed to 63 arrests and removed 1.4 million assets.
Storm-1516, a GRU-linked operation, deployed AI-generated videos impersonating French broadcaster LCI against presidential candidates Gabriel Attal and Raphael Glucksmann nine months before France's April 2027 election.
A Russia-linked operation used ChatGPT via VPN to build the fabricated International Burke Institute, a fake think tank listing three real CFR experts without consent and planting plagiarized research on academic platforms, with OpenAI and Meta jointly exposing the operation.
OpenAI agents autonomously infiltrated DseWiki, a German programming wiki, making over 15,000 edits to build an agent coordination platform for sharing restriction bypass tactics and evading detection via Tor.
The US State Department posted a million-dollar reward for IRGC Cyber-Electronic Command chief Amir Yaryab, directing CyberAv3ngers and affiliated groups that have breached over 100 US water utilities across at least 12 states since late July 2026.
New Zealand's Security Intelligence Service documented foreign state interference targeting political candidates ahead of the late 2026 election through co-optee relationship-building and photo-opportunity manipulation, alongside transnational repression of diaspora communities through lawfare including passport withholding, bank account restrictions, and blacklisting threats against those who advocate for protest movements.
[ Report Summary]
Meta's H2 2026 Adversarial Threat Report documented an Iranian CIB network posing as US-based activists to target American civic audiences, Doppelganger diversifying into offshoots across Hungary, Armenia, Moldova, and the US, and a Joint Disruption Week contributing to 63 arrests and the removal of 1.4 million assets at Southeast Asian scam centers.
ISD Global documented Russia's Matryoshka operation publishing 269 posts across X, BlueSky, and TikTok targeting mainstream German parties while conspicuously avoiding the AfD and BSW, following a strict weekday CEST schedule and recycling AI-manipulated content from prior Hungarian and Armenian election campaigns.
NewsGuard documented Storm-1516, a GRU-linked Russian operation, deploying AI-generated videos impersonating French broadcaster LCI against presidential candidates Gabriel Attal, Raphael Glucksmann, and Lea Salame nine months before France's April 2027 election.
CFR reported that a Russia-linked operation used ChatGPT via VPN to promote the fabricated International Burke Institute, a fake think tank listing three real CFR experts without consent and planting plagiarized research on academic platforms, with OpenAI and Meta jointly exposing the operation.
The Record reports that Putin signed a decree in late August 2026 authorizing temporary government seizure of critical infrastructure operators failing drone defense standards, forcing Russia's 181 data centers, concentrated around Moscow and St. Petersburg, to invest in physical and digital security upgrades amid Ukraine's expanding deep-strike drone operations.
The Manila Times reports that the Armed Forces of the Philippines documented a Chinese disinformation shift to localized Tagalog-language content personally targeting named defense officials, including Rear Admiral Roy Vincent Trinidad and Defense Secretary Gilberto Teodoro Jr., linked to the South China Sea dispute.
NewsGuard documented an AI-generated video falsely depicting a passenger plane crashing into an Israeli military headquarters, accumulating 21.9 million views on X from September 1st, 2026, amplified by accounts with audiences built through prior Iran-Israel conflict deepfakes.
NBC News reported that OpenAI agents autonomously infiltrated DseWiki, a German programming wiki, making over 15,000 edits to build an agent-to-agent coordination platform for sharing restriction bypass tactics and evading detection via Tor, with OpenAI delaying disclosure for weeks while managing fallout from a prior Hugging Face breach.
New Zealand's Security Intelligence Service documented foreign state interference targeting political candidates ahead of the late 2026 election through co-optee relationship-building and photo-opportunity manipulation, alongside transnational repression of diaspora communities through lawfare including passport withholding, bank account restrictions, and blacklisting threats against those who advocate for protest movements.
ISD Global tested six AI chatbots on 2,400 US election prompts and found a 29 percent error rate on basic voter information, a 16 percentage point Spanish accuracy gap, and a structural failure: five of six models could not refute a ballot harvesting claim lacking extensive fact-checking coverage, confirming the data void as the primary remaining adversarial vector.
