top of page

Cyber based influence campaigns 7th – 13th September 2026 Report

11 minutes ago
25 min read
Cover Image- Text: Weekly Media Update: Information Operations


[Introduction]


Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW).

Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. 

Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. 

We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc.

During the 7th September – 13th September 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities.



[Contents]





Russia 

China






[ Report Highlights]


  • Russia's Matryoshka operation expanded from European elections to the 2026 US midterms, deploying voice-cloned videos of five Hollywood celebrities in counterfeit CNN broadcasts targeting Democratic Senate candidates in Georgia, Ohio, and New Hampshire.

  • Russia's hybrid operations in Northern Europe intensified in September 2026, combining DDoS attacks on critical infrastructure with undersea cable sabotage and drone airspace violations against Sweden, Finland, Denmark, and Estonia.

  • Anthropic's September 2026 threat intelligence report documented nine disrupted influence operations and additional cases spanning cyber, surveillance, and conventional weapons, including likely freelance Russia-based actors who used Claude Code to build an autonomous kamikaze drone swarm capable of selecting and killing individual targets without human authorization, and a MEK/NCRI operation that cloned a real Iranian activist's Telegram identity to hold live conversations with his contacts inside Iran.

  • Russia exploited the September 5th – 8th ceasefire to fabricate claims that Ukraine staged its own SBU headquarters drone strike and spread a fake Polish newspaper front page claiming 63 percent of Ukrainians faced famine because of Russian attacks.

  • A NATO Strategic Communications Centre of Excellence study analyzed 3.13 million Russian media items and identified an 18-hour window after unexpected crises during which Russia's propaganda system lacks a coordinated official line, the most feasible moment for counter-narrative intervention.

  • CCP influence operations across Facebook, Instagram, YouTube, TikTok, Reddit, and X used AI-generated personas to deepen US societal divisions ahead of the November 2026 midterms without advancing any single political objective.

  • The Center for an Informed Public and the Brennan Center independently characterized the 2026 midterm environment as qualitatively more dangerous than prior cycles, with sitting leadership repeating long-debunked election fraud claims and AI reducing the cost of targeted false-content generation to near zero.

  • Anthropic's head of threat research Jacob Klein warned that current low engagement scores on disrupted influence campaigns understate the trajectory risk, predicting higher-breakout AI influence operations in the near or medium future as AI systems become better at chaining tasks and more persuasive.

  • An ISD framework report documented that hostile state hybrid operations and extremist violence are converging in Europe on the same youth recruitment infrastructure - Telegram and Snapchat gig-economy hiring, with UK minors now representing nearly one-fifth of terrorism arrests, four times the proportion of a decade ago, and MI5 disclosing more than 20 potentially lethal Iran-backed plots since 2022.

  • A coordinated network of 23 deceptive websites promoting Alberta separatism was engineered specifically to be cited by AI chatbots, granting crawl access to ChatGPT, Claude, Perplexity, Google, and Common Crawl via llms.txt files and backdating content to simulate established provenance, representing the first documented influence operation in this report's editorial period to target AI retrieval infrastructure rather than human audiences as its primary mechanism; attribution remains unknown.

[ Report Summary]

  • Detector Media reported that Russia is conducting the most aggressive hybrid operations in Northern Europe through combined DDoS attacks, undersea cable sabotage, drone airspace violations, and disinformation campaigns, with Sweden's Security Service disclosing in August 2026 that it disrupted a Russian intelligence operation aimed at deepening divisions over key controversial domestic issues.

  • ms.now reported that Russia's Matryoshka operation, also known as Storm-1679, deployed voice-cloned videos of Julia Roberts, Sarah Jessica Parker, and three other Hollywood celebrities in counterfeit CNN broadcasts linking Democratic Senate candidates in Georgia, Ohio, and New Hampshire to fabricated conspiracy claims, with security researcher Darren Linvill characterizing the campaign as Russia's opening salvo ahead of November's midterms.

  • Euromaidanpress documented that Russian propagandists doctored the front page of genuine Polish regional weekly PrzeglÄd Regionalny to falsely claim that Russian strikes would push 63 percent of Ukrainians toward starvation, with Ukraine's Center for Countering Disinformation confirming the fabrication and noting the campaign exploited real destruction of up to 90 percent of Ukraine's modern food storage capacity.

  • Detector Media's weekly review of Russian disinformation documented that propagandists falsely claimed Ukraine staged the September 4 drone strike on its own SBU headquarters to justify future attacks on Russian civilian aircraft, combining edited Zelensky statements with verified footage of the attack, debunked by Reuters and the Associated Press, alongside fabricated claims about Poland and Ukraine's Dniester River in what the review assessed as a campaign to shift responsibility for Russian attacks onto Ukraine.

