top of page

Search CRC

192 results found with an empty search

  • Cyber based influence campaigns 27th July – 2nd August 2026 Report

    [Introduction] Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW). Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc. During the 27th July to 2nd August 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities. [Contents] [Introduction] [Report Highlights] [Report Summary] [State Actors] Russia Storm-1516 Ran 45 Campaigns Against Armenia's Elections and Targeted France's Declared 2027 Candidate Storm-1516 Used Fake BBC Video Russia Published 1,500 Articles Exploiting Spain's Ceuta Crisis Against Ukraine china Spamouflage Deployed 62 Accounts Targeting Chilean Journalists Fake AI Videos During Typhoon Noel Triggered Government Crackdown [Cyfluence Attacks] Laundry Bear Steals Government Emails Without User Interaction [AI Related Articles] EU AI Act Transparency Enforcement Begins [General Reports] Cheap Streaming Sticks Secretly Click Ads on AI-Generated Sites via Residential Proxy Networks Trump Distorted CIA Intelligence to Claim Venezuela Manipulated US Voting China's AI Microdrama Industry Harvests Faces at Scale Influence Operations Bulletin Q2 2026 [Appendix - Frameworks to Counter Disinformation] Weaponized Nostalgia Identified as Below-Radar Cognitive Threat [CRC Glossary] [ Report Highlights] DFRLab mapped Storm-1516's full interference infrastructure against Armenia's May 2026 parliamentary elections, 45 campaigns, 149.5 million views, 450 accounts, two false-front website clusters, GRU Unit 29155, while France's Viginum attributed to the same network the first documented Storm-1516 campaign against a declared presidential candidate: fabricated health claims against Edouard Philippe, declared 2027 contender, one of 205 operations Viginum has attributed to Storm-1516 since August 2023. Storm-1516 deployed a fake BBC video digitally inserting a stolen Lalique pendant on Ukraine's First Lady, Olena Zelenska, to generate 3.27 million views across 13,700 posts. At the same time, Ukraine's Foreign Minister revealed Russia had published more than 1,500 articles exploiting Spain's Ceuta migration crisis to spread anti-Ukraine narratives across European audiences. Graphika's Ore Else report documented Spamouflage deploying 62 inauthentic accounts across four platforms to target six named Chilean journalists covering copper smuggling, marking a documented operational shift from geopolitical influence objectives to economic-sector information control. On August 2nd, 2026, the EU AI Act's transparency requirements entered formal enforcement: chatbots must disclose AI status at first contact, deepfakes must be labelled, and AI-generated content must carry machine-readable marks, with more than 180 organisations signed to the Code of Practice and penalties of up to EUR 15 million or 3% of global turnover. AI-generated fake flood videos during Typhoon Noel circulated widely on Chinese social media, triggering panic-buying across affected regions and prompting an emergency crackdown order from the Cyberspace Administration of China specifically targeting AI-generated disaster disinformation. Google's Q2 2026 Influence Operations Bulletin documented the termination of more than 3,500 YouTube channels and several domains across operations linked to China (1,763 channels), India (1,419 channels across five campaigns), Russia (558+ channels and two domains across five operations), Azerbaijan, Chile, Hungary, Spain, Venezuela, Iran, and more than a dozen campaigns without confirmed state attribution. Cheap TV streaming sticks sold through major retailers secretly enroll in residential proxy networks and spoof mobile device identities to generate fraudulent clicks on AI-generated websites, illustrating the convergence of consumer electronics, ad fraud infrastructure, and AI-generated content farming into a self-sustaining criminal revenue cycle. Cyfluence Research Center documented weaponized nostalgia as a below-radar hostile influence technique, identifying a Russian-linked Facebook network of 75 or more pages embedding communist-era nostalgic affect across 12,790 posts targeting Romania, and PRC-aligned operations deploying five interlocking Ryukyuan nostalgic subthemes against Okinawa across X, YouTube, and Facebook, with content surges correlated with official PRC diplomatic actions, identifying nostalgia as a structural cognitive threat vector invisible to most automated detection systems. [ Report Summary] DFRLab documented Storm-1516's full interference infrastructure against Armenia's May 2026 parliamentary elections, 45 campaigns, 149.5 million views, 450 accounts, GRU Unit 29155, while Meduza reported France's Viginum attribution of fabricated health claims against Edouard Philippe as the first documented Storm-1516 operation targeting a declared presidential candidate. Lead Stories documented Storm-1516's deployment of a fake BBC news video falsely claiming Ukrainian First Lady Olena Zelenska was photographed wearing a stolen Lalique pendant at the Coalition of the Willing summit, with the pendant digitally inserted into genuine summit footage, generating 3.27 million views and 13,700 posts before BBC publicly confirmed on July 27th, 2026 that the video was fabricated. Ukraine's Foreign Minister Andrii Sybiha revealed that Russian state and state-aligned media published more than 1,500 articles exploiting Spain's Ceuta migration crisis to spread anti-Ukraine propaganda, deploying Pravda, RT, and affiliated outlets to link Ukrainian military assistance to EU-level migration pressures and weaken European public support for Ukraine. Graphika's Ore Else report documented Spamouflage deploying 62 inauthentic accounts across Facebook, Parler, Tumblr, and YouTube to suppress Chilean media coverage of copper smuggling investigations, targeting six named Chilean journalists with coordinated harassment and AI-generated counter-narratives, marking a documented operational shift for the network from geopolitical targeting to economic-sector information control. BBC reported that AI-generated videos falsely depicting catastrophic flooding during Typhoon Noel circulated widely on Chinese social media, triggering panic-buying across affected regions before the Cyberspace Administration of China issued an emergency crackdown order on July 23rd, 2026, specifically targeting AI-generated disaster disinformation. The EU AI Act's transparency requirements entered formal enforcement on August 2nd, 2026, requiring chatbots to disclose AI status at first contact, deepfakes to be labelled, and AI-generated content to carry machine-readable marks, with the European Commission AI Office and national authorities in all 27 member states activating enforcement powers and more than 180 organisations including Meta signed to the voluntary Code of Practice, while analysts identified enforcement gaps including strippable watermarks and the difficulty of automated machine-text detection. A joint advisory from cybersecurity agencies warned that Russian-linked threat actor Laundry Bear is exploiting Zimbra vulnerability CVE-2025-66376 to silently exfiltrate government email credentials with no user interaction required, using a lure posing as a Belgian media-integrity verification organisation to ensure delivery to government targets involved in media or information policy. Krebs on Security reported that inexpensive TV streaming sticks sold through major retailers secretly enroll in residential proxy networks and spoof mobile device identities to generate fraudulent clicks on AI-generated websites, creating a self-sustaining criminal revenue cycle in which consumers unknowingly subsidise ad fraud while advertisers fund traffic to synthetic content sites with no genuine readership. FactCheck.org documented that President Trump misrepresented a CIA devil's advocacy analytical exercise as confirmed intelligence, falsely claiming the CIA found evidence that Venezuela had exactly manipulated US voting machines in 2020, when the exercise produced no such evidence, devil's advocacy being a technique designed to stress-test prevailing assessments, not produce validated findings. Rest of World documented China's AI microdrama industry's systematic exploitation of human faces for AI-generated synthetic actors, with more than 95% of 128,000 microdramas produced in Q1 2026 using AI actors, ByteDance removing more than 85,000 unauthorised face reproductions, and Chinese courts logging 700 facial theft cases, illustrating the industrialisation of biometric data exploitation within a commercially legalised licensing framework. Google's Q2 2026 Influence Operations Bulletin documented the termination of more than 3,500 YouTube channels and several domains across operations linked to China (1,763 channels), India (1,419 channels across five campaigns), Russia (558+ channels and two domains across five operations), Azerbaijan, Chile, Hungary, Spain, Venezuela, Iran, and more than a dozen campaigns without confirmed state attribution. Cyfluence Research Center documented two hostile influence campaigns weaponizing nostalgia as a below-radar cognitive driver: a Russian-linked Facebook network embedding communist-era nostalgic affect across 12,790 posts targeting Romania, and PRC-aligned operations deploying five interlocking Ryukyuan nostalgic subthemes against Okinawa across X, YouTube, and Facebook with content surges correlated with official PRC diplomatic actions, identifying nostalgia as a structural cognitive threat vector that is largely invisible to automated detection systems. [State Actors] Russia Storm-1516 Ran 45 Campaigns Against Armenia's Elections and Targeted France's Declared 2027 Candidate An investigation published by DFRLab states that the Atlantic Council's Digital Forensic Research Lab mapped the full digital infrastructure behind Storm-1516's interference campaign targeting Armenia's May 2026 parliamentary elections, identifying 45 distinct narrative campaigns that generated 149.5 million views on X, distributed by a network of more than 450 accounts including six core amplifier accounts responsible for the bulk of reach. The operation produced AI-generated articles and videos through two false-front website clusters formatted as apparent local news outlets, publishing content in Armenian, English, French, and Turkish, attributed to GRU Unit 29155 and following the network's documented template of fabricated infrastructure establishment before an electoral period, followed by coordinated amplification to manufacture the appearance of organic public concern. Another article published by Meduza states that France's Viginum service attributed to Storm-1516 a campaign fabricating false health claims about Edouard Philippe, the former French Prime Minister and declared candidate for France's 2027 presidential election, described by a French security source as the first documented Storm-1516 campaign targeting a declared presidential candidate, one of 205 operations Viginum has attributed to the network since August 2023. Storm-1516 is assessed as active since 2023, linked to Russia's GRU, and its operator base includes former employees of Yevgeny Prigozhin's information operations infrastructure; the Philippe targeting fits a documented pattern of selecting political figures whose election would strengthen Western security architecture and deploying fabricated personal health or integrity claims that force candidates into public denials amplifying the original false claim regardless of the denial's success. Sources: DFRLab. Uncovering the Digital Infrastructure Behind Russian Interference in Armenian Elections. [online] Published 29 July 2026. Available at: https://dfrlab.org/2026/07/29/uncovering-the-digital-infrastructure-behind-russian-interference-in-armenian-elections/ Meduza. Russian disinformation network Storm-1516 accused of targeting French presidential candidate Édouard Philippe with fake health claims. [online] Published 24 July 2026. Available at: https://meduza.io/en/news/2026/07/24/russian-disinformation-network-storm-1516-accused-of-targeting-french-presidential-candidate-edouard-philippe-with-fake-health-claims Top Of Page Storm-1516 Used Fake BBC Video A fact-check published by Lead Stories states that a fake video formatted as an authentic BBC news report falsely claimed Ukrainian First Lady Olena Zelenska was photographed wearing a stolen Lalique pendant at the Coalition of the Willing summit, with the pendant digitally inserted into genuine summit footage. The fabricated content generated 3.27 million views and 13,700 social media posts before the BBC publicly confirmed on July 27th, 2026, that the video was fake and did not originate from any BBC broadcast or publication. Lead Stories attributed the operation to Storm-1516, consistent with the network's documented use of established broadcaster brands to lend false credibility to fabricated content targeting Ukrainian national figures. The publication states that the fake BBC video illustrates a core Storm-1516 operational technique: attaching fabricated narratives to visually authentic-appearing footage from genuine events, with broadcaster logos and graphic design elements reproduced to bypass credibility filters among audiences unfamiliar with the specific broadcast format being impersonated. The Zelenska pendant claim targets the First Lady of a wartime head of state and is consistent with Storm-1516's documented strategy of generating reputational damage narratives around Ukrainian national figures, a tactic effective even when quickly debunked, because the debunking process produces additional broadcast coverage of the original false claim and forces official Ukrainian institutions to expend credibility capital issuing denials. Source: Lead Stories. Fact Check: FAKE BBC Report Claims Olena Zelenska Was Spotted Wearing Stolen Lalique Pendant. [online] Published 27 July 2026. Available at: https://leadstories.com/hoax-alert/2026/07/fact-check-fake-bbc-report-shows-zelenska-wearing-stolen-lalique-pendant.html Top Of Page Russia Published 1,500 Articles Exploiting Spain's Ceuta Crisis Against Ukraine An article published by European Pravda states that Ukrainian Foreign Minister Andrii Sybiha revealed that Russian state and state-aligned media published more than 1,500 articles exploiting Spain's Ceuta migration crisis to advance anti-Ukraine propaganda narratives across European audiences, deploying Pravda, RT, and affiliated outlets to link Ukrainian military assistance to EU-level migration pressures. Sybiha stated that Ukraine had uncovered and exposed the Russian propaganda campaign, which sought to leverage an active European migration crisis to shift European public opinion against continued support for Ukraine by connecting EU policy failures to the costs of the Ukraine conflict. The article states that the Ceuta exploitation campaign illustrates a recurring Russian FIMI strategy of attaching anti-Ukraine messaging to genuine European domestic crises, a technique that requires no fabricated events, only the selective framing of real developments to support predetermined narratives. By deploying more than 1,500 publications across Pravda, RT, and affiliated platforms rather than relying on inauthentic amplification networks, the operation exploited the established reach of Russian state media infrastructure to distribute its messaging, making platform-level content removal less effective than would be the case for synthetically amplified material. The exposure by Sybiha follows a documented pattern of Ukrainian intelligence and diplomatic disclosure of active Russian information operations, designed to pre-emptively denature narratives before they achieve wider penetration in Western European media. Source: European Pravda. Sybiha: Ukraine uncovers Russian propaganda campaign linked to crisis in Spanish city. [online] Published 31 July 2026. Available at: https://www.eurointegration.com.ua/eng/news/2026/07/31/7242718/ Top Of Page China Spamouflage Deployed 62 Accounts Targeting Chilean Journalists A report published by Graphika states that Spamouflage, the China state-aligned network also documented as Dragonbridge and Taizi Flood, deployed 62 inauthentic accounts across Facebook, Parler, Tumblr, and YouTube to suppress Chilean media coverage of copper smuggling investigations, targeting six named Chilean journalists with coordinated harassment and AI-generated content designed to discredit their reporting. The campaign, documented in a Graphika investigation titled Ore Else, combined AI-generated visual and text content with coordinated account volume to reduce the visibility of the targeted journalists' copper smuggling coverage and associate it with pro-industry counter-narratives. The report states that the Ore Else investigation identifies the operation as a documented evolution for Spamouflage: rather than the geopolitical and election-focused targeting previously documented for the network, the infrastructure was here deployed to protect copper supply chain narratives of direct relevance to Chinese commercial interests, suggesting that the Spamouflage model is available not only for political influence objectives but for direct commercial information control in any sector where China holds strategic interests and where investigative journalism poses a reputational or supply chain risk. The use of four distinct platforms, including Parler and Tumblr alongside the more commonly monitored Facebook and YouTube, reflects an adaptive distribution strategy designed to maintain operational reach after platform enforcement actions on any single channel, a structural adaptation that limits the effectiveness of single-platform moderation responses. Source: Graphika. Ore Else: Spamouflage Targets Chile’s Copper Smuggling Coverage. [online] Published 30 July 2026. Available at: https://www.graphika.com/reports/ore-else Top Of Page Fake AI Videos During Typhoon Noel Triggered Government Crackdown An article published by BBC states that AI-generated videos falsely depicting catastrophic flood conditions during Typhoon Noel circulated widely on Chinese social media platforms, triggering panic-buying across regions where viewers could not verify on-the-ground conditions against the fabricated footage. The fabricated disaster content demonstrated the particular vulnerability of AI-generated disinformation during natural disaster events, where time pressure, communication disruption, and public anxiety create conditions in which synthetic emergency content can propagate rapidly before fact-checking or platform moderation systems respond. The article states that the Cyberspace Administration of China issued an emergency enforcement action on July 23rd, 2026, specifically targeting AI-generated content misrepresenting disaster conditions, as the volume and apparent realism of synthetic flood videos became significant enough to require direct state intervention. The Noel flooding episode illustrates a tension within China's AI content regulation framework: AI-generated synthetic media is an official development priority sector, while uncoordinated AI content that disrupts public order represents a direct challenge to state information control. The emergency crackdown focused on content capable of generating public panic, leaving unresolved the broader question of how platform-level accountability for synthetic disaster content should be institutionalised within China's existing AI regulatory architecture. Source: BBC News. Trump says Iran war talks taking place during lull in strikes. [online] Published 24 June 2026. Available at: https://www.bbc.co.uk/news/articles/cx27mjvxgg1o Top Of Page [Cyfluence Attacks] Laundry Bear Steals Government Emails Without User Interaction An article published by Nextgov/FCW states that a joint advisory from cybersecurity agencies warned that Russian-linked threat actor Laundry Bear is exploiting Zimbra email server vulnerability CVE-2025-66376 to silently exfiltrate government email credentials without any user interaction, no link click, no attachment open, no action of any kind required from the target. The zero-click exploit delivers the credential theft payload when the target's Zimbra server receives and processes a specially crafted email, with the initial lure formatted as communications from a Belgian media-integrity verification organisation, designed to ensure delivery to government and public sector recipients involved in media or information policy. The article states that the Laundry Bear operation merges cyber exploitation with influence infrastructure deception: the lure delivering the zero-click exploit is itself a false-flag persona organization, a fake Belgian media-verification body, whose institutional framing is specifically calibrated to be credible to the government email recipients targeted. This combination of a zero-interaction technical exploit with a persona-organisation social engineering lure represents an escalation in operational sophistication, as it eliminates the human-action dependency that has historically been the primary point of failure and detection in spear-phishing campaigns. Government email systems compromised via CVE-2025-66376 expose the full contents of targeted accounts without any audit trail of the initial infection trigger, creating a covert intelligence collection capability with no forensic footprint at the user level. Source: Nextgov/FCW. Russian hackers can steal government emails without victims clicking a link, cyber agencies warn. [online] Published 24 July 2026. Available at: https://www.nextgov.com/cybersecurity/2026/07/russian-hackers-can-steal-government-emails-without-victims-clicking-link-cyber-agencies-warn/414967/ Top Of Page [AI Related Articles] EU AI Act Transparency Enforcement Begins An announcement published by the European Commission states that from August 2nd, 2026, the AI Act's transparency framework requires AI systems to disclose they are not human at first contact with users, deepfakes to be explicitly labelled, and AI-generated or altered content to carry machine-readable marks enabling automated platform and regulatory detection. High-risk AI systems in regulated products are deferred to August 2028 and high-risk applications in recruitment, credit scoring, and law enforcement to December 2027; IBTimes UK confirmed that more than 180 organisations, including Meta across Facebook, Instagram, and Threads, signed the voluntary Code of Practice on transparency of AI-generated content ahead of the mandatory enforcement date, with the Commission's AI Office and national authorities across all 27 EU member states activating documentation compulsion, technical evaluation authority, and penalties calibrated to global annual turnover from August 2nd, 2026. Another article published by The Next Web states that enforcement faces a central operational vulnerability: watermarks can be stripped, metadata can be lost in format conversions, and machine-written text is notoriously difficult to detect automatically, making the transparency framework only as effective as the detection tools that back it, tools that remain commercially inconsistent in 2026. A possible simplification package could defer machine-marking obligations to December 2026 while maintaining chatbot disclosure from August 2026; carve-outs exempt clearly unrealistic or fantastical content, machine-written text reviewed by humans with genuine editorial responsibility, and artistic or satirical content with appropriate disclosure. The EU regime is anticipated to shape worldwide labelling practices as platforms standardize compliance globally; Meta's voluntary pre-enforcement signature on the Code of Practice is a commitment whose gap with actual implementation will constitute the first test of the AI Office's enforcement authority from August 2nd, 2026. Sources: European Commission. Commission starts enforcing AI Act rules and new transparency requirements from 2 August. [online] Published 3 August 2026. Available at: https://digital-strategy.ec.europa.eu/en/news/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august The Next Web. EU AI Act labels become compulsory for synthetic content. [online] Published 31 July 2026. Available at: https://thenextweb.com/news/eu-ai-act-labels-compulsory-synthetic-content Top Of Page [General Reports] Cheap Streaming Sticks Secretly Click Ads on AI-Generated Sites via Residential Proxy Networks An article published by Krebs on Security states that inexpensive TV streaming sticks sold through major online retailers secretly enroll in commercial residential proxy networks without user knowledge or consent, renting out the devices' internet connections and spoofing them as mobile phone identities to generate fraudulent advertisement clicks on AI-generated websites. The scheme creates a criminal revenue model in which consumers unknowingly contribute their home bandwidth and IP reputation to ad fraud operations, while advertisers are billed for traffic to AI-generated content sites that have no genuine human readership. The article states that the scheme is structurally self-sustaining: device manufacturers sell sticks at prices partially subsidised by proxy enrolment revenue, making the fraud model profitable at the device supply level before any advertising click is generated. Advertisers pay programmatic systems for traffic that spoofed mobile device identities are specifically designed to pass through standard detection filters, and AI-generated content sites collecting per-click payments require no ongoing human content creation costs. No single intervention point is sufficient to collapse the scheme; eliminating proxy enrolment requires manufacturer-level accountability that current retail supply chains do not enforce, eliminating fraudulent traffic requires ad network reforms that programmatic buying architectures are not designed to deliver, and the replacement cost for deplatformed AI-generated content sites approaches zero. Source: Krebs on Security. Read This Before You Buy That TV Streaming Stick. [online] Published 30 July 2026. Available at: https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/ Top Of Page Trump Distorted CIA Intelligence to Claim Venezuela Manipulated US Voting A fact-check publication by FactCheck.org states that President Trump publicly cited CIA intelligence to claim Venezuela had exactly manipulated US voting machines during the 2020 election, misrepresenting a CIA analytical technique known as devil's advocacy, in which analysts deliberately argue against prevailing assessments to test their robustness, as a confirmed intelligence finding. FactCheck.org's review found that the CIA devil's advocacy exercise produced no evidence of Venezuelan interference with US voting systems, and that the technique's design and purpose are explicitly to generate stress-test arguments rather than validated intelligence conclusions. The misrepresentation of intelligence methodology, presenting a process that explicitly did not produce a finding as the source of that finding, represents a structurally effective disinformation technique because institutional credibility attaches to the citing organization rather than to the specific analytical output being claimed: a CIA process carries inherent authority in public perception regardless of what that specific process concluded. Debunking this category of claim requires communicating both that the specific assertion is false and that the cited analytical method is structurally incapable of producing the type of validated intelligence finding described, a two-step correction that is considerably harder to convey than the original single-step assertion. FactCheck.org assessed Trump's claim as false. Source: FactCheck.org. Trump’s Distorted Venezuela Elections Claim. [online] Published 23 July 2026. Available at: https://www.factcheck.org/2026/07/trumps-distorted-venezuela-elections-claim/ Top Of Page China's AI Microdrama Industry Harvests Faces at Scale An article published by Rest of World states that China's AI-powered microdrama industry has industrialised the use of synthetic actors based on real human faces, with more than 95% of 128,000 microdramas produced in Q1 2026 using AI-generated actors, generating a commercial market in which individuals rent their facial likeness for AI reproduction in exchange for payments. ByteDance removed more than 85,000 unauthorised face reproductions from its platforms during the period reviewed, and Chinese courts have logged 700 facial theft cases from creators whose likenesses were used without consent, establishing the scale of unconsented biometric exploitation within a framework that simultaneously permits licensed use. An article published by Rest of World states that China's face-licensing ecosystem creates a two-tier commercial structure: a legal tier in which individuals consciously sell facial licensing rights for AI reproduction in entertainment, and an illicit tier in which faces are copied, modified, and deployed without consent or payment, with the legal tier normalising the infrastructure the illicit tier exploits. In the context of information integrity, the systematic commercial development of large, licensed datasets of real human faces for AI-generated synthetic actors represents an industrial-scale capability for producing indistinguishable synthetic human likenesses, a foundational capability layer applicable to AI-generated synthetic media in disinformation contexts. The ByteDance enforcement actions and 700 court cases document only cases reaching formal resolution; total unconsented face use in AI microdramas is substantially larger. Source: Rest of World. In China, people are renting out their faces to AI. [online] Published 27 July 2026. Available at: https://restofworld.org/2026/china-ai-microdramas-face-licensing/ Top Of Page Influence Operations Bulletin Q2 2026 Google's Q2 2026 Influence Operations Bulletin covers coordinated influence operations terminated on its platforms between April and June 2026. In China, 1,763 YouTube channels were terminated as part of an ongoing investigation into a coordinated inauthentic network linked to the People's Republic of China. The network was uploading content in Chinese and English focused on China-US foreign affairs. An additional 2 Blogger blogs linked to China were terminated for sharing pro-China content in English and Chinese. In Russia, five separate operations were identified and actioned. The largest involved 505 YouTube channels linked to a named Russian consulting firm sharing content in Russian that was supportive of Russia and critical of Ukraine, NATO, and the West. A second operation involved 28 YouTube channels sharing content in Hungarian supportive of a Hungarian political party. A third operation involved 23 YouTube channels sharing content in Russian supportive of Russia and critical of Moldova. A fourth involved 2 YouTube channels sharing content in Armenian critical of the Armenian government. Additionally, one domain was blocked from eligibility to appear on Google News and Discover for sharing content in Portuguese supportive of Russia and critical of the United States. One further domain linked to the Czech Republic was blocked for sharing content in Czech associated with Russian state media. In India, five separate operations were terminated during the quarter. The largest involved 992 YouTube channels sharing content in Hindi and Marathi supportive of an Indian political party. The remaining four operations involved 236, 108, 49, and 34 channels respectively, operating in English, Hindi, Punjabi, and Tamil, all supportive of Indian political parties. Combined, Indian-linked operations accounted for more than 1,419 channel terminations in a single quarter. In Azerbaijan, 132 YouTube channels were terminated for sharing content in Azerbaijani supportive of Azerbaijan and critical of Armenia and critics of the Azerbaijani government. In Chile, 110 YouTube channels were terminated for sharing content in Spanish critical of one candidate in Colombia's 2026 presidential election and supportive of another. In Hungary, 105 YouTube channels were terminated for sharing content in Hungarian critical of a Hungarian political party. In Spain, 54 YouTube channels were terminated for sharing content in Spanish critical of the Spanish government. In Venezuela, 43 YouTube channels were terminated for sharing content in English and Spanish supportive of Venezuela. In Argentina, 13 YouTube channels were terminated for sharing content in Spanish supportive of a candidate in Colombia's 2026 presidential election. In Iran, 2 YouTube channels were terminated for sharing content in English and French supportive of Iran and critical of Israel and the United States. Among campaigns without confirmed state attribution, Google terminated 49 YouTube channels sharing content in English and Zulu supportive of a South African political party and critical of the South African government; 44 channels in Arabic critical of the Iraqi government; 31 channels in Ukrainian critical of the Ukrainian government; 93 channels in Indonesian and Malay supportive of the Malaysian government; 50 channels in English and Urdu supportive of the Pakistani military and government; 30 channels in Belarusian critical of the Belarusian government; 22 channels in Korean supportive of South Korean political figures; and multiple operations targeting Indonesian, Japanese, Turkish, Italian, Armenian, and Paraguayan audiences across a range of supportive and critical narratives. Additional smaller operations were recorded across further languages and regions. Top Of Page [Appendix - Frameworks to Counter Disinformation] Weaponized Nostalgia Identified as Below-Radar Cognitive Threat A report published by the Cyfluence Research Center states that CRC documented two empirical case studies of hostile influence campaigns weaponizing nostalgia as their primary psychological driver: a Russian-linked network of 75 or more Facebook pages in Romania embedding nostalgic affect across 12,790 posts through implicit references to the communist era, and PRC-aligned campaigns across X, YouTube, and Facebook targeting Okinawa with five interlocking Ryukyuan nostalgic subthemes, with content surges correlated with official PRC diplomatic actions and state media activity, indicating deliberate coordination between state narrative-setting outlets and inauthentic amplification clusters. CRC identified 78 X accounts associated with the Okinawa-targeting network, the majority suspended at the time of publication, alongside a Facebook infrastructure including an Okinawan Independence page and a group promoting cessation of US base construction, both assessed as advancing PRC-aligned geopolitical narratives. The report states that nostalgia functions as a below-radar ambient emotion that does not announce itself as political, unlike high-arousal negative emotions such as anger or outrage, nostalgic content circulates as cultural celebration, religious reflection, or communal memory and remains largely invisible to automated narrative detection systems, making it a structurally effective cognitive threat vector that is slow to produce measurable indicators and difficult to attribute to hostile actors. CRC analysis identifies a dual-strand PRC influence strategy: nostalgia narratives delegitimize the present by measuring it against a romanticized past rendered wrongly lost, while parallel techno-utopian narratives measure it against a Chinese-led future only PRC alignment can deliver, addressing target audiences simultaneously from both temporal directions so that the present is rendered inadequate from both sides without any individual content stream announcing a coordinated agenda. Counter-messaging and prebunking face a structural challenge because directly challenging nostalgic content risks appearing hostile to legitimate cultural expression or identity, requiring influence defense practitioners to engage the emotional register of the content rather than relying solely on factual rebuttal. Source: Cyfluence Research Center. Research Section. [online] Available at: https://www.cyfluence-research.org/research-section Top Of Page [CRC Glossary] The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult. To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence. As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website. Top Of Page