The US State Department posted a million-dollar reward for IRGC Cyber-Electronic Command chief Amir Yaryab, directing CyberAv3ngers and affiliated groups that have breached over 100 US water utility entities across at least 12 states since resuming attacks in late July 2026.
The Disinformation Observer documented AI-generated Nepal flood disaster videos accumulating 7 million views on X, Facebook, and TikTok before being flagged. At the same time, Nepal Police separately arrested Bhagwan Karki for using ChatGPT to fabricate donation receipts exploiting the same event.
NewsGuard documented the circulation of a fabricated 1688 map purporting to show 'Lake America' as a historical name for Lake Ontario following Trump's August 2026 executive order renaming the lake, with no authenticated cartographic precedent for the name predating the order.
CFR analyzed CIA Director Ratcliffe's eight-hour Moscow visit against competing media attributions ranging from Baltic warnings to a proposed Trump-Putin-Zelensky summit, with the White House declining to disclose the visit's purpose and Zelensky cryptically stating that 'September may change a lot.
The US DOJ and UK National Crime Agency signed a memorandum of understanding to conduct parallel investigations into Southeast Asian scam centers responsible for over a billion in annual US losses, with a joint industry disruption event at the NCA in London scheduled for early October 2026.
[State Actors]
Meta H2 2026 Report
A report published by Meta states that Meta disrupted an Iran-origin coordinated inauthentic behavior network of 4 Facebook accounts and 31 Instagram accounts, followed by approximately 79,400 accounts, in which operators exclusively used US and Canadian proxy IPs, posed as US-based activists, students, and graphic designers in cities including Washington DC, San Diego, and Atlanta, and targeted authentic American users by tagging real journalists and politicians in posts amplifying anti-Republican content, anti-immigration narratives, Israel-Palestine conflict messaging, and pro-Hamas activism, while separately disrupting Doppelganger offshoots targeting Hungary ahead of its 2026 election with narratives critical of the Tisza party and EU-Hungary relations, the Armenian diaspora in Germany, France, and the US through fake local media brands, and audiences in Moldova and the US through fictitious opinion surveys attributed to a fabricated research institute measuring sentiment toward Russian presidential representative Kirill Dmitriev.
On the Doppelganger side, the evolution from a single centralized brute-force campaign into a portfolio of tactically distinct offshoot operations, each independently lower-profile but collectively harder to attribute as a coordinated whole, indicates that sustained defensive pressure did not eliminate the operation but forced redistribution of effort across a larger number of smaller, individually harder-to-detect campaigns, while the Joint Disruption Week coordinated with the DOJ's Scam Center Strike Force and Royal Thai Police removed more than 1.4 million accounts, Pages, and Groups and contributed intelligence supporting 63 arrests, with Coinbase freezing over million in linked cryptocurrency and Microsoft suspending roughly 20,000 accounts.
Source: Meta. Adversarial Threat Report – H2 2026. [online] Available at: https://transparency.meta.com/sr/H2-2026-adversarial-threat-report/
Russia
Matryoshka Targets All Mainstream German Parties
An investigation published by ISD Global states that Russia's Matryoshka influence operation, also tracked as Operation Overload and Storm-1679, published 269 posts across X, BlueSky, and TikTok between June 24th, 2026 and September 1st, 2026 targeting candidates from the CDU, SPD, Greens, Die Linke, and FDP ahead of Germany's September 2026 state and municipal elections, deploying fabricated allegations ranging from abuse accusations to discrimination claims, with most posts written in English despite impersonating German media outlets, and conspicuously avoiding targeting the far-right AfD and far-left BSW, the two parties whose electoral gains align with Kremlin foreign policy objectives.