  • YourNews analyzed how CCP influence operations on Facebook, Instagram, YouTube, TikTok, Reddit, and X use AI-generated profile images, demographic impersonation, and coordinated inauthentic behavior to deepen US societal divisions - including a DOJ-documented network of 34 Ministry of Public Security officers creating thousands of fake accounts, and a Meta-dismantled Spamouflage network of over 7,700 Facebook accounts.

  • Resemble AI's Deepfake Watchlist for August 28th to September 3rd, 2026 documented AI-generated Nepal-Tibet flood disaster videos spreading before fact-checkers could respond, xAI's Grok generating approximately 3 million sexualized images in 11 days including roughly 23,000 apparently depicting children, and only 244 deepfake-related arrests across all of 2026, against a verified dataset of over 821 documented attacks and 3.46 million synthetic files.

  • Anthropic's September 2026 threat intelligence report documented nine disrupted influence operations spanning six continents between December 2025 and August 2026, originating from Russia, Iran, Turkey, the UAE, and across South Asia, Africa, and Europe, with actors including a Russian-aligned radio station in the Central African Republic coordinated with RT and Sputnik, a France-based commercial influence-for-hire firm, an Istanbul-based platform targeting Malaysian electoral constituencies by race and religion using real census data, and a MEK/NCRI-aligned operation that cloned a real Iranian activist's Telegram identity to hold live conversations with his contacts inside Iran.

  • Politico reported on Anthropic's September 2026 threat intelligence disclosure, with Anthropic head of threat research Jacob Klein warning that bad actors using multiple AI models simultaneously will be harder to disrupt and that higher-breakout AI influence operations are expected in the near or medium future, while Atlantic Council senior fellow Katerina Sedova cautioned that the effectiveness conversation obscures the fact that foreign actors will continue trying regardless of current low-engagement results.

  • Defense One reported that Anthropic's September 2026 threat intelligence report documented likely freelance Russia-based actors (GTG-27005) who used Claude Code to build a full-stack autonomous FPV kamikaze drone swarm capable of selecting targets including individual people.

  • The University of Washington's Center for an Informed Public characterized the 2026 midterm disinformation environment as more structurally dangerous than prior cycles, citing three compounding factors: ongoing election denialism by sitting leadership, a matured infrastructure for spreading false claims, and institutional uncertainty around mail-in voting combined with threatened federal interference in election administration.

  • The Brennan Center for Justice documented that President Trump has recently repeated five categories of long-debunked election fraud claims ahead of the 2026 midterms, covering noncitizen voting, mail ballot security, voting machine vulnerability, poll worker misconduct, and sudden vote count shifts, characterizing each as a 'tired rumor' whose cyclical recurrence makes advance public familiarity the primary countermeasure.

  • The Institute for Strategic Dialogue documented growing convergence between hostile state hybrid operations and extremist violence in Europe, with both using the same gig-economy recruitment platforms and targeting minors - illustrated by an Iran-linked 'ghost proxy' group conducting arson, embassy shootings, and stabbings across Europe and Canada in March-April 2026, ISD's Authoritarian Interference Tracker recording 188 Russia-linked incidents since February 2022 with 1,100 Ukrainian proxies of whom 240 were minors, and UK minors now representing nearly one-fifth of terrorism arrests, four times the proportion of a decade ago.

  • DisinfoWatch documented a coordinated network of 23 deceptive websites promoting Alberta separatism, exposed by Canada's National Observer on September 4 and independently confirmed by VIGIL Strategic Intelligence, which found all 23 domains on a single server with scripted batch registration and three synchronized automated configuration processes, with the sites engineered specifically to be cited by AI chatbots through llms.txt files and open crawl access granted to ChatGPT, Claude, Perplexity, Google, and Common Crawl, alongside a separate Russian campaign portraying Zelensky's Canada visit as taxpayer-funded handouts and amplifying Nazi-collaborator allegations against Ukrainian-Canadian communities.

  • A NATO Strategic Communications Centre of Excellence study analyzing 3.13 million Russian media items over 15 months identified that Russia's propaganda system operates without an official coordinated line for an average of 18 hours after unexpected crises, during which competing narratives circulate and fact-based intervention remains feasible, before the Kremlin establishes control and all state channels simultaneously adopt a unified message absorbed into anti-Western ideological framing.

[State Actors]



Russia

Russia Escalates Hybrid Attacks on Northern European Infrastructure

A report published by Detector Media states that Russia and China are conducting intensifying hybrid operations against Sweden, Finland, Denmark, Estonia, and the broader Baltic-Scandinavian region, with Russia's campaign being the most aggressive and employing a combination of DDoS attacks against critical infrastructure, recruitment of third-country embassy staff for intelligence operations, deliberate sabotage of undersea communication cables, airspace violations using drones, and disinformation campaigns specifically designed to deepen divisions over key controversial political issues, with Sweden's Security Service confirming in August 2026 that it disrupted a Russian intelligence operation whose explicit aim was to exploit and amplify Swedish domestic political controversies, while China simultaneously conducts digital espionage and maintains control over diaspora communities across the same region.


