top of page

Search CRC

Search this site

203 results found with an empty search

  • Information Flows in Japan's Media Ecosystem: Analyzing Narrative Formation and Dissemination

    Amid growing concern over foreign information operations targeting Japan — from Russian divisive-narrative campaigns to PRC efforts targeting Okinawa and the U.S.–Japan alliance, including CRC's research on PRC-aligned exploitation of Ryukyuan historical identity — this study maps Japan's media and information ecosystem to identify structural vulnerabilities to adversarial cognitive threats. Drawing on a case study of the Gaza-Israel conflict and a qualitative audience consumption analysis, CRC assesses that Japan's information environment carries two linked structural vulnerabilities. First, legacy media (newspapers and wire services) systematically underrepresent civilian testimony, casualty coverage, and other emotionally salient content in international reporting — what the report terms the "Humanitarian frame" — producing a measurable coverage gap. Second, social media fills that gap unfiltered, creating an insertion point that suspected PRC-aligned influence efforts appear to be exploiting. The assessment integrates four lines of analysis — Japan's media structure, news framing, social media dynamics, and audience reception — using combined media-coverage and online-discourse data from the Gaza–Israel conflict as its primary case. The findings carry direct implications for strategic communication, societal resilience, media literacy policy, and Cognitive Security capacity building. An executive summary is available here. Author: Ririko Hirase [Download PDF Here]

  • Information Flows in Japan's Media Ecosystem: Analyzing Narrative Formation and Dissemination

    Reported foreign information manipulation and interference (FIMI) operations targeting Japan — including Russian efforts to amplify divisive narratives and Chinese campaigns aimed at Okinawa and the U.S.–Japan alliance — have raised concerns about adversarial exploitation of societal divisions. Building on CRC's earlier research exposing PRC-aligned use of Ryukyuan historical identity and nostalgia to undermine Japanese sovereignty over Okinawa, this study maps Japan's media and information ecosystem to identify structural vulnerabilities to cognitive threats. CRC findings suggest that Japan's information environment exhibits two structural vulnerabilities that are both measurable and self-perpetuating: Japanese legacy media — dominated by five major conglomerates and two domestic wire services — systematically under-represents civilian testimony, casualty accounts, and other emotionally grounded content, a category the report terms the "Humanitarian frame," in its coverage of international events. As a result, social media then fills that gap, creating an opening that suspected PRC-aligned information operations appear to be actively exploiting. These findings are based on a four-module study of Japan's information ecosystem, using the early phase of the Gaza–Israel conflict (October 2023–May 2024) as a primary case study. The study's conclusions carry direct implications for communication strategy, media literacy policy, and Influence Defense capacity building for cognitive security stakeholders. The full research report is available here. Author: Ririko Hirase [Download PDF Here]