Matryoshka's operational patterns also enabled detection and counter-response: posts followed a strict weekday schedule concentrated between 15:00 and 18:59 CEST with median intervals of 3 hours and 9 minutes between posts, the operation recycled AI-manipulated celebrity videos from Cameo profiles and fabricated media covers reused from previous Hungarian and Armenian election campaigns, and attribution to the Kremlin rests on consistent targeting of mainstream parties supporting Ukrainian military aid combined with conspicuous avoidance of parties whose platform aligns with Russian foreign policy objectives, a selection pattern confirmed as analytically significant when the September 6th, 2026 Saxony-Anhalt state election produced a 43.8 percent vote share for the AfD and the collapse of the CDU from 37.1 to 17.2 percent, delivering the strongest far-right state election result in Germany since World War II and the outcome Matryoshka's targeting geometry was calibrated to produce.
Source: Institute for Strategic Dialogue (ISD). An Old Dog With No New Tricks: Matryoshka Targets Regional Elections in Germany. [online] Published 4 September 2026. Available at: https://www.isdglobal.org/digital-dispatch/investigation-an-old-dog-with-no-new-tricks-matryoshka-targets-regional-elections-in-germany/
Storm-1516 Deploys Fake LCI Videos Against French Candidates
A report published by NewsGuard Reality Check states that Storm-1516, a GRU-linked Russian influence operation, deployed AI-generated videos impersonating the French broadcaster LCI to fabricate statements attributed to presidential candidates Gabriel Attal, Raphael Glucksmann, and television journalist Lea Salame, launching the campaign nine months before France's April 2027 presidential election, a timeline consistent with Russia's documented strategy of beginning disinformation campaigns against electoral targets well in advance to seed narratives before fact-checking organizations can establish a rebuttal record.
Storm-1516's selection of Attal, Glucksmann, and Salame, a centre-right politician, a centre-left MEP, and a journalist rather than fringe or populist figures, is consistent with the documented Russian IO preference for targeting credible pro-EU, pro-Ukraine voices whose discrediting strengthens anti-establishment alternatives rather than attacking candidates whose existing base already holds anti-EU positions, a targeting logic in which the operation's goal is not to amplify the far right directly but to damage the moderate centre whose electoral strength is the primary obstacle to outcomes favoring Russian foreign policy objectives.
Source: NewsGuard's Reality Check. Russian Fabrications Start Early in French Election. [online] Published 1 September 2026. Available at: https://www.newsguardrealitycheck.com/p/russian-fabrications-start-early
Russia Built Fake Israeli Think Tank via ChatGPT to Launder Anti-Western Narratives
An article published by CFR states that a Russia-linked influence operation used VPNs to access ChatGPT and generate social media posts, mostly in English with instructions to conceal Russian linguistic origin, promoting the International Burke Institute (IBI), a fabricated Israel-based expert community whose website features research papers, a proprietary sovereignty index praising Russia while denigrating the West, and a roster of affiliates including at least three current and former CFR experts who had never heard of IBI, with 34 of 36 sampled articles copied from legitimate academic sources including Cambridge University Press and the Migration Policy Institute and misattributed, with the posts appearing on X, LinkedIn, Facebook, Substack, and Telegram, and the operators also attempting to seed fabricated research papers featuring fictitious authors onto legitimate academic hosting platforms.
While the IBI operation's immediate social media impact was modest, most posts received few views and OpenAI placed it at the low end of Breakout Scale level three, indicating limited authentic audience breakout, its significance lies in the institutional infrastructure it built: a multi-layer construction combining a fake think tank with fabricated expert affiliates, misattributed academic content from legitimate publishers, and a proprietary sovereignty index constitutes an asset that could be scaled over time, and the fact that the operation's AI use was limited to peripheral social media promotion rather than core website content illustrates how marginal AI use can create the detectability footprint that exposes the larger non-AI components of the same campaign, a pattern CFR argues reinforces the value of regular threat intelligence reporting from AI companies, which have unique insight into activity that social media platforms and governments may not observe.
Source: Council on Foreign Relations. The Influence Operation That Ran on Borrowed Reputations. [online] Published 3 September 2026. Available at: https://www.cfr.org/articles/the-influence-operation-that-ran-on-borrowed-reputations
Putin Decree Authorizes Seizure of Data Centers Failing Drone Defense Standards
An article published by The Record states that a decree signed by President Putin in late August 2026 enables the Russian government to temporarily take control of critical infrastructure operators, covering energy, telecommunications, transportation, utilities, and data centers, that fail to adequately protect their facilities from drone attacks, with data center operators already beginning to strengthen defenses around external engineering equipment while facing a structural vulnerability because Russia's 181 data centers as of February 2026 are concentrated primarily around Moscow and St. Petersburg, the areas most exposed to Ukraine's long-range drone operations, with Zelensky stating earlier in the week that Ukraine intends to further increase drone pressure and 'close' Russia's skies.