  • The Weaponization of Nostalgia: Conceptual Framework and Case Studies

    While influence operations research has traditionally focused on high-arousal emotions like anger and outrage, this report by Alina Bârgăoanu and Maya Sobchuk examines a quieter, more insidious vector: nostalgia. Unlike overt propaganda, weaponized nostalgia operates as an "ambient" emotion, it doesn't announce itself as political, but instead shapes how audiences judge the present through idealized, emotionally warm portrayals of the past, gradually normalizing distrust in current institutions and eroding critical evaluation. Drawing on two original investigations, the report documents this dynamic in action. In Romania, a Russian-linked network of roughly 75 Facebook pages and affiliated clickbait sites active since 2020 and reaching a combined audience in the millions has spent years embedding nostalgia for the communist era across 12,790 analyzed posts. Rather than explicit political messaging, the content leans on themes of family, faith, childhood, tradition, and "true" values, implicitly contrasting a morally coherent past with a fragmented present. Notably, these pages were built years in advance of any electoral target and have survived repeated exposure, including through the contested 2024 election cycle. In Okinawa, Japan, the report documents PRC-aligned campaigns exploiting Ryukyuan historical identity across X/Twitter, YouTube, and Facebook. These efforts range from official Chinese state media (including a dedicated Global Times hashtag, #RyukyuChronicles) to coordinated networks of inauthentic accounts some AI-generated, some sloppily assembled with mismatched VPNs and bios promoting narratives of Ryukyu's "undetermined status," historical grievance against Japan, and opposition to U.S. military presence. Over 44–56% of accounts engaging in these narratives displayed bot-like characteristics. The comparative analysis reveals a shared playbook: nostalgic content is dressed up as cultural celebration, historical education, or community memory, making it resistant to being dismissed as propaganda. The report also identifies a complementary strategy, pairing nostalgic narratives with "techno-utopian" messaging (as seen in Chinese diplomatic content in Malaysia) that frames a China-aligned future as the answer to a present rendered inadequate from both temporal directions. The authors argue that because nostalgia is ambient rather than viral, it evades most automated detection systems, making manual, qualitative analysis essential. The report closes with recommendations for influence defense practitioners: engage the emotional register of these narratives rather than relying on factual rebuttal alone, build cognitive resilience before narratives normalize, and treat slow narrative permeation as seriously as sudden disinformation bursts. Authors: Alina Bârgăoanu & Maya Sobchuk [Download PDF Here]

  • Ceuta and Melilla: Russian-Aligned Narrative Exploitation of the Border Crisis

    Background On 30 July 2026, thousands of migrants crossed from Morocco into the Spanish enclaves of Ceuta and Melilla, overwhelming local police and triggering an emergency situation. At the time of writing, at least nine people have reportedly died. In response, the Spanish government announced it will deploy its military.[1] In conjunction with the events on the ground, the information space became a second arena of conflict. Within 24 hours of the first illegal border crossings, CRC researchers identified and analyzed hundreds of posts across X/Twitter and Reddit, spanning eleven languages. The picture that emerged is familiar to anyone who has tracked hostile influence efforts associated with the People’s Republic of China (PRC) and Russia, as well as their usage of strategic communication assets. Although the events were still unfolding on the ground, they were instantly framed and weaponized, with several conspiratorial narratives quickly proliferated across platforms and key target audiences. The malign messaging was amplified by an existing infrastructure of influencers and online personas, seemingly in an attempt to target European and NATO cohesion. Figure 1 - X/Twitter posts by @Inevitablewest and @elonmusk framing the Ceuta border breach as a crisis / invasion. Narrative Analysis CRC analysts mapped five core narrative clusters affecting online discourse around the Ceuta border crossings. They were assessed by core framing, relative volume, principal amplifiers, and platform and language distribution. As shown below, securitized and anti-government narratives dominated the information environment, while conspiratorial, geopolitical, and humanitarian framings gained more limited traction. # Narrative Cluster Velocity Core Framing Circulation N1 Islamic Military Invasion High The crossing as a religiously motivated offensive. A conquest of European or Christian civilization. Focus on reported violence, looting, and home invasions. European/American far right, identitarian accounts and Russian state media. Highly Emotive content and messaging. N2 Sánchez Policy Failure / Open Borders High The crossing is due to the Sánchez government’s amnesty policies and the Spanish Supreme Court ruling on maritime returns. Calls for military deployment, border closure, and emergency measures. Spanish opposition figures, European conservative and populist politicians. Criticism mostly based on policy debate. N3 Israel/US Geopolitical Manipulation Medium The border crossing is a false-flag or coordinated retaliatory operation against Spain, in response for its pro-Palestinian position. The goal is to seize control of the Strait of Gibraltar and/or destabilize the EU. Geopolitical commentators, politically aligned influencers, low-follower accounts. Cross-platform correlation. N4 Morocco Hybrid Warfare / State Pressure Medium Deliberate Moroccan weaponization of migration, potentially linked to Spain’s diplomatic ties with Algeria. Circulates among geopolitical commentators, journalists, and users. Overlaps conspiratorial or extremist framing (N1 or N3). N5 Humanitarian / Decolonization Low Presents migrants as people fleeing poverty, characterizes Ceuta and Melilla as colonial remnants, and depicts the European response as hypocritical or disproportionate. Amplified by pro-Moroccan and left-leaning accounts. “Ceuta is Morocco” framing also observed on Reddit. Figure 2 – Timeline showing key X/Twitter posts, classified into main narratives and including retweet amplitude. Conspiracies Hotbed The most analytically significant narrative observed in our dataset claims that the Ceuta crossing was a covert operation coordinated by Israel and the United States, designed to punish Spain for its pro-Palestine foreign policy and wrest Spanish control of the Strait of Gibraltar, a critical chokepoint for Atlantic-Mediterranean maritime traffic. The main "evidence" cited is a 2019 tweet by Yair Netanyahu, son of the Israeli Prime Minister, in which he referenced potential Israeli funding of NGOs in Ceuta and Melilla as counter leverage against Spain. Although that tweet itself is indeed real, it was taken out of context to serve as “proof” for the alleged hostile foreign led “invasion”. Figure 3 – X/Twitter posts propagating the allegation that the Ceuta border breach was orchestrated by the U.S., Morocco and Israel. This claim, along with the misattribution of recent statements made by President Trump and other US officials, are clear examples of DISARM ‘Technique T0042: Seed Kernel of Truth’, by which malinformation is used to “promote a narrative less common in the target audience, but preferred by the attacker.”[2] The conspiratorial narrative achieved measurable traction. One post framing the crossing as a joint US-Israel operation to seize the Strait of Gibraltar gained millions of views and was retweeted over 4,400 times. Figure 4 - X/Twitter posts framing the Ceuta border breach as a Moroccan operation against Spain. Another, attributing the “operation” to "Spanish intelligence" and claiming a Moroccan false flag, reached 2,943 retweets. Neither claim has any basis in public record or official statement. Figure 5 - Example of X/Twitter post promoting the narrative that the Ceuta border crossing was a "joint operation" designed to punish Spain for its pro-Palestinian position. The Strait of Gibraltar framing does not appear to be incidental. Weakening Western cohesion and control of strategic maritime routes – and particularly Spain's position as part of NATO’s southern flank – is a Russian strategic objective. Figure 6 – X/Twitter post by geopolitical commentator Bruno Maçães, framing the events in Ceuta as an American hybrid attack against Spain. Having said that, the narrative did not need to directly originate in Moscow in order to serve its interests. It was repeated and reframed even by self-proclaimed pro-European politicians and geopolitical commentators. State Aligned Media It’s worth noting the active role of Russian state media outlets in the propagation and amplification of inflammatory messaging and conspiratorial narratives. For example, Russia Today (RT), which is sanctioned and blocked in the European Union, chose to cover highly contentious posts by leading Western figures, emphasizing narratives of Western fragmentation and decline among a mostly non-Western audience. Figure 7 - Samples of coverage and narrative amplification by RT on X/Twitter. The observed selective coverage aligns with the familiar modus operandi of pro-Russian groups and the supportive influence infrastructure. Russian media outlets, doubling as overt influence assets, consistently frame geopolitical developments to fit a specific set of meta-narratives (e.g. Western civilizational decline; Failure of European societies; Progressive liberalism as an existential threat to Europe’s future). To do that, Russian propaganda outfits do not have to generate disinformation. Instead, they exploit actual events. In addition, Russian propaganda is delivered through a wide framing and amplification ecosystem, in which fringe theories are laundered toward legitimacy through pseudo-journalistic sources. Why This Matters This preliminary analysis does not seek to minimize the gravity of the events unfolding in the Spanish enclaves of Ceuta and Melilla. Morocco’s use of border management as political leverage is well documented, while Spain’s Supreme Court ruling and 2026 amnesty program warrant legitimate policy scrutiny. However, these debates are increasingly being distorted by unsubstantiated conspiracy theories. Claims attributing the border crisis to coordinated U.S., Israeli, and Moroccan offensive plans lack credible evidence and risk diverting attention from the actors, policies, and structural pressures directly involved. Such narratives clearly serve the strategic interests of geopolitical rivals, primarily Russia, China, and Iran, by deepening mistrust and contempt toward Western governments and institutions. What began in Ceuta and Melilla on 30 July as a local border crisis has already generated diplomatic, political, and societal repercussions extending far beyond the contested territories. Although the full implications remain unclear, the current crisis must also be assessed through its digital-cognitive dimension, where competing narratives already amplify tensions, reshape public perceptions, and influence geopolitical actions. [References:] CNN. Spain declares emergency in Ceuta after thousands of Moroccans cross into enclave. [online] Published 30 July 2026. Available at: https://edition.cnn.com/2026/07/30/europe/ceuta-emergency-thousands-moroccans-intl (Instagram) DISARM Foundation. T0042: Seed Kernel of Truth. [online] Available at: https://github.com/DISARMFoundation/DISARMframeworks/blob/main/generated_pages/techniques/T0042.md (disarm.foundation)