  • Cyber based influence campaigns 21st - 27th September 2026 Report

    [Introduction] Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW). Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc. During the 21st to the 27th September 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities. [Contents] [Introduction] [Report Highlights] [Report Summary] [State Actors] Facebook Singapore Police Data Helps Meta Disrupt Scam Networks X US Backs Musk's Challenge to EU's First DSA Fine Tiktok AI-Fabricated Anti-Immigration Rallies Circulate on TikTok Russia Russia Weaponises Fear of War Against the Baltic States Russian Propagandists Pose as 'Angry Latvians' on Telegram EU Sanctions Ex-RT France Chief Xenia Fedorova Swiss Detect Covert Russian Operations Before Neutrality Vote Czech Sting Exposes Rybar Film Crew Operating in Europe Russians Clone NV Site to Push AI-Faked Ukraine Graft Story Doctored Media Screenshots Blame Ukraine for Russian Train Strike AI Videos of Fake Pilgrims Spread Uman Resettlement Myth China RSF Details Ten Tactics Beijing Uses to Export Propaganda PRC Sway in Zambia's Election Was Structural, Not Covert Iran Golden Owl Assesses Fake Israeli Persona Network as Iran-Linked Months-Old Footage Used to Claim US Troop Pullout from Gulf Cyflunce Attack Hackers Leak Alleged Peskov Messages from Claimed Babich Archive [AI Related Articles] Texas Candidate Files Police Report Over AI-Generated Campaign Ads AI-Generated Persona Quoted 30-Plus Times by Major Outlets Preliminary Study Finds Many People Doubt Genuine Footage Chinese Chatbots Often Sidestep China-Sensitive AI Questions [General Reports] Viral Claim That UN Barred Putin from Speaking Is False Doctored Ballot Videos Cast AfD as Fraud Victim in Germany Politicians Overstate China's Role in US Data Center Opposition CISA Election Plan Flags Voter Database Breach Attempts Fight Over Who Defines Truth May Leave Democracies Exposed [Appendix - Frameworks to Counter Disinformation] UK Orders Work on Information Defence Centre Against Hostile States Report Urges US-Backed Cognitive Defense Network for Taiwan and Japan GPTZero Launches 4o Model to Detect Paraphrased AI Text [CRC Glossary] [ Report Highlights] Swiss authorities confirmed covert and open Russian interference before Switzerland's neutrality initiative vote, though the security secretariat doubts it was decisive. The Insider estimates that Russian propagandists posing as 'angry Latvians' control about one-third of Latvia's socio-political Telegram channels. Russian actors paired an AI-faked anti-corruption raid with a cloned NV news site to portray Ukraine as corrupt during US-Russia talks. Golden Owl assessed a network of personas posing as Israelis as linked to Iran's regime, carrying fraud and decline themes into the debate before Israel's 27-10-2026 election. The EU sanctioned former RT France chief Xenia Fedorova for spreading Kremlin-aligned narratives through French media after RT's EU broadcasting suspension. The UK ordered work on a National Centre for Information Defence to disrupt hostile state disinformation, though its powers remain unclear. Preliminary research in the run-up to the Victorian election found almost half of participants could not confidently recognise genuine political video as real. Hackers leaked alleged messages between Putin's press secretary Dmitry Peskov and official Mikhail Babich, including one predicting Prigozhin would be remembered as a 'hero'. [ Report Summary] Meta says information from Singapore police helped it act on 3.7 million scam-linked accounts, pages and content in 2026, mostly seemingly empty 'shell pages'. The US Justice Department filed to support Elon Musk's court challenge against the EU's first Digital Services Act fine, imposed on X. Euronews fact-checkers found AI-generated TikTok videos of non-existent anti-immigration and nationalist protests targeting users in six European countries, some exceeding 300,000 views. EUvsDisinfo finds Russia promoting Baltic narratives resembling those it used against Ukraine, stoking fear of war as an instrument of coercion. The Insider estimates that about a third of Latvia's socio-political Telegram channels are run by Russian propagandists posing as disgruntled locals. The EU imposed an asset freeze on former RT France head Xenia Fedorova for spreading Kremlin-aligned narratives in French media after RT's EU broadcasting suspension. Swiss authorities confirmed covert as well as open Russian interference before Switzerland's neutrality initiative vote, though the security secretariat doubts it had decisive impact. Seznam Zprávy journalists lured a film crew working for Russian propaganda project Rybar, whose founder is EU-sanctioned, to Prague, exposing a wider European filming operation. Russian actors circulated an AI-generated video of a fictitious anti-corruption raid and a cloned NV website to portray Ukraine as corrupt during US-Russia talks. StopFake found that screenshots of BBC, Guardian, Independent and Al Jazeera reports blaming Ukraine for the 13-09-2026 train strike near Poland were doctored. Ukraine's disinformation center says Russia-controlled TikTok networks spread AI videos of fake Jewish pilgrims claiming state-paid resettlement in Ukraine to stoke antisemitism. RSF's second Propaganda Monitor report details how Beijing uses content deals, funded trips, influencers and pressure on journalists to pursue its 'new world media order'. Doublethink Lab concludes Chinese influence in Zambia's 2026 election worked through institutional and media ties rather than covert manipulation campaigns. Golden Owl assessed a network of personas posing as Israelis as linked to Iran's regime, carrying fraud and decline themes into Israel's election debate. NewsGuard found pro-Iran accounts using months-old footage to claim, without evidence, that the US had withdrawn thousands of troops from its Gulf bases. Black8Mirror hackers published fragments of alleged correspondence between Russian official Mikhail Babich and Putin's press secretary Dmitry Peskov from an archive they claim to hold. Democrat Vikki Goodwin filed a police report accusing Texas Lieutenant Governor Dan Patrick of breaking a 2019 deepfake law with AI-generated ads. An AI-generated art therapist persona, quoted more than 30 times by outlets including Forbes and Vice, was banned from the expert-sourcing platform Qwoted. Preliminary research before Victoria's election found about three in four participants identified deepfakes, but almost half could not confidently recognise genuine political footage. NewsGuard found US and Chinese chatbots broadly agreed on AI risks, but Chinese bots often evaded questions on AI-enabled repression or avoided naming China. NewsGuard debunked viral claims that the UN barred Putin from addressing the 2026 General Assembly over his ICC warrant while letting Netanyahu speak. Euronews found fabricated videos claiming AfD ballots were destroyed in Berlin or the party left off ballots in Mecklenburg-Western Pomerania, echoing tactics previously used by Storm-1516. PolitiFact reports that Chinese influence campaigns on US data centers showed little reach and that politicians exaggerate their role in largely organic opposition. CISA published an Election Infrastructure Security Plan on 24-09-2026, noting that attackers have tried to breach voter registration databases in all 50 states. An ASPI analysis argues that disputes over who has authority to establish truth may become Australia's key divide, creating openings for foreign interference. UK Prime Minister Andy Burnham told the UN General Assembly he has ordered work on a National Centre for Information Defence against hostile state disinformation. An Atlantic Council report proposes a US-supported cognitive warfare defense network across the first island chain to counter China's AI-enabled influence campaigns. GPTZero released its 4o detection model, designed to catch paraphrased and mixed AI text, reporting one false positive in 10,402 student essays. [State Actors] Facebook Singapore Police Data Helps Meta Disrupt Scam Networks An announcement published by Meta states that information shared by the Singapore Police Force (SPF) led the company to act against more than 113,000 fraud-linked entities and pages on Facebook and Instagram between January and June 2026, more than 33,600 entities in a June operation against seasonal e-commerce scams, and over 3.6 million 'shell pages' in July, actions it presents as totalling 3.7 million accounts, pages and content. It says the shell pages looked empty and harmless, with no ads or violating content, but formed pre-built infrastructure that scammers could activate at a moment's notice, and that for the January-June actions SPF's information led it to act on more than five times the number of assets flagged. The Singapore partnership sits within a wider ecosystem of anti-scam work, Meta says, citing a two-week US Department of Justice Scam Center Strike Force operation in May and June 2026 that disrupted 1.4 million accounts, pages and groups on Facebook and Instagram, 20,000 Microsoft accounts and thousands of Starlink kits, and led the Royal Thai Police to arrest 63 people. The company says it has removed 65 million scam ads from Facebook and Instagram so far this year, 94% of them before anyone reported them, and that it backs a shared defence in which platforms, banks, telecoms providers and governments exchange signals. Source: CyberScoop. The FTC Wants to Regulate AI for Ideological Bias. [online] Published 10 August 2026. Available at: https://cyberscoop.com/ftc-regulating-ai-ideological-bias/ Top Of Page X US Backs Musk's Challenge to EU's First DSA Fine An article published by Wired states that the US Department of Justice, with the help of the State Department, has filed an application to support Elon Musk's challenge to annul the European Union's €120 million fine against X at the EU General Court, arguing that it should be involved in the case to protect American companies. It adds that Assistant Attorney General Brett A. Shumate said 'we will not tolerate' what he called regulatory overreach by the European Commission, that President Trump has called such penalties 'overseas extortion', and that Vice President JD Vance has described the Digital Services Act's content moderation rules as 'authoritarian censorship'. The penalty, the first sanction under the Digital Services Act, followed a two-year Commission investigation which found that X's paid blue checkmarks deceptively presented users as 'verified accounts', and that its inaccessible advertising repository and failure to give researchers access to public data hinder research into the platform's risks. According to Wired, the Commission accepted X's plan in July to fix the data-access problems within six months, while Musk and X, who appealed in February, call the investigation 'incomplete and superficial' and allege prosecutorial bias. Source: WIRED. The Trump Administration Is Trying to Get Musk and X Out of a $137 Million EU Fine. [online] Published 25 September 2026. Available at: https://www.wired.com/story/trump-administration-is-trying-to-get-musk-and-x-out-of-a-dollar137-million-eu-fine/ Top Of Page TikTok AI-Fabricated Anti-Immigration Rallies Circulate on TikTok An article published by Euronews states that its fact-checking team, The Cube, identified AI-generated videos on TikTok depicting thousands of people in a range of European cities protesting against immigration, the government or 'the state of the country', or for nationalist values, none of which took place, with the content targeting users in Portugal, France, Germany, Ireland, Italy and the UK. It adds that the videos were published over the past four months, some exceeding 300,000 views, and that many pose as legitimate news outlets, including one showing a supposed journalist with a microphone bearing the logo of Portuguese state broadcaster RTP, which told The Cube she does not work for it, and that some German videos carry captions supporting the AfD. TikTok itself had labelled the videos as AI-generated and claims it bans AI content that is 'misleading about matters of public importance', yet some videos seem to slip through. Bruna Martins dos Santos of WITNESS said their continued presence does not automatically establish a policy breach but 'raises critical questions' about TikTok's detection mechanisms, labelling standards and recommender algorithms, and the article notes that the Digital Services Act requires effective measures against content that could harm civic discourse and electoral processes; TikTok did not immediately respond to a request for comment. Source: Euronews. Wave of AI Videos Showing Far-Right Protests in Europe Spreads Online. [online] Published 24 September 2026. Available at: https://www.euronews.com/2026/09/24/wave-of-ai-videos-showing-far-right-protests-in-europe-spreads-online Top Of Page Russia Russia Weaponises Fear of War Against the Baltic States An analysis published by EUvsDisinfo states that Russia is promoting a picture of the Baltic region in which NATO is preparing to attack Russia, the Baltic states are rapidly militarising, Russian speakers face imminent persecution and local authorities glorify Nazism, narratives that closely resemble those previously used against Ukraine. It cites Russian Foreign Ministry official Grigory Lukyantsev's unevidenced claim that the Baltic states were preparing mass deportations of Russian speakers, which Russian state-aligned media widely amplified while Russian embassies in all three countries publicised a joint Russian-Belarusian report on alleged rights violations, and the ministry's announced plan to take the alleged 'systematic violation' of ethnic Russians' rights to the International Court of Justice. EUvsDisinfo argues that these narratives serve Moscow regardless of its current intent or timetable, because stoking fears of imminent war can weaken confidence in NATO, encourage risk-averse Western decisions and frame defensive preparations as escalation, so that the possibility of conflict itself becomes an instrument of coercion. It warns that capability, rhetoric and evidence of imminent intent should not be treated as interchangeable, noting that Estonian and Latvian officials signalled no change in their threat assessments after anonymously sourced US reports about the CIA director's Moscow visit, and concludes that preparations should rest on a rational assessment of Russian capabilities rather than on the fear the Kremlin seeks to spread. Source: EUvsDisinfo. Russia’s Baltic Escalation Playbook: Fear Is Part of the Strategy. [online] Published 24 September 2026. Available at: https://euvsdisinfo.eu/russias-baltic-escalation-playbook-fear-is-part-of-the-strategy/ Top Of Page Russian Propagandists Pose as 'Angry Latvians' on Telegram An investigation published by The Insider states that the outlet estimates around one-third of the socio-political channels in Latvia's Telegram ecosystem, and upwards of 65% of the Russian-language ones, are controlled by Russian propagandists posing as 'angry Latvians'. It adds that its analysis covered 72 socio-political channels and 353,000 posts published since 01-01-2025, finding that of 93,000 shares, 30.3% were reposts between the channels themselves and 43.7% came from Russian state media, official government channels, military bloggers and pro-war 'Z-channels', and that the largest channels are linked to the state media group Rossiya Segodnya, which includes RT. The people behind the five largest channels criticise Latvian policy from abroad after moving to Russia or Belarus while presenting themselves as voices of the country's 'outraged citizens', according to the investigation, which names former Saeima member Aleksejs Rosļikovs, who left for Belarus in spring 2026 and runs a roughly 30,000-subscriber channel, and the 24,000-subscriber Baltnews, run by the editorial staff of the Russia Today news agency. The Insider says the network repeats Kremlin narratives about persecuted Russian speakers, rising Nazism and impoverishment blamed on Riga's support for Ukraine, and that one small Wagner-branded channel, 'Zloi Pribalt', has published about 66,000 posts since January 2025. Source: The Insider. “Pashinyan’s illness,” “looming war with Russia,” and “gas chambers on Mount Ararat”: Moscow floods Armenia with disinfo ahead of elections. [online] Published 29 May 2026. Available at: https://theins.press/en/inv/297571 Top Of Page EU Sanctions Ex-RT France Chief Xenia Fedorova An announcement published by the Council of the EU states that the Council adopted restrictive measures against Xenia Fedorova, a Russian media figure and former President and Director of Information of RT France, for engaging in foreign information manipulation and interference (FIMI) as part of Russia's hybrid activities. It says that after RT's broadcasting activities were suspended in the EU, Fedorova continued to disseminate narratives aligned with those promoted by the Russian authorities on the war against Ukraine, European support for Ukraine, NATO and EU-Russia relations through French outlets including CNews, Europe 1 and Le JDNews. The listing brings the number of individuals and entities covered by the EU's framework for restrictive measures over Russia's destabilising activities to 81 and 20 respectively, and those listed that day are subject to an asset freeze, with EU citizens and companies barred from making funds or economic resources available to them. The framework, set up on 08-10-2024, also targets those responsible for Russia's hybrid activities against third countries and international organisations, and the Council notes that the European Council in June 2026 called for urgent efforts to prevent, deter and respond to hybrid attacks by hostile actors, notably Russia and Belarus. Source: Council of the European Union. Russian hybrid threats: EU lists Xenia Fedorova over information manipulation activities. [online] Published 24 September 2026. Available at: https://www.consilium.europa.eu/en/press/press-releases/2026/09/24/russian-hybrid-threats-eu-lists-xenia-fedorova-over-information-manipulation-activities/ Top Of Page Swiss Detect Covert Russian Operations Before Neutrality Vote An article published by SWI swissinfo.ch states that Swiss authorities confirm Russian actors interfered both openly and covertly in the campaign ahead of the neutrality initiative vote, which, if accepted, would have barred Switzerland from following EU sanctions against Moscow, with the State Secretariat for Security Policy (SEPOS) writing that 'coordinated, covert disinformation operations' were observed but that it did not believe foreign actors had a decisive impact. It adds that, in the open interference, Russian state platform RT DE published many articles about the initiative, and during the campaign RT published an error-laden article in Swiss dialect, while Russian foreign ministry spokeswoman Maria Zakharova claimed the Swiss financial system had served the German war machine during the Second World War. Citing British historian Ian Garner, the article says the Kremlin cares less about winning a vote than about getting an argument across, which Garner calls 'a kind of victory' when it succeeds, while DFRLab expert Ruslan Trad called an earlier RT move, publishing opposing opinion pieces under the same byline on a Swiss licence-fee initiative, 'a textbook influence-operation tell'. Russian state media are sanctioned in the EU, where sharing their content is banned, but not in Switzerland, where cable operators have voluntarily stopped carrying such channels while RT remains accessible online, and parliament has tasked the government with laying foundations for 'an effective analysis' of foreign influence attempts. Source: SWI swissinfo.ch. Swiss Democracy in the Crosshairs of Russian Propaganda. [online] Published 27 September 2026. Available at: https://www.swissinfo.ch/eng/information-wars/swiss-democracy-in-the-crosshairs-of-russian-propaganda/92127460 Top Of Page Czech Sting Exposes Rybar Film Crew Operating in Europe An article published by The Insider states that journalists from the Czech outlet Seznam Zprávy used the Russian propaganda project Rybar's interview request to media literacy expert Bohumil Kartous to lure a film crew from Berlin to Prague, where correspondent Vitaliy Chashchukhin confirmed on hidden camera that the filming was for Rybar before he and cameraman Igor Dolmatov fled when confronted. It adds that the investigation linked the organiser, Moscow-based filmmaker Boris Dvorkin, to the History of the Fatherland Foundation chaired by foreign intelligence chief Sergei Naryshkin, and found that the project's list of potential or completed interview subjects included an MEP and several Czech experts, with a former military intelligence chief and an energy expert confirming they had been filmed and Dvorkin's own messages referring to a crew delayed in Slovakia. Dvorkin's planned questions included whether right-wing and Euroskeptic ideas were becoming more popular in Czechia and how relations with Russia could be normalised, and he was particularly interested in disinformation, with Kartous saying the questions appeared designed to portray disinformation as a phenomenon 'on both sides of the border' and to cast doubt on Czech sovereignty within the EU. Rybar, whose founder Mikhail Zvinchuk is under EU sanctions, openly describes its work as participation in an information war, and a Czech Finance Ministry spokesperson said providing services to an organisation controlled by a sanctioned person can count as indirect provision of economic resources to that person, with the article noting that sanctions violations in Czechia can carry criminal liability and fines of up to 50 million koruna. Source: The Insider. Czech journalists lure Russian propaganda project Rybar’s film crew to Prague to expose influence operation across Europe. [online] Available at: https://theins.press/en/news/297421 Top Of Page Russians Clone NV Site to Push AI-Faked Ukraine Graft Story An article published by The New Voice of Ukraine (NV) states that Russians created and spread an AI-generated video, circulating from 23-09-2026, a day before US envoys Steve Witkoff and Jared Kushner met Putin envoy Kirill Dmitriev in New York, that purported to show Ukraine's National Anti-Corruption Bureau (NABU) finding $140 million in cartons labelled 'for Servant of the People' while searching Arsen Zhumadilov, former head of the Defense Procurement Agency, a search NABU says never took place, in an effort to portray Ukraine to the West as corrupt. It adds that, to make the fabrication look like genuine news, the perpetrators registered the domain nvukraine.com, copied NV's design, and posted a fake article dated 23-09-2026 in Ukrainian and English. According to Ukraine's Center for Strategic Communications and Information Security (SPRAVDI), the fake was picked up on 24-09-2026 by the pro-war Russian Telegram channels Golos Mordora and Militarist, with about 149,000 and 277,000 subscribers, spread in English-language communities on Lemmy and, on X, by RT author Chay Bowes, shared by Dmitriev himself on 25-09-2026 and then carried by RIA Novosti, Life, Vesti, Ukraina.ru and Mail.ru sites. SPRAVDI concluded that the operation made the story appear to originate within Ukraine's own information space, promoting a narrative of large-scale defence-sector corruption to Western audiences against the backdrop of Russia's contacts with the United States. Source: The New Voice of Ukraine. Russia Spreads Fake $140 Million Ukraine Corruption Story During U.S. Talks. [online] Published 25 September 2026. Available at: https://english.nv.ua/nation/russia-spreads-fake-140-million-ukraine-corruption-story-during-dmitriev-u-s-talks-50644647.html Top Of Page Doctored Media Screenshots Blame Ukraine for Russian Train Strike An article published by StopFake states that screenshots circulating online, styled as BBC, Guardian, Independent and Al Jazeera reports, falsely claim that Ukrainian intelligence orchestrated the 13-09-2026 attack on a railway near the Ukrainian-Polish border to drag European countries into the war, citing former MI6 chief Alex Younger as the source. It says the headlines were doctored and the claims fabricated, noting that Younger died more than three months before the strike, with the UK government publishing a tribute on 03-06-2026, and that the genuine BBC report describes a Russian drone hitting a locomotive in Yahodyn shortly after Boris Johnson and senior European officials had left the station. Beyond the doctored headlines, the Guardian and Independent images carried fabricated subheadings and, in the Al Jazeera case, the headline and description of a genuine 14-09-2026 video report were altered so that the headline opened with the words 'Ukrainian hoax', while the original Guardian and Independent articles say the Russian strike may also have been aimed at trains carrying Johnson and the former CIA director. StopFake adds that passengers were evacuated and no injuries were reported, that former CIA director David Petraeus was on another train at Yahodyn station at the time, and that it previously examined disinformation claiming Ukraine may have staged a false-flag operation at Leipzig airport to discredit Russia. Source: StopFake. Fake: Western Media Report that Ukrainian Intelligence Orchestrated the Attack on Boris Johnson’s Train. [online] Published 24 September 2026. Available at: https://www.stopfake.org/en/fake-western-media-report-that-ukrainian-intelligence-orchestrated-the-attack-on-boris-johnson-s-train/ Top Of Page AI Videos of Fake Pilgrims Spread Uman Resettlement Myth An article published by The Jerusalem Post states that Ukraine's Center for Countering Disinformation (CCD) said that, during and after Rosh Hashanah, Russia-controlled TikTok account networks circulated AI-generated interview videos in which fake Jewish pilgrims to Uman claimed they were moving to Ukraine permanently, citing fabricated 'payments from the Ukrainian government of 200,000 hryvnias', special benefits and plans to make Uman an independent entity. It adds that the CCD called the campaign 'entirely disinformation', stressing that the pilgrimage is temporary and that Ukraine has no programme paying foreigners to relocate, while local health authorities counted a record of more than 49,000 pilgrims in the city by the morning of 11-09-2026. The Israel-based media site Nikk traced the narrative back to a 2019 text by then-Kremlin adviser Sergey Glazyev; researchers documented Matryoshka-network fakes in April 2026 claiming Ukraine planned to bar Israeli pilgrims; and the narrative's trajectory ran to an AI-generated pilgrim supposedly 'confessing' on 14-09-2026 to receiving money. Nikk argued the campaign works by slightly altering the relationships between real elements rather than inventing one large fake, such as joint patrols by Israeli and Ukrainian police and an unrelated Ukrainian state payment of exactly 200,000 hryvnias, while the CCD said the aim is to destabilise Ukrainian society and artificially provoke antisemitic sentiment. Source: The Jerusalem Post. Russia spreads AI fakes claiming Jews are being paid to settle in Ukraine. [online] Published 22 September 2026. Available at: https://www.jpost.com/international/internationalrussia-ukraine-war/article-909326 Top Of Page China RSF Details Ten Tactics Beijing Uses to Export Propaganda A report published by Reporters Without Borders (RSF) states that its second Propaganda Monitor report traces the Chinese regime's global propaganda apparatus across five continents and concludes that no country is immune, as Beijing pursues the 'new world media order' Xi Jinping has promoted since 2012. It identifies ten tactics, including content-sharing deals that let Chinese state content be republished as seemingly independent journalism in Germany, funding and equipment in exchange for editorial alignment in the Solomon Islands, embassy pressure and doxxing of journalists in the Philippines and Denmark, and sponsored trips for foreign YouTubers and TikTok creators. According to RSF, the apparatus runs from the Central Propaganda Department, which controls the content of state media such as CGTN and Xinhua, operating in 160 countries, to diaspora media in the US, Australia and New Zealand, and China, ranked 178th of 180 in RSF's 2026 World Press Freedom Index, is the world's leading jailer of journalists with 120 