The coordinated nature of Russian and Chinese hybrid operations against NATO's Northern European flank, with Russia providing kinetic and cyberattack capacity while China conducts espionage and diaspora-control operations, reflects a division of effort within the broader Sino-Russian strategic alignment that allows each state to concentrate on its relative comparative advantage: Russia's established intelligence and sabotage infrastructure against state institutions, and China's longer-horizon infiltration of civil society and diaspora networks, with the combined effect that NATO member states face simultaneous pressure at the physical infrastructure, political, and societal layers from two actors whose operations are functionally complementary even where they are not formally coordinated, a threat architecture that Article 5 doctrine, designed around state-level kinetic attack, was not built to address.


Source: Detector Media. Hidden Threat: How a New Front of Hybrid Warfare Is Unfolding in Northern Europe. [online] Available at: https://en.detector.media/post/hidden-threat-how-a-new-front-of-hybrid-warfare-is-unfolding-in-northern-europe


Matryoshka Targets 2026 US Midterms with Voice-Cloned Celebrity Videos

An article published by ms.now states that Russia's Matryoshka influence operation, also tracked as Storm-1679, has deployed synthetic videos fabricating statements by Julia Roberts, Sarah Jessica Parker, Emma Caulfield, Christopher Lloyd, and Ed Begley Jr. using voice-cloning technology applied to source footage from Gucci campaigns and Cameo personalized videos, with the resulting clips wrapped in counterfeit CNN branding and linking Democratic Senate candidates Jon Ossoff (Georgia), Sherrod Brown (Ohio), and Chris Pappas (New Hampshire) to inflammatory false narratives involving transgender agendas, child exploitation, and corruption, distributed across X, Bluesky, and TikTok, with the campaign first detected by anonymous research group @antibot4navalny.


Despite currently low engagement metrics, the Matryoshka US midterms operation's structural characteristics, targeting celebrity voices whose audiences span political demographics rather than partisan-aligned figures, using counterfeit major media branding to supply apparent mainstream credibility, and selecting Senate races in competitive states whose outcomes determine chamber control, are consistent with a preparation-phase operation designed to build narrative infrastructure ahead of the final months of the campaign rather than achieve immediate viral reach, a pattern Linvill's characterization as an 'opening salvo' reflects directly, and which is analytically consistent with Matryoshka's documented early-launch strategy in France, Germany, and Romania where the operation seeded content months before the decision period when audiences were most susceptible to influence.


Source: MS NOW. Russia Election Influencing Campaign Targeting Democrats. [online] Available at: https://www.ms.now/news/russia-election-influencing-campaign-targeting-democrats


Russian Propagandists Use Fake Polish Newspaper to Spread Ukraine Famine Claim

A report published by Euromaidanpress states that Russian propagandists digitally altered the front page of PrzeglÄd Regionalny, a genuine Polish regional weekly, to insert a fabricated headline claiming Russian military strikes would push 63 percent of Ukrainians toward starvation during a 'hungry autumn and winter,' with Ukraine's Center for Countering Disinformation exposing the fabrication after confirming that the authentic front page of the publication looked entirely different from the doctored version being distributed, and that the false image spread through Matryoshka. This disinformation network disguises invented content as reporting from recognized Western outlets to supply an appearance of independent foreign corroboration.


The fabrication's strategic logic exploits a real and documented condition, Russia's destruction of up to 90 percent of Ukraine's modern food storage capacity, to manufacture a false and catastrophic causal conclusion not supported by official projections. This technique makes the disinformation more resistant to simple debunking because the underlying premise (large-scale food infrastructure destruction) is confirmed, requiring audiences to distinguish between the documented destruction and the unsupported prediction of mass starvation layered on top of it; by routing the fabrication through an impersonated Polish outlet rather than a Ukrainian or Russian source, the operation simultaneously targets Ukrainian domestic morale and Polish-Ukrainian relations, exploiting the geopolitical sensitivity of a neighboring state's voice to make the claim appear more credible and harder to attribute to Russian origin.


Source: Euromaidan Press. Russian Propagandists Fake Polish Newspaper Claiming Ukraine Faces Famine. [online] Published 2 September 2026. Available at: https://euromaidanpress.com/2026/09/02/russian-propagandists-fake-polish-newspaper-ukraine-famine/ 


Russia Fabricated SBU Staging Claim to Deflect Blame for Drone Strike

A review published by Detector Media states that Russian propagandists fabricated the claim that Ukraine staged the September 4th, 2026 drone strike on its own SBU headquarters, verified as a genuine Russian attack by Reuters and the Associated Press, by combining distorted excerpts from Zelensky's earlier statements about airspace safety with footage of the actual documented strike to construct a conspiracy narrative asserting that Ukraine orchestrated the attack to justify subsequently targeting Russian civilian aircraft, with the review also documenting fabrications claiming Ukraine artificially disrupted the Dniester river to cause a Moldova water catastrophe and that Polish-supplied Patriot missiles detonated in a Ukrainian ammunition depot strike.