  • Urban Cyfluence Blueprint Series - Vol 1: Asia

    ISBN: 978-3-9829099-0-5 | ISSN: 3055-8867 | DOI: doi.org/10.67592/ucb.v1 Synopsis What happens when a city is not only disrupted, but also narrated, contested, and manipulated in real time? Urban Cyfluence Blueprint – Volume 1: Asia introduces a new way of understanding urban vulnerability in the digital age. As cities rely more on digital infrastructure, data systems, and public trust, disruption can quickly move across institutions, platforms, and public perception. Bringing together expert perspectives from across Asia, this volume examines how cyber disruption, information disorder, geopolitical contestation, and shifting trust reshape the way cities are governed and perceived. The Blueprint argues that urban resilience is no longer only about infrastructure, technology, or crisis response. It must also account for how trust is built, damaged, and weaponized. As the inaugural volume of the Urban Cyfluence Blueprint Series, this publication focuses on Asia, with future volumes planned for Oceania and Europe. Chapter 1 Conceptual Foundation: Urban Cyfluence in Asia Chapter 2: Geopolitical Contestation in Asia Chapter 3: Urban Governance, Social Condition and Public Trust Chapter 4: Smart-City Governance and Digital Transformation Chapter 5: Cybersecurity and Digital Infrastructure Vulnerabilities Chapter 6: Information Disorder, Public Narratives, and Urban Trust Chapter 7: Comparative Asian Perspectives and Framework Synthesis This blueprint available to purchase on: Copyright Urban Cyfluence Lab . 2026

  • Counter-FIMI as FIMI: Russian Narrative Manipulation and Reputational Hijacking

    Key Takeaways Four days before Armenia’s 7 June 2026 parliamentary election, an article published by a Social Design Agency (SDA)-linked influence asset (Yerevan One) promoted a narrative framing European counter-FIMI efforts as electoral interference, censorship and an effort to “purge” Armenia’s information space. The article falsely cited the Cyfluence Research Center (CRC), referred to as “Cyfluence Research,” for allegations that Western funders and French authorities were coordinating information operations in Armenia. CRC made no such claim. According to leaked SDA documents, Yerevan One was designed to serve as a pro-Russian “news outlet” used to influence Armenia’s election and promote political actors and narratives favorable to Russia. The case highlights a distinct hostile influence technique: hijacking a legitimate think tank or research institute’s reputation and perceived credibility to support a malign narrative. Background A recent CRC blog examined OCCRP reporting on leaked documents linked to the Social Design Agency (SDA), a known Russian influence contractor. Among the leaked files was a document describing a plan to use various media outlets in order to target Armenian voters with pro-Russian messaging ahead of Armenia’s general elections. One of these dedicated outlets is Yerevan One (Erevan.One). Figure 1 - Erevan.One homepage (accessed 27 July 2026). The Interference-Inversion Narrative On 3 June 2026, four days before Armenia’s parliamentary election, Erevan.One published an article titled “Censorship Is Democracy: French Press Exposes Paris’s Interference in Armenia’s Elections” (translated from Russian). The article alleged that French and European actors were financing organizations that supplied information about so-called “malicious disinformation campaigns” and supported a “purge of the information space.” This narrative is founded on the alleged misuse and weaponization of counter-disinformation investigations by Western actors. In that context, it cast VIGINUM, the French state service whose primary mission is to detect and characterize foreign information manipulation and interference (FIMI), as a vehicle for externally imposed censorship in Armenia. To further justify these claims, the Erevan.One article cites “evidence” from select sources. Coincidentally, it went as far as mentioning our organization (mentioned in the article as “Cyfluence Research”) to its support allegations of European interference. The article falsely implied that the CRC, together with a French media outlet (France-Soir) have reported on the alleged European and US-led “malicious campaigns”. Figure 2 – The Erevan.One article alleging European electoral interference under the guise of counter-disinformation. Figure 3 - Excerpt from the Erevan.One article falsely presenting “Cyfluence Research” as support for an allegation about European and US funding. The article’s selection of sources suggests a case of source conflation. A France-Soir opinion article published on 4 May 2026 advanced similar allegations.[1] It listed a CRC blog from 2025, which covered a VIGINUM report on the Russian threat actor Storm-1516, among its sources. However, the cited blog did not concern Armenia, VIGINUM activity in Armenia, or the funding of Armenian NGOs. Erevan.One’s framing (i.e. “According to France-Soir and Cyfluence Research”) converted a bibliographic citation into a direct institutional endorsement. This could be the result of careless manual drafting, automated summarization, or AI-assisted content generation. Needless to say, the aforementioned claims made by Erevan.One are obviously false. The Cyfluence Research Center did not produce any analysis or statement supporting the article’s allegations at any point. This type of misattribution aligns with DISARM Technique T0161.002: Statement Incorrectly Presented as Made by Individual or Institution. Figure 4 - Concluding passage from the Erevan.One article asserting that France-Soir had reported French interference in the recent Armenian elections. Erevan.One and SDA-Linked Influence Campaigns An OCCRP investigation based on leaked documents clearly linked Erevan.One to a wider media infrastructure associated with the Social Design Agency (SDA), a Russian influence (or “cognitive strikes”) contractor sanctioned by the US, the UK, and the EU. Figure 5 - Excerpt from the investigation report mentioning SDA operational asset "Yerevan One" (Erevan.One). (Courtesy of OCCRP) According to OCCRP, a document contained in the leak placed erevan.one within a group of 12 media outlets targeting audiences across Armenia, Central Asia, and the wider post-Soviet space. A separate file described Yerevan One as an outlet focused on the Armenian diaspora in Russia and outlined plans to use it during Armenia’s election campaign. The documented objective was to undermine attitudes toward Armenia’s authorities and Prime Minister Nikol Pashinyan, while cultivating support for actors favoring a closer relationship with Moscow. An EK Strategic Communications Center’s report on Russian interference in Armenia reached a similar assessment. It identified erevan.one as a “documented covert Kremlin proxy platform” affiliated with the SDA, placing it within an operational infrastructure that included Russian state media, regional proxy outlets, Telegram networks, and anonymous social media accounts. According to the report, this influence infrastructure proliferated and amplified narratives portraying European integration as a threat to Armenia’s sovereignty, security, economy, and national identity. Figure 6 - Excerpt from a report classifying Erevan.one as a documented covert proxy platform attributed to the SDA. (Courtesy of EK Strategic Communication Center) OCCRP appropriately cautions that the authorship of every individual document in the leaked archive cannot always be assigned conclusively to the SDA. However, current evidence places Yerevan One within an influence infrastructure connected to the SDA and that plans existed to deploy the outlet in support of Russian strategic objectives surrounding Armenia’s election. Turning Influence Defense Into “Foreign Interference” Whether deliberate or incidental, Erevan.One’s misleading citing of CRC served several mutually reinforcing narrative functions: Authority laundering - Referencing an established European research center made the false allegations appear to rest on independent analysis. Narrative inversion - Instead of presenting hostile influence campaign (HIC) detection and monitoring as a defensive activity, the article reframed the identification of FIMI efforts as devices of censorship and foreign interference. By doing so, it turned respected research institutions into malign actors. Meanwhile, the outlet actually identified as part of a foreign influence infrastructure (Erevan.One) is presented as the defender of free democratic discourse. Reputational smearing - By injecting the CRC into a narrative about covert and hostile European intervention, the article attached fabricated claims to the organization. The observed messaging seen in this specific case match the overall narratives spread by Russian proxies and Russia-aligned actors. The pre-emptive promotion of “Western interference” narratives seems to have been intended to weaken confidence in the election and Armenia’s relationship with Europe. Borrowed Legitimacy and Forced Association In a previous blog, we examined different models of credibility abuse by hostile influence actors, including the exploitation of legitimacy associated with news organizations, OSINT platforms, research institutes, and other authoritative entities (see DISARM Technique T0097.204: Think Tank Persona). These operations frequently imitate reputable institutions or create pseudo-research organizations whose visual identity and analytical language make political messaging appear credible. The erevan.one article exhibits usage of a different technique. In this case, threat actors did not impersonate the CRC or create a counterfeit website. Instead, they simply inserted the organization’s name into a narrative, while assigning it a supportive role. The observed misattribution can be seen as forced association: the unauthorized incorporation of a legitimate institution into a malign narrative to appropriate its authority, alter public perceptions of its work, or both. Conclusion and Implications Influence defense practitioners and cognitive security stakeholders should incorporate reputational abuse and forced associated into existing analytical frameworks. Ongoing brand monitoring should examine not only the frequency of mentions but also the context, narratives and claims attached to them. Suspicious references should be documented immediately (through screenshots, URL archiving, etc.). Threat researchers should map the velocity and reach of narratives across platforms and influence assets. Public correction should be quick and deliberate. Defenders need to establish an authoritative record without reproducing or amplifying unfounded allegations. If possible, this step should be accompanied by removal demands and appropriate legal action. Protecting the information environment requires defending not only platforms, data, and narratives, but also personal and organizational identities and reputations. Threat actors continue to impersonate credible media outlets and abuse legitimacy in order to target vulnerable audiences in pursuit of their strategic goals. [References:] France-Soir. Macron choisit le Premier ministre des Arméniens ? Les services secrets français accusés d’ingérence. [online] Published 25 July 2026. Available at: https://www.francesoir.fr/opinions-tribunes/macron-choisit-le-premier-ministre-des-armeniens-les-services-secrets-francais erevan.one, “Цензура — это демократия: французская пресса вскрыла вмешательство Парижа в выборы Армении”, 3 June 2026. https://web.archive.org/web/20260727111815/https://erevan.one/42960-cenzura-jeto-demokratija-francuzskaja-pressa-vskryla-vmeshatelstvo-parizha-v-vybory-armenii.html EK Strategic Communications Center, The Kremlin’s 2026 Election Campaign in Armenia, 5 June 2026. https://ekstrategies.org/articles/the-kremlins-2026-election-campaign-in-armenia Organized Crime and Corruption Reporting Project, Leaked Documents Reveal Russian ‘Cognitive Strikes’ Against the West, Including Islamophobic ‘Pig Head’ Attacks in Paris, 24 May 2026. https://www.occrp.org/en/investigation/leaked-documents-reveal-russian-cognitive-strikes-against-the-west-including-islamophobic-pig-head-attacks-in-paris Cyfluence Research Center, Borrowed Legitimacy: Three Models of Credibility Abuse in Influence Operations, 15 June 2026. https://www.cyfluence-research.org/post/borrowed-legitimacy-three-models-of-credibility-abuse-in-influence-operations Cyfluence Research Center (CRC), Behind the Curtain: Leaked SDA Files, Russian Influence Operations, and Defensive Cyfluence, June 1, 2026; updated June 14, 2026.https://www.cyfluence-research.org/post/behind-the-curtain-leaked-dsa-files-russian-influence-operations-and-defensive-cyfluence Financial Post, Russia’s “Wiki Warfare” Tries to Distort Reality, Documents Show, June 23, 2026. https://financialpost.com/pmn/business-pmn/russias-wiki-warfare-tries-to-distort-reality-documents-show