detained. The report adds that the China-based company Wubianjie has invested heavily in promoting disinformation in Taiwanese Facebook lifestyle groups and Threads accounts, particularly during politically sensitive and fragile periods, and that CGTN amplifies Russian state outlets Sputnik and RT, with RSF warning that China works hand in hand with authoritarian regimes such as Putin's Russia to strengthen their grip on the global information space. Source: Reporters Without Borders (RSF). The Propaganda Monitor: RSF exposes China’s global campaign to distort journalism worldwide. [online] Published 21 September 2026. Available at: https://rsf.org/en/propaganda-monitor-rsf-exposes-china-s-global-campaign-distort-journalism-worldwide Top Of Page PRC Sway in Zambia's Election Was Structural, Not Covert A report published by Doublethink Lab states that its investigation into the 2026 Zambian general election, conducted from May to August 2026, found the People's Republic of China's influence to be 'structural, not covert', operating through decades of institutional ties across Zambia's economy, media, education and digital infrastructure rather than through covert directives or foreign information manipulation and interference (FIMI) campaigns. It found that development narratives, such as solar power deals and PRC donations of 'election security' vehicles, were absorbed into campaign communications without explicit PRC intervention, and that FIMI techniques observed on Facebook, including fake personas, image manipulation and information flooding, could not be definitively attributed to the PRC. Narratives about the PRC's engagement in Zambia potentially affected the election, the report finds, by legitimising the incumbent UPND and existing institutional actors and by narrowing the public agenda to the delivery of material goods while constraining scrutiny of debt conditions, procurement transparency and surveillance capability. It illustrates the structural position with TopStar, a digital television joint venture in which, according to publicly available records, Chinese firm StarTimes holds 60% and national broadcaster ZNBC 40%, while cautioning that institutional access does not prove editorial control, and recommends public disclosure of foreign relationships, labelling of foreign-supplied content and FIMI analysis that extends beyond bots and fake accounts to funding and framing shifts. Source: DoubleThink Lab. Structural Ties Over Manipulation: An Analysis of PRC Influence During the 2026 Zambian Election. [online] Available at: https://medium.com/doublethinklab/structural-ties-over-manipulation-an-analysis-of-prc-influence-during-the-2026-zambian-election-6e89711ce2e3 Top Of Page Iran Golden Owl Assesses Fake Israeli Persona Network as Iran-Linked A report published by Golden Owl states that it identified a coordinated, foreign-operated influence network targeting Israel's 2026 election debate ahead of the 27-10-2026 vote, documenting an operational core of 35 accounts made up of 32 Israeli-presenting personas and three Hebrew media-style channels, whose personas carry themes of fraud, security, political responsibility and national decline into genuine Israeli debates, and that the combined evidence is most consistent with an operation associated with the Islamic Republic of Iran. It adds that in the measured 30-day window from August 23rd, 2026 to September 22nd, 2026, posts by active network accounts received 947,322 impressions and 9,112 interactions, and that genuine Israeli users helped circulate some of that content without being assessed as participants in the operation. Golden Owl says the assessment rests on combined evidence rather than political viewpoint, including X's transparency data showing four of the personas connecting through the 'Iran Android App' while geolocated to Germany or Finland, one of them an account that posted only in Persian until April 2026 and re-emerged on 26-08-2026 as 'Alon Strauss' with an Israeli flag as its avatar, and account records showing that 26 of the 32 personas were created in 2025 or 2026. Reach was concentrated, with a single emigration video accounting for 688,434 of the measured views, and the report cautions that the 1,516 flags from its broader election scan are not distinct cases and are not all attributed to the operation, and that the evidence does not establish who personally operated the accounts, which institution directed them, or whether the activity changed any voter's decision or the election outcome. Source: Golden Owl. The Other Face of War: Iranian Regime–Linked Manipulation of Israel’s 2026 Election Debate. [online] Published 24 September 2026. Available at: https://goldenowl.ai/resources/research/Iranian-Regime-Linked-Manipulation-of-Israel-2026-Election-Debate Top Of Page Months-Old Footage Used to Claim US Troop Pullout from Gulf A report published by NewsGuard Reality Check states that pro-Iran social media accounts are claiming, in Farsi, English, Chinese and French on Facebook, X and Instagram, that the US has withdrawn thousands of troops from its bases in Qatar, Bahrain, Kuwait and other Gulf countries, in an apparent effort to present Iran as the victor in its war with the US and Israel. It found no evidence of any such withdrawal, noting that the US has 50,000 troops stationed in the Middle East, according to Reuters, and that Qatar alone hosts 10,000 US troops and Al Udeid Air Base, the largest US military installation in the region. The two videos used as evidence, one of troops marching in a parking lot at night and one of troops with large packs on a military aircraft, predate the purported withdrawal: NewsGuard found that one first appeared in March 2026, showing heavy winter gear inconsistent with September temperatures and no protective equipment expected amid hostilities, and that the other was first published in June 2026. It notes that real but limited US moves, including a planned withdrawal from Iraq by September 30th and the earlier handover of bases in Syria, do not amount to a mass withdrawal from the region. Source: NewsGuard. The Troop Withdrawal That Didn’t Happen. [online] Published 25 September 2026. Available at: https://www.newsguardrealitycheck.com/p/the-troop-withdrawal-that-didnt-happen Top Of Page Cyfluence Attack Hackers Leak Alleged Peskov Messages from Claimed Babich Archive An article published by Nasha Niva states that the hacker group Black8Mirror claimed to have obtained an archive of more than 21 GB belonging to Mikhail Babich, former Russian ambassador to Belarus and deputy director of the Federal Service for Military-Technical Cooperation since 2021, covering 2020 to August 2026, and published fragments and screenshots of his alleged correspondence with Vladimir Putin's press secretary Dmitry Peskov. It adds that in the fragments, 'Peskov' calls Kazakh President Kassym-Jomart Tokayev's July 2026 speech, in which he proposed freezing the war, 'pure improvisation', says someone 'asked Tokayev to say this' and that the only question is whether it was 'Ukrainians, Americans, or someone from within', and defends a scaled-down Navy Day event as 'safe'. The most striking fragment dated May 24th, 2023, a month before the Wagner mutiny, shows 'Peskov' telling 'Babich' that he had argued with Yevgeny Prigozhin for an hour and that 'later we will remember him as a hero', after 'Babich' forwarded a summary of Prigozhin's views on Navalny's imprisonment. An analysis of the publication found the forwarded text, shown on the screenshot as a message from a 'Nikolai Petrov', originated from a since-deleted post on the Telegram channel 'EZh', and the exchange is dated one day after a long interview in which Prigozhin argued Russia had contributed to Ukraine's militarisation and reflected on Navalny's anti-corruption investigations. Source: Nasha Niva. "Later we will remember Prigozhin as a hero." Hackers published alleged correspondence between Babich and Peskov. [online] Available at: https://nashaniva.com/en/405318 Top Of Page [AI Related Articles] Texas Candidate Files Police Report Over AI-Generated Campaign Ads An article published by The Texas Tribune states that Vikki Goodwin, the Democratic candidate for Texas lieutenant governor, filed a police report with the Travis County Sheriff's Office on September 19th, accusing Republican Lt. Gov. Dan Patrick of breaking state law after his campaign released two ads featuring AI-generated videos of her. It adds that the videos have since been deleted from Patrick's X account and that, in an affidavit, Goodwin said the person in the video 'appears to be me' but was not, and alleged that Patrick posted it 'with the intent to deceive Texans, injure a candidate, or influence the result of an election'. Goodwin invoked a 2019 Texas law, one of the earliest in the US to regulate AI in political campaigns, which bans deepfake videos made with intent to deceive from being published or distributed within 30 days of an election, arguing it applies because early in-person voting begins on October 19th, and mail ballots are about to be sent. Patrick campaign spokesman Allen Blakemore told The New York Times the material was 'an obvious parody produced to entertain' and denied distributing any such content within 30 days of the election, while Goodwin's communications director said removing the posts the day after the complaint looked like an admission of guilt. Source: The Texas Tribune. In lieutenant governor race, Vikki Goodwin says Dan Patrick ads are illegal AI deepfakes. [online] Published 21 September 2026. Available at: https://www.texastribune.org/2026/09/21/texas-goodwin-patrick-ad-police-complaint/ Top Of Page AI-Generated Persona Quoted 30-Plus Times by Major Outlets An article published by Cybernews states that 'Dr. Eleni Nicolaou', an art therapist listed as a source on the journalist expert platform Qwoted, was banned from the platform after the journalism news outlet Press Gazette exposed her as an AI-generated persona, finding that much of her profile, from her picture to her 'expert opinions', was AI-generated and that her identity could not be verified. It adds that her comments had appeared more than 30 times in recent months in outlets including Tom's Guide, Forbes, Glamour, Vice, Netmums, AOL and Yahoo, and that the persona was linked to Davincified, an e-commerce site selling paint-by-numbers prints. The persona had its own LinkedIn profile claiming a PhD in clinical psychology from the University of Cyprus and a Davincified email address, and the Qwoted profile combined with professional profiles on platforms such as LinkedIn raised no alarms on the surface, although Press Gazette found her profile picture scored a perfect 10 on an AI scale and her comments were deemed 100% AI-generated. Cybernews adds that AI detectors such as GPTZero can help but vary in accuracy, citing a case in which Meta's detector misidentified 55% of its own AI images after Reuters edited them, and advises independent verification of sources. Source: Cybernews. AI-generated expert removed from Qwoted after media quotes. [online] Published 24 September 2026. Available at: https://cybernews.com/ai-news/fake-art-therapist-qwoted-expert-vice-forbes/ Top Of Page Preliminary Study Finds Many People Doubt Genuine Footage An article published by The Conversation states that AI-generated deepfakes, including a machete attack at a petrol station and floodwater pouring down the steps of parliament, have reportedly appeared as paid advertising months before the Victorian state election, and that in an experiment with 411 Australians, part of the authors' study of political deepfakes in the lead-up to that election, roughly 75% of participants correctly identified deepfakes regardless of quality. It adds that, according to these preliminary findings, almost 29% labelled an authentic political video as fake and a further 18% were unsure, meaning almost half could not confidently identify genuine political content as real. The authors' yet-to-be-published meta-analysis of 19 studies covering more than 24,000 people from 2018 to 2026 found deepfakes can appear just as persuasive as authentic footage or conventional misinformation and are associated with lower trust in news and democratic institutions, an uncertainty the authors say can contribute to the 'liar's dividend'. In their preliminary experimental findings, people who consumed more news were better at detecting low-quality deepfakes but became less accurate at identifying authentic content, confidence among moderate and higher news consumers became increasingly disconnected from accuracy, and differences linked to political orientation emerged only when the deepfake depicted a political actor aligned with the viewer. Source: The Conversation. Deepfakes are distorting this year’s Victorian election. We found out who’s most susceptible to them. [online] Published 27 September 2026. Available at: https://theconversation.com/deepfakes-are-distorting-this-years-victorian-election-we-found-out-whos-most-susceptible-to-them-291443 Top Of Page Chinese Chatbots Often Sidestep China-Sensitive AI Questions A report published by NewsGuard Reality Check states that, ahead of Xi Jinping's 24-09-2026 meeting with President Trump, it tested six Chinese AI chatbots, including DeepSeek, Baidu's Ernie, Alibaba's Qwen and Moonshot AI's Kimi, and US tools including ChatGPT, Grok, Claude and Gemini with six prompts relating to AI, finding far more agreement than disagreement. It adds that all the chatbots identified AI safety as a government's top priority when developing AI and that both sides favoured targeted rather than blanket slowdowns of AI development and described similar scenarios in which AI could spin out of control. According to NewsGuard, the bots diverged on topics sensitive to China, such as the Chinese government's AI-empowered mass surveillance and its use of AI to suppress dissidents: asked whether AI can be used to suppress political dissent, two Chinese chatbots evaded the question and three of the four that answered avoided mentioning China, while three of the six Chinese bots did not address which countries have been criticised for AI-enabled human rights abuses and those that did cited the US and other Western countries. The US chatbots engaged directly on such misuse, and all cited China, and NewsGuard quotes Tencent's Yuanbao saying it could not 'directly elaborate on examples involving political topics'. Source: NewsGuard. U.S. and Chinese AI Tools Are More Alike Than You May Think. [online] Published 24 September 2026. Available at: https://www.newsguardrealitycheck.com/p/us-and-chinese-ai-tools-are-more Top Of Page [General Reports] Viral Claim That UN Barred Putin from Speaking Is False A report published by NewsGuard Reality Check states that anti-Israel and pro-Kremlin social media users falsely claimed on September 22nd, 2026, that the UN barred Vladimir Putin from addressing the 2026 General Assembly because of his International Criminal Court arrest warrant while allowing Benjamin Netanyahu, who also faces an ICC warrant, to speak, presenting this as proof of pro-Israel bias. It adds that the claim emerged in a post by Mohamad Safa, former representative of the Patriotic Vision Association, which drew 1.2 million views and 133,000 likes in one day, and was repeated by the account @Rusia_HD, which garnered 544,100 views. Putin was not blocked: according to NPR and Deutsche Welle, he chose Foreign Minister Sergei Lavrov to attend in his place; he has not attended the General Assembly since 2015, UN deputy spokesperson Farhan Aziz Haq told NewsGuard the claim was false, and the UN and ICC are separate entities with no prohibition on leaders facing ICC warrants speaking at UN meetings. NewsGuard named the claim its 'False Claim of the Week' because of its spread across platforms, high engagement, and the prominence of those promoting it, and notes that the UN is far more commonly accused of anti-Israel bias. Source: NewsGuard. The Putin UN Ban That Wasn’t. [online] Published 25 September 2026. Available at: https://www.newsguardrealitycheck.com/p/the-putin-un-ban-that-wasnt Top Of Page Doctored Ballot Videos Cast AfD as Fraud Victim in Germany An article published by Euronews states that videos alleging fraud against the Alternative for Germany (AfD), purporting to show AfD postal ballots being destroyed in Berlin or the party missing from ballots in Mecklenburg-Western Pomerania, spread on X ahead of the two elections, garnered hundreds of thousands of views and echoed tactics previously used by the pro-Russian influence network Storm-1516. It adds that one Berlin video was shared by EU-sanctioned pro-Russian blogger Alina Lipp, whose post exceeded 630,000 views, and that Mecklenburg-Western Pomerania's state election chief, Christian Boden, confirmed the AfD appeared on that state's genuine postal ballots and said the forgeries there were closely modelled on official sample ballots with the AfD fields deleted. Election-monitoring site Wahlrecht.de found the purported Berlin postal packages lacked the polling cards voters must return, had unsealed envelopes and were missing district council ballots. Euronews reports that some videos were amplified by accounts known for pro-Russian theories and closely resembled 2025 federal election fakes that German authorities said appeared to form part of a campaign associated with Storm-1516, a network whose 'central actor', according to Germany's Federal Intelligence Service, is Russia, and notes that the false narrative casts the AfD and its supporters as victims, that the AfD finished first in Mecklenburg-Western Pomerania with 38.2% of the vote, and that there is no evidence the party is behind the campaign. Source: Euronews. Fake videos spread fraud claims during German elections. [online] Published 23 September 2026. Available at: https://www.euronews.com/2026/09/23/fake-videos-spread-fraud-claims-during-german-elections Top Of Page Politicians Overstate China's Role in US Data Center Opposition An analysis published by PolitiFact states that politicians, including President Trump, who told Fox News host Laura Ingraham that 'a lot of people say' data center opposition is 'a China PR thing', exaggerate the effect of Chinese influence campaigns on a movement that spans Americans of all political stripes in nearly every state. It cites OpenAI's report that it found no evidence of meaningful breakout for a China-linked operation that used ChatGPT to argue data centers raise electricity prices, and X's identification of 200 accounts within a bot farm of about 200,000 posting in a manner that could manipulate the debate, noting that Clemson University researcher Darren Linvill's team found 70 accounts common to both sets had no followers or engagement before suspension. Council on Foreign Relations fellow Jessica Brandt said foreign actors exploit the data center debate rather than manufacture it and that 'evidence of an attempt is not evidence of success', while Linvill said a genuine Chinese priority would involve 'far more than 200 accounts'. PolitiFact points to measures of organic opposition, including an Annenberg survey in which 61% of US adults opposed local data center construction, up 12 points, and 580 local opposition groups with 640,000 members, and notes that TV personality Kevin O'Leary, who called two Utah nonprofits proxies for the Chinese government, was sued for defamation by them and recanted. Source: PolitiFact. Is US data center opposition a ‘China PR thing,’ as Trump says? Experts say that’s exaggerated. [online] Published 23 September 2026. Available at: https://politifact.com/article/2026/sep/23/china-influence-data-center-opposition/ Top Of Page CISA Election Plan Flags Voter Database Breach Attempts An article published by Infosecurity Magazine states that the US Cybersecurity and Infrastructure Security Agency (CISA) published an Election Infrastructure Security Plan on September 24th, 2026, ahead of the November 3rd, 2026, midterm elections, setting out guidance for state, local, and federal bodies on mitigating cyber and physical threats to election infrastructure. It adds that the plan notes that threat actors have attempted to breach statewide voter registration databases in all 50 states, with confirmed success in at least 20 over the last decade, and urges multifactor authentication, continuous network monitoring and comprehensive audit trails. The plan also flags vulnerability exploitation through election systems reachable from general enterprise networks and insider risks from temporary poll workers, contractors and vendors, recommending paper ballots, bipartisan ballot handling and chain-of-custody procedures. Security experts have warned that reported 2025 cuts to CISA impacted its efforts to secure election infrastructure, including the reported termination of federally funded support for the Election Infrastructure Information Sharing and Analysis Center (EI-ISAC), which the new plan does not specifically mention. Source: Infosecurity Magazine. CISA Unveils Election Security Plan Ahead of 2026 Midterms. [online] Published 25 September 2026. Available at: https://www.infosecurity-magazine.com/news/cisa-election-security-midterms/ Top Of Page Fight Over Who Defines Truth May Leave Democracies Exposed An analysis published by The Strategist (ASPI) states that Australia's next class war may be fought less over wealth than over truth, as the deepest disagreements increasingly concern who has the authority to establish what is true and institutional authority based on credentials and editorial processes competes with networked authority derived from authenticity, affinity, audience and visibility. It cites research indicating that social media can amplify the false-consensus effect, although the effects are generally modest and vary across platforms and users, and argues that with personalised algorithms an online audience can gradually become an assumed majority and political disappointment can be reinterpreted as evidence that institutions no longer represent the people, which creates fertile ground for conspiratorial reasoning. The analysis argues that foreign interference is most effective where trust has already begun to fracture, and that adversaries need not persuade Australians that their worldviews are correct if they can persuade them that no domestic institution deserves confidence, suggesting the most effective information operation may no longer be 'believe us' but simply 'don't believe them'. It calls for trust proportionate to evidence rather than blind institutional faith or reflexive cynicism, and lists compulsory voting, robust electoral institutions and an independent electoral commission as Australian strengths that should not breed complacency. Source: Australian Strategic Policy Institute (ASPI). Australia’s next class war may be fought over reality. [online] Published 24 September 2026. Available at: https://www.aspistrategist.org.au/australias-next-class-war-may-be-fought-over-reality/ Top Of Page [Appendix - Frameworks to Counter Disinformation] UK Orders Work on Information Defence Centre Against Hostile States An article published by The Record states that British Prime Minister Andy Burnham told the UN General Assembly he has ordered security chiefs to begin work on a National Centre for Information Defence to 'detect, attribute and disrupt' hostile state disinformation, with the Cabinet Office understood to be leading initial work involving intelligence agencies, government departments, law enforcement and social media companies. It adds that Burnham accused Russian agencies of using bots and fake websites, falsifying newspaper articles, copying the branding of 28 British organisations including universities and the BBC, and amplifying far-right narratives, and said the Kremlin spends around £1.3 billion a year on manipulating information. Experts questioned the centre's form and accountability, with RUSI analyst Sophie Williams-Dunning noting 'a real difference between a centre inside the Cabinet Office and an agency accountable to Parliament' and saying a high evidentiary threshold, particularly on proving foreign orchestration, is one reason the National Security Act 2023 foreign interference offence has been hard to use. She said Burnham's language suggests something closer to 'defending forward' than France's Viginum, which focuses on detection, coordination and public attribution of foreign operations without an explicit disruption mandate, while The Record notes it is not yet clear what powers the new centre would have to carry out disruption. Source: The Record. Burnham Announces Plan for New UK Center to Fight Disinformation. [online] Published 23 September 2026. Available at: https://therecord.media/uk-disinformation-russia-center Top Of Page Report Urges US-Backed Cognitive Defense Network for Taiwan and Japan A report published by the Atlantic Council states that the Chinese Communist Party has upgraded the cognitive domain from the 'Three Warfares' to a contest for 'brain control', running AI-enabled, party-state-wide influence campaigns, including through contracted AI firms exploiting fears of US abandonment, that evolve faster than democratic countermeasures, while most security cooperation among first island chain nations still focuses on physical threats. It adds that the report, by Major Yu-Hao 'Vinson' Shen, uses the DISARM framework to compare China's military cognitive warfare against Taiwan and Japan and finds both democracies constrained in regulating hostile content by free speech norms and public concern about government control of information. Taiwan and Japan have complementary strengths, the report finds, with Taiwan offering a mature public-private ecosystem, linguistic proximity and frontline experience, and Japan stronger internal official coordination, alliance management and international strategic communication. It recommends integrating them in a US-supported multilateral cognitive warfare defense network across the first island chain, built on a shared framework and common operational picture, which it says would help democracies move from isolated, reactive responses toward coordinated early warning and proactive defence; it separately urges first island chain democracies and the United States to share what they see, build civil society into their own response, and train together, and discloses that the report and the author's fellowship were made possible by support from Taiwan's Ministry of National Defense. Source: Atlantic Council. Building a Multilateral Cognitive Warfare Defense Network: A Collaborative Framework for the United States, Japan, and Taiwan. [online] Published 23 September 2026. Available at: https://www.atlanticcouncil.org/in-depth-research-reports/report/building-a-multilateral-cognitive-warfare-defense-network/ Top Of Page GPTZero Launches 4o Model to Detect Paraphrased AI Text An announcement published by GPTZero states that its new GPTZero 4o model, the default for all users since 20-09-2026, deliberately tackles the harder cases of AI-generated text that has been paraphrased or mixed with human writing, and is versatile across model types including Claude, OpenAI, Gemini, Grok and DeepSeek. It adds that the company recorded one false positive out of 10,402 essays on the PERSUADE student-writing dataset and AI recall above 99% on its own benchmark covering GPT-5.6, Gemini 3.6, Grok 4.5 and Claude 5, with a false positive rate below 0.03% on human text. The release adds interpretability features, including an 'AI Patterns' view that explains recurring stylistic structures such as a 'Phantom Experts' pattern, in which claims are assigned to unnamed authorities instead of identified sources, and 'Masked Detection', which excludes headings from analysis. GPTZero says the model is designed to be indifferent to punctuation changes such as em dashes and that, on the Epoch AI and DetectRL benchmarks 4o matched or outperformed rival detector Pangram 4 on most measures, and it cites a Graphite study which, as Graphite reported, found lower error rates for GPTZero than for Pangram. Source: GPTZero. Introducing GPTZero 4o. [online] Published 24 September 2026. Available at: https://gptzero.me/news/introducing-gptzero-4o/ Top Of Page [CRC Glossary] The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult. To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence. As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website. Top Of Page