The SBU staging fabrication exemplifies a structurally distinctive disinformation technique: rather than denying that the event occurred, Russian propagandists acknowledged the strike but reframed its cause and attribution to convert a documented Russian attack into evidence of Ukrainian aggression, a technique that is more resistant to simple factual correction because debunking requires not only confirming the event happened - which Russian propagandists concede - but also disproving the fabricated causal narrative layered over it, placing a higher cognitive burden on audiences who must process two distinct claims rather than one; additionally, by framing Ukraine as willing to attack its own institutions to manufacture justifications for strikes on civilian targets, the fabrication attempts to preemptively delegitimize any future Ukrainian defensive responses by casting the victim as the aggressor before those responses occur.


Source: Detector Media. “Ukraine Attacked the SBU Headquarters Itself.” Review of Russian Fakes from August 2–8, 2026. [online] Published 11 September 2026. Available at: https://en.detector.media/post/ukraine-attacked-the-sbu-headquarters-itself-review-of-russian-fakes-from-august-2-8-2026


Russia-Linked Team Builds Autonomous Drone Swarm

An article published by Defense One states that Anthropic's September 2026 threat intelligence report identified likely freelance Russia-based actors (GTG-27005) who used Claude Code to build a full-stack autonomous first-person-view kamikaze drone swarm, operation-named 'DronDoc' or 'Serafim,' comprising shared swarm memory with fault-tolerant coordination logic, an onboard small language model governing attack-observe-return behaviors, terminal guidance software steering drones to their target via onboard camera and issuing the call to detonate, a control-link geolocation module to find opposing drone operators, and a passive acoustic detection layer, with the onboard model designed to select targets including a 'person' target class and issue detonation commands without a human in the loop, the computer vision classifier trained on scraped Ukrainian combat footage splitting targets into 'enemy' and 'friendly' classes with Russian systems allow-listed, a fixed coordinate in Donetsk Oblast as the demonstration strike point, and hardware-in-loop testing confirmed on real development boards at TRL 3-4, while separately the Russian-attributed Midnight Blizzard group (GTG-20006) used Claude to automate every phase of their espionage kill chain against more than 20 Ukrainian and European government, military, diplomatic, and defense-industrial targets, including bulk-exporting mailboxes of drone component manufacturers and stealing a complete proprietary drone vision SDK, compromising three hotel WiFi networks via DNS hijacking to deliver malware to guests associated with Ukraine, and exfiltrating more than 300,000 national identity records from a North African government.


Anthropic's assessment that GTG-27005 represents likely freelance actors, a small specialized team with claimed ties to a Russian university research center and asserted funding from Russia's Advanced Research Foundation and Ministry of Defence, neither of which Anthropic verified, places autonomous drone-AI at TRL 3-4 within reach of non-state actors rather than only state defense programs: when a commercially available AI coding tool substitutes for the full software engineering workforce required to build autonomous terminal guidance, swarm coordination, and person-classification firmware, the barrier separating individual-operator capability from state weapons programs collapses at the development layer even if hardware procurement and operational deployment gaps remain; this is structurally distinct from the GTG-20006 Midnight Blizzard case, which represents a state actor using the same class of tools to achieve full automation of an espionage kill chain that previously required large specialized operator teams, the two cases document AI capability democratization at both the freelance and state ends of the actor spectrum simultaneously, consistent with Anthropic's finding that 'sophistication has stopped being a reliable signal of who is behind an operation'.


Source: Defense One. Russia Is Weaponizing US-Built AI to Make Killer Drones, Cyberattack Bots, and Fake News. [online] Published 11 September 2026. Available at: https://www.defenseone.com/technology/2026/09/russia-weaponizing-us-built-ai-make-killer-drones-cyberattack-bots-and-fake-news/415949/


China

CCP Influence Operations Use AI Personas to Fragment US Audiences

An analysis published by YourNews states that Chinese Communist Party influence operations targeting American social media users span Facebook, Instagram, YouTube, TikTok, Reddit, and X, employing tactics including a 2023 DOJ-charged '912 Special Project Working Group' of 34 Ministry of Public Security officers who created thousands of fake accounts to harass Chinese dissidents, attack CCP critics, and spread propaganda, a Meta-dismantled Spamouflage network comprising over 7,700 Facebook accounts, 954 pages, 15 groups, and 15 Instagram accounts operating as a coordinated inauthentic behavior network, and AI-enabled impersonation generating profile photographs, articles, videos, and audio recordings within minutes to allow individual operators to maintain multiple accounts posing as distinct demographic segments.