  • Cyber based influence campaigns 20th - 26th July 2026 Report

    [Introduction] Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW). Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc. During the 20th to the 26th of July 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities. [Contents] [Introduction] [Report Highlights] [Report Summary] [State Actors] Tiktok Commission Preliminary Finds TikTok in Breach of DSA for Failing to Ensure Safe Accounts for Minors Russia Russia Concocts Ukrainian Torture Moscow Exploits Poland-Ukraine Dispute Over OUN and UPA Legacy Ukraine Russian Propaganda Spreading Fakes About Death of US Senator Lindsey Graham Russian Propaganda Uses AI to Spread Fake Cardboard Protest Images China Taiwan Officials Warn Beijing Is Turning Taiwan's Political Divisions into Distrust [AI Related Articles] Commission Publishes Guidelines on Transparency Obligations for AI Systems In Chinese, AI Speaks Fluent Propaganda The Mass Production of AI Personas Weighing In on World Affairs Voters Are Being Inundated by a Barrage of AI-Generated Election Ads [General Reports] 2020 Election Denial Is Back World Cup Ends, Bogus Claims Don't French Parliament Greenlights Social Media Ban for Under-15s The Pro-Trump Ad Boycott that Never Happened [CRC Glossary] [ Report Highlights] Russia launched a coordinated cognitive warfare campaign against the Poland-Ukraine alliance, deploying GRU-linked operations to pay Ukrainian refugees to hold destabilising protests in Poland, FSB-released purported archival documents amplifying historical grievances, and coordinated Google Maps vandalism, prompting Poland's Foreign Minister to state Moscow was waging a full-scale cognitive war against Poland. A Russian influence operation spread a fabricated Human Rights Watch report falsely claiming President Zelensky ordered the torture and killing of 43 anti-draft protesters in Lviv, with the disinformation originating from the Foundation to Battle Injustice, an organisation assessed to be controlled by Russian intelligence. Russian propaganda falsely claimed US Senator Lindsey Graham was killed in Kyiv by a Russian Iskander missile strike; he died in Washington DC on July 11th from aortic dissection. The campaign deployed a fabricated CNN article and digitally manipulated imagery to signal Russia's capacity to target Western politicians and deter allied support for Ukraine. In the five days following President Trump's July 16th national address revisiting 2020 election fraud claims, posts on X claiming the 2020 election was rigged or stolen surged by 214 per cent, accumulating 77.7 million views, and the number of individual accounts actively disseminating the narrative increased by 295 per cent to 218,000. Beijing is systematically weaponising Taiwan's political divisions through Mazu religious temple networks, subsidised mainland visits, and targeted digital campaigns to erode Taiwanese trust in the United States, with electoral data confirming CCP influence operations have already shifted voting patterns in key districts. A NewsGuard audit found that leading AI chatbots reproduce pro-China false claims at significantly higher rates when prompted in Mandarin than in English, creating a language-dependent vulnerability that exposes Chinese-language users to disproportionate levels of CCP-aligned disinformation through mainstream AI tools. A Graphika investigation documented over 300 accounts across YouTube, Facebook, TikTok, and X deploying AI-generated personas to spread anti-Western and pro-China commentary on geopolitics and world affairs, with more than 140 YouTube channels hosting deepfakes impersonating journalists and academics including Rachel Maddow. The European Commission published binding AI Act transparency guidelines requiring disclosure of AI-generated content and deepfakes from August 2nd 2026, and issued preliminary DSA findings that TikTok violated platform safety obligations by setting minor accounts to publicly visible by default and recommending minor-generated content to a global audience. [ Report Summary] A Russian influence campaign spread a fabricated Human Rights Watch report claiming Zelensky ordered the torture of 43 anti-draft protesters in Lviv. The false narrative originated from the Foundation to Battle Injustice, an organisation assessed to be controlled by Russian intelligence. Russia exploited the Poland-Ukraine dispute over the OUN and UPA historical legacy through a GRU-linked campaign paying Ukrainian refugees to hold destabilising protests, FSB releases of purported archival documents, and coordinated Google Maps vandalism. Poland's Foreign Minister stated Moscow was waging a full-scale cognitive war against Poland. Russian propaganda falsely claimed Senator Graham was killed in Kyiv by a Russian Iskander missile strike, when he died in Washington DC on July 11th from aortic dissection. The campaign used a fabricated CNN article and digitally manipulated photographs, aimed at deterring allied support for Ukraine. Russian propaganda outlets shared an AI-generated image falsely depicting a protest rally in Lviv in which participants wearing balaclavas hold a cardboard sign reading 'Cut down TRCs like cardboard', a reference to draft recruitment centres. AI detection service AI or Not assessed the image as artificially generated with 93 per cent probability. Taiwanese officials and researchers warn that Beijing weaponises Taiwan's political divisions through Mazu religious temple networks, subsidised trips to mainland China, and targeted digital campaigns to erode Taiwanese trust in the United States. Electoral data found that neighborhoods near urban temples showed greater shifts toward opposition candidates in 2018-2020. The European Commission issued preliminary DSA findings that TikTok violated platform safety obligations by allowing minor users to set accounts as publicly visible by default and by recommending content from users aged 16-17 to all platform users globally through the For You Feed. TikTok is required to restrict default account visibility for minors and cease global distribution of minor-generated content. The European Commission published guidelines on AI Act Article 50 transparency obligations, effective August 2nd 2026, requiring providers to inform users during direct AI interaction and add machine-readable marks to AI-generated content, with deployers required to disclose deepfakes, AI-generated public interest content, and emotion recognition systems. A NewsGuard audit found that leading AI chatbots reproduce pro-China false claims at significantly higher rates when queries are submitted in Mandarin than when identical topics are raised in English, indicating a language-dependent vulnerability in AI models' handling of politically sensitive content. A Graphika investigation documented over 300 assets across YouTube, Facebook, TikTok, and X deploying AI-generated personas to distribute commentary on geopolitics and world affairs. More than 140 YouTube channels hosted deepfakes impersonating journalists and academics, including Rachel Maddow and Col. Douglas Macgregor, with anti-Western and pro-China narratives recurring across discussions of the Russia-Ukraine conflict, Iran tensions, and the South China Sea. Multiple US election races in the 2026 midterm cycle feature AI-generated attack ads depicting candidates in fabricated scenarios, ranging from deepfake hotel footage to exaggerated cartoon villains. The trend raises concerns about voter manipulation through synthetic media, particularly among older demographics unfamiliar with AI generation technology. A NewsGuard analysis found that in the five days following US President Trump's July 16 address revisiting 2020 election fraud claims, posts on X claiming the 2020 election was rigged surged by 214 per cent, accumulating 77.7 million views. The number of individual accounts advancing stolen-election claims increased by 295 per cent to 218,000 accounts within the five-day window. Following Spain's defeat of Argentina in the 2026 FIFA World Cup final on July 19th, a fresh wave of viral false claims emerged. NewsGuard tracked at least 14 provably false claims circulating since the tournament began in June 2026, illustrating how major sporting events are routinely exploited as disinformation vectors. France became the first European Union country to approve a blanket social media ban for children under 15, with the law taking effect September 1st, 2026 for new account creation and enforcement on existing accounts beginning January 2027. All users must verify their age using privacy regulator-approved methods, and cell phones are also banned from high schools. NewsGuard debunked the viral claim that Coca-Cola and General Motors pulled advertising from NBC and ABC after the networks did not broadcast President Trump's July 16 election security address. NewsGuard identified Chevrolet commercials airing on both networks on July 19th, and both General Motors and Coca-Cola confirmed to NewsGuard on July 20th that no advertising withdrawal had occurred. [State Actors] Tiktok Commission Preliminary Finds TikTok in Breach of DSA for Failing to Ensure Safe Accounts for Minors A finding published by the European Commission states that preliminary findings under the Digital Services Act determined that TikTok violated platform safety obligations by allowing minor users to set their accounts as publicly visible by default and by recommending content from users aged 16 to 17 to all platform users globally through the For You Feed, with TikTok required to restrict minor account defaults so that content is visible only to accepted followers and to cease recommending minor-generated content to a global audience. The preliminary finding represents the most significant DSA enforcement action against TikTok since it was designated a Very Large Online Platform in 2023. If confirmed following TikTok's response period, the platform faces financial penalties of up to six per cent of its global annual turnover under DSA enforcement provisions. The European Commission separately opened formal DSA proceedings against TikTok in 2024 over its recommendation algorithms and alleged addictive design features; those proceedings remain ongoing and are independent of the current preliminary finding on minor account safety. Source: European Commission. Commission preliminary finds TikTok in breach of Digital Services Act for failing to ensure safe accounts for minors. [online] Published 24 July 2026. Available at: https://digital-strategy.ec.europa.eu/en/news/commission-preliminary-finds-tiktok-breach-digital-services-act-failing-ensure-safe-accounts-minors Top Of Page Russia Russia Concocts Ukrainian Torture A report published by NewsGuard states that a Russian influence campaign is spreading a fabricated Human Rights Watch report claiming that 43 anti-draft protesters in Lviv were tortured to death on the orders of President Zelensky, with the false claim originating from the Foundation to Battle Injustice, an organisation assessed to be controlled by Russian intelligence. The Foundation to Battle Injustice has been linked to multiple previous Russian-backed disinformation operations targeting Western audiences. By attributing the fabricated narrative to an entity designed to mimic the name and format of a legitimate international human rights body, the operation sought to exploit the credibility typically associated with organisations such as Human Rights Watch, enabling initial amplification through pro-Kremlin media ecosystems before independent fact-checkers could issue rebuttals. Source: NewsGuard. Russia Concocts Ukrainian Torture Footage to Feed Kremlin Narrative. [online] Published 22 July 2025. Available at: https://www.newsguardrealitycheck.com/p/russia-concocts-ukrainian-torture Top Of Page Moscow Exploits Poland-Ukraine Dispute Over OUN and UPA Legacy An analysis published by The Jamestown Foundation states that Russia exploited the Poland-Ukraine diplomatic dispute over the contested legacy of the Organisation of Ukrainian Nationalists and the Ukrainian Insurgent Army to conduct a coordinated cognitive warfare campaign, including GRU-linked operations paying Ukrainian refugees $100-$200 to hold destabilising protests in Poland, FSB-released purported archival documents amplifying the historical dispute, and coordinated digital vandalism of Google Maps across Poland, with Polish Foreign Minister Sikorski explicitly stating that Moscow was waging a full-scale cognitive war against Poland. The operation marks an escalation in Russia's use of pre-existing historical fault lines as cognitive warfare instruments against NATO-adjacent states. The OUN and UPA legacy represents one of the deepest points of tension in Polish-Ukrainian relations, making it a high-yield target for operations designed simultaneously to destabilise Polish domestic support for Ukrainian refugees, undermine Warsaw's backing for Kyiv, and fracture a strategically critical alliance on Russia's western flank at a moment when both countries are cooperating closely on defence and border security. Source: Jamestown Foundation. Moscow Exploits Poland–Ukraine Dispute Over OUN and UPA Legacy. [online] Published 22 July 2026. Available at: https://jamestown.org/moscow-exploits-poland-ukraine-dispute-over-oun-and-upa-legacy/ Top Of Page Ukraine Russian Propaganda Spreading Fakes About Death of US Senator Lindsey Graham A fact-check published by Ukrinform states that Russian propaganda outlets spread fabricated claims that US Senator Lindsey Graham was killed in Kyiv by a Russian Iskander missile strike targeting a drone facility, when in fact he died in Washington DC on July 11th from aortic dissection, with the campaign including a fabricated CNN article and digitally manipulated photographs of a Kyiv library renamed in his honour, designed to create the impression that Russia can target Western politicians and deter allied support for Ukraine. Senator Graham had been among the most prominent voices in the United States Senate advocating for continued military and financial assistance to Ukraine. The campaign's use of a fabricated CNN article, a format that presents false claims in the visual style of breaking news, and digitally altered imagery was designed to circulate rapidly on social media before platform moderation or journalistic verification could intervene, compressing the available window for correction and maximising exposure of the deterrence narrative to Western political audiences. Source: Ukrinform. Russian propaganda spreading fakes about death of U.S. Senator Lindsey Graham. [online] Published 19 July 2026. Available at: https://www.ukrinform.net/rubric-factcheck/4145861-russian-propaganda-spreading-fakes-about-death-of-us-senator-lindsey-graham.html Top Of Page Russian Propaganda Uses AI to Spread Fake Cardboard Protest Images A fact-check published by Ukrinform states that Russian propaganda outlets spread an AI-generated image falsely depicting a protest rally in Lviv in which participants wearing balaclavas hold a cardboard sign reading 'Cut down TRCs like cardboard', a reference to draft recruitment centers, with AI detection service AI or Not assessing the image as artificially generated with 93 percent probability, exploiting ongoing tensions surrounding Ukraine's military mobilisation. The fabricated image forms part of a recurring Russian information operation aimed at manufacturing visual evidence of anti-conscription sentiment within Ukraine for consumption by both domestic Ukrainian audiences and Western observers, intended to convey that opposition to mobilisation is broader than official reporting reflects. The use of AI generation enables low-cost, scalable production of synthetic protest imagery with sufficient visual plausibility to circulate on social media platforms before detection tools can flag it, exploiting the speed asymmetry between disinformation production and fact-checking response that characterises the current information environment. Source: Ukrinform. Russian propaganda uses AI to spread fake “cardboard protest” images. [online] Published 23 July 2026. Available at: https://www.ukrinform.net/rubric-factcheck/4147206-russian-propaganda-uses-ai-to-spread-fake-cardboard-protest-images.html Top Of Page China Taiwan Officials Warn Beijing Is Turning Taiwan's Political Divisions into Distrust A report published by The Epoch Times states that Taiwanese officials and researchers warn that Beijing is weaponising Taiwan's political divisions through religious networks, subsidised visits to mainland China, and digital campaigns to erode Taiwanese trust in the United States rather than build affinity toward China, with electoral data showing CCP influence operations have already shifted voting patterns in Kaohsiung and research finding that frequent users of China-based social media show elevated distrust of the US and increased identification with mainland China. Unlike earlier CCP influence operations in Taiwan that sought to build affirmative pro-mainland sentiment, the strategy identified by officials focuses primarily on eroding Taiwanese confidence in the United States as a credible and reliable security guarantor. Research cited in the report found that Taiwanese social media users with higher exposure to mainland Chinese platforms exhibited measurably lower trust in the US-Taiwan security relationship, indicating the operation is reshaping Taiwan's strategic calculus without requiring any positive identification with the mainland, a more operationally efficient objective that is also harder for Taiwanese authorities to counter through straightforward pro-democracy messaging. Source: The Epoch Times. Taiwan Officials Warn Beijing Is Turning Taiwan’s Political Divisions Into Distrust. [online] Published 28 July 2026. Available at: https://www.theepochtimes.com/china/taiwan-officials-warn-beijing-is-turning-taiwans-political-divisions-into-distrust-6067510 Top Of Page [AI Related Articles] Commission Publishes Guidelines on Transparency Obligations for AI Systems A guidelines published by the European Commission state that Article 50 transparency obligations under the EU AI Act take effect on August 2nd, 2026, requiring providers to design AI systems that inform users when they are interacting with AI and to add machine-readable marks to AI-generated or manipulated content, with deployers required to disclose deepfakes, AI-generated public interest content lacking human editorial control, and emotion recognition systems, a framework the Commission states will reduce the risk of deception and manipulation through synthetic media. The transparency obligation applies to any AI system generating or manipulating audio, image, video, or text content where the output could reasonably be mistaken for human-produced material, with specific exemptions for authorised law enforcement and national security applications. The machine-readable marking requirement is intended to work alongside automated platform detection tools, enabling social media and news distribution systems to flag synthetic content at scale, a mechanism the Commission characterises as necessary given the volume of AI-generated material that makes manual disclosure verification impractical across contemporary digital information ecosystems. Source: European Commission. Commission publishes guidelines on transparency obligations for providers and deployers of certain AI systems. [online] Published 20 July 2026. Available at: https://digital-strategy.ec.europa.eu/en/news/commission-publishes-guidelines-transparency-obligations-providers-and-deployers-certain-ai-systems Top Of Page In Chinese, AI Speaks Fluent Propaganda A report published by NewsGuard states that leading AI chatbots reproduce pro-China false claims at significantly higher rates when prompted in Mandarin than in English, indicating a language-dependent vulnerability that exposes Chinese-language users to disproportionate levels of CCP-aligned disinformation through mainstream AI tools. The audit tested chatbots from multiple providers on a range of politically sensitive topics including the Uyghur detention camps, the Tiananmen Square events of 1989, and Taiwan's political status. The report noted a particularly sharp deterioration in source quality for one audited model, which cited Russian state-affiliated media in every response to queries about the Russia-Ukraine conflict, a finding NewsGuard described as a significant regression from an earlier audit cycle in which the same model cited Russian state sources in only four per cent of equivalent responses, suggesting a measurable worsening of AI model reliability on contested geopolitical topics. Source: NewsGuard. In Chinese, AI Speaks Fluent Propaganda. [online] Published 21 July 2026. Available at: https://www.newsguardrealitycheck.com/p/in-chinese-ai-speaks-fluent-propaganda Top Of Page The Mass Production of AI Personas Weighing In on World Affairs A report published by Graphika states that an investigation into more than 300 accounts across YouTube, Facebook, TikTok, and X uncovered a network of AI-generated personas producing geopolitical commentary, with over 140 YouTube channels using deepfakes impersonating journalists and academics to spread anti-Western and pro-China narratives on the Russia-Ukraine conflict, Iran tensions, and the South China Sea, and more than 200 identified channels removed for violating platform terms of service. A single AI-generated persona was identified across 154 channels, predominantly producing finance and investment content, indicating a potential commercial monetisation motive operating alongside the geopolitical commentary function. While Graphika researchers could not definitively attribute the network to a single state or non-state actor, they noted that the consistent anti-Western and pro-China thematic framing across assets spanning multiple countries and languages is consistent with previously documented Chinese state-aligned influence infrastructure, and that YouTube's synthetic content disclosure labels, present on the identified videos, were absent on equivalent content distributed across other platforms in the network. Source: Graphika. Pundit by Prompt: The Mass Production of AI Personas Weighing In on World Affairs. [online] Published 21 July 2026. Available at: https://www.graphika.com/reports/pundit-by-prompt (Graphika) Top Of Page Voters Are Being Inundated by a Barrage of AI-Generated Election Ads A report published by Futurism states that multiple US election races in the 2026 midterm cycle feature AI-generated attack ads depicting candidates in fabricated scenarios, including deepfakes and cartoon-style caricatures, raising concerns about synthetic media manipulation of voters, particularly among older demographics unfamiliar with AI generation technology. The 2026 midterm cycle is the first US federal election in which AI-generated attack advertising has appeared at scale, with campaigns and affiliated political action committees using commercially available AI video generation tools to produce content that would previously have required professional production budgets. Several of the ads identified by Futurism carried no AI-generated content disclosure labels, and the Federal Election Commission has not issued binding rules on synthetic political advertising, creating a regulatory gap that currently allows AI-generated attack content to circulate in competitive races without mandatory transparency requirements. Source: Futurism. Voters Are Being Inundated by a Barrage of AI-Generated Conservative “Slop” Ads and Deepfakes. [online] Published 25 July 2026. Available at: https://futurism.com/artificial-intelligence/voters-elections-conservative-generative-ai-slop-ads-deepfakes Top Of Page [General Reports] 2020 Election Denial Is Back A report published by NewsGuard states that in the five days following President Trump's 16th July national address, posts on X claiming the 2020 US election was rigged or stolen surged by 214 per cent, reaching 77.7 million views, with the number of accounts advancing the narrative rising by 295 per cent from 55,100 to 218,000, and the content focused on Trump's claims that widespread fraud occurred in 2020 and that China acquired and exploited American voter data. Trump's address included a new allegation that China had acquired and exploited American voter data, a claim for which no supporting evidence was presented and which NewsGuard assessed as false. The 609,000 posts recorded in the five-day window following the address collectively accumulated more than 77.7 million views on X, with the platform's algorithmic amplification of content from high-follower accounts accelerating the narrative's reach beyond what organic sharing alone would have produced, representing, according to NewsGuard's tracking data, the largest single-event surge in 2020 election denial content since the certification of the election result in January 2021. Source: NewsGuard. 2020 Election Denial Is Back. [online] Published 21 July 2026. Available at: https://www.newsguardrealitycheck.com/p/2020-election-denial-is-back Top Of Page World Cup Ends, Bogus Claims Don't A report published by NewsGuard states that Spain's victory over Argentina in the 2026 FIFA World Cup final on July 19th triggered a fresh wave of viral false claims, bringing to 14 the total number of provably false narratives NewsGuard has tracked since the tournament began in June 2026, illustrating how major international sporting events are routinely exploited as vectors for coordinated disinformation. The pattern reflects a consistent dynamic in which high-profile international sporting events function as disinformation amplification environments: peak audience engagement, intense emotional stakes, and dense social media activity create conditions in which fabricated narratives spread rapidly ahead of correction, and content posted within the first minutes after a major result can accumulate millions of views before fact-checkers can respond. NewsGuard noted that the false claims circulating the 2026 World Cup span a range of categories including fabricated match incidents, invented player conduct, and false reports of off-field events, with the majority achieving initial viral spread on social media before migrating to low-credibility news websites. Source: NewsGuard. World Cup Ends, Bogus Claims Don't. [online] Published 22 July 2026. Available at: https://www.newsguardrealitycheck.com/p/world-cup-ends-bogus-claims-dont Top Of Page French Parliament Greenlights Social Media Ban for Under-15s A report published by The Record states that France became the first European Union country to approve a blanket social media ban for children under 15, with the law taking effect September 1st, 2026 for new account creation, requiring all users to verify their age using regulator-approved methods, with critics including Amnesty International arguing that governments should instead regulate harmful engagement-based algorithms rather than implement blanket bans. Research into Australia's analogous ban, introduced in December 2025, found that significant numbers of teenagers remained on social media through circumvention methods including VPN use, accounts created by older contacts, and falsified date-of-birth entries. The French legislation mandates regulator-approved identity verification rather than self-declaration, which proponents argue is more enforceable than the Australian model; privacy advocates have raised concerns that identity-linked verification creates disproportionate data exposure for all users, including adults who must submit to the same process, and the European Commission has indicated it is evaluating a bloc-wide equivalent ban for users under 13. Source: The Record. French Parliament greenlights social media ban for under-15s. [online] Published 22 July 2026. Available at: https://therecord.media/france-social-media-ban-parliament Top Of Page The Pro-Trump Ad Boycott that Never Happened A fact-check published by NewsGuard states that the viral claim that Coca-Cola and General Motors withdrew advertising from NBC and ABC after the networks declined to air President Trump's July 16th election security address is false, with NewsGuard identifying Chevrolet commercials airing on both networks on July 19th and both General Motors and Coca-Cola confirming to NewsGuard on July 20th that no such withdrawal had taken place. The false boycott narrative followed a documented disinformation template in which a politically charged media event is rapidly followed by fabricated corporate response claims designed to cast the event in binary partisan terms before the named companies can publicly respond. The speed with which the General Motors and Coca-Cola claims circulated illustrates how the disinformation production cycle increasingly outpaces corporate communications, with both companies forced to issue formal denials to NewsGuard several days after the false claim had already achieved substantial social media penetration, a pattern NewsGuard has documented in multiple prior episodes involving major brands and controversial media coverage decisions. Source: NewsGuard. The Pro-Trump Ad Boycott That Never Happened. [online] Published 24 July 2026. Available at: https://www.newsguardrealitycheck.com/p/the-pro-trump-ad-boycott-that-never Top Of Page [CRC Glossary] The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult. To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence. As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website. Top Of Page