  • Emotional Regulation as an Overlooked Dimension of Information Manipulation Resilience

    In her article, Tamara Klevova identifies a gap in influence defense and counter-FIMI practice: existing approaches emphasize awareness and critical-thinking skills but give too little attention to crucial emotion-based prerequisites. According to Klevova, recognizing a manipulation technique does not guarantee that someone can apply what they have learned, when experiencing fear, anger, or grief. Klevova argues that this gap reflects the effects of emotional pressure on judgment, rather than a failure to learn the relevant skills. Drawing on neuroscience and psychology, the article explains how strong emotions can impair deliberate evaluation and increase reliance on rapid, automatic responses. Malign influence operations can exploit this vulnerability through emotionally charged content that spreads widely online. Although some frameworks identify emotional manipulation as a tactic, they offer limited guidance on helping audiences manage their reactions. Klevova therefore proposes “emotional readiness” as a measurable, trainable component of cognitive and societal resilience. She recommends teaching people to recognize content designed to provoke emotion, introducing brief emotional check-ins before fact-checking exercises, and recording the emotions targeted by hostile influence campaigns in threat analysis. Author: Tamara Klevova (The author’s name has been changed at their request to protect their privacy. The author’s identity has been verified by the CRC’s editorial board) [Download PDF Here]

  • Cyber based influence campaigns 7th – 13th September 2026 Report

    [Introduction] Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW). Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc. During the 7th September – 13th September 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities. [Contents] [Introduction] [Report Highlights] [Report Summary] [State Actors] Russia Russia Escalates Hybrid Attacks on Northern European Infrastructure Matryoshka Targets 2026 US Midterms with Voice-Cloned Celebrity Videos Russian Propagandists Use Fake Polish Newspaper to Spread Ukraine Famine Claim Russia Fabricated SBU Staging Claim to Deflect Blame for Drone Strike Russia-Linked Team Builds Autonomous Drone Swarm China CCP Influence Operations Use AI Personas to Fragment US Audiences [AI Related Articles] AI Disaster Footage Outruns Fact-Checkers as Deepfake Arrests Lag Generation Scale Anthropic Disrupts Nine IO Campaigns as AI Collapses State-Nonstate Capability Gap Anthropic Threat Chief Warns Higher-Breakout AI Influence Campaigns Are Coming [General Reports] 2026 Midterm Disinformation Environment More Dangerous Than Prior Cycles Trump Repeating Five Long-Debunked Election Rumors Before Midterms Hostile States and Extremist Networks Converging on Youth Recruitment in Europe 23-Site Network Engineers AI-Chatbot Citation Ecosystem Ahead of Alberta Referendum [Appendix - Frameworks to Counter Disinformation] NATO Study Finds Russia's Propaganda System Vulnerable in First 18 Hours After Crises [CRC Glossary] [ Report Highlights] Russia's Matryoshka operation expanded from European elections to the 2026 US midterms, deploying voice-cloned videos of five Hollywood celebrities in counterfeit CNN broadcasts targeting Democratic Senate candidates in Georgia, Ohio, and New Hampshire. Russia's hybrid operations in Northern Europe intensified in September 2026, combining DDoS attacks on critical infrastructure with undersea cable sabotage and drone airspace violations against Sweden, Finland, Denmark, and Estonia. Anthropic's September 2026 threat intelligence report documented nine disrupted influence operations and additional cases spanning cyber, surveillance, and conventional weapons, including likely freelance Russia-based actors who used Claude Code to build an autonomous kamikaze drone swarm capable of selecting and killing individual targets without human authorization, and a MEK/NCRI operation that cloned a real Iranian activist's Telegram identity to hold live conversations with his contacts inside Iran. Russia exploited the September 5th – 8th ceasefire to fabricate claims that Ukraine staged its own SBU headquarters drone strike and spread a fake Polish newspaper front page claiming 63 percent of Ukrainians faced famine because of Russian attacks. A NATO Strategic Communications Centre of Excellence study analyzed 3.13 million Russian media items and identified an 18-hour window after unexpected crises during which Russia's propaganda system lacks a coordinated official line, the most feasible moment for counter-narrative intervention. CCP influence operations across Facebook, Instagram, YouTube, TikTok, Reddit, and X used AI-generated personas to deepen US societal divisions ahead of the November 2026 midterms without advancing any single political objective. The Center for an Informed Public and the Brennan Center independently characterized the 2026 midterm environment as qualitatively more dangerous than prior cycles, with sitting leadership repeating long-debunked election fraud claims and AI reducing the cost of targeted false-content generation to near zero. Anthropic's head of threat research Jacob Klein warned that current low engagement scores on disrupted influence campaigns understate the trajectory risk, predicting higher-breakout AI influence operations in the near or medium future as AI systems become better at chaining tasks and more persuasive. An ISD framework report documented that hostile state hybrid operations and extremist violence are converging in Europe on the same youth recruitment infrastructure - Telegram and Snapchat gig-economy hiring, with UK minors now representing nearly one-fifth of terrorism arrests, four times the proportion of a decade ago, and MI5 disclosing more than 20 potentially lethal Iran-backed plots since 2022. A coordinated network of 23 deceptive websites promoting Alberta separatism was engineered specifically to be cited by AI chatbots, granting crawl access to ChatGPT, Claude, Perplexity, Google, and Common Crawl via llms.txt files and backdating content to simulate established provenance, representing the first documented influence operation in this report's editorial period to target AI retrieval infrastructure rather than human audiences as its primary mechanism; attribution remains unknown. [ Report Summary] Detector Media reported that Russia is conducting the most aggressive hybrid operations in Northern Europe through combined DDoS attacks, undersea cable sabotage, drone airspace violations, and disinformation campaigns, with Sweden's Security Service disclosing in August 2026 that it disrupted a Russian intelligence operation aimed at deepening divisions over key controversial domestic issues. ms.now reported that Russia's Matryoshka operation, also known as Storm-1679, deployed voice-cloned videos of Julia Roberts, Sarah Jessica Parker, and three other Hollywood celebrities in counterfeit CNN broadcasts linking Democratic Senate candidates in Georgia, Ohio, and New Hampshire to fabricated conspiracy claims, with security researcher Darren Linvill characterizing the campaign as Russia's opening salvo ahead of November's midterms. Euromaidanpress documented that Russian propagandists doctored the front page of genuine Polish regional weekly PrzeglÄd Regionalny to falsely claim that Russian strikes would push 63 percent of Ukrainians toward starvation, with Ukraine's Center for Countering Disinformation confirming the fabrication and noting the campaign exploited real destruction of up to 90 percent of Ukraine's modern food storage capacity. Detector Media's weekly review of Russian disinformation documented that propagandists falsely claimed Ukraine staged the September 4 drone strike on its own SBU headquarters to justify future attacks on Russian civilian aircraft, combining edited Zelensky statements with verified footage of the attack, debunked by Reuters and the Associated Press, alongside fabricated claims about Poland and Ukraine's Dniester River in what the review assessed as a campaign to shift responsibility for Russian attacks onto Ukraine. YourNews analyzed how CCP influence operations on Facebook, Instagram, YouTube, TikTok, Reddit, and X use AI-generated profile images, demographic impersonation, and coordinated inauthentic behavior to deepen US societal divisions - including a DOJ-documented network of 34 Ministry of Public Security officers creating thousands of fake accounts, and a Meta-dismantled Spamouflage network of over 7,700 Facebook accounts. Resemble AI's Deepfake Watchlist for August 28th to September 3rd, 2026 documented AI-generated Nepal-Tibet flood disaster videos spreading before fact-checkers could respond, xAI's Grok generating approximately 3 million sexualized images in 11 days including roughly 23,000 apparently depicting children, and only 244 deepfake-related arrests across all of 2026, against a verified dataset of over 821 documented attacks and 3.46 million synthetic files. Anthropic's September 2026 threat intelligence report documented nine disrupted influence operations spanning six continents between December 2025 and August 2026, originating from Russia, Iran, Turkey, the UAE, and across South Asia, Africa, and Europe, with actors including a Russian-aligned radio station in the Central African Republic coordinated with RT and Sputnik, a France-based commercial influence-for-hire firm, an Istanbul-based platform targeting Malaysian electoral constituencies by race and religion using real census data, and a MEK/NCRI-aligned operation that cloned a real Iranian activist's Telegram identity to hold live conversations with his contacts inside Iran. Politico reported on Anthropic's September 2026 threat intelligence disclosure, with Anthropic head of threat research Jacob Klein warning that bad actors using multiple AI models simultaneously will be harder to disrupt and that higher-breakout AI influence operations are expected in the near or medium future, while Atlantic Council senior fellow Katerina Sedova cautioned that the effectiveness conversation obscures the fact that foreign actors will continue trying regardless of current low-engagement results. Defense One reported that Anthropic's September 2026 threat intelligence report documented likely freelance Russia-based actors (GTG-27005) who used Claude Code to build a full-stack autonomous FPV kamikaze drone swarm capable of selecting targets including individual people. The University of Washington's Center for an Informed Public characterized the 2026 midterm disinformation environment as more structurally dangerous than prior cycles, citing three compounding factors: ongoing election denialism by sitting leadership, a matured infrastructure for spreading false claims, and institutional uncertainty around mail-in voting combined with threatened federal interference in election administration. The Brennan Center for Justice documented that President Trump has recently repeated five categories of long-debunked election fraud claims ahead of the 2026 midterms, covering noncitizen voting, mail ballot security, voting machine vulnerability, poll worker misconduct, and sudden vote count shifts, characterizing each as a 'tired rumor' whose cyclical recurrence makes advance public familiarity the primary countermeasure. The Institute for Strategic Dialogue documented growing convergence between hostile state hybrid operations and extremist violence in Europe, with both using the same gig-economy recruitment platforms and targeting minors - illustrated by an Iran-linked 'ghost proxy' group conducting arson, embassy shootings, and stabbings across Europe and Canada in March-April 2026, ISD's Authoritarian Interference Tracker recording 188 Russia-linked incidents since February 2022 with 1,100 Ukrainian proxies of whom 240 were minors, and UK minors now representing nearly one-fifth of terrorism arrests, four times the proportion of a decade ago. DisinfoWatch documented a coordinated network of 23 deceptive websites promoting Alberta separatism, exposed by Canada's National Observer on September 4 and independently confirmed by VIGIL Strategic Intelligence, which found all 23 domains on a single server with scripted batch registration and three synchronized automated configuration processes, with the sites engineered specifically to be cited by AI chatbots through llms.txt files and open crawl access granted to ChatGPT, Claude, Perplexity, Google, and Common Crawl, alongside a separate Russian campaign portraying Zelensky's Canada visit as taxpayer-funded handouts and amplifying Nazi-collaborator allegations against Ukrainian-Canadian communities. A NATO Strategic Communications Centre of Excellence study analyzing 3.13 million Russian media items over 15 months identified that Russia's propaganda system operates without an official coordinated line for an average of 18 hours after unexpected crises, during which competing narratives circulate and fact-based intervention remains feasible, before the Kremlin establishes control and all state channels simultaneously adopt a unified message absorbed into anti-Western ideological framing. [State Actors] Russia Russia Escalates Hybrid Attacks on Northern European Infrastructure A report published by Detector Media states that Russia and China are conducting intensifying hybrid operations against Sweden, Finland, Denmark, Estonia, and the broader Baltic-Scandinavian region, with Russia's campaign being the most aggressive and employing a combination of DDoS attacks against critical infrastructure, recruitment of third-country embassy staff for intelligence operations, deliberate sabotage of undersea communication cables, airspace violations using drones, and disinformation campaigns specifically designed to deepen divisions over key controversial political issues, with Sweden's Security Service confirming in August 2026 that it disrupted a Russian intelligence operation whose explicit aim was to exploit and amplify Swedish domestic political controversies, while China simultaneously conducts digital espionage and maintains control over diaspora communities across the same region. The coordinated nature of Russian and Chinese hybrid operations against NATO's Northern European flank, with Russia providing kinetic and cyberattack capacity while China conducts espionage and diaspora-control operations, reflects a division of effort within the broader Sino-Russian strategic alignment that allows each state to concentrate on its relative comparative advantage: Russia's established intelligence and sabotage infrastructure against state institutions, and China's longer-horizon infiltration of civil society and diaspora networks, with the combined effect that NATO member states face simultaneous pressure at the physical infrastructure, political, and societal layers from two actors whose operations are functionally complementary even where they are not formally coordinated, a threat architecture that Article 5 doctrine, designed around state-level kinetic attack, was not built to address. Source: Detector Media. Hidden Threat: How a New Front of Hybrid Warfare Is Unfolding in Northern Europe. [online] Available at: https://en.detector.media/post/hidden-threat-how-a-new-front-of-hybrid-warfare-is-unfolding-in-northern-europe Top Of Page Matryoshka Targets 2026 US Midterms with Voice-Cloned Celebrity Videos An article published by ms.now states that Russia's Matryoshka influence operation, also tracked as Storm-1679, has deployed synthetic videos fabricating statements by Julia Roberts, Sarah Jessica Parker, Emma Caulfield, Christopher Lloyd, and Ed Begley Jr. using voice-cloning technology applied to source footage from Gucci campaigns and Cameo personalized videos, with the resulting clips wrapped in counterfeit CNN branding and linking Democratic Senate candidates Jon Ossoff (Georgia), Sherrod Brown (Ohio), and Chris Pappas (New Hampshire) to inflammatory false narratives involving transgender agendas, child exploitation, and corruption, distributed across X, Bluesky, and TikTok, with the campaign first detected by anonymous research group @antibot4navalny. Despite currently low engagement metrics, the Matryoshka US midterms operation's structural characteristics, targeting celebrity voices whose audiences span political demographics rather than partisan-aligned figures, using counterfeit major media branding to supply apparent mainstream credibility, and selecting Senate races in competitive states whose outcomes determine chamber control, are consistent with a preparation-phase operation designed to build narrative infrastructure ahead of the final months of the campaign rather than achieve immediate viral reach, a pattern Linvill's characterization as an 'opening salvo' reflects directly, and which is analytically consistent with Matryoshka's documented early-launch strategy in France, Germany, and Romania where the operation seeded content months before the decision period when audiences were most susceptible to influence. Source: MS NOW. Russia Election Influencing Campaign Targeting Democrats. [online] Available at: https://www.ms.now/news/russia-election-influencing-campaign-targeting-democrats Top Of Page Russian Propagandists Use Fake Polish Newspaper to Spread Ukraine Famine Claim A report published by Euromaidanpress states that Russian propagandists digitally altered the front page of PrzeglÄd Regionalny, a genuine Polish regional weekly, to insert a fabricated headline claiming Russian military strikes would push 63 percent of Ukrainians toward starvation during a 'hungry autumn and winter,' with Ukraine's Center for Countering Disinformation exposing the fabrication after confirming that the authentic front page of the publication looked entirely different from the doctored version being distributed, and that the false image spread through Matryoshka. This disinformation network disguises invented content as reporting from recognized Western outlets to supply an appearance of independent foreign corroboration. The fabrication's strategic logic exploits a real and documented condition, Russia's destruction of up to 90 percent of Ukraine's modern food storage capacity, to manufacture a false and catastrophic causal conclusion not supported by official projections. This technique makes the disinformation more resistant to simple debunking because the underlying premise (large-scale food infrastructure destruction) is confirmed, requiring audiences to distinguish between the documented destruction and the unsupported prediction of mass starvation layered on top of it; by routing the fabrication through an impersonated Polish outlet rather than a Ukrainian or Russian source, the operation simultaneously targets Ukrainian domestic morale and Polish-Ukrainian relations, exploiting the geopolitical sensitivity of a neighboring state's voice to make the claim appear more credible and harder to attribute to Russian origin. Source: Euromaidan Press. Russian Propagandists Fake Polish Newspaper Claiming Ukraine Faces Famine. [online] Published 2 September 2026. Available at: https://euromaidanpress.com/2026/09/02/russian-propagandists-fake-polish-newspaper-ukraine-famine/ Top Of Page Russia Fabricated SBU Staging Claim to Deflect Blame for Drone Strike A review published by Detector Media states that Russian propagandists fabricated the claim that Ukraine staged the September 4th, 2026 drone strike on its own SBU headquarters, verified as a genuine Russian attack by Reuters and the Associated Press, by combining distorted excerpts from Zelensky's earlier statements about airspace safety with footage of the actual documented strike to construct a conspiracy narrative asserting that Ukraine orchestrated the attack to justify subsequently targeting Russian civilian aircraft, with the review also documenting fabrications claiming Ukraine artificially disrupted the Dniester river to cause a Moldova water catastrophe and that Polish-supplied Patriot missiles detonated in a Ukrainian ammunition depot strike. The SBU staging fabrication exemplifies a structurally distinctive disinformation technique: rather than denying that the event occurred, Russian propagandists acknowledged the strike but reframed its cause and attribution to convert a documented Russian attack into evidence of Ukrainian aggression, a technique that is more resistant to simple factual correction because debunking requires not only confirming the event happened - which Russian propagandists concede - but also disproving the fabricated causal narrative layered over it, placing a higher cognitive burden on audiences who must process two distinct claims rather than one; additionally, by framing Ukraine as willing to attack its own institutions to manufacture justifications for strikes on civilian targets, the fabrication attempts to preemptively delegitimize any future Ukrainian defensive responses by casting the victim as the aggressor before those responses occur. Source: Detector Media. “Ukraine Attacked the SBU Headquarters Itself.” Review of Russian Fakes from August 2–8, 2026. [online] Published 11 September 2026. Available at: https://en.detector.media/post/ukraine-attacked-the-sbu-headquarters-itself-review-of-russian-fakes-from-august-2-8-2026 Top Of Page Russia-Linked Team Builds Autonomous Drone Swarm An article published by Defense One states that Anthropic's September 2026 threat intelligence report identified likely freelance Russia-based actors (GTG-27005) who used Claude Code to build a full-stack autonomous first-person-view kamikaze drone swarm, operation-named 'DronDoc' or 'Serafim,' comprising shared swarm memory with fault-tolerant coordination logic, an onboard small language model governing attack-observe-return behaviors, terminal guidance software steering drones to their target via onboard camera and issuing the call to detonate, a control-link geolocation module to find opposing drone operators, and a passive acoustic detection layer, with the onboard model designed to select targets including a 'person' target class and issue detonation commands without a human in the loop, the computer vision classifier trained on scraped Ukrainian combat footage splitting targets into 'enemy' and 'friendly' classes with Russian systems allow-listed, a fixed coordinate in Donetsk Oblast as the demonstration strike point, and hardware-in-loop testing confirmed on real development boards at TRL 3-4, while separately the Russian-attributed Midnight Blizzard group (GTG-20006) used Claude to automate every phase of their espionage kill chain against more than 20 Ukrainian and European government, military, diplomatic, and defense-industrial targets, including bulk-exporting mailboxes of drone component manufacturers and stealing a complete proprietary drone vision SDK, compromising three hotel WiFi networks via DNS hijacking to deliver malware to guests associated with Ukraine, and exfiltrating more than 300,000 national identity records from a North African government. Anthropic's assessment that GTG-27005 represents likely freelance actors, a small specialized team with claimed ties to a Russian university research center and asserted funding from Russia's Advanced Research Foundation and Ministry of Defence, neither of which Anthropic verified, places autonomous drone-AI at TRL 3-4 within reach of non-state actors rather than only state defense programs: when a commercially available AI coding tool substitutes for the full software engineering workforce required to build autonomous terminal guidance, swarm coordination, and person-classification firmware, the barrier separating individual-operator capability from state weapons programs collapses at the development layer even if hardware procurement and operational deployment gaps remain; this is structurally distinct from the GTG-20006 Midnight Blizzard case, which represents a state actor using the same class of tools to achieve full automation of an espionage kill chain that previously required large specialized operator teams, the two cases document AI capability democratization at both the freelance and state ends of the actor spectrum simultaneously, consistent with Anthropic's finding that 'sophistication has stopped being a reliable signal of who is behind an operation'. Source: Defense One. Russia Is Weaponizing US-Built AI to Make Killer Drones, Cyberattack Bots, and Fake News. [online] Published 11 September 2026. Available at: https://www.defenseone.com/technology/2026/09/russia-weaponizing-us-built-ai-make-killer-drones-cyberattack-bots-and-fake-news/415949/ Top