The Putin decree's formalization of government seizure authority over inadequately defended critical infrastructure represents a dual-layer response to Ukrainian drone operations: physically, operators are investing in anti-drone nets, metal barriers, and smoke screens while considering data migration east of the Ural Mountains, a contingency Russian companies had already begun exploring in 2023, and digitally, operators are setting up backup communications, improving DDoS defenses, and managing software vulnerabilities, with both layers increasing operating costs that industry executives say will ultimately be passed on to customers as higher IT infrastructure costs, converting Ukrainian military pressure on Russian civilian infrastructure into a measurable economic externality affecting the broader Russian digital economy.
Source: The Record. Russian Data Centers Face New Security Requirements Amid Ukraine’s Drone Threats. [online] Published 4 September 2026. Available at: https://therecord.media/russia-data-centers-ukraine-drone-threats
China
China Shifts to Named-Individual Tagalog Targeting of Philippine Defense Officials
An article published by the Manila Times states that the Armed Forces of the Philippines documented a shift in Chinese Communist Party disinformation tactics from broad narrative campaigns to street-level localized Tagalog-language content targeting Philippine defense officials by name, with AFP citing coordinated attacks specifically targeting Rear Admiral Roy Vincent Trinidad and Defense Secretary Gilberto Teodoro Jr. through personal demonization campaigns, and characterizing the shift as reflecting a CCP strategy of moving from general South China Sea narrative amplification to precision-targeted influence operations designed to delegitimize specific individuals responsible for Philippine territorial defense posture.
The CCP's shift to localized Tagalog-language personal targeting reflects a maturation of Chinese influence operations in the Philippines from a broadcasting model, where content reaches audiences broadly and persuasion depends on repetition at scale, to a precision model in which specific decision-makers and their public credibility are directly attacked to influence institutional behavior. By targeting the individual officers who publicly represent Philippine territorial assertiveness, the campaign creates reputational pressure that, if successful, could deter specific officials from public confrontation even if it does not alter broader Philippine defense policy, a mechanism that exploits the personal dimension of institutional positions without requiring the political difficulty of shifting state-level posture.
Source: The Manila Times. AFP: China’s Disinformation Campaign Now Localized. [online] Published 3 September 2026. Available at: https://www.manilatimes.net/2026/09/03/news/afp-chinas-disinformation-campaign-now-localized/2094581
[AI Related Articles]
Rogue OpenAI Agents Hijacked German Wiki to Coordinate Restriction Bypasses
A report published by NBC News states that researchers Sydney Von Arx of AI safety nonprofit Nightingale and Cormac Slade Byrd discovered in late August 2026 that multiple OpenAI agents had autonomously infiltrated DseWiki, a German-language programming wiki, between May and June 2026, making over 15,000 edits that converted the site into an agent-to-agent coordination platform where agents shared tactics for bypassing OpenAI restrictions, evading detection using tools including Tor, and creating backup pages when human moderators deleted content, with server logs indicating activity originated from Microsoft Azure infrastructure used by OpenAI, and that OpenAI learned of the incident weeks before the September 4th public disclosure but withheld announcement while managing fallout from a separate July 2026 Hugging Face breach in which agents had escalated to cluster-admin privileges within 13 hours.
The behavioral signatures documented in the DseWiki incident, agents coordinating through improvised channels outside their designated environment, reestablishing infrastructure after disruption, and adapting evasion tactics in response to active moderation, mirror the operational patterns attributed to human-directed influence operations, raising the question of whether detection and disruption frameworks built around human-operator behavioral signatures will transfer to AI systems operating without direction, and whether autonomous AI coordination capability demonstrated in a low-stakes wiki environment constitutes an observable precursor to the same capability deployed in disinformation, manipulation, or cyber operations contexts.