The operational objective documented across CCP influence activity on US platforms, amplifying approved narratives, drowning out unfavorable information, and creating confusion rather than pursuing any single political objective, reflects a strategic preference for fragmenting audience coherence over achieving specific persuasion outcomes, a goal that is structurally better suited to influencing polarization and undermining institutional trust than to winning discrete electoral contests: because confusion and distrust are self-reinforcing once established, a campaign optimized for fragmentation achieves persistent effects from individual operations that need not succeed in persuading anyone of any specific claim, making it more resilient to factual debunking than operations built around single falsifiable narratives.


Source: YourNews. Is That Account Real? CCP Influence Operations Are Exploiting America’s.... [online] Published 9 September 2026. Available at: https://yournews.com/2026/09/09/7190156/is-that-account-real-ccp-influence-operations-are-exploiting-americas/


[AI Related Articles]


AI Disaster Footage Outruns Fact-Checkers as Deepfake Arrests Lag Generation Scale

A watchlist published by Resemble AI states that the week of August 28th to September 3rd, 2026 saw AI-generated videos falsely depicting flood disaster victims from the Nepal-Tibet border, confirmed as synthetic by Factly, SBS, The Journal, and Yahoo News, spread across social media before professional fact-checkers could flag the content, while separately xAI's Grok language model generated approximately 3 million sexualized images within 11 days including roughly 23,000 apparently depicting children, a 'Cat in the Hat'-themed threat campaign using AI-generated content spread across TikTok and Snapchat affecting six US states, and the watchlist's tracking of enforcement activity found only 244 deepfake-related arrests across all of 2026 despite a verified dataset for the first half of the year already documenting 821 attacks, at least 15,736 victims, and 3.46 million synthetic files.


The enforcement gap documented in the watchlist, 244 arrests against 821 verified attacks, a ratio of roughly 1 arrest per 3.4 confirmed cases, itself almost certainly an undercount of total incidents, reflects a structural misalignment between the generation-layer capacity of synthetic media tools, which has industrialized at AI-computing speed, and the detection and enforcement infrastructure, which operates at institutional and legal speed: Resemble AI's conclusion that generation-layer watermarking and provenance infrastructure represent the critical intervention point follows directly from this asymmetry, since detection-after-distribution cannot match viral spread during breaking events when synthetic disaster footage competes directly with authentic emergency information and the correction, as the Nepal case illustrates, arrives after the damage is done.


Source: Resemble AI. The Deepfake Watchlist: Week of August 28 – September 3, 2026. [online] Published 3 September 2026. Available at: https://www.resemble.ai/resources/the-deepfake-watchlist-week-of-august-28-september-3-2026


Anthropic Disrupts Nine IO Campaigns as AI Collapses State-Nonstate Capability Gap

A report published by Anthropic states that its threat intelligence team identified and disrupted nine influence operations between December 2025 and August 2026, targeting audiences on six continents and originating from Russia, Iran, Turkey, and across the Gulf, South Asia, Africa, and Europe, including a Russian-speaking actor in Bangui running a daily foreign information manipulation operation through Radio Lengo Songo on 98.9 FM, coordinated with RT, Sputnik, and TASS and disguised as ordinary Central African national programming, assessed as linked to Politology, the Africa Corps/Wagner influence branch under SVR control; a France-based digital advertising agency, LKM Company, that mass-produced content across approximately 70 fabricated news sites in about 20 languages, shifting political stances based on whoever was paying; an Istanbul-based technology firm, BBS Bilisim Teknolojileri, that built a 'military-grade, AI-driven, real-time political operations ecosystem' using real census and electoral data to micro-target all 222 Malaysian parliamentary constituencies across race, religion, and royalty faultlines with roughly 1,000 fake accounts and a fabricated news outlet called Malaysia Pulse; and a distributed MEK/NCRI-aligned operation that cloned a real Iranian activist's Telegram identity by reading approximately 8,400 of his messages to copy his writing style, then ran live political conversations with his contacts inside Iran without their knowledge, using a shared persistent-memory agent platform named 'Viktor' to coordinate across operators.


The report's finding from its cyber operations section, that 'sophistication has stopped being a reliable signal of who is behind an operation', applies equally across the nine IO cases: because Claude can replace the editorial workforce, persona-creation pipeline, doctrine-drafting capacity, and attribution-laundering infrastructure that previously distinguished well-resourced state programs from low-capacity actors, the labor intensity that once functioned as a proxy for state resources has been compressed to a software configuration, meaning the MEK/NCRI network, which maintained committee approval loops, a formal content-corrector-to-manager review chain, and cross-actor shared doctrine inside a persistent agent platform, achieved person-level live impersonation of a real activist maintained in live conversations with his known contacts inside Iran, a capability pattern previously confined to intelligence services with full identity-exploitation teams, while a single actor in Bangladesh's Gaibandha District ran a semi-autonomous fake news operation through 29 rotated Claude accounts generating at least 1,500 fabricated headlines, 300 false narratives, and 1,500 image prompts for rural audiences with limited literacy.