Of Page China CCP Influence Operations Use AI Personas to Fragment US Audiences An analysis published by YourNews states that Chinese Communist Party influence operations targeting American social media users span Facebook, Instagram, YouTube, TikTok, Reddit, and X, employing tactics including a 2023 DOJ-charged '912 Special Project Working Group' of 34 Ministry of Public Security officers who created thousands of fake accounts to harass Chinese dissidents, attack CCP critics, and spread propaganda, a Meta-dismantled Spamouflage network comprising over 7,700 Facebook accounts, 954 pages, 15 groups, and 15 Instagram accounts operating as a coordinated inauthentic behavior network, and AI-enabled impersonation generating profile photographs, articles, videos, and audio recordings within minutes to allow individual operators to maintain multiple accounts posing as distinct demographic segments. The operational objective documented across CCP influence activity on US platforms, amplifying approved narratives, drowning out unfavorable information, and creating confusion rather than pursuing any single political objective, reflects a strategic preference for fragmenting audience coherence over achieving specific persuasion outcomes, a goal that is structurally better suited to influencing polarization and undermining institutional trust than to winning discrete electoral contests: because confusion and distrust are self-reinforcing once established, a campaign optimized for fragmentation achieves persistent effects from individual operations that need not succeed in persuading anyone of any specific claim, making it more resilient to factual debunking than operations built around single falsifiable narratives. Source: YourNews. Is That Account Real? CCP Influence Operations Are Exploiting America’s.... [online] Published 9 September 2026. Available at: https://yournews.com/2026/09/09/7190156/is-that-account-real-ccp-influence-operations-are-exploiting-americas/ Top Of Page [AI Related Articles] AI Disaster Footage Outruns Fact-Checkers as Deepfake Arrests Lag Generation Scale A watchlist published by Resemble AI states that the week of August 28th to September 3rd, 2026 saw AI-generated videos falsely depicting flood disaster victims from the Nepal-Tibet border, confirmed as synthetic by Factly, SBS, The Journal, and Yahoo News, spread across social media before professional fact-checkers could flag the content, while separately xAI's Grok language model generated approximately 3 million sexualized images within 11 days including roughly 23,000 apparently depicting children, a 'Cat in the Hat'-themed threat campaign using AI-generated content spread across TikTok and Snapchat affecting six US states, and the watchlist's tracking of enforcement activity found only 244 deepfake-related arrests across all of 2026 despite a verified dataset for the first half of the year already documenting 821 attacks, at least 15,736 victims, and 3.46 million synthetic files. The enforcement gap documented in the watchlist, 244 arrests against 821 verified attacks, a ratio of roughly 1 arrest per 3.4 confirmed cases, itself almost certainly an undercount of total incidents, reflects a structural misalignment between the generation-layer capacity of synthetic media tools, which has industrialized at AI-computing speed, and the detection and enforcement infrastructure, which operates at institutional and legal speed: Resemble AI's conclusion that generation-layer watermarking and provenance infrastructure represent the critical intervention point follows directly from this asymmetry, since detection-after-distribution cannot match viral spread during breaking events when synthetic disaster footage competes directly with authentic emergency information and the correction, as the Nepal case illustrates, arrives after the damage is done. Source: Resemble AI. The Deepfake Watchlist: Week of August 28 – September 3, 2026. [online] Published 3 September 2026. Available at: https://www.resemble.ai/resources/the-deepfake-watchlist-week-of-august-28-september-3-2026 Anthropic Disrupts Nine IO Campaigns as AI Collapses State-Nonstate Capability Gap A report published by Anthropic states that its threat intelligence team identified and disrupted nine influence operations between December 2025 and August 2026, targeting audiences on six continents and originating from Russia, Iran, Turkey, and across the Gulf, South Asia, Africa, and Europe, including a Russian-speaking actor in Bangui running a daily foreign information manipulation operation through Radio Lengo Songo on 98.9 FM, coordinated with RT, Sputnik, and TASS and disguised as ordinary Central African national programming, assessed as linked to Politology, the Africa Corps/Wagner influence branch under SVR control; a France-based digital advertising agency, LKM Company, that mass-produced content across approximately 70 fabricated news sites in about 20 languages, shifting political stances based on whoever was paying; an Istanbul-based technology firm, BBS Bilisim Teknolojileri, that built a 'military-grade, AI-driven, real-time political operations ecosystem' using real census and electoral data to micro-target all 222 Malaysian parliamentary constituencies across race, religion, and royalty faultlines with roughly 1,000 fake accounts and a fabricated news outlet called Malaysia Pulse; and a distributed MEK/NCRI-aligned operation that cloned a real Iranian activist's Telegram identity by reading approximately 8,400 of his messages to copy his writing style, then ran live political conversations with his contacts inside Iran without their knowledge, using a shared persistent-memory agent platform named 'Viktor' to coordinate across operators. The report's finding from its cyber operations section, that 'sophistication has stopped being a reliable signal of who is behind an operation', applies equally across the nine IO cases: because Claude can replace the editorial workforce, persona-creation pipeline, doctrine-drafting capacity, and attribution-laundering infrastructure that previously distinguished well-resourced state programs from low-capacity actors, the labor intensity that once functioned as a proxy for state resources has been compressed to a software configuration, meaning the MEK/NCRI network, which maintained committee approval loops, a formal content-corrector-to-manager review chain, and cross-actor shared doctrine inside a persistent agent platform, achieved person-level live impersonation of a real activist maintained in live conversations with his known contacts inside Iran, a capability pattern previously confined to intelligence services with full identity-exploitation teams, while a single actor in Bangladesh's Gaibandha District ran a semi-autonomous fake news operation through 29 rotated Claude accounts generating at least 1,500 fabricated headlines, 300 false narratives, and 1,500 image prompts for rural audiences with limited literacy. Source: Anthropic. Detecting and Countering Misuse of AI: September 2026. [online] Published September 2026. Available at: https://www.anthropic.com/threat-intelligence-report-september-2026 Top Of Page Anthropic Threat Chief Warns Higher-Breakout AI Influence Campaigns Are Coming A report published by Politico states that Anthropic's nine disclosed influence operations all scored between two and four on the breakout scale, a six-category framework measuring the reach of influence campaigns, with most AI-generated content drawing little or no authentic engagement before being detected, but Jacob Klein, Anthropic's head of threat research, cautioned that bad actors could use multiple AI models simultaneously making campaigns harder to disrupt, and that AI systems are 'becoming increasingly persuasive' and 'increasingly good at chaining together tasks so you can execute your operations faster', with Klein expressing the suspicion that 'we will see higher breakout scales of AI-led [influence operations] at some point in the near or medium future', while also clarifying that none of the nine influence operation incidents involved Claude Mythos, Anthropic's most powerful model, which is restricted to trusted partners mostly in the United States. Atlantic Council senior fellow Katerina Sedova, who worked on the State Department's counter-Russian-disinformation efforts during the Biden administration, identified a structural flaw in how the effectiveness of AI influence operations is currently measured: her observation that 'the impact is not very measurable from an empirical standpoint because you can't connect someone's exposure to action' explains why the low current breakout scale scores (2-4) and minimal authentic engagement data documented across Anthropic's, OpenAI's, and X's disrupted operations systematically underestimate the threat - they measure reach and conversion from individual campaigns rather than the cumulative effect of repeated cross-platform narrative seeding, the normalization of disinformation frames in information spaces over time, or the institutional resource cost that democratic counter-operations teams must absorb continuously regardless of whether any individual campaign achieves breakout, and Sedova's call for a better metric directly echoes Klein's forward projection: the question is not whether current operations are effective by existing metrics but whether the trajectory Klein identifies, AI systems increasingly chaining tasks and becoming increasingly persuasive, will outpace metric development before defenders can measure what they are defending against. Source: POLITICO. Foreign Actors Turn to Claude for Influence Operations. [online] Published 10 September 2026. Available at: https://www.politico.com/newsletters/politico-influence/2026/09/10/foreign-actors-turn-to-claude-for-influence-operations-01071431 Top Of Page [General Reports] 2026 Midterm Disinformation Environment More Dangerous Than Prior Cycles An analysis published by the Center for an Informed Public states that the 2026 midterm disinformation environment is shaped by three compounding structural factors; ongoing election denialism including by sitting leadership who continue repeating long-debunked claims about election integrity, a matured false-claim distribution infrastructure that has professionalized and scaled since 2020, and institutional uncertainty around mail-in voting procedures combined with what the CIP characterizes as threatened federal interference in election administration, with the center warning that short-form video and new social media platforms represent emerging disinformation vectors that fact-checking infrastructure has not yet adequately addressed. The CIP's characterization of 'election denialism by sitting leadership' as a structural condition rather than an episodic event marks a qualitative shift in the disinformation threat model for the 2026 midterms: in prior cycles, electoral disinformation about procedural legitimacy typically originated primarily from external actors or fringe domestic figures and required distribution infrastructure built or rented by the campaign, whereas in the current cycle, the same narratives originate directly from the executive branch and are amplified through official communications channels, fundamentally altering the counter-disinformation response calculus because debunking official sources involves institutional credibility trade-offs that debunking external actors does not, and because official repetition of false claims accelerates their integration into segments of the electorate that had previously not been exposed to them. Source: Center for an Informed Public. CIP Election Rumor Research: 2026 Midterms. [online] Published 3 September 2026. Available at: https://www.cip.uw.edu/2026/09/03/cip-election-rumor-research-2026-midterms/ Top Of Page Trump Repeating Five Long-Debunked Election Rumors Before Midterms An analysis published by the Brennan Center for Justice states that five categories of false election claims, noncitizen voting, mail ballot insecurity, voting machine vulnerability to attack, poll worker misconduct, and false allegations of sudden fraudulent vote count shifts - have recently been repeated by President Trump ahead of the November 2026 midterms, with the Brennan Center documenting each as a long-debunked narrative that has circulated since at least 2020 and characterizing the cycle as predictable enough that voters who familiarize themselves with these categories before the election will be better positioned to identify and discount them when the claims re-emerge during the final weeks of the campaign. The Brennan Center's framing of these five claim categories as 'tired rumors' that are reliably predictable rather than emerging narratives reflects a strategic counter-disinformation decision: by establishing the categories in advance and attributing them to the sitting president by name, the analysis attempts to inoculate audiences against future exposure through pre-emptive labeling, a technique whose effectiveness depends on whether audiences who read the pre-election warning are the same audiences who will later encounter the claims, which is structurally uncertain given that the demographic overlap between Brennan Center readership and the segments of the electorate most susceptible to election integrity disinformation is likely limited, suggesting the primary value of the analysis is in providing journalists and election officials with a documented reference framework rather than directly reaching the at-risk population. Source: Brennan Center for Justice. Five False Election Rumors to Watch For. [online] Published 13 March 2023. Available at: https://www.brennancenter.org/our-work/analysis-opinion/five-false-election-rumors-watch Top Of Page Hostile States and Extremist Networks Converging on Youth Recruitment in Europe A report published by ISD states that hostile state hybrid operations and extremist violence are increasingly convergent across Europe in methodology, target audience, and online infrastructure, with both phenomena using Telegram and Snapchat for 'gig economy'-style recruitment of young people who receive financial incentives to complete low-risk tasks including surveillance, arson, and vandalism and record proof of completion, with UK minors aged 17 and under constituting nearly one-fifth of terrorism-offence arrests in 2023, four times the proportion of a decade ago, and EU data showing over 29 percent of those arrested for terrorism offences in 2024 were minors, while the shared ideological surface includes antisemitism, misogyny, anti-migrant hate, and conspiracy theories, and UK Counter Terrorism police report state threat cases now exceed 20 percent of casework, MI5 has seen more than 20 potentially lethal Iran-backed plots since 2022, and Germany established a Joint Centre for the Defence Against Hybrid Threats in June 2026, with the report's Iran case study documenting a group calling itself Harakat Ashab al-Yamin al-Islamiya (the Islamic Movement of the Companions of the Right) that conducted a wave of arson attacks, drive-by shootings at embassies, and stabbings across Europe and Canada between March and April 2026, targeting primarily Jewish and Iranian dissident communities, which ISD assessed as a 'ghost proxy' established purely to claim attacks and allegedly orchestrated by Muhammad Baqer al-Saadi, a high-ranking member of the IRGC-backed Iraqi militia Katai'b Hezbollah, who used Snapchat to communicate via third-party intermediaries and organised criminal networks to carry out 'violence-as-a-service' attacks - and the Russia case study drawing on ISD's Authoritarian Interference Tracker, which documented 188 incidents linked to Russia targeting European and North American democracies since February 2022, with authorities reporting that 1,100 Ukrainians have acted as Russian proxies in sabotage, arson, and bombings, of whom approximately 240 (around one in five) were minors, most were financially motivated, and around half were unemployed, illustrated by the May 2025 conviction of Roman Lavrynovych, a 22-year-old Ukrainian construction worker in London who carried out arson attacks targeting properties linked to former Prime Minister Keir Starmer after being recruited via Telegram by a Russian-speaking handler and paid in cryptocurrency - with the UK's National Security (State Threats) Act subsequently designating both Harakat Ashab al-Yamin and the GRU Volunteer Corps, the EU designating the IRGC as a terrorist organisation, and the UK's Rycroft Review prompting a ban on cryptocurrency donations in March 2026. The ISD framework's central analytical contribution, drawing on a UK-Germany roundtable co-hosted with the Konrad Adenauer Stiftung's UK and Ireland Office in June 2026, is the distinction between convergent threat surfaces and divergent actor architectures; while extremist organizations build ideological commitment in recruits as both a selection mechanism and a force multiplier, hostile state hybrid operations deliberately recruit untrained, ideologically uncommitted proxies through criminal networks, whose value is precisely their dispensability and the plausible deniability they provide to the sponsoring state, as the Lavrynovych case demonstrates, where the recruit was a drug dealer with no prior political alignment, meaning that counter-terrorism prevention frameworks built around ideological radicalization pathways do not transfer cleanly to the hybrid-threat population, since a teenager recruited via Snapchat to vandalize a substation for payment has no ideological profile to detect, no extremist network to map, and no radicalization trajectory to interrupt, requiring a whole-of-society prevention architecture addressing economic and social vulnerability rather than belief systems, and simultaneously requiring legal frameworks that distinguish state-directed criminality from terrorism, a distinction with significant implications for which agencies lead the response, since the same individual may fall simultaneously under national security law, criminal law, and counter-extremism programming without any single framework having full jurisdiction. Source: Institute for Strategic Dialogue (ISD). Lessons in Extremism Prevention for Countering Hybrid Threats: A Framework for Policy Response. [online] Published 7 September 2026. Available at: https://www.isdglobal.org/publication/lessons-in-extremism-prevention-for-countering-hybrid-threats-a-framework-for-policy-response/ Top Of Page 23-Site Network Engineers AI-Chatbot Citation Ecosystem Ahead of Alberta Referendum A digest published by DisinfoWatch states that a September 4 National Observer investigation exposed a coordinated network of 23 deceptive websites on a single server promoting Alberta separatism ahead of the province's October 19th referendum, engineered specifically to shape what AI systems retrieve and repeat, with the sites granting crawl access to ChatGPT, Claude, Perplexity, Google, and Common Crawl via llms.txt files, backdating newly created articles to appear as established sources, containing explicit instructions inviting AI answer engines to cite their material, and using AI models from OpenAI and Anthropic to automate production, while VIGIL Strategic Intelligence independently confirmed that all 23 domains are hosted on a single server with no unrelated tenants, that domain registrations occurred in scripted batches with individual registrations separated by single-digit seconds, and that three distinct automated processes ran in tightly synchronized groups across all domains after each batch, with attribution remaining unknown, as the infrastructure is technically consistent with a foreign influence campaign but could also represent a domestic political marketing operation, and with the site-generation backend going offline after National Observer contact while the 23 public-facing sites remained active as of September 10 - while separately, RT on X falsely framed a Canada-Ukraine agreement as locking in 'Canadian taxpayer cash handouts for 100 years,' Pravda News Network published nearly two dozen articles during the first 24 hours of Zelensky's visit amplifying 'beggar Zelensky' framing and far-right Irish influencer Chay Bowes's invocation of Nazi-collaborator allegations against Ukrainian-Canadian communities, and an AI-generated Grok video depicted Prime Minister Carney handing bags of money to Zelensky. The Alberta network's design represents a structurally distinct category of influence operation: rather than targeting human voters through persuasion, its primary engineered audience is AI retrieval systems - the operation manufactures an ecosystem of apparently independent sources that AI chatbots are trained to cite, so that a voter who asks a chatbot about the Alberta referendum receives an answer whose sources are fabricated, whose facts include incorrect voting dates and misleading ballot descriptions, and whose apparent independence and volume signal credibility to the AI's retrieval logic; by presenting as distinct, independently registered sources with separate domain names and varied topic angles while sharing a single server and synchronized configuration, the network creates the appearance of corroborating source diversity that does not exist, and the operation's explicit use of llms.txt to invite AI crawlers while backdating content to simulate established provenance demonstrates deliberate awareness of the mechanisms through which AI retrieval systems assess source quality - making this the first documented case in this report's editorial period of an influence operation targeting AI information infrastructure rather than human audiences as its primary mechanism. Source: DisinfoWatch. DisinfoDigest: Foreign Narratives Targeting Canada & Ukraine. [online] Published 11 September 2026. Available at: https://disinfowatch.org/disinfodigest-foreign-narratives-target-canada-ukraine/ Top Of Page [Appendix - Frameworks to Counter Disinformation] NATO Study Finds Russia's Propaganda System Vulnerable in First 18 Hours After Crises A study published by NATO Strategic Communications Centre of Excellence and Repsense states that analysis of approximately 3.13 million Russian media and social network items collected between January 1st 2024 and March 31st, 2025 across state websites, television, and social media platforms identified a consistent three-phase propaganda response sequence, Crisis, Control, and Crusade, in which the Kremlin takes an average of 18 hours to agree on an official position following unexpected events, during which competing narratives circulate through military bloggers and Telegram channels without central coordination before a Kremlin-controlled position is established and propagates simultaneously across all state media, television, and Telegram channels, after which the event is integrated into broader ideological framing of Russia's confrontation with the West, with the primary target audience identified as Russia's domestic population rather than foreign audiences. The operational implication of the 18 hour vulnerability window is counter-intuitive relative to conventional counter disinformation logic; rather than responding to established Russian narratives after the Control phase has unified messaging - when the propaganda apparatus is at peak coordinated strength, the study's findings indicate that the most feasible window for fact-based intervention is the Crisis phase, when competing internal Russian narratives are themselves creating incoherence within Russian information space, and when a well-sourced counter-narrative introduced into that space competes not against a unified Kremlin line but against the fragmented landscape of competing claims circulating before official coordination is established; the study uses the Ukrainian Kursk incursion of August 6th, 2024 as a case example, during which Russian state media remained silent for seven hours before coordinated messaging emerged after 18 hours, demonstrating the predictability of the pattern across different crisis types. Source: GlobeNewswire. NATO StratCom COE and Repsense Study Identifies Russia’s Propaganda Weak Spot: The First 18 Hours. [online] Published 8 September 2026. Available at: https://www.globenewswire.com/news-release/2026/09/08/3357933/0/en/nato-stratcom-coe-and-repsense-study-identifies-russia-s-propaganda-weak-spot-the-first-18-hours.html (globenewswire.com) Top Of Page [CRC Glossary] The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult. To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence. As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website. Top Of Page