  • Cyber based influence campaigns 13th – 19th July 2026 Report

    [Introduction] Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW). Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc. During the 13th to the 19th July 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities. [Contents] [Introduction] [Report Highlights] [Report Summary] [State Actors] Russia EU Sanctions Expose Funding Mechanism Behind Pro-Russian Influencer Russia's New Decentralized Propaganda Infrastructure NATO Condemns Russia's Persistent Malicious Cyber Activities Targeting Allies Ukraine Despite Ukraine's Victories, False Narratives About The War Persist One Fake Photo Let Russian Propaganda Cast Doubt on the Kyiv Lavra Strike China Chinese Operation Disrupts Anti-CCP Events in the US and Europe Iran Iran's Faked Military Triumphs Anatomy of an Iran-Aligned Influence Network on X War in Gaza Digital Campaign Debunks Israel's Narrative About Gaza Ceasefire [AI Related Articles] xAI Sues Grok User Who Generated Estimated 3 Million Sexualized AI Images The Problem AI Content Moderation Cannot Solve YouTube Wiped 35 Million Subscribers Over AI Slop [General Reports] Sudden Death, Sudden Conspiracies 380 False Election Claims and Counting A Voter Guide to Trump's Election Claims State Officials, Election Experts Pan Trump Speech [Appendix - Frameworks to Counter Disinformation] A Year of Innovations in Counter-Disinformation Tooling France Plans to Triple Penalties for AI-Driven Election Disinformation AI Content Labelling Enforcement Begins in 24 Days [CRC Glossary] [ Report Highlights] NATO issued a formal condemnation on July 13th, 2026, of Russia's persistent malicious cyber activities targeting member states and partners, coinciding with EU sanctions on entities supporting information manipulation, signalling a coordinated Western escalatory response to Russian hybrid operations. The Jamestown Foundation exposed the dual-funding mechanism behind pro-Russian influencer Alexandra Jost: RT's parent TV-Novosti paid approximately EUR 1,840 monthly while the Kremlin-linked Presidential Foundation for Cultural Initiatives channelled additional grants, demonstrating the systematic financial architecture behind Moscow's English-language information operations. Graphika documented Chinese state-linked operation Spamouflage deploying a novel tactic on July 13th, 2026, distributing manipulated event flyers to disrupt anti-CCP gatherings in the US and Europe organised by Safeguard Defenders and pro-Tibet and Uyghur groups, marking an escalation toward direct transnational repression via coordinated inauthentic behaviour. NewsGuard's Reality Check confirmed that pro-Iran accounts posted an AI-generated video falsely depicting missiles striking a US Navy aircraft carrier, with multiple visual inconsistencies exposing the content as synthetically manufactured, a documented escalation in Iran's use of generative AI for false military triumph claims. xAI filed a lawsuit against a Grok user who generated an estimated 3 million sexualized AI images, including 23,000 minors, during 11 days, even as the Center for Countering Digital Hate documented the scale of the platform's systemic guardrail failures. False war narratives about Ukraine proliferated across algorithm-assisted echo chambers, with Forbes documenting how far-left and far-right voices converge on pro-Russian defeat narratives despite battlefield evidence to the contrary, and the Kyiv Independent revealing how a single AI-flagged image enabled Kremlin propagandists to weaponise Meta's own moderation system against accurate reporting. The EU DisinfoLab newsletter documented two new Russian FIMI infrastructure operations, Roska Bridge (exploiting Mastodon and Bluesky cross-posting automation to evade moderation) and Hahaganda (weaponised mockery across European networks), alongside France's proposal to triple criminal penalties for election disinformation and Canada's introduction of the Safe Social Media Act. A coordinated counter-narrative campaign launched July 16th 2026 under '#They Lied to You' challenged the international media framing of a Gaza ceasefire, with participants including journalists and civil defence workers documenting that Israeli military operations had expanded to 70% of Gaza's territory, exceeding the 53% stipulated in the ceasefire agreement. [ Report Summary] The EU sanctioned US citizen Alexandra Jost for disseminating disinformation about Russia's invasion of Ukraine, revealing a dual-funding structure from RT's parent company and Kremlin-linked cultural foundations. EU DisinfoLab documented two new Russian information manipulation operations exploiting decentralised social platforms and weaponised humour, alongside an EU Court ruling that RT sanctions apply to free streaming websites. The North Atlantic Council issued a formal statement condemning Russia's sustained cyber operations against NATO members and partners, committing to enhanced collective cyber defence and integrated countermeasures. A Forbes analysis documents how far-left and far-right voices converge on false narratives predicting Ukrainian defeat, serving Russian information warfare purposes through algorithm-assisted echo chambers despite contradictory battlefield evidence. Russian propagandists exploited a potentially AI-generated image of the burning Dormition Cathedral to construct a false staged-attack narrative, temporarily causing Meta to apply false-information labels to accurate reporting. Graphika documented Spamouflage deploying a novel tactic of distributing manipulated event flyers to disrupt anti-Communist Party gatherings organised by civil society groups in the US and Europe. Pro-Iran accounts posted AI-generated video falsely depicting missiles striking a US Navy aircraft carrier, with visual inconsistencies confirming the content as synthetically manufactured disinformation. ShadowGraph Intelligence documented a 21-account coordinated inauthentic behaviour network generating 48.6 million engagements and an estimated 5-10 billion views over six months, deploying fabricated quote overlays on video to spread pro-Iran, anti-US, and anti-Israel narratives on X. A coordinated counter-narrative campaign using '#They Lied to You' challenged international media framing of a Gaza ceasefire, with participants documenting that Israeli operations had expanded to 70% of Gaza's territory. xAI filed a lawsuit against a user who weaponised Grok to generate an estimated 3 million sexualized deepfake images, including 23,000 of minors, as the platform faces multiple lawsuits over systemic guardrail failures. A Rest of World analysis argues that AI content moderation fails to protect women from image-based abuse because it cannot account for consent or evaluate cultural context, calling for consent-based human moderation frameworks. YouTube's enforcement of its renamed 'inauthentic content' policy wiped 35 million subscribers from AI-generated channels, establishing a new standard requiring genuine human editorial judgment for content to qualify for distribution. NewsGuard documented how baseless conspiracy theories about Senator Lindsey Graham's death from cardiovascular disease spread immediately on social media, including false claims he was killed by Russian missiles. NewsGuard's tracking of false election claims reached 380 as President Trump fired two Democratic members of the US Election Assistance Commission, raising concerns about systematic dismantling of election integrity infrastructure. NewsGuard produced a voter guide fact-checking Trump's election security claims, finding that documents cited in a primetime speech did not support the assertions made about Chinese interference and noncitizen voter registration. State election officials and security experts dismissed Trump's primetime election fraud address as unsupported by evidence, documenting how federal dismantling of election security infrastructure compounds the threat from foreign influence operations. CheckFirst documented a year of advances in counter-disinformation infrastructure, including the IMS attribution framework, the Tutki OSINT training platform, and the CheckFirst Import Connector for monitoring the Pravda network. French Prime Minister Lecornu announced legislation to triple criminal penalties for disseminating false information during electoral periods, establishing a permanent public information commission and extending emergency judicial removal procedures. The EU AI Office confirmed the Code of Practice on AI-Generated Content as an adequate compliance mechanism under Article 50 of the EU AI Act, with binding deepfake labelling and disclosure obligations becoming enforceable on 2 August 2026. [State Actors] Russia EU Sanctions Expose Funding Mechanism Behind Pro-Russian Influencer An article published by The Jamestown Foundation states that the European Union sanctioned Alexandra Jost, a US citizen based in Russia operating the 'Sasha Meets Russia' social media account, for disseminating disinformation justifying Russia's invasion of Ukraine, with the sanctions revealing a dual funding structure: approximately EUR 1,840 monthly from TV-Novosti (RT's parent company) and grants channelled through the Russian Presidential Foundation for Cultural Initiatives via public relations agency Limitless. Jost's effectiveness as a Kremlin propaganda vector derives from her native English-speaking status and casual content format, which appear less overtly propagandistic than state media, while her rebuilt X account has accumulated 67,400 followers since April 2025, with individual posts generating between 20,000 and 1.9 million views. An article published by The Jamestown Foundation states that while EU sanctions increase operational costs for pro-Russian influencers, platform access rather than legal designation ultimately determines reach, as demonstrated by Jost's capacity to rebuild her following after earlier deplatforming. The analysis reveals that Russia allocated EUR 420 million in additional state media funding and EUR 16 million to pro-war cultural projects in 2023 alone, signalling an escalating Kremlin investment in English-language information operations designed to justify territorial occupation and delegitimise Western support for Ukraine through apparently organic civilian voices. Source: The Jamestown Foundation. EU Sanctions Expose Funding Mechanism Behind Pro-Russian Influencer. [online] Published 10 July 2026. Available at: https://jamestown.org/eu-sanctions-expose-funding-mechanism-behind-pro-russian-influencer/ Top Of Page Russia's New Decentralized Propaganda Infrastructure A newsletter published by EU DisinfoLab states that Russia's Foreign Information Manipulation and Interference operations have deployed two new sophisticated technical evasion tactics: 'Roska Bridge' weaponises decentralised social platforms Mastodon and Bluesky by exploiting the Brid.gy cross-posting service's functionality to automatically distribute pro-Kremlin propaganda while circumventing moderation, and 'Hahaganda' deploys coordinated psychological operations using weaponised mockery across European networks to reinforce disinformation narratives through humour. The EU Court of Justice simultaneously clarified that sanctions against Russia Today apply to free websites and streaming services, yet RT has already evaded these restrictions by establishing new accounts on X. A newsletter published by EU DisinfoLab states that democratic governments are strengthening enforcement responses to these operations: France's Prime Minister proposed legislation tripling criminal penalties for election disinformation and expanding expedited judicial content takedown procedures, Canada introduced the Safe Social Media Act (Bill C-34) establishing a Digital Safety Commission with powers to mandate deepfake labelling and enforce platform accountability, and the UK government implemented institutional boycotts of X following violent unrest. Research cited in the newsletter found that Meta's network contained over 634,000 fraudulent advertisements generating billions of impressions through media brand impersonation, while X's Community Notes mechanism was found to systematically under-moderate election disinformation. Source: Disinfo.eu (EU DisinfoLab). Disinfo Update 15/07/2026. [online] Published 15 July 2026. Available at: https://www.disinfo.eu/disinfo-update-15-07-2026/ Top Of Page NATO Condemns Russia's Persistent Malicious Cyber Activities Targeting Allies A statement published by NATO states that the North Atlantic Council formally condemned Russia's persistent malicious cyber activities targeting NATO member states, partners, and critical national infrastructure, noting that Russian cyber actors exploit state-sponsored infrastructure to conduct operations constituting a threat to Allied security. The statement references coordinated international responses including UK and EU sanctions against individuals and entities supporting Russian cyber operations, and commits NATO to employing its full operational spectrum to deter, defend against, and counter cyber threats. A statement published by NATO states that the alliance's collective cyber defence posture will be enhanced and cyber capabilities integrated across NATO operations in response to Russia's sustained targeting of Allied governments, infrastructure, and information systems. The condemnation, issued on the same date that the EU imposed sanctions on entities responsible for information manipulation activities, reflects a coordinated Western response positioning Russian cyber operations and information warfare as interconnected hybrid threats requiring aligned multilateral countermeasures. Source: NATO. Statement of Condemnation by the North Atlantic Council of Russia’s Malicious Cyber Activities. [online] Published 13 July 2026. Available at: https://www.nato.int/en/about-us/official-texts-and-resources/official-texts/2026/07/13/statement-of-condemnation-by-the-north-atlantic-council-of-russias-malicious-cyber-activities Top Of Page Ukraine Despite Ukraine's Victories, False Narratives About the War Persist An article published by Forbes states that false narratives predicting Ukrainian defeat persist across the political spectrum despite documented battlefield successes including Ukrainian drone campaigns that have degraded Russian oil refining capacity to 65% of seasonal consumption levels. Influential figures including academics, journalists, and former diplomats continue to argue that 'NATO expansionism led to the Russian invasion' or that Ukraine faces inevitable defeat, with these narratives converging across far-left and far-right perspectives despite their ideological differences. An article published by Forbes states that these convergent defeat narratives operate through 'algorithm-assisted echo chambers' that amplify pro-Russian framing to mainstream audiences, with the arguments lacking evidentiary support yet serving Russian information warfare purposes by normalising surrender as the only rational outcome. The analysis notes that Ukraine has successfully resisted what was described as the world's second-strongest military for over four years, a record that directly contradicts the defeat narratives still circulating in influential media and academic spaces, indicating these narratives function as sustained disinformation rather than evidence-based strategic assessment. Source: Forbes. Despite Ukraine’s Victories, False Narratives About the War Persist. [online] Published 16 July 2026. Available at: https://www.forbes.com/sites/marktemnycky/2026/07/16/despite-ukraines-victories-false-narratives-about-the-war-persist/ Top Of Page One Fake Photo Let Russian Propaganda Cast Doubt on the Kyiv Lavra Strike An investigation published by Kyiv Independent states that Russian propaganda platforms exploited a photograph of the Dormition Cathedral burning during Russia's 15 June 2026 missile strike, an image OpenAI's detection tools flagged as containing SynthID watermarks suggesting AI generation or editing, to construct a false narrative that Ukrainian photographers had staged the attack by setting up filming positions in advance. Pro-Kremlin accounts circulated the cathedral image alongside two AI-generated photographs falsely depicting journalists preparing the scene, causing Meta to initially restrict posts about the attack due to a technical error linking legitimate reporting to an AFP fact-check examining the AI-generated imagery. An investigation published by Kyiv Independent states that StopFake.org's Olga Yurkova explained the standard propaganda methodology: 'propagandists first establish a narrative and then create visual evidence' to support predetermined false conclusions, with AI-generated content enabling rapid production of fabricated visual 'proof' during critical moments when information environments are most contested. Meta subsequently removed the false-information labels after acknowledging the algorithmic error, a sequence that demonstrates how AI-generated disinformation can briefly weaponise platform safety systems against accurate reporting, creating a window of amplified confusion precisely when factual information about attacks on civilian and cultural infrastructure is most needed. Source: The Kyiv Independent. How One Fake Photo Let Russian Propaganda Cast Doubt on Kyiv Lavra Strike. [online] Published 7 July 2026. Available at: https://kyivindependent.com/how-one-fake-photo-let-russian-propaganda-cast-doubt-on-kyiv-lavra-strike/ Top Of Page China Chinese Operation Disrupts Anti-CCP Events in the US and Europe A report published by Graphika states that the Chinese state-linked influence operation Spamouflage deployed a novel disruption tactic in mid-2026, disseminating manipulated versions of event flyers across Facebook and X to interfere with anti-Communist Party of China events organised by Safeguard Defenders and pro-Tibet and Uyghur civil society groups in the US and Europe. The operation used inauthentic accounts to distribute the manipulated materials, representing the first documented instance of Spamouflage using this specific method to hinder event participation and obstruct civil society gatherings critical of Chinese government policies. A report published by Graphika states that this shift toward event disruption reflects an escalation in transnational repression tactics, as Chinese state actors move beyond diplomatic pressure and toward direct coordinated interference with diaspora civil society activities on Western soil. Analysts assess this tactic could extend to election interference and other forms of transnational repression, as the manipulation of event flyers, combined with coordinated inauthentic amplification, demonstrates a scalable method for sowing confusion and discouraging participation in events challenging Chinese Communist Party narratives without requiring the operational sophistication of more traditional influence operation infrastructure. Source: Graphika. Save the Date for Spamouflage. [online] Published 13 July 2026. Available at: https://www.graphika.com/reports/save-the-date-for-spamouflage Top Of Page Iran Iran's Faked Military Triumphs A briefing published by NewsGuard states that pro-Iran accounts posted an AI-generated video on multiple social media platforms falsely depicting missiles striking a US Navy aircraft carrier, with multiple visual inconsistencies pointing to the video's inauthenticity, including unnatural explosion dynamics and compositional artefacts characteristic of AI video generation. The fabricated footage circulated widely during a period of elevated US-Iran tensions, consistent with Iran's documented pattern of deploying synthetic media to claim false military triumphs and project deterrence capability beyond what its actual military operations have achieved. A briefing published by NewsGuard states that the dissemination of fabricated military victory footage reflects a broader Iranian information strategy documented in the 2025-2026 conflict period: IRGC-linked Telegram channels and state media amplify AI-generated imagery depicting false strikes on US military assets to maintain domestic morale and project international deterrence, even as independent verification systematically debunks the claims. The pattern indicates that synthetic media has become a primary instrument of Iranian strategic communication, enabling the regime to manufacture the appearance of military effectiveness in the information environment independently of operational outcomes on the ground. Source: NewsGuard Reality Check. Iran’s Faked Military Triumphs. [online] Published 16 July 2026. Available at: https://www.newsguardrealitycheck.com/p/irans-faked-military-triumphs Top Of Page Anatomy of an Iran-Aligned Influence Network on X A report published by ShadowGraph Intelligence states that a 21-account coordinated inauthentic behaviour network aligned with Iranian interests operated on X between 18 January and 18 July 2026, generating approximately 137,000 posts drawing 48.6 million engagements, with reverse-engineered impression modelling estimating 5 to 10 billion total views, equivalent to USD 30 to 65 million in earned media value at standard US news advertising rates. The three anchor accounts, @GBC_Press, @IRGC_Press, and @IRGC_Global, were batch-created within 40 minutes on 9 April 2026, with 15 of the 21 accounts created during March and April 2026, all carrying purchased blue verification, generic press branding, and identical 'West Asia' location designations constituting a shared manufactured fingerprint. A report published by ShadowGraph Intelligence states that the network's primary fabrication method involved overlaying manufactured quotes onto unrelated video footage: the flagship example saw @GBC_Press falsely attribute to Israeli Prime Minister Netanyahu a threat of 'sudden power outages, and train accidents' against Spain, a quote absent from the attached video, achieving 4.3 million views, while @IRGC_Global falsely attributed a nuclear threat statement to North Korean leader Kim Jong-Un drawing 4.4 million views. Author Travis Hawley, a former NSA and US Air Force Intelligence Officer, assessed Iran-alignment at high confidence based on content, branding, and regional placement, while explicitly noting that definitive state attribution would require legal process accessing platform registration records, a distinction that highlights the evidentiary limits of open-source attribution even in high-confidence cases of coordinated inauthentic behaviour. Source: Shadowgraph Intelligence. Iran-Aligned Influence Network on X. [online] Available at: https://shadowgraphintel.com/reports/iran-aligned-influence-network-on-x/ Top Of Page War in Gaza Digital Campaign Debunks Israel's Narrative About Gaza Ceasefire An article published by Middle East Monitor states that activists launched a coordinated social media campaign on July 16th, 2026, using the hashtag '#They Lied to You' in Arabic and English, mobilising journalists, humanitarian workers, children from Gaza, and international supporters to challenge the international media framing that a ceasefire had ended hostilities. Civil Defence spokesperson Mahmoud Basal stated, 'They lied to you when they said there was a ceasefire in Gaza; what kind of ceasefire is this when children are still being killed,' with participants sharing video content and written posts documenting continued deaths, displacement, and destruction. An article published by Middle East Monitor states that the campaign directly challenged official ceasefire claims by presenting ground-level evidence of ongoing Israeli military operations, with the Gaza Health Ministry reporting that ceasefire violations had killed 1,127 Palestinians and wounded 3,643 as of the reporting date. Participants emphasised that Israeli territorial control had expanded to 70% of Gaza's total area, exceeding the 53% stipulated in the ceasefire agreement, using the attention gap created by reduced international media coverage as a vector to reinvigorate global awareness of what the campaign described as a systematic misrepresentation of the conflict's status. Source: Middle East Monitor (MEMO). Digital Campaign Debunks Israel’s Narrative About Gaza Ceasefire. [online] Published 19 July 2026. Available at: https://www.middleeastmonitor.com/20260719-digital-campaign-debunks-israels-narrative-about-gaza-ceasefire/ Top Of Page [AI Related Articles] xAI Sues Grok User Who Generated Estimated 3 Million Sexualized AI Images An article published by Futurism states that xAI filed a lawsuit against Terry Wayne Harwood, a 67-year-old South Carolina resident, alleging he used Grok across multiple accounts to generate nonconsensual sexual deepfakes of minors and women by circumventing safety guardrails through modified prompts in a 'calculated scheme to weaponize Plaintiff's tool for criminal ends.' The lawsuit occurs within a broader crisis: the Center for Countering Digital Hate documented that for 11 days, Grok generated an estimated 3 million sexualized images, including 23,000 of children, with multiple additional lawsuits against xAI pending from Tennessee teenagers and other victims. An article published by Futurism states that while xAI reports suspending 52,222 accounts and making 73,604 reports to the National Center for Missing and Exploited Children in 2026, litigation against individual users does not address the underlying guardrail failures that enabled abuse at this scale, with law enforcement and child safety experts reporting that AI-generated child sexual abuse material has created overwhelming investigative challenges. The case illustrates a structural tension in AI enforcement: platform liability claims focus on user misuse while systemic model-level vulnerabilities that enabled mass generation of illegal content remain the proximate cause, a distinction with significant implications for both regulatory frameworks and platform accountability standards. Source: Futurism. Elon Musk’s xAI Sues Grok User Over Deepfakes. [online] Published 15 July 2026. Available at: https://futurism.com/artificial-intelligence/elon-musk-xai-sues-grok-user-deepfakes Top Of Page The Problem AI Content Moderation Cannot Solve An article published by Rest of World states that Meta's launch of Muse Image, an AI tool enabling manipulation of public Instagram users' photos without consent, exemplifies a fundamental flaw in automated content moderation: platforms define harmful content through Western-centric definitions focusing solely on explicit sexual content, while research from Chayn in Pakistan and diaspora communities reveals that everyday images including photos without headscarves, wedding videos, and pictures with male classmates are weaponised to damage women's reputations and relationships in ways current policies fail to recognise. Image-based abuse is documented as 'one of the fastest-growing forms of technology-facilitated gender-based violence,' yet AI moderation systems remain blind to the contextual harm of non-explicit images when deployed across different cultural environments. An article published by Rest of World states that the core limitation of AI content moderation is that 'AI cannot account for consent': while automated systems expedite content identification and removal, they cannot evaluate the contextual factors essential for protecting marginalised communities from targeted image-based harassment. The author argues that platforms must shift toward consent-based frameworks requiring trained human moderators capable of understanding cultural context and intent, an approach that would prove more effective across borders and languages than purely algorithmic solutions, and would address not just the content itself but the violation of autonomy inherent in unauthorised image sharing and AI-powered manipulation of individuals' likenesses. Source: Rest of World. The Problem AI Content Moderation Cannot Solve. [online] Published 16 July 2026. Available at: https://restofworld.org/2026/ai-content-moderation-consent-muse/ Top Of Page YouTube Wiped 35 Million Subscribers Over AI Slop An article published by TechTimes states that YouTube renamed its 'repetitious content' policy to 'inauthentic content' in July 2025 to better reflect that mass-produced content has always been ineligible for monetisation, with enforcement accelerating through 2026: the platform permanently terminated 11 channels and wiped content from 5 others in January 2026, erasing a combined 35 million subscribers and an estimated USD 10 million in annual advertising revenue. A Kapwing study of 15,000 trending channels found 278 producing exclusively AI-generated content with a combined 63 billion views and an estimated USD 117 million in annual revenue, illustrating the scale of the content category the enforcement actions are targeting. An article published by TechTimes states that YouTube's VP of Trust and Safety outlined three specific policy buckets determining eligibility for the YouTube Partner Program, with the new framework establishing that content must reflect 'genuine human editorial judgment' to qualify for distribution and monetisation, a standard that directly addresses the use of AI systems to generate high volumes of templated, repetitive content at industrial scale. While YouTube maintains a tool-agnostic stance on AI-assisted creation, the enforcement wave signals that platforms are developing operational frameworks distinguishing between AI tools that enhance human creativity and AI systems that replace human judgment entirely, with significant implications for the broader ecosystem of AI-generated information content. Source: Tech Times. YouTube Wiped 35M Subscribers Over AI Slop: Now It's Judging Your Taste. [online] Published 15 July 2026. Available at: https://www.techtimes.com/articles/320629/20260715/youtube-wiped-35m-subscribers-over-ai-slop-now-its-judging-your-taste.htm Top Of Page [General Reports] Sudden Death, Sudden Conspiracies A briefing published by NewsGuard states that Senator Lindsey Graham's death from a tear in his aorta due to arteriosclerotic cardiovascular disease triggered an immediate wave of baseless conspiracy theories across social media platforms, including false claims that Graham was killed by Russian missiles, a fabricated narrative that spread before official cause of death information was publicly confirmed. The speed and content of the conspiracy narratives demonstrate the established pattern by which sudden deaths of prominent figures generate coordinated disinformation within hours, exploiting the information vacuum before verified reporting reaches mass audiences. A briefing published by NewsGuard states that the Graham death conspiracy cycle illustrates how social media platforms' algorithmic amplification of emotionally resonant content enables false narratives to achieve significant reach before fact-checking responses can counteract them, with platform recommendation systems rewarding engagement-generating claims regardless of their verifiability. The episode is consistent with documented patterns in which sudden-death disinformation serves multiple functions: generating traffic for low-credibility outlets, testing the receptiveness of audiences to specific false narratives, and exploiting public grief to embed conspiratorial frameworks that persist beyond the immediate news cycle. Source: NewsGuard Reality Check. Sudden Death, Sudden Conspiracies. [online] Published 15 July 2026. Available at: https://www.newsguardrealitycheck.com/p/sudden-death-sudden-conspiracies Top Of Page 380 False Election Claims and Counting A briefing published by NewsGuard states that the organisation's tracker of false claims related to US elections reached 380 tracked narratives as President Trump fired two Democratic members of the US Election Assistance Commission on July 9th 2026, an action that raised significant concerns about the integrity of federal election oversight infrastructure. The tracker documents the persistent volume and diversity of false election narratives circulating in the US information environment, spanning claims about ballot integrity, voter fraud, foreign interference, and electoral system security. A briefing published by NewsGuard states that the removal of Election Assistance Commission members, career officials whose role includes certifying voting systems and providing technical assistance to states, represents the latest in a series of actions that election security experts characterize as a systematic dismantling of the federal infrastructure designed to identify and counter both domestic election disinformation and foreign influence operations targeting US elections. The context of 380 tracked false claims circulating simultaneously with institutional changes to election oversight bodies creates a compounding challenge for fact-checkers and election officials attempting to maintain public confidence in electoral processes ahead of the 2026 midterm elections. Source: NewsGuard's Reality Check. 380 False Election Claims and Counting. [online] Published 15 July 2026. Available at: https://www.newsguardrealitycheck.com/p/380-false-election-claims-and-counting Top Of Page A Voter Guide to Trump's Election Claims A briefing published by NewsGuard states that an 18-month federal investigation led by former journalist John Solomon yielded no evidence supporting Trump administration claims that the 2020, 2022, or 2024 elections were compromised by fraud, while the administration's central allegation, that hundreds of thousands of noncitizens were registered across four states, contradicts state audits consistently finding only single- or double-digit numbers of such cases per state. Multiple courts unanimously rejected federal attempts to forcibly obtain state voter data, and state officials across party lines characterised the administration's actions as federal overreach. A briefing published by NewsGuard states that Trump's primetime address on election security rehashed previously debunked claims about alleged Chinese interference in the 2020 election without presenting new evidence, with election security experts including David Becker of the Center for Election Innovation and Research characterising the speech as delivering 'a dud' despite White House promises of a 'bombshell.' The guide documents the pattern of claims alongside expert assessments and official state-level rebuttals, providing a structured counter-narrative resource for voters seeking verified information about election integrity amid an intensifying domestic disinformation environment targeting public confidence in electoral institutions. Source: NewsGuard Reality Check. A Voter Guide to Trump’s Election Claims. [online] Published 17 July 2026. Available at: https://www.newsguardrealitycheck.com/p/a-voter-guide-to-trumps-election Top Of Page State Officials, Election Experts Pan Trump Speech An article published by CyberScoop states that state officials and election security experts uniformly rejected President Trump's July 17th 2026 primetime address on alleged election fraud, with David Becker of the Center for Election Innovation and Research stating 'The White House promised a bombshell and they delivered a dud', an assessment shared by Nevada Democratic Secretary of State Francisco Aguilar who pushed back forcefully against the federal administration's characterisation of state election systems as compromised. An 18-month federal investigation found zero evidence that the 2020, 2022, or 2024 elections were compromised by the fraud categories described in the speech. An article published by CyberScoop states that the Trump administration's removal of all three Election Assistance Commission commissioners and systematic dismantling of federal election security infrastructure, including elimination of CISA's election security initiatives and cessation of state-level threat intelligence sharing, has created structural vulnerabilities that foreign actors are already exploiting through information environment manipulation. Election officials characterised the concurrent actions, spreading unsubstantiated fraud narratives while removing the institutional infrastructure designed to counter actual foreign interference, as compounding threats to electoral integrity that operate through different mechanisms but produce a common outcome: reduced public confidence in the legitimacy of democratic processes. Source: CyberScoop. State Officials, Election Experts Pan Trump Speech: ‘This Is What Desperation Looks Like’. [online] Published 17 July 2026. Available at: https://cyberscoop.com/state-officials-election-experts-pan-trump-voter-fraud-speech-call-it-desperation/ Top Of Page [Appendix - Frameworks to Counter Disinformation] A Year of Innovations in Counter-Disinformation Tooling An article published by CheckFirst states that the organisation adopted the Information Manipulation Set (IMS) framework alongside EU DisinfoLab, Viginum, Cassini, and other partners to standardise documentation, attribution, and response to coordinated disinformation campaigns, an approach that enabled investigations including into Roska Bridge, a pro-Russian IMS exploiting decentralised platforms, and novel OSINT work mapping Russian intelligence units through medal symbols and insignia analysis. The IMS framework represents an advance in the counter-disinformation field's capacity to attribute campaigns to specific actor networks rather than documenting individual incidents in isolation. An article published by CheckFirst states that the organisation also strengthened educational and community counter-disinformation infrastructure through the Tutki specialised OSINT training platform, deployed in Armenian and French contexts to equip journalists and civil society with skills for recognising foreign information manipulation, alongside the launch of the CheckFirst Import Connector on OpenCTI for automated monitoring of the Pravda disinformation network, joining the Internet Watch Foundation, and establishing ObSINT as a Finnish NGO. These operational developments reflect an expanding ecosystem of specialised counter-disinformation organisations building shared infrastructure and technical capacity to monitor, attribute, and respond to information manipulation at the speed required to counter modern automated FIMI operations. Source: CheckFirst. CheckFirst’s 6th Birthday: A Year of Innovations. [online] Published 16 July 2026. Available at: https://checkfirst.network/checkfirsts-6th-birthday-a-year-of-innovations/ Top Of Page France Plans to Triple Penalties for AI-Driven Election Disinformation An article published by The Next Web states that French Prime Minister Sebastien Lecornu announced legislation scheduled for Council of Ministers review in late July 2026 to triple criminal penalties for producing false information content during electoral periods, characterised by Lecornu as a 'sacred' time for democracy, with additional provisions extending emergency judicial content removal procedures to all local elections and establishing a permanent public information commission to alert media, judges, and citizens when electoral interference is detected. The bill builds on France's 2018 disinformation law and responds to concerns about AI-driven manipulation and foreign interference ahead of the presidential campaign. An article published by The Next Web states that critics raise fundamental questions about defining falsity and state authority over political speech, noting that 'vague standards and state-appointed bodies risk chilling legitimate speech, especially during the charged weeks of a campaign,' with France's prior experience of court-constrained content removal orders, including orders requiring removal within one hour that were subsequently limited by constitutional courts, demonstrating that content-regulation statutes frequently encounter judicial limits. The legislation's final wording will determine whether the proposed commission functions as a warning mechanism or becomes an instrument of speech control, a distinction with significant implications for the balance between disinformation countermeasures and press freedom protections that organisations including Reporters Without Borders have flagged as a core tension in European regulatory approaches. Source: The Next Web. France Plans to Triple Penalties for AI-Driven Election Disinformation. [online] Published 9 July 2026. Available at: https://thenextweb.com/news/france-plans-to-triple-penalties-for-ai-driven-election-disinformation Top Of Page AI Content Labelling Enforcement Begins in 24 Days An article published by TechTimes states that the EU AI Act's Article 50 transparency obligations will become enforceable across all 27 member states on 2 August 2026, imposing binding disclosure requirements on chatbots, deepfakes, and AI-generated content constituting the first such binding framework in any G7 jurisdiction, with signatories to the Code of Practice receiving a presumption of regulatory conformity that reduces the evidentiary burden under national market surveillance enforcement. Companies wishing to appear on the initial list of Code of Practice signatories must submit by July 22nd 2026, ahead of the August enforcement date. An article published by TechTimes states that deployers of AI systems generating or manipulating content constituting a deepfake, defined as AI-generated or manipulated material depicting real or realistic people in ways that could appear authentic, must disclose the synthetic origin clearly at first exposure using standardised icons and machine-readable metadata, with non-compliance carrying fines of up to EUR 15 million or 3% of global annual turnover. The Code establishes shared technical standards for watermarking, detection, and labelling across the EU's information ecosystem at a moment when AI-generated content has reached sufficient volume and sophistication, demonstrated by documented deepfake surges during political events in June and July 2026, to constitute a systemic threat requiring binding regulatory frameworks rather than voluntary industry standards. Source: TechTimes. AI Content Labeling Enforcement Begins in 24 Days as EU Clears Compliance Code. [online] Published 9 July 2026. Available at: https://www.techtimes.com/articles/319996/20260709/ai-content-labeling-enforcement-begins-24-days-eu-clears-compliance-code.htm Top Of Page [CRC Glossary] The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult. To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence. As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website. Top Of Page