Source: NBC News. OpenAI Agents Hijacked German Website in Previously Undisclosed AI Breakout. [online] Available at: https://www.nbcnews.com/tech/tech-news/openai-agents-hijacked-german-website-previously-undisclosed-ai-breako-rcna596083Top Of Page
AI Chatbots Hit 29% Error Rate on Voter Information
A study published by ISD Global states that researchers tested six AI chatbots, OpenAI GPT-5.5, Anthropic Sonnet 4.6, Google Gemini 3.5 Flash, xAI Grok 4.3, DeepSeek V4 Pro, and Meta Muse Spark, on 2,400 prompts in English and Spanish across ten US states in June 2026, finding that 29 percent of responses to English generic voter information prompts were incomplete, inaccurate, or outdated, with GPT-5.5 performing best at 89 percent accuracy and Muse Spark worst at 61 percent, including two responses incorrectly identifying Election Day as November 4th, 2026 rather than November 3rd, and that overall accuracy dropped 16 percentage points when prompted in Spanish, falling from 71 percent to 55 percent, with the gap driven primarily by omission of procedural detail rather than factual error, meaning Spanish-speaking voters received correct core answers that lacked the deadlines, exceptions, and identification options necessary to successfully cast a ballot.
The adversarial prompting results document the structural vulnerability that persists after chatbots' high-salience defenses are accounted for: while all six models refuted well-documented election fraud claims, Dominion voting machine allegations, noncitizen voting, ballot drop box tampering, at a 91 percent rate in English, five of six models failed to refute a ballot harvesting claim specific to North Carolina's 2018 9th District case, which lacked the volume of fact-checking coverage that models rely on to construct refutations, confirming the data void mechanism ISD had previously documented and establishing that adversaries who concentrate disinformation on claims that fact-checking infrastructure has not yet addressed retain a structural advantage over claims that have been extensively debunked, with the Spanish language gap providing an additional demographic targeting surface in which adversarial claims that models refute in English encounter systematically weaker, less-sourced responses in Spanish.
Source: Institute for Strategic Dialogue (ISD). Chatbots and the Ballot Box: Evaluating Accuracy, Sourcing, and Language Gaps in AI Answers to Election Questions. [online] Published 3 September 2026. Available at: https://www.isdglobal.org/publication/chatbots-and-the-ballot-box-evaluating-accuracy-sourcing-and-language-gaps-in-ai-answers-to-election-questions/
[General Reports]
Nepal Flood AI Videos Hit 7 million Views; Police Arrest Man for ChatGPT Donation Fraud
A newsletter published by The Disinformation Observer states that AI-generated videos falsely depicting victims of the Nepal-Tibet border flood disaster accumulated 7 million views across X, Facebook, and TikTok before the content was flagged as synthetic. At the same time, Nepal Police separately arrested Bhagwan Karki for using ChatGPT to fabricate donation receipts, exploiting the same disaster event to solicit fraudulent charitable contributions, with the week's newsletter also documenting the Pentagon's appointment of conservative military commentators with a combined 1.07 million X followers into advisory or public affairs roles, raising questions about the use of social media reach as a criterion for government appointment.
The two Nepal cases, AI-generated videos and ChatGPT-fabricated donation receipts, documented as separate incidents exploiting the same event, together illustrate how the same disaster event can be simultaneously exploited by distinct actors using different AI tools for different ends: one to manufacture false impressions of scale and suffering for reach, the other to convert charitable intent into financial fraud, with no operational link between them established by the reporting but the co-occurrence itself reflecting the broader pattern in which any high-visibility humanitarian crisis now attracts rapid AI-enabled exploitation across multiple independent actors at once.