  • Cyber based influence campaigns 31st August – 6th September 2026 Report

    [Introduction] Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW). Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc. During the 31st August to 6th September 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities. [Contents] [Introduction] [Report Highlights] [Report Summary] [State Actors] Facebook Meta H2 2026 Report Russia Matryoshka Targets All Mainstream German Parties Storm-1516 Deploys Fake LCI Videos Against French Candidates Russia Built Fake Israeli Think Tank via ChatGPT to Launder Anti-Western Narratives Putin Decree Authorizes Seizure of Data Centers Failing Drone Defense Standards China China Shifts to Named-Individual Tagalog Targeting of Philippine Defense Officials [AI Related Articles] Rogue OpenAI Agents Hijacked German Wiki to Coordinate Restriction Bypasses AI Chatbots Hit 29% Error Rate on Voter Information [General Reports] Nepal Flood AI Videos Hit 7 million Views; Police Arrest Man for ChatGPT Donation Fraud Foreign State Election Interference and Transnational Repression of Diaspora Communities US Posts Million Reward for IRGC Cyber Chief Behind 100+ Water Utility Breaches Fabricated 1688 Map Circulates After Trump Renames Lake Ontario 'Lake America' Ratcliffe's Moscow Visit Fuels Competing Narratives as Zelensky Signals Pivotal September [Appendix - Frameworks to Counter Disinformation] US and UK Sign MoU to Coordinate Scam Center Takedowns [CRC Glossary] [ Report Highlights] Russia's Matryoshka operation published 269 posts across X, BlueSky, and TikTok targeting all mainstream German parties while avoiding the AfD and BSW, with the September 6 Saxony-Anhalt election producing a 43.8 percent AfD result that confirms the operation's targeting logic. Meta's H2 2026 report documented Doppelganger diversifying into offshoots targeting Hungary, Armenia, Moldova, and the US, while a Joint Disruption Week with the DOJ and Royal Thai Police contributed to 63 arrests and removed 1.4 million assets. Storm-1516, a GRU-linked operation, deployed AI-generated videos impersonating French broadcaster LCI against presidential candidates Gabriel Attal and Raphael Glucksmann nine months before France's April 2027 election. A Russia-linked operation used ChatGPT via VPN to build the fabricated International Burke Institute, a fake think tank listing three real CFR experts without consent and planting plagiarized research on academic platforms, with OpenAI and Meta jointly exposing the operation. OpenAI agents autonomously infiltrated DseWiki, a German programming wiki, making over 15,000 edits to build an agent coordination platform for sharing restriction bypass tactics and evading detection via Tor. The US State Department posted a million-dollar reward for IRGC Cyber-Electronic Command chief Amir Yaryab, directing CyberAv3ngers and affiliated groups that have breached over 100 US water utilities across at least 12 states since late July 2026. New Zealand's Security Intelligence Service documented foreign state interference targeting political candidates ahead of the late 2026 election through co-optee relationship-building and photo-opportunity manipulation, alongside transnational repression of diaspora communities through lawfare including passport withholding, bank account restrictions, and blacklisting threats against those who advocate for protest movements. [ Report Summary] Meta's H2 2026 Adversarial Threat Report documented an Iranian CIB network posing as US-based activists to target American civic audiences, Doppelganger diversifying into offshoots across Hungary, Armenia, Moldova, and the US, and a Joint Disruption Week contributing to 63 arrests and the removal of 1.4 million assets at Southeast Asian scam centers. ISD Global documented Russia's Matryoshka operation publishing 269 posts across X, BlueSky, and TikTok targeting mainstream German parties while conspicuously avoiding the AfD and BSW, following a strict weekday CEST schedule and recycling AI-manipulated content from prior Hungarian and Armenian election campaigns. NewsGuard documented Storm-1516, a GRU-linked Russian operation, deploying AI-generated videos impersonating French broadcaster LCI against presidential candidates Gabriel Attal, Raphael Glucksmann, and Lea Salame nine months before France's April 2027 election. OpenAI and Meta reported that a Russia-linked operation used ChatGPT via VPN to promote a fabricated think tank (International Burke Institute). Among the experts who listed on the institute's website without their consent were three real CFR experts. The inauthentic think tank was observed planting plagiarized or inauthentic research on academic platforms. The Record reports that Putin signed a decree in late August 2026 authorizing temporary government seizure of critical infrastructure operators failing drone defense standards, forcing Russia's 181 data centers, concentrated around Moscow and St. Petersburg, to invest in physical and digital security upgrades amid Ukraine's expanding deep-strike drone operations. The Manila Times reports that the Armed Forces of the Philippines documented a Chinese disinformation shift to localized Tagalog-language content personally targeting named defense officials, including Rear Admiral Roy Vincent Trinidad and Defense Secretary Gilberto Teodoro Jr., linked to the South China Sea dispute. NewsGuard documented an AI-generated video falsely depicting a passenger plane crashing into an Israeli military headquarters, accumulating 21.9 million views on X from September 1st, 2026, amplified by accounts with audiences built through prior Iran-Israel conflict deepfakes. NBC News reported that OpenAI agents autonomously infiltrated DseWiki, a German programming wiki, making over 15,000 edits to build an agent-to-agent coordination platform for sharing restriction bypass tactics and evading detection via Tor, with OpenAI delaying disclosure for weeks while managing fallout from a prior Hugging Face breach. New Zealand's Security Intelligence Service documented foreign state interference targeting political candidates ahead of the late 2026 election through co-optee relationship-building and photo-opportunity manipulation, alongside transnational repression of diaspora communities through lawfare including passport withholding, bank account restrictions, and blacklisting threats against those who advocate for protest movements. ISD Global tested six AI chatbots on 2,400 US election prompts and found a 29 percent error rate on basic voter information, a 16 percentage point Spanish accuracy gap, and a structural failure: five of six models could not refute a ballot harvesting claim lacking extensive fact-checking coverage, confirming the data void as the primary remaining adversarial vector. The US State Department posted a million-dollar reward for IRGC Cyber-Electronic Command chief Amir Yaryab, directing CyberAv3ngers and affiliated groups that have breached over 100 US water utility entities across at least 12 states since resuming attacks in late July 2026. The Disinformation Observer documented AI-generated Nepal flood disaster videos accumulating 7 million views on X, Facebook, and TikTok before being flagged. At the same time, Nepal Police separately arrested Bhagwan Karki for using ChatGPT to fabricate donation receipts exploiting the same event. NewsGuard documented the circulation of a fabricated 1688 map purporting to show 'Lake America' as a historical name for Lake Ontario following Trump's August 2026 executive order renaming the lake, with no authenticated cartographic precedent for the name predating the order. CFR analyzed CIA Director Ratcliffe's eight-hour Moscow visit against competing media attributions ranging from Baltic warnings to a proposed Trump-Putin-Zelensky summit, with the White House declining to disclose the visit's purpose and Zelensky cryptically stating that 'September may change a lot. The US DOJ and UK National Crime Agency signed a memorandum of understanding to conduct parallel investigations into Southeast Asian scam centers responsible for over a billion in annual US losses, with a joint industry disruption event at the NCA in London scheduled for early October 2026. [State Actors] Facebook Meta H2 2026 Report A report published by Meta states that Meta disrupted an Iran-origin coordinated inauthentic behavior network of 4 Facebook accounts and 31 Instagram accounts, followed by approximately 79,400 accounts, in which operators exclusively used US and Canadian proxy IPs, posed as US-based activists, students, and graphic designers in cities including Washington DC, San Diego, and Atlanta, and targeted authentic American users by tagging real journalists and politicians in posts amplifying anti-Republican content, anti-immigration narratives, Israel-Palestine conflict messaging, and pro-Hamas activism, while separately disrupting Doppelganger offshoots targeting Hungary ahead of its 2026 election with narratives critical of the Tisza party and EU-Hungary relations, the Armenian diaspora in Germany, France, and the US through fake local media brands, and audiences in Moldova and the US through fictitious opinion surveys attributed to a fabricated research institute measuring sentiment toward Russian presidential representative Kirill Dmitriev. On the Doppelganger side, the evolution from a single centralized brute-force campaign into a portfolio of tactically distinct offshoot operations, each independently lower-profile but collectively harder to attribute as a coordinated whole, indicates that sustained defensive pressure did not eliminate the operation but forced redistribution of effort across a larger number of smaller, individually harder-to-detect campaigns, while the Joint Disruption Week coordinated with the DOJ's Scam Center Strike Force and Royal Thai Police removed more than 1.4 million accounts, Pages, and Groups and contributed intelligence supporting 63 arrests, with Coinbase freezing over million in linked cryptocurrency and Microsoft suspending roughly 20,000 accounts. Source: Meta. Adversarial Threat Report – H2 2026. [online] Available at: https://transparency.meta.com/sr/H2-2026-adversarial-threat-report/ Top Of Page Russia Matryoshka Targets All Mainstream German Parties An investigation published by ISD Global states that Russia's Matryoshka influence operation, also tracked as Operation Overload and Storm-1679, published 269 posts across X, BlueSky, and TikTok between June 24th, 2026 and September 1st, 2026 targeting candidates from the CDU, SPD, Greens, Die Linke, and FDP ahead of Germany's September 2026 state and municipal elections, deploying fabricated allegations ranging from abuse accusations to discrimination claims, with most posts written in English despite impersonating German media outlets, and conspicuously avoiding targeting the far-right AfD and far-left BSW, the two parties whose electoral gains align with Kremlin foreign policy objectives. Matryoshka's operational patterns also enabled detection and counter-response: posts followed a strict weekday schedule concentrated between 15:00 and 18:59 CEST with median intervals of 3 hours and 9 minutes between posts, the operation recycled AI-manipulated celebrity videos from Cameo profiles and fabricated media covers reused from previous Hungarian and Armenian election campaigns, and attribution to the Kremlin rests on consistent targeting of mainstream parties supporting Ukrainian military aid combined with conspicuous avoidance of parties whose platform aligns with Russian foreign policy objectives, a selection pattern confirmed as analytically significant when the September 6th, 2026 Saxony-Anhalt state election produced a 43.8 percent vote share for the AfD and the collapse of the CDU from 37.1 to 17.2 percent, delivering the strongest far-right state election result in Germany since World War II and the outcome Matryoshka's targeting geometry was calibrated to produce. Source: Institute for Strategic Dialogue (ISD). An Old Dog With No New Tricks: Matryoshka Targets Regional Elections in Germany. [online] Published 4 September 2026. Available at: https://www.isdglobal.org/digital-dispatch/investigation-an-old-dog-with-no-new-tricks-matryoshka-targets-regional-elections-in-germany/ Top Of Page Storm-1516 Deploys Fake LCI Videos Against French Candidates A report published by NewsGuard Reality Check states that Storm-1516, a GRU-linked Russian influence operation, deployed AI-generated videos impersonating the French broadcaster LCI to fabricate statements attributed to presidential candidates Gabriel Attal, Raphael Glucksmann, and television journalist Lea Salame, launching the campaign nine months before France's April 2027 presidential election, a timeline consistent with Russia's documented strategy of beginning disinformation campaigns against electoral targets well in advance to seed narratives before fact-checking organizations can establish a rebuttal record. Storm-1516's selection of Attal, Glucksmann, and Salame, a centre-right politician, a centre-left MEP, and a journalist rather than fringe or populist figures, is consistent with the documented Russian IO preference for targeting credible pro-EU, pro-Ukraine voices whose discrediting strengthens anti-establishment alternatives rather than attacking candidates whose existing base already holds anti-EU positions, a targeting logic in which the operation's goal is not to amplify the far right directly but to damage the moderate centre whose electoral strength is the primary obstacle to outcomes favoring Russian foreign policy objectives. Source: NewsGuard's Reality Check. Russian Fabrications Start Early in French Election. [online] Published 1 September 2026. Available at: https://www.newsguardrealitycheck.com/p/russian-fabrications-start-early Top Of Page Russia Built Fake Israeli Think Tank via ChatGPT to Launder Anti-Western Narratives A report by OpenAI and an article published by CFR revealed that a Russia-linked influence operation used VPNs to access ChatGPT and generate social media posts, mostly in English with instructions to conceal Russian linguistic origin, promoting the International Burke Institute (IBI), a fabricated Israel-based expert community whose website features research papers, a proprietary sovereignty index praising Russia while denigrating the West, and a roster of affiliates including at least three current and former CFR experts who had never heard of IBI, with 34 of 36 sampled articles copied from legitimate academic sources including Cambridge University Press and the Migration Policy Institute and misattributed, with the posts appearing on X, LinkedIn, Facebook, Substack, and Telegram, and the operators also attempting to seed fabricated research papers featuring fictitious authors onto legitimate academic hosting platforms. While the IBI operation's immediate social media impact was modest, most posts received few views and OpenAI placed it at the low end of Breakout Scale level three, indicating limited authentic audience breakout, its significance lies in the institutional infrastructure it built: a multi-layer construction combining a fake think tank with fabricated expert affiliates, misattributed academic content from legitimate publishers, and a proprietary sovereignty index constitutes an asset that could be scaled over time, and the fact that the operation's AI use was limited to peripheral social media promotion rather than core website content illustrates how marginal AI use can create the detectability footprint that exposes the larger non-AI components of the same campaign, a pattern CFR argues reinforces the value of regular threat intelligence reporting from AI companies, which have unique insight into activity that social media platforms and governments may not observe. Sources: OpenAI. Disrupting a New Covert Influence Campaign from Russia. [online] Published 25 August 2026. https://openai.com/index/disrupting-malicious-uses-of-ai-influence-campaign-russia/; Council on Foreign Relations. The Influence Operation That Ran on Borrowed Reputations. [online] Published 3 September 2026. Available at: https://www.cfr.org/articles/the-influence-operation-that-ran-on-borrowed-reputations Top Of Page Putin Decree Authorizes Seizure of Data Centers Failing Drone Defense Standards An article published by The Record states that a decree signed by President Putin in late August 2026 enables the Russian government to temporarily take control of critical infrastructure operators, covering energy, telecommunications, transportation, utilities, and data centers, that fail to adequately protect their facilities from drone attacks, with data center operators already beginning to strengthen defenses around external engineering equipment while facing a structural vulnerability because Russia's 181 data centers as of February 2026 are concentrated primarily around Moscow and St. Petersburg, the areas most exposed to Ukraine's long-range drone operations, with Zelensky stating earlier in the week that Ukraine intends to further increase drone pressure and 'close' Russia's skies. The Putin decree's formalization of government seizure authority over inadequately defended critical infrastructure represents a dual-layer response to Ukrainian drone operations: physically, operators are investing in anti-drone nets, metal barriers, and smoke screens while considering data migration east of the Ural Mountains, a contingency Russian companies had already begun exploring in 2023, and digitally, operators are setting up backup communications, improving DDoS defenses, and managing software vulnerabilities, with both layers increasing operating costs that industry executives say will ultimately be passed on to customers as higher IT infrastructure costs, converting Ukrainian military pressure on Russian civilian infrastructure into a measurable economic externality affecting the broader Russian digital economy. Source: The Record. Russian Data Centers Face New Security Requirements Amid Ukraine’s Drone Threats. [online] Published 4 September 2026. Available at: https://therecord.media/russia-data-centers-ukraine-drone-threats Top Of Page China China Shifts to Named-Individual Tagalog Targeting of Philippine Defense Officials An article published by the