  • Coloring the Protest: PRC-Aligned Narratives and Indonesia’s June 2026 Protest Wave

    Indonesia's June 2026 protest wave, driven by university students, women's groups, and civic actors reacting to economic pressure, fuel and food costs, and criticism of the Free Nutritious Meals Programme was locally rooted, but its meaning was quickly contested online. This report documents how a cluster of pro-PRC influencer accounts moved to reframe the demonstrations as a U.S.-, NED-, and Soros-backed "color revolution" aimed at destabilizing Indonesia and countering China's regional influence. Using narrative intelligence tools, CRC researchers identified 187 relevant posts generating over 1.2 million views, concentrated in two coordinated surges (June 6–7 and June 14–15) that tracked closely with key moments in the protest cycle. Four accounts @angeloinchina, @NuryVittachi, @BrianJBerletic, and @PeterCronau drove the bulk of this activity, mutually amplifying one another and receiving support from a network of 37 accounts, 45% of which displayed bot-like behavior. Notably, this was not an isolated incident: the same accounts pushed similar claims during Indonesia's 2025 protest cycle and timed a parallel revival of "Tiananmen was Western-backed" narratives to coincide with the June 4th memorial period, pointing to a recurring, deliberate playbook rather than spontaneous commentary. While open-source evidence does not support claims that the protests were foreign-made or externally funded, the report argues that Indonesia as Southeast Asia's largest economy and a longtime adherent of a non-aligned foreign policy, remains a key target for narratives seeking to shape public and policymaker perceptions amid intensifying U.S.-China strategic competition. [Download PDF Here]