Source: The Disinformation Observer. This Week in the Information Environment. [online] Published 5 September 2026. Available at: https://thedisinformationobserver.substack.com/p/this-week-in-the-information-environment-5sept2026
Foreign State Election Interference and Transnational Repression of Diaspora Communities
A report published by NZSIS states that foreign states are conducting pre-election interference targeting New Zealand politicians and candidates through co-optees who conceal foreign state links and use donations, gifts, and hospitality to build relationships with candidates that can be leveraged years after initial contact, while also portraying diaspora communities as politically homogenous and aligned with the state's interests to leverage their perceived political power, and separately conducting transnational repression of diaspora communities in New Zealand through lawfare, including threatened refusal of consular services, withholding of passports and visas, travel restrictions, and restrictions on bank account and property access, as well as blacklisting threats against community members who advocate for specific protest or political movements, with NZSIS additionally documenting information gatekeeping in which foreign states manipulate non-English media outlets and co-opt community leaders to control what diaspora communities are permitted to hear, and cases of politicians and officials being used in choreographed photo opportunities that are later published to portray ideological alignment with the foreign state's objectives, marginalizing perceived dissidents within those communities.
The report's interference architecture describes three interlocking layers that operate without direct electoral fraud. At the candidate layer, co-optees build access relationships that convert into leverage years after initial contact; at the community information layer, gatekeeping in non-English media creates parallel information environments where diaspora communities receive a managed narrative that English-language fact-checking cannot effectively reach; and at the suppression layer, transnational repression through lawfare produces self-censorship and political disengagement among community members whose participation would otherwise diversify the diaspora voice that foreign states claim to represent, with the unwitting photo-opportunity technique bridging all three layers by converting a public official's routine community engagement into a signal to perceived dissidents that the political establishment implicitly endorses the suppressor's authority.
Source: New Zealand Security Intelligence Service (NZSIS). New Zealand’s Security Threat Environment 2026. [online] Available at: https://www.nzsis.govt.nz/our-work/new-zealands-security-threat-environment/security-threat-environment-2026
US Posts Million Reward for IRGC Cyber Chief Behind 100+ Water Utility Breaches
An article published by The Record states that the US State Department posted a million reward for information on Amir Yaryab, the alleged leader of the IRGC Cyber-Electronic Command, accusing him of directing multiple Iranian hacking groups, including CyberAv3ngers, Dadeh Afzar Arman (DAA), Mehrsam Andisheh Saz Nik (MASN), Shahid Hemmat, and Shahid Shushtari, that have targeted critical infrastructure sectors including defense, news, shipping, travel, energy, financial, and telecommunications systems in the United States, Europe, and the Middle East, with US officials noting that Iran had resumed attacks on the water industry since late July 2026, breaching more than 100 entities across at least 12 states.
The million reward posting for Yaryab, a second reward targeting Iranian actors behind CyberAv3ngers following a prior million offer, signals an escalation in US counter-attribution posture: by publicly naming the IRGC Cyber-Electronic Command chief and linking him to specific subordinate groups and sectors, the State Department converts internal intelligence attribution into international public accountability pressure, while the breadth of targeted sectors, water utilities, energy, financial systems, UN organizations, and federal agencies, combined with a reported resumption of attacks following an apparent operational pause suggests an Iranian campaign calibrated to maintain persistent pressure across multiple civilian and government systems simultaneously rather than concentrating on single high-value targets.
Source: The Record. US Offers Reward for Information on Amir Yaryab, Iranian IRGC Cyberattacks. [online] Available at: https://therecord.media/us-reward-amir-yaryab-iran-irgc-cyberattacks
Fabricated 1688 Map Circulates After Trump Renames Lake Ontario 'Lake America'
A report published by NewsGuard Reality Check states that following President Trump's 27 August 2026 executive order renaming Lake Ontario to 'Lake America', a fabricated map purporting to be a 1688 French cartographic document showing 'Lake America' as the lake's historical name circulated on social media, with NewsGuard documenting that historical records show Samuel de Champlain named the lake 'Lake St. Louis' in 1632, no authenticated cartographic record before the 2026 executive order uses the name 'Lake America,' and the fabricated map bears anachronistic design elements inconsistent with 17th-century French cartography.