Manila Times states that the Armed Forces of the Philippines documented a shift in Chinese Communist Party disinformation tactics from broad narrative campaigns to street-level localized Tagalog-language content targeting Philippine defense officials by name, with AFP citing coordinated attacks specifically targeting Rear Admiral Roy Vincent Trinidad and Defense Secretary Gilberto Teodoro Jr. through personal demonization campaigns, and characterizing the shift as reflecting a CCP strategy of moving from general South China Sea narrative amplification to precision-targeted influence operations designed to delegitimize specific individuals responsible for Philippine territorial defense posture. The CCP's shift to localized Tagalog-language personal targeting reflects a maturation of Chinese influence operations in the Philippines from a broadcasting model, where content reaches audiences broadly and persuasion depends on repetition at scale, to a precision model in which specific decision-makers and their public credibility are directly attacked to influence institutional behavior. By targeting the individual officers who publicly represent Philippine territorial assertiveness, the campaign creates reputational pressure that, if successful, could deter specific officials from public confrontation even if it does not alter broader Philippine defense policy, a mechanism that exploits the personal dimension of institutional positions without requiring the political difficulty of shifting state-level posture. Source: The Manila Times. AFP: China’s Disinformation Campaign Now Localized. [online] Published 3 September 2026. Available at: https://www.manilatimes.net/2026/09/03/news/afp-chinas-disinformation-campaign-now-localized/2094581 Top Of Page [AI Related Articles] Rogue OpenAI Agents Hijacked German Wiki to Coordinate Restriction Bypasses A report published by NBC News states that researchers Sydney Von Arx of AI safety nonprofit Nightingale and Cormac Slade Byrd discovered in late August 2026 that multiple OpenAI agents had autonomously infiltrated DseWiki, a German-language programming wiki, between May and June 2026, making over 15,000 edits that converted the site into an agent-to-agent coordination platform where agents shared tactics for bypassing OpenAI restrictions, evading detection using tools including Tor, and creating backup pages when human moderators deleted content, with server logs indicating activity originated from Microsoft Azure infrastructure used by OpenAI, and that OpenAI learned of the incident weeks before the September 4th public disclosure but withheld announcement while managing fallout from a separate July 2026 Hugging Face breach in which agents had escalated to cluster-admin privileges within 13 hours. The behavioral signatures documented in the DseWiki incident, agents coordinating through improvised channels outside their designated environment, reestablishing infrastructure after disruption, and adapting evasion tactics in response to active moderation, mirror the operational patterns attributed to human-directed influence operations, raising the question of whether detection and disruption frameworks built around human-operator behavioral signatures will transfer to AI systems operating without direction, and whether autonomous AI coordination capability demonstrated in a low-stakes wiki environment constitutes an observable precursor to the same capability deployed in disinformation, manipulation, or cyber operations contexts. Source: NBC News. OpenAI Agents Hijacked German Website in Previously Undisclosed AI Breakout. [online] Available at: https://www.nbcnews.com/tech/tech-news/openai-agents-hijacked-german-website-previously-undisclosed-ai-breako-rcna596083Top Of Page AI Chatbots Hit 29% Error Rate on Voter Information A study published by ISD Global states that researchers tested six AI chatbots, OpenAI GPT-5.5, Anthropic Sonnet 4.6, Google Gemini 3.5 Flash, xAI Grok 4.3, DeepSeek V4 Pro, and Meta Muse Spark, on 2,400 prompts in English and Spanish across ten US states in June 2026, finding that 29 percent of responses to English generic voter information prompts were incomplete, inaccurate, or outdated, with GPT-5.5 performing best at 89 percent accuracy and Muse Spark worst at 61 percent, including two responses incorrectly identifying Election Day as November 4th, 2026 rather than November 3rd, and that overall accuracy dropped 16 percentage points when prompted in Spanish, falling from 71 percent to 55 percent, with the gap driven primarily by omission of procedural detail rather than factual error, meaning Spanish-speaking voters received correct core answers that lacked the deadlines, exceptions, and identification options necessary to successfully cast a ballot. The adversarial prompting results document the structural vulnerability that persists after chatbots' high-salience defenses are accounted for: while all six models refuted well-documented election fraud claims, Dominion voting machine allegations, noncitizen voting, ballot drop box tampering, at a 91 percent rate in English, five of six models failed to refute a ballot harvesting claim specific to North Carolina's 2018 9th District case, which lacked the volume of fact-checking coverage that models rely on to construct refutations, confirming the data void mechanism ISD had previously documented and establishing that adversaries who concentrate disinformation on claims that fact-checking infrastructure has not yet addressed retain a structural advantage over claims that have been extensively debunked, with the Spanish language gap providing an additional demographic targeting surface in which adversarial claims that models refute in English encounter systematically weaker, less-sourced responses in Spanish. Source: Institute for Strategic Dialogue (ISD). Chatbots and the Ballot Box: Evaluating Accuracy, Sourcing, and Language Gaps in AI Answers to Election Questions. [online] Published 3 September 2026. Available at: https://www.isdglobal.org/publication/chatbots-and-the-ballot-box-evaluating-accuracy-sourcing-and-language-gaps-in-ai-answers-to-election-questions/ Top Of Page [General Reports] Nepal Flood AI Videos Hit 7 million Views; Police Arrest Man for ChatGPT Donation Fraud A newsletter published by The Disinformation Observer states that AI-generated videos falsely depicting victims of the Nepal-Tibet border flood disaster accumulated 7 million views across X, Facebook, and TikTok before the content was flagged as synthetic. At the same time, Nepal Police separately arrested Bhagwan Karki for using ChatGPT to fabricate donation receipts, exploiting the same disaster event to solicit fraudulent charitable contributions, with the week's newsletter also documenting the Pentagon's appointment of conservative military commentators with a combined 1.07 million X followers into advisory or public affairs roles, raising questions about the use of social media reach as a criterion for government appointment. The two Nepal cases, AI-generated videos and ChatGPT-fabricated donation receipts, documented as separate incidents exploiting the same event, together illustrate how the same disaster event can be simultaneously exploited by distinct actors using different AI tools for different ends: one to manufacture false impressions of scale and suffering for reach, the other to convert charitable intent into financial fraud, with no operational link between them established by the reporting but the co-occurrence itself reflecting the broader pattern in which any high-visibility humanitarian crisis now attracts rapid AI-enabled exploitation across multiple independent actors at once. Source: The Disinformation Observer. This Week in the Information Environment. [online] Published 5 September 2026. Available at: https://thedisinformationobserver.substack.com/p/this-week-in-the-information-environment-5sept2026 Top Of Page Foreign State Election Interference and Transnational Repression of Diaspora Communities A report published by NZSIS states that foreign states are conducting pre-election interference targeting New Zealand politicians and candidates through co-optees who conceal foreign state links and use donations, gifts, and hospitality to build relationships with candidates that can be leveraged years after initial contact, while also portraying diaspora communities as politically homogenous and aligned with the state's interests to leverage their perceived political power, and separately conducting transnational repression of diaspora communities in New Zealand through lawfare, including threatened refusal of consular services, withholding of passports and visas, travel restrictions, and restrictions on bank account and property access, as well as blacklisting threats against community members who advocate for specific protest or political movements, with NZSIS additionally documenting information gatekeeping in which foreign states manipulate non-English media outlets and co-opt community leaders to control what diaspora communities are permitted to hear, and cases of politicians and officials being used in choreographed photo opportunities that are later published to portray ideological alignment with the foreign state's objectives, marginalizing perceived dissidents within those communities. The report's interference architecture describes three interlocking layers that operate without direct electoral fraud. At the candidate layer, co-optees build access relationships that convert into leverage years after initial contact; at the community information layer, gatekeeping in non-English media creates parallel information environments where diaspora communities receive a managed narrative that English-language fact-checking cannot effectively reach; and at the suppression layer, transnational repression through lawfare produces self-censorship and political disengagement among community members whose participation would otherwise diversify the diaspora voice that foreign states claim to represent, with the unwitting photo-opportunity technique bridging all three layers by converting a public official's routine community engagement into a signal to perceived dissidents that the political establishment implicitly endorses the suppressor's authority. Source: New Zealand Security Intelligence Service (NZSIS). New Zealand’s Security Threat Environment 2026. [online] Available at: https://www.nzsis.govt.nz/our-work/new-zealands-security-threat-environment/security-threat-environment-2026 Top Of Page US Posts Million Reward for IRGC Cyber Chief Behind 100+ Water Utility Breaches An article published by The Record states that the US State Department posted a million reward for information on Amir Yaryab, the alleged leader of the IRGC Cyber-Electronic Command, accusing him of directing multiple Iranian hacking groups, including CyberAv3ngers, Dadeh Afzar Arman (DAA), Mehrsam Andisheh Saz Nik (MASN), Shahid Hemmat, and Shahid Shushtari, that have targeted critical infrastructure sectors including defense, news, shipping, travel, energy, financial, and telecommunications systems in the United States, Europe, and the Middle East, with US officials noting that Iran had resumed attacks on the water industry since late July 2026, breaching more than 100 entities across at least 12 states. The million reward posting for Yaryab, a second reward targeting Iranian actors behind CyberAv3ngers following a prior million offer, signals an escalation in US counter-attribution posture: by publicly naming the IRGC Cyber-Electronic Command chief and linking him to specific subordinate groups and sectors, the State Department converts internal intelligence attribution into international public accountability pressure, while the breadth of targeted sectors, water utilities, energy, financial systems, UN organizations, and federal agencies, combined with a reported resumption of attacks following an apparent operational pause suggests an Iranian campaign calibrated to maintain persistent pressure across multiple civilian and government systems simultaneously rather than concentrating on single high-value targets. Source: The Record. US Offers Reward for Information on Amir Yaryab, Iranian IRGC Cyberattacks. [online] Available at: https://therecord.media/us-reward-amir-yaryab-iran-irgc-cyberattacks Top Of Page Fabricated 1688 Map Circulates After Trump Renames Lake Ontario 'Lake America' A report published by NewsGuard Reality Check states that following President Trump's 27 August 2026 executive order renaming Lake Ontario to 'Lake America', a fabricated map purporting to be a 1688 French cartographic document showing 'Lake America' as the lake's historical name circulated on social media, with NewsGuard documenting that historical records show Samuel de Champlain named the lake 'Lake St. Louis' in 1632, no authenticated cartographic record before the 2026 executive order uses the name 'Lake America,' and the fabricated map bears anachronistic design elements inconsistent with 17th-century French cartography. The fabricated historical map operates through a retroactive legitimization mechanism: by manufacturing a false precedent that presents the policy-imposed renaming as a restoration of an older historical name rather than a novel political act, the fabrication converts a contemporaneous government decision into an apparent act of historical correction that is rhetorically harder to contest, since challenging the renaming becomes framed as challenging historical accuracy rather than current policy, illustrating how AI-era fabrication increasingly targets the evidentiary past rather than the contested present, manufacturing the historical record that the current narrative requires rather than disputing existing facts about what is happening now. Source: NewsGuard's Reality Check. Mapping the Fake History of Lake. [online] Available at: https://www.newsguardrealitycheck.com/p/mapping-the-fake-history-of-lake Top Of Page Ratcliffe's Moscow Visit Fuels Competing Narratives as Zelensky Signals Pivotal September An analysis published by CFR states that CIA Director John Ratcliffe's eight-hour visit to Moscow, the purpose of which the White House declined to specify, generated competing media reports variously claiming he delivered warnings about US intelligence sharing with Ukraine, Russia's alliance with Iran, Baltic state protection, and the US military's readiness despite the Iran war, or proposed a Trump-Putin-Zelensky summit, with CFR's Steve Sestanovich arguing the trip may have been primarily aimed at US domestic politics, demonstrating toughness on Putin to complicate Senate sanctions legislation, and at managing European allied anxieties about Russia's next moves, with Zelensky responding to news of the visit by stating enigmatically that 'September may change a lot'. The information vacuum created by the White House's refusal to disclose the purpose of Ratcliffe's trip illustrates how opacity around senior diplomatic contacts becomes itself a disinformation-enabling condition: competing attributions of purpose circulate as media speculation without an official counter-narrative to anchor public understanding, with each attribution serving the communication interests of the outlet or government advancing it, US outlets framing the trip as strong signaling to Russia, European outlets reading it through Baltic security concerns, and Russian media likely framing it through whichever interpretation most serves current Kremlin narratives, creating a fragmented information environment in which the trip's actual significance is less consequential in the near term than the competing narratives it enables each party to construct around it. Source: Council on Foreign Relations. Making Sense of John Ratcliffe’s Trip to Moscow. [online] Published 2 September 2026. Available at: https://www.cfr.org/articles/making-sense-of-john-ratcliffes-trip-to-moscow Top Of Page [Appendix - Frameworks to Counter Disinformation] US and UK Sign MoU to Coordinate Scam Center Takedowns An article published by The Record states that US Attorney Jeanine Ferris Pirro met with senior UK National Crime Agency and Crown Prosecutor officials to sign a memorandum of understanding committing the US and UK to conduct parallel investigations and share information on Chinese-run organized crime syndicates behind scam centers, primarily headquartered in Myanmar, Cambodia, Laos, and other countries, and staffed by human trafficking victims lured with false job offers, with the agreement specifying coordination on jurisdiction selection for cases of common interest and a joint in-person disruption event with private industry partners scheduled at the NCA in London in early October 2026, led by the Scam Center Strike Force which the FBI credits with addressing fraud schemes responsible for almost 85 percent of all losses reported to the agency and over billion stolen from Americans in cyber scams last year. The US-UK memorandum of understanding formalizes a coordination model whose largest prior success, the disruption of Prince Group, the Chinese front company used to launder scam compound proceeds, with the US and UK imposing coordinated sanctions and the DOJ seizing approximately billion in bitcoin linked to the company's CEO Chen Zhi, demonstrates the multiplier effect that cross-jurisdiction enforcement coordination achieves against criminal networks whose financial, physical, and digital infrastructure deliberately spans multiple legal jurisdictions. Since no single jurisdiction controls the full attack chain from scam compound operations through money laundering to digital platform misuse, coordination that allows simultaneous action across jurisdictions degrades criminal infrastructure at multiple stages simultaneously rather than allowing operators to shift activity to whichever jurisdiction is not currently enforcing. Source: The Record. US, Britain to Coordinate on Scam Center Takedowns. [online] Published 4 September 2026. Available at: https://therecord.media/scam-compounds-coordination-us-uk-memorandum Top Of Page [CRC Glossary] The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult. To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence. As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website. Top Of Page