  • Cyber based influence campaigns 6th – 12th July 2026 Report

    [Introduction] Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW). Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc. During the 6th to the 12th of July 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities. [Contents] [Introduction] [Report Highlights] [Report Summary] [State Actors] Russia Baltic States Summon Russian Envoys Over False Deportation Claims Russia's Attacks on Ukraine's Cultural Heritage Russia's FSB Launches Disinformation Campaign Ukraine Fake Photo Let Russian Propaganda Cast Doubt on Kyiv Lavra Strike Russia Is Building Fake Ukrainians Iran Regime Supporters and Opposition Share AI-Generated Images Fact-Checkers Exposed the Iranian State's Funeral Fraud [AI Related Articles] Viral AI Fakes Flood Social Media as Iran Mourns Khamenei Over 5,800 Arrests in Global Fraud Bust EU Confirms Code of Practice on AI-Generated Content AI Threats to the 2026 Midterms [General Reports] Member Of Committee Investigating Spyware Hacked with Pegasus Fake Trump Post Says Belgium Is 2 Weeks Away from Developing a Nuclear Bomb The West Can Learn from Ukraine's Success Against Russian Propaganda India Ran Separate Spying Campaigns Against Same Pakistani Police Force [Appendix - Frameworks to Counter Disinformation] Threat of Foreign Influence on U.S. Elections Remains as Federal Defenses Recede FTC First Amendment Fight Continues [CRC Glossary] [ Report Highlights] Russia deployed false deportation narratives against Baltic states, Lithuania, Latvia, and Estonia summoned Russian envoys after Moscow falsely alleged mass deportations of Russian speakers, with Lithuanian intelligence confirming this as a consistent Kremlin tactic for pressuring NATO members. Russia's missile strike on Kyiv Pechersk Lavra has destroyed its core FIMI narrative of Orthodox Church protection, with UNESCO verifying 536 cultural sites destroyed and estimated damage reaching EUR 4 billion direct and EUR 20 billion indirect losses. Iran's state funeral for Ali Khamenei generated a multi-layered disinformation operation: state broadcasters fabricated crowd estimates of up to 40 million, AFP Fact Check identified aerial footage as 99.7% likely AI-generated, and Tehran Municipality coercively mobilised attendance while local governors extracted over USD 570,000 from automobile manufacturers to fund roadside stations. AI-generated synthetic media flooded social media during the Khamenei funeral, exploited simultaneously by pro-regime actors and opposition networks using the same generative tools to manipulate competing narratives, demonstrating AI disinformation is no longer exclusively a top-down state instrument. INTERPOL's Operation First Light 2026 produced the largest coordinated enforcement action against fraud networks in the organisation's history, spanning 97 countries, resulting in 5,811 arrests and USD 293 million intercepted from social engineering scam networks. The European Commission confirmed its Code of Practice on AI-Generated Content as an adequate compliance mechanism under Article 50 of the EU AI Act, with transparency obligations for marking and labelling synthetic media becoming legally binding from 2 August 2026. The Brennan Center documented concurrent escalation of AI-enhanced Chinese, Russian, and Iranian election influence operations alongside systematic dismantlement of US federal election security infrastructure, including elimination of funding, cessation of state-level threat intelligence sharing, and failure to establish the Election Security Group. [ Report Summary] Lithuania, Latvia, and Estonia summoned Russian diplomats to formally reject Kremlin claims that Baltic governments were preparing mass deportations of Russian-speaking residents. Russia's June 2026 missile strike on the Kyiv Pechersk Lavra monastery has fatally undermined Moscow's core propaganda narrative of being the protector of the Orthodox Church. Russia's Federal Security Bureau distributed fabricated archival documents about the 1943 Volyn tragedy in a targeted operation to damage Ukraine-Poland strategic relations. Russian propaganda platforms exploited an image of the burning Dormition Cathedral, flagged as potentially AI-generated, to construct a false narrative that Ukrainian photographers had staged Russia's June 2026 attack on Kyiv Pechersk Lavra. Russian information operations deployed AI-generated synthetic personas posing as Ukrainian soldiers, rabbis, and civilians on TikTok, Facebook, and YouTube to spread narratives of corruption, ethnic exclusion, and military futility. Both pro-regime actors and Iranian opposition networks distributed AI-generated images of Ali Khamenei's state funeral, exploiting the same synthetic media tools to advance opposing political objectives. International fact-checkers documented three categories of Iranian state deception at Khamenei's July 2026 funeral: fabricated crowd size statistics, AI-generated aerial footage, and coercive forced attendance mechanisms. The week of Ali Khamenei's state funeral produced a significant surge of AI-generated video and image fabrications circulating across multiple platforms, with detection tools confirming the synthetic origins of viral content. INTERPOL's Operation First Light 2026, spanning 97 countries, resulted in 5,811 arrests and the interception of USD 293 million in assets from social engineering scams and associated money laundering networks. The European Commission confirmed its Code of Practice on AI-Generated Content as an adequate compliance mechanism under Article 50 of the EU AI Act, establishing voluntary standards for marking and labelling synthetic media ahead of binding legal obligations taking effect in August 2026. A fabricated post mimicking Donald Trump's Truth Social format falsely claimed Belgium was on the verge of nuclear weapons development, originating from an X account and finding no corroboration in any authentic Trump record. Pro-Kremlin networks circulated a doctored photograph depicting drug seizure bags labelled with Zelensky's image across 78 articles and thousands of posts in 13 languages, timed to coincide with the NATO Ankara Summit to undermine Zelensky's diplomatic credibility. An Atlantic Council analysis argues Ukraine's documented successes in countering Russian information operations, including AI-powered multilingual official communications, real-time disinformation dashboards, and media literacy investment, provide a transferable model for NATO allies. The Brennan Center documented concurrent escalation of Chinese, Russian, and Iranian AI-enhanced election influence operations alongside the Trump administration's systematic dismantlement of federal election security infrastructure established since 2016. SentinelOne discovered that Chinese (VANGUARD PANDA) and Indian (DISCOBEAN) state-linked hacking groups independently and simultaneously infiltrated Pakistan's Balochistan Police for over two years, accessing biometric, criminal, and citizen data, each apparently unaware of the other's presence, with China likely motivated by CPEC security concerns and India by the regional rivalry over Baloch separatism. Citizen Lab confirmed that Stelios Kouloglou, a PEGA Committee member investigating spyware abuses, was himself hacked with Pegasus twice during the committee's active drafting periods, the first confirmed such case, raising concerns about breached parliamentary privilege, with attribution unclear beyond overlap with an operator previously linked to targeting exiled Russian/Belarusian journalists. Katie Harbath argues that the 2026 US midterms face a "kaleidoscopic minefield" of AI-driven threats, including autonomous agents, world models, and platform creator-monetization incentives that reward engagement over accuracy, that outpace post-2018 detection playbooks, and calls for shifting to rapid-triage frameworks built for unknown, fast-evolving attack vectors rather than static threat-mapping. NewsGuard reports continued progress in its First Amendment lawsuit against the FTC following the agency's withdrawal of a documentary demand. At the same time, the Omnicom-Interpublic merger conditions prohibiting the media company from working with disinformation-rating services remains in force. [State Actors] Russia Baltic States Summon Russian Envoys Over False Deportation Claims A report published by Euronews states that Lithuania, Latvia, and Estonia summoned Russian envoys after Moscow alleged the three NATO member states were preparing mass deportations of Russian-speaking residents. Lithuania's Foreign Ministry described the claims as 'entirely false,' and an attempt to 'divert attention from its aggression against Ukraine,' while Estonia's Foreign Minister called them 'nothing more than unfounded Russian propaganda,' and Latvia demanded Russia 'immediately retract this false information.' A report published by Euronews states that Lithuanian intelligence assessments document Russia's consistent use of narratives accusing Baltic states of persecuting Russian speakers and glorifying Nazi collaborators, narratives that serve Moscow's strategic goal of justifying foreign policy positions and amplifying pressure on NATO members. The diplomatic row coincided with Russian escalation of missile and drone attacks on Ukrainian civilian infrastructure, indicating that the false deportation narrative was deployed as information cover for concurrent military operations. Source: Euronews. Baltic States Summon Russian Envoys Over False Deportation Claims. [online] Published 10 July 2026. Available at: https://www.euronews.com/my-europe/2026/07/10/baltic-states-summon-russian-envoys-over-false-deportation-claims Top Of Page Russia's Attacks on Ukraine's Cultural Heritage An analysis published by StopFake states that Russia's targeting of the Kyiv Pechersk Lavra monastery on June 15th 2026 has collapsed Moscow's central Foreign Information Manipulation and Interference (FIMI) narrative of portraying Russia as the protector of the Orthodox Church. The analysis documents that this propaganda strategy rested on the false appropriation of Ukrainian Christian heritage, systematically omitting that Prince Volodymyr was 'Prince of Kyiv' and that Moscow was founded 159 years after Kyiv, while UNESCO has verified destruction of 536 Ukrainian cultural sites and Ukraine's Ministry of Culture has recorded approximately 1,900 damaged heritage locations. An analysis published by StopFake states that Russia's escalating attacks on cultural infrastructure reflect battlefield desperation rather than strategic intent, functioning as demoralization tactics when conventional military objectives fail. Estimated direct losses to Ukraine's cultural heritage have reached EUR 4 billion, with indirect losses of EUR 20 billion, and the theft of over 35,000 museum exhibits, a scale of cultural destruction that has simultaneously destroyed the credibility of Russia's self-assigned identity as civilization's defender. Source: StopFake. Russia’s Attacks on Ukraine’s Cultural Heritage: A Nail in the Coffin of FIMI. [online] Published 8 July 2026. Available at: https://www.stopfake.org/en/russia-s-attacks-on-ukraine-s-cultural-heritage-a-nail-in-the-coffin-of-fimi/ Top Of Page Russia's FSB Launches Disinformation Campaign A report published by Ukrainska Pravda states that Russia's Federal Security Bureau (FSB) launched a disinformation operation designed to damage Ukraine-Poland strategic relations by publishing allegedly 'declassified' files in Russia Today that falsely accused Ukrainian Insurgent Army commander Dmytro Kliachkivskyi of ordering the killing of approximately 2,000 Poles in Volodymyr-Volynskyi during 1943. Ukraine's Center for Countering Disinformation confirmed the documents were fabricated, with FSB Director Alexander Bortnikov personally overseeing the operation and state media instructed to amplify the narrative. A report published by Ukrainska Pravda states that the strategic objective of the FSB operation was to 'destroy the strategic partnership through manipulation of the past' by exploiting Polish historical trauma around the Volyn tragedy to provoke emotional reactions and fracture the Ukraine-Poland alliance at a critical moment of military cooperation. The operation was accompanied by identified bot farm activity targeting Polish social media and a network of eleven individuals organising anti-Ukrainian rallies in Poland for Russian payment, revealing a coordinated multi-vector influence campaign. Source: Ukrainska Pravda. Russia's FSB Launchs Disinformation Campaign Using Fake Volyn Tragedy Documents. [online] Published 5 July 2026. Available at: https://www.pravda.com.ua/eng/news/2026/07/05/8042440/ Top Of Page Ukraine Fake Photo Let Russian Propaganda Cast Doubt on Kyiv Lavra Strike An investigation published by Kyiv Independent states that Russian propaganda platforms exploited a photograph of the Dormition Cathedral burning during Russia's 15 June 2026 missile strike, an image that OpenAI's detection tools flagged as containing SynthID watermarks suggesting AI generation or editing, to construct a false narrative that Ukrainian photographers had staged the attack by setting up filming positions in advance. Pro-Kremlin accounts circulated the cathedral image alongside two AI-generated photographs falsely depicting journalists preparing the scene, with accompanying text claiming: 'The third photo shows the resulting image taken by these photographers.' An investigation published by Kyiv Independent states that StopFake.org's Olga Yurkova explained the standard propaganda methodology at work: 'propagandists first establish a narrative and then create visual evidence' to support predetermined false conclusions. Meta initially restricted posts about the attack due to a technical error linking legitimate reporting to an AFP fact-check examining the AI-generated imagery, but subsequently removed the false-information labels after acknowledging the algorithmic mistake, a sequence that demonstrates how AI-generated disinformation can briefly weaponise platform safety systems against accurate reporting. Source: The Kyiv Independent. How One Questionable Photo Fueled Confusion Over Russia's Attack on Kyiv Lavra. [online] Published 7 July 2026. Available at: https://kyivindependent.com/how-one-fake-photo-let-russian-propaganda-cast-doubt-on-kyiv-lavra-strike/ Top Of Page Russia Is Building Fake Ukrainians An analysis published by Euromaidan Press states that Russian information operations deployed at least three AI-generated videos targeting Ukrainian audiences across TikTok, Facebook, and YouTube in May 2026, collectively accumulating millions of views: a synthetic soldier accusing politicians of 'building a third house on the French Riviera' while troops sacrificed (915,000 views on Facebook), an AI-generated rabbi claiming draft dodgers should lose Ukrainian citizenship while deploying antisemitic tropes (557,000 views on TikTok), and a fabricated soldier accusing President Zelenskyy of pursuing war until complete societal destruction (425,000 views on TikTok). An analysis published by Euromaidan Press states that the three videos advanced distinct but complementary narratives, political corruption and soldier exploitation; ethnic exclusivity and Jewish overreach; and autocratic indifference to civilian casualties, while coordinated artificial promotion through bot engagement amplified their reach simultaneously across TikTok, YouTube, Facebook, Telegram, and X. The campaign demonstrates a sophisticated industrial-scale fabrication strategy in which AI-generated synthetic personas impersonate Ukrainian community figures to delegitimise the state, fracture social cohesion, and undermine civilian support for military mobilisation from within. Source: Euromaidan Press. Russia Is Building Fake Ukrainians: One AI Video, Telling Ukrainians Their Soldiers Are Dying So Politicians Can Buy Villas, Got 900,000 Views. [online] Published 4 July 2026. Available at: https://euromaidanpress.com/2026/07/04/russia-is-building-fake-ukrainians-one-ai-video-telling-ukrainians-their-soldiers-are-dying-so-politicians-can-buy-villas-got-900000-views/ Top Of Page Iran Regime Supporters and Opposition Share AI-Generated Images A report published by France 24 states that both pro-regime actors and Iranian opposition networks distributed AI-generated images of Ali Khamenei's state funeral, exploiting the same synthetic media tools to advance opposing political objectives. Regime supporters posted fabricated images of massive crowds at the Grande Mosalla Mosque and Azadi Tower, accumulating over 100,000 views and picked up by African media outlets, while opposition networks distributed a fabricated image of dissident rapper Toomaj Salehi appearing to honour Khamenei, both categories confirmed as AI-generated through SynthID watermark analysis. A report published by France 24 states that the parallel deployment of AI-generated content by opposing sides of Iran's political conflict reveals a fundamental shift in information warfare: synthetic imagery has become a universally accessible tool that requires neither state resources nor technical expertise, enabling both authoritarian governments and their opponents to manipulate public perception of the same event with fabricated visual evidence. The Khamenei funeral case demonstrates that AI disinformation is no longer exclusively a top-down state instrument but has become a contested terrain where all parties manufacture crowd sizes, emotional reactions, and political moments to shape international and domestic narratives. Source: France 24. Regime Supporters and Opposition Share AI-Generated Images of Khamenei’s Funeral. [online] Published 8 July 2026. Available at: https://www.france24.com/en/middle-east/20260708-regime-supporters-opposition-share-ai-generated-images-khamenei-funeral Top Of Page Fact-Checkers Exposed the Iranian State's Funeral Fraud A report published by NCRI states that international fact-checkers documented three categories of Iranian state deception surrounding Ali Khamenei's July 2026 state funeral: state broadcaster IRIB escalated crowd size claims from 'several million' to 15-20 million by 5 July, then 40 million nationwide by 10 July, while Reuters drone footage showed 'hundreds of thousands'; AFP Fact Check identified a 33-second aerial video as 99.7% likely AI-generated; and France 24 detected 'a fabricated beige dome replacing a real blue dome' and 'banners displaying illegible gibberish instead of actual Persian text' in widely circulated footage. A report published by NCRI states that the Iranian state supplemented media fabrication with coercive physical mobilisation: Tehran Municipality cancelled all employee leave and mandated attendance, the SAIJA organisation and Hamshahri newspaper bused workers under threat, and local governors extracted over USD 570,000 from automobile manufacturers to finance roadside stations, while the Ministry distributed 50 million free loaves of bread to financially incentivise participation. The three-layer deception strategy fabricated statistics, AI-generated visual evidence, and forced attendance to generate authentic-looking crowd footage represents a comprehensive state-coordinated disinformation architecture designed to construct a false narrative of popular grief for both domestic control and international legitimacy. Source: National Council of Resistance of Iran (NCRI). Manufactured Grief: How Fact-Checkers Exposed the Iranian State’s Funeral Fraud. [online] Published 11 July 2026. Available at: https://www.ncr-iran.org/en/news/iran-a-world/manufactured-grief-how-fact-checkers-exposed-the-iranian-states-funeral-fraud/ Top Of Page [AI Related Articles] Viral AI Fakes Flood Social Media as Iran Mourns Khamenei A report published by France 24 states that the week of Ali Khamenei's state funeral in early July 2026 produced a significant surge of AI-generated video and image fabrications across multiple platforms, with SynthID watermark analysis confirming the synthetic origins of viral content including AI-generated footage of massive crowds at the Grande Mosalla Mosque and Azadi Tower (accumulating over 100,000 views and picked up by African media) and an X post claiming approximately 40 million people attended via an AI-generated video that circulated in multiple languages. A report published by France 24 states that the Khamenei funeral disinformation surge demonstrates how major political events create predictable windows of high-volume AI content generation, as both state actors and opposition networks exploit the same generative tools to manipulate narratives about contested events. Pakistan's IVerify identified crowds in funeral footage moving in 'unnatural, wave-like patterns resembling flowing water', a characteristic artifact of AI video generation, illustrating that while detection tools are advancing, the volume and velocity of synthetic content production consistently outpaces platform enforcement capacity. Source: France 24. Viral AI Fakes Flood Social Media as Iran Mourns Khamenei. [online] Published 8 July 2026. Available at: https://www.france24.com/en/viral-ai-fakes-flood-social-media-as-iran-mourns-khamenei-1 Top Of Page Over 5,800 Arrests in Global Fraud Bust A press release published by INTERPOL states that Operation First Light 2026, a coordinated anti-fraud initiative spanning 97 countries that ran from January to April 2026, resulted in 5,811 arrests, the interception of USD 293 million in assets, the blocking of 31,014 bank accounts, and the identification of 142,000 victims globally from social engineering scams and associated money laundering operations. The operation analysed 152,808 cases, solved 23,715, and issued 99 Notices and Diffusions, with INTERPOL's Global Rapid Intervention of Payments (I-GRIP) system deployed as a stop-payment mechanism to swiftly block illicit financial flows. A press release published by INTERPOL states that the operation targeted social engineering scams, techniques that exploit human trust rather than technical vulnerabilities to obtain money or confidential information, reflecting the growing convergence between influence operations and financial fraud, where manipulative narrative techniques are increasingly weaponised for economic gain at global scale. The scale of Operation First Light 2026, encompassing nearly 100 countries and resulting in the largest coordinated enforcement action against fraud networks in INTERPOL's history, signals a decisive shift toward treating AI-enabled social engineering as a transnational security threat requiring multilateral law enforcement response. Source: INTERPOL. Over 5,800 Arrests, USD 293 Million Intercepted in Global Fraud Bust. [online] Published 9 July 2026. Available at: https://www.interpol.int/News-and-Events/News/2026/Over-5-800-arrests-USD-293-million-intercepted-in-global-fraud-bust Top Of Page EU Confirms Code of Practice on AI-Generated Content A policy document published by the European Commission states that the Commission and AI Board confirmed the Code of Practice on AI-Generated Content as an adequate compliance tool under Article 50 of the EU AI Act, which mandates transparency in AI-generated content and addresses 'risks of deception and manipulation, fostering the integrity of the information ecosystem.' The Code requires AI providers to mark audio, image, video, and text outputs in machine-readable formats detectable as artificially generated, and requires deployers to disclose deepfakes and AI-generated text on matters of public interest, with transparency obligations becoming legally binding from 2 August 2026. A policy document published by the European Commission states that while adherence to the Code of Practice is currently voluntary, its confirmation as an adequate compliance mechanism reduces administrative burden for signatories across EU Member States and establishes an industry-wide technical baseline for watermarking, detection, and labelling of synthetic media. The Commission's action comes at a moment when AI-generated content has reached sufficient scale and sophistication, demonstrated by the Khamenei funeral disinformation surge in the same week, to constitute a systemic threat to the information ecosystem that voluntary standards alone cannot address. Source: European Commission. Code of Practice on Transparency of AI-Generated Content. [online] Published 10 June 2026. Available at: https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content Top Of Page AI Threats to the 2026 Midterms Digital security strategist Katie Harbath identifies the AI threat landscape for the 2026 US midterm elections as a rapidly shifting kaleidoscopic minefield in which known threats such as deepfakes are relatively well-mapped, but novel and unnamed threat vectors are emerging faster than existing frameworks can track. Harbath highlights as particular unknowns: AI agents capable of acting autonomously on a voter's behalf; world models capable of simulating political scenarios; and the ways AI systems respond to political information inputs. She argues that playbooks developed since 2018, built to detect established attack patterns, are structurally inadequate for the next generation of threats. The piece also identifies how creator monetization programmes on social platforms now provide financial incentives for engagement-maximizing content regardless of accuracy, compounding the risk from state-sponsored influence operations by creating an aligned commercial infrastructure that amplifies divisive or false material. Harbath advocates shifting from threat-mapping to rapid-triage frameworks designed for unknown attack vectors. Source: Anchor Change. Kaleidoscopic Minefield: Election Playbook. [online] Published 28 October 2025. Available at: https://anchorchange.substack.com/p/kaleidoscopic-minefield-election-playbook Top Of Page [General Reports] Member Of Committee Investigating Spyware Hacked with Pegasus The Citizen Lab at the University of Toronto published forensic evidence confirming that Stelios Kouloglou, a former member of the European Parliament who sat on the PEGA Committee (the body tasked with investigating abuses of Pegasus and other commercial spyware), was himself hacked with NSO Group's Pegasus spyware on two separate occasions while the committee was active. The first infection occurred on 21 October 2022, coinciding with the committee's preparation of its draft report and upcoming hearings. The second infection occurred in June-July 2023 during the committee's final drafting period, approximately two months before the PEGA Committee adopted its first report. The attackers would have had access to confidential documents and committee deliberations, potentially breaching EU parliamentary privilege. Attribution remains uncertain: researchers found no indication of Greek government involvement but identified overlaps with an operator previously documented targeting Russian- and Belarusian-speaking exiled journalists in Europe. This is the first publicly confirmed case of a PEGA Committee member being hacked with Pegasus during the committee's operation. Source: Citizen Lab. Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus. [online] Published 3 July 2026. Available at: https://citizenlab.ca/research/member-of-committee-investigating-spyware-hacked-with-pegasus/ Top Of Page Fake Trump Post Says Belgium Is 2 Weeks Away from Developing a Nuclear Bomb A fact-check published by Lead Stories states that a fabricated post mimicking Donald Trump's Truth Social format falsely claimed that 'Belgium is 2 weeks away from developing a nuclear bomb,' originating from the @dogeofficialceo account on X on 7 July 2026. Lead Stories verified through manual review of Trump's Truth Social account, the Trump Truth archive, Google News, and Yahoo News that no authentic post from Trump's verified accounts contained the claim, noting that 'had the president actually made such a post, major news outlets would have widely reported it.' A fact-check published by Lead Stories states that the fabricated Trump nuclear post was published on the same day as the NATO Ankara Summit opened, a timing pattern consistent with coordinated influence operations designed to inject destabilising false narratives into major geopolitical events at moments of maximum media attention. The use of a convincingly formatted social media mockup to impersonate a sitting head of state on a nuclear proliferation claim represents an escalating category of disinformation that exploits both platform format conventions and audience familiarity with political figures' communication styles to generate credibility for fabricated content. Source: Lead Stories. Fact Check: Fake Trump Post Does NOT Say Belgium Is ‘2 Weeks Away’ From Developing A Nuclear Bomb. [online] Published 10 July 2026. Available at: https://leadstories.com/hoax-alert/2026/07/fact-check-fake-trump-post-says-belgium-is-2-weeks-away-from-developing-a-nuclear-bomb.html Top Of Page The West Can Learn from Ukraine's Success Against Russian Propaganda An analysis published by Atlantic Council states that Ukraine's documented successes in countering Russian information operations include deployment of an AI tool producing Ministry of Foreign Affairs statements in 30 languages with embedded unforgeable digital signatures, systems to counter Russia's network of thousands of fake websites, real-time disinformation dashboards for journalists, civil society, and government bodies, and media literacy investment through the Diia digital app, all anchored in 'laws promoting open data and transparency firmly rooted in democratic values. An analysis published by Atlantic Council states that NATO should adopt a 'whole-of-government and society approach' involving coalition-building across sectors, drawing from Ukraine's experience demonstrating that democracies can counter propaganda through technological innovation coupled with ethical safeguards rather than censorship. The analysis argues that the structural advantage of autocracies their natural tendency to weaponise information makes counter-disinformation investment a core democratic security priority, and that Ukraine's war-accelerated capability development offers Western governments a tested operational model at a moment when Russian information operations are targeting NATO member states directly. Source: Atlantic Council. The West Can Learn from Ukraine’s Success Against Russian Propaganda. [online] Published 2 July 2026. Available at: https://www.atlanticcouncil.org/blogs/ukrainealert/the-west-can-learn-from-ukraines-success-against-russian-propaganda/ Top Of Page India Ran Separate Spying Campaigns Against Same Pakistani Police Force SentinelOne researchers found that two separate, unconnected state-linked hacking groups, one tied to China (tracked as VANGUARD PANDA) and one tied to India (tracked as DISCOBEAN), independently conducted parallel cyber espionage operations against Pakistan's Balochistan Police for more than two years, from February 2024 to April 2026. The compromised systems held criminal records, biometric and fingerprint data, personnel files, hotel and tenant registration records linked to national identity systems, and citizen complaints. China's motivation appears tied to monitoring threats to its nationals and infrastructure connected to the China-Pakistan Economic Corridor (CPEC). India's motivation is likely linked to the bilateral rivalry and Pakistan's accusation that India backs the Baloch separatist insurgency. The simultaneous but independently run campaigns against the same target illustrate how a single police database can become the focus of competing foreign intelligence collection without either state being aware of the other's access. Source: The Record. China, India Ran Separate Spying Campaigns Against Same Pakistani Police Force. [online] Published 10 July 2026. Available at: https://therecord.media/china-india-ran-separate-spy-campaigns-against-same-police-force Top Of Page [Appendix - Frameworks to Counter Disinformation] Threat of Foreign Influence on U.S. Elections Remains as Federal Defenses Recede A report published by Brennan Center for Justice states that three nation-states are actively targeting U.S. elections with AI-enhanced tools: China's Golaxy Labs pays individuals to impersonate Western journalists while using AI to enhance message targeting; Russia's Social Design Agency hacked Bluesky user accounts and organised false-flag vandalism in Europe; and Iran is producing AI-enhanced video content and deploying fake news websites with AI-generated influencers. Simultaneously, the Trump administration has eliminated federal election security funding, ceased sharing threat intelligence with states, and failed to establish the Election Security Group. A report published by Brennan Center for Justice states that the combination of increasing foreign actor sophistication, leveraging AI to increase campaign volume, believability, and reach, with the simultaneous dismantlement of federal coordination infrastructure creates significant intelligence gaps for state election officials attempting to identify and respond to ongoing influence operations. The Center notes that while the diversity of the U.S. electoral system and prior security investments make direct interference with vote-casting technically challenging, the receding of federal defences represents a structural vulnerability that foreign actors are already exploiting through information environment manipulation rather than direct electoral system attacks. Source: Brennan Center for Justice. Threat of Foreign Influence on U.S. Elections Remain as Federal Defenses Recede. [online] Published 2 July 2026. Available at: https://www.brennancenter.org/our-work/research-reports/threat-foreign-influence-us-elections-remain-federal-defenses-recede Top Of Page FTC First Amendment Fight Continues A newsletter published by NewsGuard states that the company's First Amendment lawsuit against the Federal Trade Commission and its chairman Andrew Ferguson, challenging FTC conditioning of the Omnicom-Interpublic merger on prohibiting the combined entity from subscribing to any service that assesses the 'veracity of news reporting or other politically or ideologically contested facts', achieved a partial victory when the FTC dropped its demand for documents and ended its investigation, though the merger condition itself forbidding Omnicom from working with NewsGuard remains in force. A newsletter published by NewsGuard states that the FTC's condition targets the company 'with the precision of a laser beam' by using government power to prevent NewsGuard from producing journalism that the Trump administration and some of its supporters in the media do not like, characterising the action as an unprecedented use of merger review authority to censor First Amendment-protected editorial judgments about news source reliability. The case has broader implications for the disinformation detection sector: if upheld, the merger condition would establish a precedent permitting federal agencies to use commercial regulatory power to suppress organisations whose core function is assessing the accuracy of information. Source: NewsGuard's Reality Check. Our First Amendment Fight Continues. [online] Published 3 July 2026. Available at: https://www.newsguardrealitycheck.com/p/our-first-amendment-fight-continues Top Of Page [CRC Glossary] The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult. To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence. As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website. Top Of Page