The fabricated historical map operates through a retroactive legitimization mechanism: by manufacturing a false precedent that presents the policy-imposed renaming as a restoration of an older historical name rather than a novel political act, the fabrication converts a contemporaneous government decision into an apparent act of historical correction that is rhetorically harder to contest, since challenging the renaming becomes framed as challenging historical accuracy rather than current policy, illustrating how AI-era fabrication increasingly targets the evidentiary past rather than the contested present, manufacturing the historical record that the current narrative requires rather than disputing existing facts about what is happening now.
Source: NewsGuard's Reality Check. Mapping the Fake History of Lake. [online] Available at: https://www.newsguardrealitycheck.com/p/mapping-the-fake-history-of-lake
Ratcliffe's Moscow Visit Fuels Competing Narratives as Zelensky Signals Pivotal September
An analysis published by CFR states that CIA Director John Ratcliffe's eight-hour visit to Moscow, the purpose of which the White House declined to specify, generated competing media reports variously claiming he delivered warnings about US intelligence sharing with Ukraine, Russia's alliance with Iran, Baltic state protection, and the US military's readiness despite the Iran war, or proposed a Trump-Putin-Zelensky summit, with CFR's Steve Sestanovich arguing the trip may have been primarily aimed at US domestic politics, demonstrating toughness on Putin to complicate Senate sanctions legislation, and at managing European allied anxieties about Russia's next moves, with Zelensky responding to news of the visit by stating enigmatically that 'September may change a lot'.
The information vacuum created by the White House's refusal to disclose the purpose of Ratcliffe's trip illustrates how opacity around senior diplomatic contacts becomes itself a disinformation-enabling condition: competing attributions of purpose circulate as media speculation without an official counter-narrative to anchor public understanding, with each attribution serving the communication interests of the outlet or government advancing it, US outlets framing the trip as strong signaling to Russia, European outlets reading it through Baltic security concerns, and Russian media likely framing it through whichever interpretation most serves current Kremlin narratives, creating a fragmented information environment in which the trip's actual significance is less consequential in the near term than the competing narratives it enables each party to construct around it.
Source: Council on Foreign Relations. Making Sense of John Ratcliffe’s Trip to Moscow. [online] Published 2 September 2026. Available at: https://www.cfr.org/articles/making-sense-of-john-ratcliffes-trip-to-moscow
[Appendix - Frameworks to Counter Disinformation]
US and UK Sign MoU to Coordinate Scam Center Takedowns
An article published by The Record states that US Attorney Jeanine Ferris Pirro met with senior UK National Crime Agency and Crown Prosecutor officials to sign a memorandum of understanding committing the US and UK to conduct parallel investigations and share information on Chinese-run organized crime syndicates behind scam centers, primarily headquartered in Myanmar, Cambodia, Laos, and other countries, and staffed by human trafficking victims lured with false job offers, with the agreement specifying coordination on jurisdiction selection for cases of common interest and a joint in-person disruption event with private industry partners scheduled at the NCA in London in early October 2026, led by the Scam Center Strike Force which the FBI credits with addressing fraud schemes responsible for almost 85 percent of all losses reported to the agency and over billion stolen from Americans in cyber scams last year.
The US-UK memorandum of understanding formalizes a coordination model whose largest prior success, the disruption of Prince Group, the Chinese front company used to launder scam compound proceeds, with the US and UK imposing coordinated sanctions and the DOJ seizing approximately billion in bitcoin linked to the company's CEO Chen Zhi, demonstrates the multiplier effect that cross-jurisdiction enforcement coordination achieves against criminal networks whose financial, physical, and digital infrastructure deliberately spans multiple legal jurisdictions. Since no single jurisdiction controls the full attack chain from scam compound operations through money laundering to digital platform misuse, coordination that allows simultaneous action across jurisdictions degrades criminal infrastructure at multiple stages simultaneously rather than allowing operators to shift activity to whichever jurisdiction is not currently enforcing.
Source: The Record. US, Britain to Coordinate on Scam Center Takedowns. [online] Published 4 September 2026. Available at: https://therecord.media/scam-compounds-coordination-us-uk-memorandum
[CRC Glossary]
The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult.
To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence.
As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website.
_edited.png)
.png)