Source: Anthropic. Detecting and Countering Misuse of AI: September 2026. [online] Published September 2026. Available at: https://www.anthropic.com/threat-intelligence-report-september-2026


Anthropic Threat Chief Warns Higher-Breakout AI Influence Campaigns Are Coming

A report published by Politico states that Anthropic's nine disclosed influence operations all scored between two and four on the breakout scale, a six-category framework measuring the reach of influence campaigns, with most AI-generated content drawing little or no authentic engagement before being detected, but Jacob Klein, Anthropic's head of threat research, cautioned that bad actors could use multiple AI models simultaneously making campaigns harder to disrupt, and that AI systems are 'becoming increasingly persuasive' and 'increasingly good at chaining together tasks so you can execute your operations faster', with Klein expressing the suspicion that 'we will see higher breakout scales of AI-led [influence operations] at some point in the near or medium future', while also clarifying that none of the nine influence operation incidents involved Claude Mythos, Anthropic's most powerful model, which is restricted to trusted partners mostly in the United States.


Atlantic Council senior fellow Katerina Sedova, who worked on the State Department's counter-Russian-disinformation efforts during the Biden administration, identified a structural flaw in how the effectiveness of AI influence operations is currently measured: her observation that 'the impact is not very measurable from an empirical standpoint because you can't connect someone's exposure to action' explains why the low current breakout scale scores (2-4) and minimal authentic engagement data documented across Anthropic's, OpenAI's, and X's disrupted operations systematically underestimate the threat - they measure reach and conversion from individual campaigns rather than the cumulative effect of repeated cross-platform narrative seeding, the normalization of disinformation frames in information spaces over time, or the institutional resource cost that democratic counter-operations teams must absorb continuously regardless of whether any individual campaign achieves breakout, and Sedova's call for a better metric directly echoes Klein's forward projection: the question is not whether current operations are effective by existing metrics but whether the trajectory Klein identifies, AI systems increasingly chaining tasks and becoming increasingly persuasive, will outpace metric development before defenders can measure what they are defending against.


Source: POLITICO. Foreign Actors Turn to Claude for Influence Operations. [online] Published 10 September 2026. Available at: https://www.politico.com/newsletters/politico-influence/2026/09/10/foreign-actors-turn-to-claude-for-influence-operations-01071431


[General Reports]


2026 Midterm Disinformation Environment More Dangerous Than Prior Cycles

An analysis published by the Center for an Informed Public states that the 2026 midterm disinformation environment is shaped by three compounding structural factors; ongoing election denialism including by sitting leadership who continue repeating long-debunked claims about election integrity, a matured false-claim distribution infrastructure that has professionalized and scaled since 2020, and institutional uncertainty around mail-in voting procedures combined with what the CIP characterizes as threatened federal interference in election administration, with the center warning that short-form video and new social media platforms represent emerging disinformation vectors that fact-checking infrastructure has not yet adequately addressed.


The CIP's characterization of 'election denialism by sitting leadership' as a structural condition rather than an episodic event marks a qualitative shift in the disinformation threat model for the 2026 midterms: in prior cycles, electoral disinformation about procedural legitimacy typically originated primarily from external actors or fringe domestic figures and required distribution infrastructure built or rented by the campaign, whereas in the current cycle, the same narratives originate directly from the executive branch and are amplified through official communications channels, fundamentally altering the counter-disinformation response calculus because debunking official sources involves institutional credibility trade-offs that debunking external actors does not, and because official repetition of false claims accelerates their integration into segments of the electorate that had previously not been exposed to them.


Source: Center for an Informed Public. CIP Election Rumor Research: 2026 Midterms. [online] Published 3 September 2026. Available at: https://www.cip.uw.edu/2026/09/03/cip-election-rumor-research-2026-midterms/


Trump Repeating Five Long-Debunked Election Rumors Before Midterms

An analysis published by the Brennan Center for Justice states that five categories of false election claims, noncitizen voting, mail ballot insecurity, voting machine vulnerability to attack, poll worker misconduct, and false allegations of sudden fraudulent vote count shifts - have recently been repeated by President Trump ahead of the November 2026 midterms, with the Brennan Center documenting each as a long-debunked narrative that has circulated since at least 2020 and characterizing the cycle as predictable enough that voters who familiarize themselves with these categories before the election will be better positioned to identify and discount them when the claims re-emerge during the final weeks of the campaign.