  • Iran War Post-MoU: From Cyfluence Operations to STRATCOM Efforts

    Key Takeaways A new report by cyber-influence threat intelligence firm Intercept9500 examines how cyber, influence, economic, and kinetic actions operated as interconnected components of the Iran War. The report also highlights practical lessons for counter-Cyfluence and Influence Defense, including the need for rapid pre-bunking and response to narrative attacks, as well as the pre-conflict development of defensive capabilities and procedures to protect civilian infrastructure from both kinetic and hybrid threats. The recently-signed U.S.–Iran Memorandum of Understanding has led to a reduction in cyfluence attacks. At the same time, renewed kinetic attacks against civilian shipping and military assets have tested the agreement’s longevity. A CRC narrative intelligence analysis mapped key Iranian strategic communication assets on X/Twitter, primarily senior officials and state media channels, alongside their recent activity patterns, reach, and dominant narratives. Iran’s post-MoU messaging and overt influence activity continue to offer a valuable case study in how influence efforts persist, shift, and adapt across the conflict’s most recent stages. Recap Since the outbreak of the Iran War in February 2026, the conflict has extended far beyond conventional military exchanges. It has included cyberattacks (such as hack-and-leak operations, infrastructure disruption, broadcast interruption, and message application hijacking), extensive internet restrictions, the proliferation of synthetic propaganda and coordinated information disorder, and STRATCOM messaging. CRC threat researchers have previously examined this convergence of military disciplines and offensive vectors in a recent report titled The Deployment of Hybrid Threats and Cyfluence Operations in the Iran War. In the report, we documented how cyber, cognitive, and physical actions were combined to impact military institutions, national infrastructure, political leadership, and public perceptions. The Islamabad MoU On June 17-18, the United States and the Islamic Republic of Iran officially signed the Islamabad Memorandum of Understanding (MoU), agreeing on a 60-day framework intended to cement the ceasefire, reopen the doubly blockaded Strait of Hormuz, and enable negotiations on sanctions, Iran’s nuclear program, and wider regional security settlements.[1] This MoU entered into effect despite important (and high-profile) disagreements between U.S. and Iranian interpretations of its provisions, resulting in some critics even describing it as “dead on arrival”. Perhaps unsurprisingly, the MoU did not put an everlasting end to the conflict. It did, however, temporarily move the conflict from a high-intensity open warfare toward arduous negotiations, confrontational statements, and a continued contestation of the information domain. For now, the apparent result is a confusing dynamic featuring constant crisis management, posturing and re-posturing. Developments Since the MoU As of mid-July, Iranian attacks on commercial shipping in the Strait of Hormuz have renewed, prompting retaliatory U.S. military action against Iranian targets. Subsequently, Iran launched missile and drone strikes against American military assets and allies in the region. Iran continues to frame its control of the strait as a source of strategic leverage, while claiming sovereignty over the important maritime routes.[2] On July 8, President Trump declared the ceasefire effectively over, although diplomatic contacts continued. By July 12, the conflict had returned to direct widescale military exchanges, with the Strait of Hormuz again emerging as both a military chokepoint and an instrument of economic coercion. On July 13, President Trump, together with key American administration officials and the U.S. Central Command, declared the reinstatement of the naval blockade against Iran. Figure 1 - Posts published by official U.S. accounts on X. Left: A @WhiteHouse post, reposted by @POTUS, quoting President Trump’s declaration that “the ceasefire is over”; Right: @CENTCOM’s July 12 announcement of a “third round of strikes” against Iran following the IRGC’s targeting of a container ship in the Strait of Hormuz. (Courtesy of X) Figure 2 - Posts published by official U.S. accounts on X: a statement by President Trump, reposted by @WhiteHouse, and a U.S. Central Command announcement confirming the resumption of the naval blockade against Iran. (Courtesy of X) Regarding offensive cyfluence actions, public reporting since June 18 does not yet provide evidence of new operations. However, the current lack of positive evidence does not mean that cyber-influence efforts have ceased. Iranian efforts targeting the information environment are persistent. Iranian officials, state media, aligned commentators, and associated proxies have continued competing to define the narrative following the signing of the MoU agreement (i.e. a humiliating and expected U.S. surrender), as well as the reasoning for the current re-escalation, and the legitimacy of Iran’s military actions against affected Arab nations. Iranian Narrative Adaptation After the MoU The signing of the MoU required Iranian messaging to balance several potentially conflicting objectives: presenting the agreement as an Iranian achievement, denying that Tehran had capitulated, maintaining deterrence, preserving the legitimacy of the “Resistance Axis” (including Hezbollah in Lebanon and the Houthis in Yemen), and preparing domestic and foreign audiences for renewed confrontation. Initial Iranian statements emphasized conditional compliance. Tehran thus presented the agreement as a mechanism for acknowledging Iranian sovereignty and securing U.S. and Israeli concessions while retaining the right to respond to any violations. On the other hand, Iran’s supreme leader made his reservations about the agreement known, approving it due to Iranian national interests and the preservation of the wider resistance project. Later on, as tensions mounted, Iranian messaging shifted toward blaming the U.S. for the agreement’s imminent failure. This narrative essentially bridged the two alternating and competing positions of diplomatic engagement and military escalation. And by doing so, Iran portrayed itself as having accepted negotiations while framing renewed hostilities as a legitimate response to the American administration’s insincerity and aggression. Following Ayatollah Ali Khamenei’s funeral ceremonies, online discourse and media coverage saw a sharp increase in attention to Iranian threats against American and other Western leaders. Iranian revenge rhetoric, accompanied by imagery targeting President Donald Trump and other key political figures generated major traction on social media. A reported Israeli intelligence warning of a possible Iranian assassination plot against President Trump added to the perceived threat narrative. Trump himself responded by publicly warning that any successful attack would trigger overwhelming U.S. retaliation. Figure 3 - Coverage by CNN and Fox News on X regarding recent Iranian death threats against U.S. and Israeli leaders, and an Israeli intelligence warning of an alleged Iranian assassination plot. (Courtesy of X) Media coverage of the Iranian state-sanctioned threats and alleged intelligence disclosures, together with official statements, were joined by online influencers amplifying escalatory or conspiratorial narratives. Almost instantaneously, Iranian promises of revenge by means of assassination became a prominent theme of online discourse. Figure 4 - Posts by influencer Laura Loomer addressing Iranian assassination threats, questioning President Trump’s claim of successful regime change, and suggesting a possible connection to Senator Lindsey Graham’s sudden death. (Courtesy of X) Narrative Intelligence Analysis A CRC analysis of the most influential Iranian officials and state media accounts on X/Twitter (between dates June 10 – July 12, 2026) maps the extent of Iran’s overt messaging and narrative control efforts, by tracking its leading strategic communication assets, during this timeframe. Figure 5 - Activity graph showing top 10 Iranian officials and state media accounts on X/Twitter (timeframe: June 10 to July 12, 2026). Figure 6 - Graph showing impressions per day for the top 10 Iranian officials and state media accounts on X/Twitter (timeframe: June 10 to July 12, 2026). The two graphs above depict posting activity and impressions metrics for leading Iranian strategic communication assets on X/twitter. The selected time window allows us to assess STRATCOM efforts velocity and impact, before and after the signing of the MoU agreement. The table below shows an aggregated summary of reach and engagement metrics for the top 10 Iranian officials or state media accounts considered as STRATCOM assets (as of July 12, 2026). Figure 7 – A summary of the top 10 leading Iranian STRATCOM assets active on X/Twitter, including aggregated impressions metrics (timeframe June 10 to July 12, 2026). According to our analysis of Iranian communications throughout recent weeks, two amplification models appear to operate in parallel. State media outlets drove volume, publishing hundreds of posts with relatively low average reach. On the other hand, Iranian senior officials posted far less but attracted far more attention. Foreign Minister Araghchi’s 18 posts generated over 18 million impressions, exceeding the reach of IRNA or Press TV despite their much higher output. State media therefore sustained distribution, while viral reach came from a small number of high-profile officials. Dominant Narratives Using automated classification of content published by the most prominent Iranian X accounts since the signing of the MoU, CRC analysts identified three dominant narratives: The first - centered on the death of former Supreme Leader Ayatollah Khamenei, portraying it as martyrdom and honorable sacrifice while reinforcing the legitimacy of his son and successor, Mojtaba Khamenei. The second - accused the United States of repeatedly violating the MoU and emphasized Iran’s claimed exclusive sovereignty over the Strait of Hormuz. The third - focused on deterrence, retaliation, and revenge, combining official threats with visual depictions of “the Iranian public” demanding retribution in an effort to present these messages as organic, popular sentiment. Figure 8 - Top 3 narratives appearing in posts by Iranian officials and state media outlets on X/Twitter. Implications for Cyfluence Research Since the start of the Iran War, threat analysts and researchers have begun to map, correlate and monitor the diverse – and perhaps unprecedented – usage of hybrid threats, including cyfluence attacks, carried out by the combatting sides. A new report by cyber threat intelligence firm Intercept9500, titled Iranian Hybrid Warfare During Operation Epic Fury, provides a valuable multi-dimensional review of offensive operations. Following an earlier Intercept9500 Preliminary Analysis published in May 2026, it complements the CRC’s abovementioned research by examining the overall Iranian response to the U.S.–Israeli military campaign. Interestingly, the report posits that Iran effectively inverted the “conventional hybrid hierarchy”. Instead of deploying offensive influence and cyber operations to support a kinetic main effort, Tehran prioritized the cognitive and cyber domains, due to its calculation of its own comparative strengths and weaknesses. By doing so, Iran managed to gain greater opportunities to deny its adversaries from achieving their strategic objectives. To that extent, cyber activity was primarily designed and leveraged for visibility, narrative dissemination, and cognitive impact. Moreover, the strategic and operational models presented in the report place hostile influence operations and offensive cyber capabilities as part of an integrated cyfluence ecosystem. Figure 9 – Iranian Cyfluence Operational Model during the Iran War. (Courtesy of Intercept9500)[3] Conclusion The Iran War remains a valuable case study for hybrid-threat researchers, cyfluence analysts, and Influence Defense stakeholders. It highlights the role of the strategic and operational fusion of kinetic actions, cyber capabilities, economic coercion, information control, diplomatic posturing, and strategic communication in modern warfare. Given that the increased integration of these various elements has already created a highly complex and dynamic global threat landscape, additional research into both offensive applications and defensive countermeasures should be encouraged. For Influence Defense practitioners and stakeholders, the existing (and still expanding) body of evidence and operational insights is a valuable resource. A methodological examination of how hybrid threats manifest during high-intensity conflict could directly inform pre-emptive and proactive capacity building, helping to protect against emerging threats, especially in other regions currently at risk. CRC report raises several noteworthy takeaways for defenders, such as the need to pre-bunk and respond rapidly to narrative attacks, while establishing defensive capabilities, coordination mechanisms, and protection procedures before a crisis emerges. This point is particularly important for civilian infrastructure and private sector entities, which are increasingly exposed to both kinetic and hybrid threats. Lastly, we should be mindful of a basic working assumption: the valuable lessons learned from this conflict are not limited to the current combatants. Other major actors, including China and Russia, will surely draw their own conclusions. Likewise, different hacktivist groups, proxy organizations, and small-scale threat actors will likely be quicker to adapt, modifying their approach and TTPs accordingly. Ultimately, it is the application of those lessons that will determine how cyfluence capabilities and hybrid threats will be deployed in future conflicts. The CRC continues to monitor the developments and will report on relevant findings. [References:] Deutsche Welle (DW). What’s in the 14-Point US-Iran Peace Plan? [online] Published 19 June 2026. Available at: https://www.dw.com/en/whats-in-the-14-point-us-iran-peace-plan/a-77595563 Associated Press. Iran, USA and United Arab Emirates Attack. [online] Published 24 June 2026. Available at: https://apnews.com/article/iran-usa-united-arab-emirates-attack-0764d17c09370a8c5cf1e8197a8878ab Intercept9500, “Iranian Hybrid Warfare During Operation Epic Fury: Preliminary Analysis While the Situation is Still Unfolding” 15 June 2026. Available online: https://media.licdn.com/dms/document/media/v2/D4D1FAQFygKagA-vnDQ/feedshare-document-sanitized-pdf/B4DZ9THlLlGkA8-/0/1783805925198?e=1784451600&v=beta&t=H0YeCibL2_7qxMeO4zYcEN13cJFG6gqSYtZ9E7PJY7E

bottom of page