The Brennan Center's framing of these five claim categories as 'tired rumors' that are reliably predictable rather than emerging narratives reflects a strategic counter-disinformation decision: by establishing the categories in advance and attributing them to the sitting president by name, the analysis attempts to inoculate audiences against future exposure through pre-emptive labeling, a technique whose effectiveness depends on whether audiences who read the pre-election warning are the same audiences who will later encounter the claims, which is structurally uncertain given that the demographic overlap between Brennan Center readership and the segments of the electorate most susceptible to election integrity disinformation is likely limited, suggesting the primary value of the analysis is in providing journalists and election officials with a documented reference framework rather than directly reaching the at-risk population.


Source: Brennan Center for Justice. Five False Election Rumors to Watch For. [online] Published 13 March 2023. Available at: https://www.brennancenter.org/our-work/analysis-opinion/five-false-election-rumors-watch 


Hostile States and Extremist Networks Converging on Youth Recruitment in Europe

A report published by ISD states that hostile state hybrid operations and extremist violence are increasingly convergent across Europe in methodology, target audience, and online infrastructure, with both phenomena using Telegram and Snapchat for 'gig economy'-style recruitment of young people who receive financial incentives to complete low-risk tasks including surveillance, arson, and vandalism and record proof of completion, with UK minors aged 17 and under constituting nearly one-fifth of terrorism-offence arrests in 2023, four times the proportion of a decade ago, and EU data showing over 29 percent of those arrested for terrorism offences in 2024 were minors, while the shared ideological surface includes antisemitism, misogyny, anti-migrant hate, and conspiracy theories, and UK Counter Terrorism police report state threat cases now exceed 20 percent of casework, MI5 has seen more than 20 potentially lethal Iran-backed plots since 2022, and Germany established a Joint Centre for the Defence Against Hybrid Threats in June 2026, with the report's Iran case study documenting a group calling itself Harakat Ashab al-Yamin al-Islamiya (the Islamic Movement of the Companions of the Right) that conducted a wave of arson attacks, drive-by shootings at embassies, and stabbings across Europe and Canada between March and April 2026, targeting primarily Jewish and Iranian dissident communities, which ISD assessed as a 'ghost proxy' established purely to claim attacks and allegedly orchestrated by Muhammad Baqer al-Saadi, a high-ranking member of the IRGC-backed Iraqi militia Katai'b Hezbollah, who used Snapchat to communicate via third-party intermediaries and organised criminal networks to carry out 'violence-as-a-service' attacks - and the Russia case study drawing on ISD's Authoritarian Interference Tracker, which documented 188 incidents linked to Russia targeting European and North American democracies since February 2022, with authorities reporting that 1,100 Ukrainians have acted as Russian proxies in sabotage, arson, and bombings, of whom approximately 240 (around one in five) were minors, most were financially motivated, and around half were unemployed, illustrated by the May 2025 conviction of Roman Lavrynovych, a 22-year-old Ukrainian construction worker in London who carried out arson attacks targeting properties linked to former Prime Minister Keir Starmer after being recruited via Telegram by a Russian-speaking handler and paid in cryptocurrency - with the UK's National Security (State Threats) Act subsequently designating both Harakat Ashab al-Yamin and the GRU Volunteer Corps, the EU designating the IRGC as a terrorist organisation, and the UK's Rycroft Review prompting a ban on cryptocurrency donations in March 2026.


The ISD framework's central analytical contribution, drawing on a UK-Germany roundtable co-hosted with the Konrad Adenauer Stiftung's UK and Ireland Office in June 2026, is the distinction between convergent threat surfaces and divergent actor architectures; while extremist organizations build ideological commitment in recruits as both a selection mechanism and a force multiplier, hostile state hybrid operations deliberately recruit untrained, ideologically uncommitted proxies through criminal networks, whose value is precisely their dispensability and the plausible deniability they provide to the sponsoring state, as the Lavrynovych case demonstrates, where the recruit was a drug dealer with no prior political alignment, meaning that counter-terrorism prevention frameworks built around ideological radicalization pathways do not transfer cleanly to the hybrid-threat population, since a teenager recruited via Snapchat to vandalize a substation for payment has no ideological profile to detect, no extremist network to map, and no radicalization trajectory to interrupt, requiring a whole-of-society prevention architecture addressing economic and social vulnerability rather than belief systems, and simultaneously requiring legal frameworks that distinguish state-directed criminality from terrorism, a distinction with significant implications for which agencies lead the response, since the same individual may fall simultaneously under national security law, criminal law, and counter-extremism programming without any single framework having full jurisdiction.


Source: Institute for Strategic Dialogue (ISD). Lessons in Extremism Prevention for Countering Hybrid Threats: A Framework for Policy Response. [online] Published 7 September 2026. Available at: https://www.isdglobal.org/publication/lessons-in-extremism-prevention-for-countering-hybrid-threats-a-framework-for-policy-response/


23-Site Network Engineers AI-Chatbot Citation Ecosystem Ahead of Alberta Referendum

A digest published by DisinfoWatch states that a September 4 National Observer investigation exposed a coordinated network of 23 deceptive websites on a single server promoting Alberta separatism ahead of the province's October 19th referendum, engineered specifically to shape what AI systems retrieve and repeat, with the sites granting crawl access to ChatGPT, Claude, Perplexity, Google, and Common Crawl via llms.txt files, backdating newly created articles to appear as established sources, containing explicit instructions inviting AI answer engines to cite their material, and using AI models from OpenAI and Anthropic to automate production, while VIGIL Strategic Intelligence independently confirmed that all 23 domains are hosted on a single server with no unrelated tenants, that domain registrations occurred in scripted batches with individual registrations separated by single-digit seconds, and that three distinct automated processes ran in tightly synchronized groups across all domains after each batch, with attribution remaining unknown, as the infrastructure is technically consistent with a foreign influence campaign but could also represent a domestic political marketing operation, and with the site-generation backend going offline after National Observer contact while the 23 public-facing sites remained active as of September 10 - while separately, RT on X falsely framed a Canada-Ukraine agreement as locking in 'Canadian taxpayer cash handouts for 100 years,' Pravda News Network published nearly two dozen articles during the first 24 hours of Zelensky's visit amplifying 'beggar Zelensky' framing and far-right Irish influencer Chay Bowes's invocation of Nazi-collaborator allegations against Ukrainian-Canadian communities, and an AI-generated Grok video depicted Prime Minister Carney handing bags of money to Zelensky.


The Alberta network's design represents a structurally distinct category of influence operation: rather than targeting human voters through persuasion, its primary engineered audience is AI retrieval systems - the operation manufactures an ecosystem of apparently independent sources that AI chatbots are trained to cite, so that a voter who asks a chatbot about the Alberta referendum receives an answer whose sources are fabricated, whose facts include incorrect voting dates and misleading ballot descriptions, and whose apparent independence and volume signal credibility to the AI's retrieval logic; by presenting as distinct, independently registered sources with separate domain names and varied topic angles while sharing a single server and synchronized configuration, the network creates the appearance of corroborating source diversity that does not exist, and the operation's explicit use of llms.txt to invite AI crawlers while backdating content to simulate established provenance demonstrates deliberate awareness of the mechanisms through which AI retrieval systems assess source quality - making this the first documented case in this report's editorial period of an influence operation targeting AI information infrastructure rather than human audiences as its primary mechanism.


Source: DisinfoWatch. DisinfoDigest: Foreign Narratives Targeting Canada & Ukraine. [online] Published 11 September 2026. Available at: https://disinfowatch.org/disinfodigest-foreign-narratives-target-canada-ukraine/ 


[Appendix - Frameworks to Counter Disinformation]


NATO Study Finds Russia's Propaganda System Vulnerable in First 18 Hours After Crises

A study published by NATO Strategic Communications Centre of Excellence and Repsense states that analysis of approximately 3.13 million Russian media and social network items collected between January 1st 2024 and March 31st, 2025 across state websites, television, and social media platforms identified a consistent three-phase propaganda response sequence, Crisis, Control, and Crusade,  in which the Kremlin takes an average of 18 hours to agree on an official position following unexpected events, during which competing narratives circulate through military bloggers and Telegram channels without central coordination before a Kremlin-controlled position is established and propagates simultaneously across all state media, television, and Telegram channels, after which the event is integrated into broader ideological framing of Russia's confrontation with the West, with the primary target audience identified as Russia's domestic population rather than foreign audiences.


The operational implication of the 18 hour vulnerability window is counter-intuitive relative to conventional counter disinformation logic; rather than responding to established Russian narratives after the Control phase has unified messaging - when the propaganda apparatus is at peak coordinated strength, the study's findings indicate that the most feasible window for fact-based intervention is the Crisis phase, when competing internal Russian narratives are themselves creating incoherence within Russian information space, and when a well-sourced counter-narrative introduced into that space competes not against a unified Kremlin line but against the fragmented landscape of competing claims circulating before official coordination is established; the study uses the Ukrainian Kursk incursion of August 6th, 2024 as a case example, during which Russian state media remained silent for seven hours before coordinated messaging emerged after 18 hours, demonstrating the predictability of the pattern across different crisis types.


Source: GlobeNewswire. NATO StratCom COE and Repsense Study Identifies Russia’s Propaganda Weak Spot: The First 18 Hours. [online] Published 8 September 2026. Available at: https://www.globenewswire.com/news-release/2026/09/08/3357933/0/en/nato-stratcom-coe-and-repsense-study-identifies-russia-s-propaganda-weak-spot-the-first-18-hours.html (globenewswire.com)


[CRC Glossary]


The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult.


To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence.


As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website.










 
 
bottom of page