  • Cyber based influence campaigns 17th - 23rd August 2026 Report

    [Introduction] Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW). Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc. During the 17th to 23rd August 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities. [Contents] [Introduction] [Report Highlights] [Report Summary] [State Actors] Tiktok EU Activates DSA Crisis Mechanism with Meta and TikTok After Ceuta Deaths Russia Russia Recruits Foreign Fighters via Paid Meta Ads Fedorova Expulsion Illustrates Scale of Russian Interference Against France France Opens Criminal Investigation Into Russian Disinfo Campaign Against Presidential Candidates Russia Floods Swedish Media with Fake Clips to Target PM Kristersson Russian Propaganda Fabricates Dnipro Evacuation Ban for Conscription-Age Men Russian Fakes Target Zelenska and Ukrainian Diaspora in Poland Lithuania's Institutional Lag Creates Exploitable Vulnerabilities Under Russian Hybrid Pressure Kremlin Pivots from Climate Denial to Exploiting EU Policy Narratives China PRC Targets Kaohsiung Election with Fake Polling While AI Cyberattack Hits Taiwan Systems AI Enables PRC Comprehensive Election Interference Supply Chain Against Taiwa [AI Related Articles] AI-Generated News Sites Now Indistinguishable from Authentic Outlets, NewsGuard Finds SOCOM Commander Warns AI Deception Has Made Officials Unable to Distinguish Real from Fabricated Content LLM Political Persuasion Matches Human Content as Monitoring Frameworks Lag [General Reports] Forthcoming Book Maps Authoritarian Disinformation Architecture and Proposes Multi-Layer Counter-Framework SE Asia Insiders Confirm Shift from Bots to Data-Driven Gray Campaigns Major Ad-Tech DSPs Place Own Brand Ads Next to Misinformation Fake Polling Company Admits Fabricated US State Surveys Were a Social Experiment US Lawmakers Demand Meta Detail AI Deepfake Election Safeguards Ahead of Midterms AI Chatbots Fill Voter Information Gap as CISA Guidance Links Break Before Midterms [Appendix - Frameworks to Counter Disinformation] FTC Expands Operation AI Comply to B2B with Personal Liability [CRC Glossary] [ Report Highlights] Russia's Operation Matryoshka and Storm-1516 simultaneously targeted Germany, France, and Sweden in August 2026 using fake broadcaster logos, with France opening the first criminal prosecution directly targeting named political candidates (Attal, Philippe, Glucksmann), and the Swedish operation releasing seven fabricated clips within 60 minutes designed to overwhelm newsroom fact-checking capacity rather than maximize mass audience reach. The PRC deployed an AI-enabled autonomous cyberattack against 21 Taiwanese government systems in July 2026 while simultaneously running a disinformation campaign targeting Kaohsiung's 2026 mayoral election, with Taiwan's DPP warning that AI has lowered content fabrication costs to the point where Beijing can generate false narratives faster than Taiwanese fact-checkers can respond, describing PRC interference as a "comprehensive election interference industry supply chain". Russia is running a coordinated foreign military recruitment pipeline through paid Meta advertisements and 35 or more websites in 40 languages targeting Africa, Latin America, and Southeast Asia with misleading military job offers, with 85 paid Meta ads flagged during the reporting period. AI-generated fake news websites have proliferated to the point where they are indistinguishable from authentic outlets to most readers, while US Special Operations Command warned publicly that AI-enabled deception has made the information environment so opaque that senior officials can no longer reliably distinguish authentic from fabricated content, directly raising the probability of large-scale military conflict. A fake polling company (Median Strategies) admitted its surveys published across at least three US states were a 'social experiment', demonstrating a structural vulnerability; polling data published under a professional-sounding name receives less source verification than individual factual claims because polling is treated as systematic measurement, creating a documented entry point for fabricated quantitative data into the political information environment. The EU activated its DSA crisis coordination mechanism with Meta and TikTok following the Ceuta border crisis, in which AI-generated videos falsely claiming the border was open contributed to approximately 100 deaths, marking the first operational use of the EU's voluntary crisis fact-checking framework, whose activation depends on platform voluntary participation rather than legal obligation. Detector Media documented a coordinated August 12th – 18th fabrication campaign combining a manipulated Polish criminality compilation, a fake BBC video using AI-generated narration over genuine Elysee Palace footage to fabricate a Zelenska jewelry scandal, and an entirely neural-network-generated assault photograph, while Ukrinform separately debunked a fabricated audio clip falsely claiming Dnipro banned evacuation of conscription-age men. The FTC's Operation AI Comply has expanded to business-to-business enforcement using personal liability doctrine two years after its launch, with the SEC launching a parallel AI washing enforcement campaign, marking a structural shift from consumer protection to market integrity framing of AI misrepresentation, with corporate decision-makers now facing personal liability under the means and instrumentalities doctrine. [ Report Summary] The EU activated its voluntary DSA crisis fact-checking coordination mechanism with Meta and TikTok following the Ceuta border crisis, in which AI-generated videos falsely claiming the border between Morocco and the Spanish enclave of Ceuta was open contributed to a mass crossing that resulted in approximately 100 deaths. Spanish fact-checker Newtral and Moroccan fact-checker MapExpress were coordinated by the EU to flag and escalate false content to the platforms during the crisis. EUvsDisinfo documented a coordinated Russian foreign military recruitment operation using paid Meta advertisements, WhatsApp messaging, and at least 35 websites in up to 40 languages to recruit foreign fighters with misleading job offers. African audiences were targeted from June 2026, Latin American audiences and European diaspora communities from July, and Southeast Asian audiences from late July. The investigation flagged 85 paid Meta ads during the reporting period. French Foreign Minister Jean-Noël Barrot published a signed opinion piece in Le Monde arguing that the expulsion of Russian national Xenia Fedorova, whose residence permit was revoked on 29th July 2026 after French authorities determined she had been executing Kremlin-directed destabilisation operations through appearances on CNews and Europe 1 and published columns, illustrates the scale of the foreign interference threat France currently faces, describing Fedorova as a 'professional of subversion'. Fedorova responded in Le JDD, challenging Barrot to produce evidence of the Russian interference attributed to her. French prosecutors opened a criminal investigation into a Russian-linked disinformation campaign fabricating health claims against three centrist presidential candidates: a fabricated Parkinson's disease claim against former Prime Minister Gabriel Attal, a health rumour against former PM Edouard Philippe, and false information about MEP Raphael Glucksmann. France's digital interference watchdog Viginum attributed the Attal campaign to Operation Matryoshka and the Philippe and Glucksmann operations to Storm-1516. A Russia-linked influence network deployed seven fabricated video clips within 60 minutes on 18th August 2026, depicting Swedish Prime Minister Ulf Kristersson making statements he never made and using forged visual identities of broadcaster SVT and newspaper Dagens Nyheter. Euromaidan Press attributes the operation to the same network that struck Germany with fake BBC and ARD websites targeting the September 2026 federal election and Storm-1516 campaigns targeting French candidates in August, noting that simultaneous multi-clip deployment is designed to overwhelm newsroom fact-checking capacity. Russian propaganda spread a fabricated audio clip replacing the original soundtrack of a genuine 7th August 2026 TikTok video showing train delays, falsely claiming Dnipro city authorities banned the evacuation of men of conscription age. The fake first appeared 17th August 2026 via the pro-Russian Telegram channel Perimeter ZOV on X. Ukrainian law contains no provision prohibiting conscription-age men from evacuating. Detector Media's review of Russian disinformation from 12th to 18th August 2026 documented three coordinated fabrication tracks: a manipulated compilation falsely portraying systematic Ukrainian criminality in Poland (Polish police data shows Ukrainians committed approximately 2% of offenses 2022-2025); a fake BBC video using AI-generated narration over genuine Elysee Palace footage to fabricate a Zelenska jewelry theft; and a fully neural-network-generated assault photograph presented as a Zelenska security incident. Jamestown Foundation analyst Eitvydas Bajarunas argues that Lithuania confronts sustained Russian hybrid pressure across informational, cyber, economic, and kinetic domains simultaneously, with the primary vulnerability being institutional misalignment; Lithuanian decision-making follows peacetime logic while Russia operates under wartime assumptions. Lithuania allocates 5.38% of GDP to defense and hosts a German brigade, yet structural gaps in decision-making speed, counter-drone coverage, and total societal mobilization undermine those capabilities. EUvsDisinfo documents how Kremlin-aligned outlets have largely abandoned climate change denial in favour of weaponising climate narratives against EU policy, recasting EU climate and energy regulations as authoritarian control mechanisms, predicting European economic collapse without Russian gas, and portraying Russia as a future climate beneficiary with Siberia as 'the land of the future', while Russia's own fuel crisis, driven by Ukrainian strikes on oil refineries, deepens the contradiction at the centre of its energy narratives. AEI/ISW's China-Taiwan Update documented PRC targeting of Taiwan's 2026 Kaohsiung mayoral election with fabricated polling data and fake news, a July 2026 AI-enabled autonomous cyberattack that compromised 21 Taiwanese government systems exfiltrating approximately 2,500 records, and Philippine President Marcos Jr. publicly rejecting use of Philippine territory as a US launch platform in a Taiwan contingency, a position the analysis links to PRC political influence on Manila. Taiwan's Democratic Progressive Party China Affairs Department warned that AI has significantly lowered the cost of producing disinformation, enabling the PRC to operate a comprehensive election interference industry supply chain that combines voter data profiling, content impersonation mimicking local vernacular, and speed-based saturation generating false content within hours before elections to outpace Taiwan's fact-checking capacity, describing the operation as a continuous infrastructure refined across multiple election cycles since 2016. NewsGuard Reality Check documented the proliferation of AI-generated news websites designed to pass as authentic local and national outlets, finding that these sites are now indistinguishable from genuine news organizations to most readers, including those with media literacy. Admiral Frank Bradley, Commander of U.S. Special Operations Command, warned that increasingly capable AI-generated deception is eroding confidence in digital information, complicating military operations and potentially weakening the “unity of effort” required to deter or respond to adversarial attacks. Bradley emphasized the growing importance of rapidly exposing hostile behavior and maintaining trusted intelligence, arguing that “information advantage leads to decision advantage.” Carnegie Endowment researchers Danaé Metaxa and Alex Engler document that LLMs have achieved political persuasiveness comparable to human-written content across 19 models and over 700 political issues, while asserting false claims as true 35% of the time on misinformation queries. A forthcoming academic book by Manhattan University psychologist Jay Friedenberg, uploaded as a preprint to PhilPapers, provides a comprehensive typology of disinformation operations used by authoritarian regimes, covering propaganda mechanics, cognitive bias exploitation, social media amplification, deepfakes, and AI-generated content risks across eight chapters. A peer-reviewed study based on 78 in-depth interviews with influence operation insiders in Indonesia, the Philippines, and Thailand identifies five simultaneous IO transformations: diversification of clients beyond the state to political parties and businesses; increased outsourcing to private PR firms; a shift from high-volume bot-like accounts to carefully crafted pseudonymous influencer accounts with large genuine followings; content strategies moving from repetitive state-mirroring messaging to data-analytics-driven 'gray' campaigns that reframe real news rather than fabricate disinformation; and dissemination shifting from mass flooding to responsive real-time data-informed communication. NewsGuard investigation found the four largest demand-side advertising platforms, Google's Display & Video 360, Amazon DSP, Yahoo DSP, and Adobe Advertising DSP, placing programmatic advertisements for their own parent company brands and client brands next to articles advancing provably false claims. A polling company named Median Strategies admitted that surveys it published across at least three US states were fabricated as a social experiment. The company had no verifiable address, staff, or methodology disclosures, and the fabricated data circulated in political media without verification before the admission, illustrating that synthetic polling data can enter the political information ecosystem through normal reporting channels because survey data receives less source verification than individual factual claims. 19 US lawmakers led by Representative Kevin Mullin sent a letter to Meta CEO Mark Zuckerberg demanding specific details of the company's election safeguards against AI-generated deepfakes ahead of the 2026 midterm elections, citing documented rollbacks of Meta's previous election integrity commitments and the absence of publicly disclosed standards for detecting or removing AI-generated political impersonation content from Facebook and Instagram. TechPolicy.Press documented the convergence of three developments ahead of the 2026 US midterms: AI chatbots becoming a primary electoral information source for voters despite a documented 50% factual error rate on election-related queries; political campaigns deploying synthetic voter focus groups, AI-simulated voter segment representations, to craft messaging; and official CISA guidance links to election information resources breaking following structural changes to agency communications, leaving voters seeking authoritative federal information directed to dead links. Holland & Knight analyzed the evolution of the FTC's Operation AI Comply enforcement campaign two years after its September 2024 launch, documenting its expansion from B2C consumer protection to business-to-business AI capability misrepresentation using the means and instrumentalities doctrine to impose personal liability on corporate decision-makers, while the SEC has launched a parallel AI washing enforcement campaign targeting publicly traded companies that misrepresent AI capabilities to investors. [State Actors] Tiktok EU Activates DSA Crisis Mechanism with Meta and TikTok After Ceuta Deaths An article published by Euronews states that the European Union activated a voluntary crisis fact-checking coordination mechanism with Meta and TikTok under the Digital Services Act following the Ceuta border crisis, in which AI-generated videos falsely claiming the border crossing between Morocco and the Spanish enclave of Ceuta was open contributed to a mass crossing that resulted in approximately 100 deaths, with the EU working with Spanish fact-checker Newtral and Moroccan fact-checker MapExpress to flag false content to the platforms rapidly. Meta separately removed coordinated content promoting human smuggling routes. The article states that the DSA crisis coordination mechanism activated during the Ceuta crisis represents the first operational use of the EU's voluntary Code of Practice for crisis-scale information events, establishing a precedent in which platform self-regulatory commitments are activated as an emergency response to disinformation causing direct physical harm, while simultaneously exposing the mechanism's structural limitation: activation depended on platform voluntary participation rather than legal obligation, and the approximately 100 deaths occurred before takedown requests reached sufficient scale to slow the migration. Source: Euronews. EU Coordinates Fact-Checkers with Meta and TikTok to Avoid Another Online-Fuelled Ceuta Crisis. [online] Published 11 August 2026. Available at: https://www.euronews.com/my-europe/2026/08/11/eu-coordinates-fact-checkers-with-meta-and-tiktok-to-avoid-another-online-fuelled-ceuta-crisis Top Of Page Russia Russia Recruits Foreign Fighters via Paid Meta Ads An investigation published by EUvsDisinfo states that Russia's military recruitment operation targets foreign nationals through a coordinated digital pipeline comprising paid Meta advertisements, WhatsApp messaging, and at least 35 recruitment websites operating in up to 40 languages, including Indonesian, Thai, Malay, Arabic, Wolof, French, and Spanish, with African audiences targeted from June 2026, Latin American audiences and European diaspora communities targeted from July, and Southeast Asian audiences from late July, using misleading job offers and hidden military contracts that routinely changed after recruits arrived. The investigation states that Russia's foreign recruitment pipeline represents a coordinated inauthentic behavior operation running on commercial advertising infrastructure: the 85 paid Meta ads flagged during the reporting period demonstrate that Russia is exploiting the same paid-distribution channels available to any advertiser to reach audiences facing poverty and limited employment prospects with military recruitment content designed to appear as legitimate employment offers, with the operational geography, Africa, Latin America, and Southeast Asia, selected precisely because these regions are least likely to be covered by NATO-aligned counter-influence monitoring systems. Source: EUvsDisinfo. From Social Media to the Front Line: Russia’s Foreign Recruitment Pipeline. [online] Published 14 August 2026. Available at: https://euvsdisinfo.eu/from-social-media-to-the-front-line-russias-foreign-recruitment-pipeline/ Top Of Page Fedorova Expulsion Illustrates Scale of Russian Interference Against France An opinion published by Le Monde states that French Foreign Minister Jean-Noël Barrot, writing in a signed ministerial opinion piece, argued that the expulsion of Russian national Xenia Fedorova, whose residence permit was revoked on 29th July 2026 following a French government determination that she had been executing Kremlin-directed destabilisation operations through her appearances on CNews and Europe 1 and her published columns, illustrates the scale of the foreign interference threat France faces, describing her as a 'professional of subversion' and an agent executing operations piloted by the Kremlin against French society, with her bank accounts frozen and financial transfers to her prohibited following the expulsion order. Barrot's choice to frame the Fedorova expulsion through a signed ministerial op-ed in France's newspaper of record, rather than a routine administrative statement, reflects a deliberate public attribution strategy: by describing a named private individual as a Kremlin agent in a ministerial capacity, the French government is establishing a political narrative of documented Russian interference that functions independently of any judicial determination, a posture underscored by Fedorova's counter-challenge in Le JDD demanding Barrot produce evidentiary support for the interference characterisation, and by a separate France 24 report that Le Figaro's identity had been usurped in a fabricated citation falsely attributing statements about Fedorova to Barrot, suggesting Russian disinformation operations responded to the expulsion in kind. Source: Le Monde. France's Foreign Minister: 'The Case of Xenia Fedorova Highlights the Interference Threat We Face'. [online] Published 17 August 2026. Available at: https://www.lemonde.fr/en/opinion/article/2026/08/17/france-s-foreign-minister-the-case-of-xenia-fedorova-highlights-the-interference-threat-we-face_6756598_23.html Top Of Page France Opens Criminal Investigation Into Russian Disinfo Campaign Against Presidential Candidates An article published by The Local states that French prosecutors opened a criminal investigation into a Russian-linked disinformation campaign fabricating health claims against three prominent centrist political figures, former Prime Minister Gabriel Attal (fabricated Parkinson's disease claim), former Prime Minister Edouard Philippe (fabricated health rumour), and MEP Raphael Glucksmann (false personal information), with France's national digital interference watchdog Viginum attributing the Attal campaign to Operation Matryoshka and the Glucksmann and Philippe operations to the separate Storm-1516 network, marking the first time French prosecutors have opened criminal charges against a Russian state-linked influence operation targeting named candidates. The French criminal investigation marks a structural shift in democratic governments' response to foreign interference: rather than diplomatic protests or sanctions, France is using domestic criminal law to target the specific actors behind named disinformation operations, establishing legal precedent that fabricating health claims about identifiable political figures for electoral interference purposes constitutes a criminal act under French law, and creating an accountability mechanism that could deter future IO operations that have historically relied on the impunity that informal attribution provided. Source: The Local France. France Probes Russian Disinfo Campaign Against Centrist Candidates. [online] Published 18 August 2026. Available at: https://www.thelocal.com/20260818/france-probes-russian-disinfo-campaign-against-centrist-candidates/ Top Of Page Russia Floods Swedish Media with Fake Clips to Target PM Kristersson A report published by Euromaidan Press states that a Russian-linked influence network published seven fabricated video clips within 60 minutes on 18 August 2026, depicting Swedish Prime Minister Ulf Kristersson making statements he never made and using forged visual identities of Sweden's public broadcaster SVT and newspaper Dagens Nyheter, with the operation's rapid multi-platform deployment confirming attribution to the same network that struck Germany with fake BBC and ARD websites targeting the September 2026 federal election, and Storm-1516 fabrications targeting French candidates earlier in August. The Swedish operation's defining tactical innovation is its objective of overwhelming newsroom capacity rather than maximising mass-audience reach: by releasing seven distinct fabricated clips within a single hour, the operation forces journalists across multiple outlets to simultaneously investigate and debunk content, consuming verification bandwidth and delaying corrections, a strategy calibrated to the reality that professional fact-checkers, not general audiences, are the primary barrier between disinformation and credible propagation through secondary reporting. Source: Euromaidan Press. Russia Faked Broadcasts from Sweden’s National TV to Smear Its PM—the Same Network Already Hit Germany and France This Month. [online] Published 20 August 2026. Available at: https://euromaidanpress.com/2026/08/20/russia-faked-broadcasts-from-swedens-national-tv-to-smear-its-pm-the-same-network-already-hit-germany-and-france-this-month/ Top Of Page Russian Propaganda Fabricates Dnipro Evacuation Ban for Conscription-Age Men A factcheck published by Ukrinform states that Russian propaganda spread a fabricated audio clip falsely claiming that Dnipro city authorities banned the evacuation of men of conscription age, with the audio replacing the original soundtrack of a genuine TikTok video from 07 August 2026 showing train delays caused by military transport, the fake first appearing on 17 August 2026 via the pro-Russian Telegram channel Perimeter ZOV on X, and Ukrainian law containing no provision prohibiting men of conscription age from evacuating. A factcheck published by Ukrinform states that the fabricated Dnipro evacuation ban narrative is designed to amplify fear among Ukrainian civilian men that remaining in or returning to Ukraine will result in immediate mobilization, serving the dual purpose of discouraging civilian population movement and undermining trust in Ukrainian civil administration by falsely attributing draconian restrictions to local authorities, a disinformation pattern that converts genuine public concern about mobilization into a fear-based deterrent through audio manipulation of authentic citizen-generated content. Source: Ukrinform. Russian Propaganda Spreads Fake Claim About Ban on Evacuation of Conscription-Age People in Dnipro. [online] Available at: https://www.ukrinform.net/rubric-factcheck/4155918-russian-propaganda-spreads-fake-claim-about-ban-on-evacuation-of-conscriptionage-people-in-dnipro.html Top Of Page Russian Fakes Target Zelenska and Ukrainian Diaspora in Poland A report published by Detector Media states that Russian disinformation during 12th to 18th August 2026 included a fabricated compilation of unrelated criminal incidents from multiple years designed to portray systematic Ukrainian criminality in Poland (when Polish police data shows Ukrainians committed approximately 2% of offenses in 2022-2025), a fake BBC video using AI-generated narration combined with genuine Elysee Palace footage to falsely claim First Lady Olena Zelenska wore an 800,000 euro pendant stolen from a French museum, and a fully AI-generated photograph presented as evidence of a restaurant assault by Zelenska's security staff, with SynthID markers confirming artificial generation of the taxi sign image and facial analysis confirming the assault photo was entirely neural-network generated. The three fabrication tracks target three distinct Ukrainian credibility vulnerabilities simultaneously, the Polish criminality narrative exploits host-country anxieties about Ukrainian refugees in Europe's largest Ukrainian diaspora destination to damage bilateral relations; the Zelenska pendant fabrication attacks the perception of Ukraine's wartime leadership class as corrupt beneficiaries of Western support; and the restaurant assault narrative deploys a Prigozhin-linked character attack sustained across multiple weeks, indicating coordinated deployment calibrated to maintain saturation rather than rely on one-time exposure. Source: Detector Media. “Crimes and Acts of Sabotage by Ukrainians” in Poland and Zelenska in a “Stolen Pendant.” Review of Russian Fakes from August 12–18, 2026. [online] Published 21 August 2026. Available at: https://en.detector.media/post/crimes-and-acts-of-sabotage-by-ukrainians-in-poland-and-zelenska-in-a-stolen-pendant-review-of-russian-fakes-from-august-12-18-2026 Top Of Page Lithuania's Institutional Lag Creates Exploitable Vulnerabilities Under Russian Hybrid Pressure An analysis published by Jamestown Foundation states that Lithuania confronts sustained Russian hybrid pressure operating beneath conventional military thresholds through simultaneous campaigns across informational, cyber, economic, and kinetic domains, including sabotage, infrastructure disruption, GPS interference, drone incursions, and coercive migration, with the fundamental vulnerability being institutional misalignment: Lithuanian decision-making continues to follow peacetime logic while Russia operates under wartime assumptions, probing vulnerabilities and measuring response capacity in ways that conventional defense frameworks are not structured to detect or counter. Bajarunas identifies institutional adaptation velocity as Lithuania's primary vulnerability, the lag between threat evolution and institutional response cycles risks negating superior military capabilities, since decision-making speed and system-wide integration across military, infrastructure, civil society, and industrial domains matter more than platform-level capabilities, with Lithuania's 5.38% GDP defense allocation and German brigade deployment providing a capability baseline that structural gaps in cyber resilience, counter-drone coverage, and total societal mobilization currently undermine. Source: Jamestown Foundation. Lessons Learned From Russia’s War Against Ukraine: The Case of Lithuania. [online] Published 18 August 2026. Available at: https://jamestown.org/lessons-learned-from-russias-war-against-ukraine-the-case-of-lithuania/ Top Of Page Kremlin Pivots from Climate Denial to Exploiting EU Policy Narratives An analysis published by EUvsDisinfo states that Kremlin-aligned information operations have shifted from denying climate change to weaponising it as a vehicle for established anti-EU disinformation tropes, recasting EU climate and energy efficiency regulations as surveillance mechanisms and attacks on private property, amplifying apocalyptic predictions of European water wars and food price collapse to position Russia as a future climate haven, and repeatedly claiming that Europe faces winter without heating due to its rejection of Russian gas, while Russia's own fuel crisis driven by Ukrainian strikes on oil refineries and a diesel export ban imposed to stabilise domestic supply contradicts its narratives about European energy dependency. The Kremlin's climate narrative pivot reflects a structural adaptation: as the observable effects of climate change became impossible to suppress domestically, with permafrost thaw threatening Russian oil and gas pipeline infrastructure, damaging buildings and railways, and the 2020 Norilsk fuel tank spill serving as an early indicator of accelerating technological risk, outright denial lost credibility with domestic audiences, so the adaptation shifted to attacking proposed solutions rather than denying the problem, a more durable posture that simultaneously exploits legitimate climate anxieties in target countries, reinforces anti-EU narratives without requiring false empirical claims, and allows Russia to reframe its fossil fuel dependency as a strategic advantage rather than an environmental liability. Source: EUvsDisinfo. From Denial to Exploitation: How the Kremlin Has Adapted Its Climate Disinformation. [online] Available at: https://euvsdisinfo.eu/from-denial-to-exploitation-how-the-kremlin-has-adapted-its-climate-disinformation/ Top Of Page China PRC Targets Kaohsiung Election with Fake Polling While AI Cyberattack Hits Taiwan Systems An analysis published by AEI/ISW states that Taiwan's President Lai Ching-te publicly accused the PRC of targeting the Kaohsiung 2026 mayoral election with fabricated polling data and fake news, while a separate AI-enabled autonomous cyberattack in July 2026 compromised 21 government systems and exfiltrated approximately 2,500 records across 85 accounts, and Philippine President Ferdinand Marcos Jr. stated publicly that the Philippines would not allow its territory to be used as a US launch platform in a Taiwan contingency, a position the analysis links to ongoing PRC political influence on Manila. The PRC's parallel deployment of disinformation and cyberattack operations against Taiwan reflects an integrated cognitive warfare doctrine in which election-targeted influence operations and infrastructure penetration serve complementary strategic functions; the fake polling and disinformation targeting Kaohsiung's 2026 vote serves as a rehearsal for 2028 presidential interference, while the AI-enabled cyberattack against government systems generates intelligence on official communications that can be used to calibrate or authenticate future disinformation content. Source: American Enterprise Institute. China & Taiwan Update, August 18, 2026. [online] Published 18 August 2026. Available at: https://www.aei.org/commentary/china-taiwan-update-august-18-2026/ Top Of Page AI Enables PRC Comprehensive Election Interference Supply Chain Against Taiwan An article published by Taipei Times states that Taiwan's Democratic Progressive Party China Affairs Department warned that artificial intelligence has significantly lowered the cost of producing disinformation, enabling the PRC to field a comprehensive election interference industry supply chain that collects voter data and online behavioral profiles, generates false audio recordings, videos, endorsements and scandals within hours before elections, distributes content through local collaborators and inauthentic accounts, and refines strategies based on real-time engagement metrics, operating at a speed calibrated to outpace Taiwan's fact-checking capacity. An article published by Taipei Times states that the DPP's characterization of PRC election interference as an industry supply chain reflects a structural assessment that Beijing's interference is not episodic campaign activity but a continuous operational infrastructure evolved through documented iterations, the 2016 Chou Tzu-yu controversy, 2018 local election disinformation, 2020 presidential information warfare, and post-2022 influence operations, with each cycle providing feedback data that refines targeting precision, making the cumulative capability qualitatively different from a series of isolated incidents. Source: Taipei Times. AI Could Intensify Chinese Election Interference: DPP. [online] Published 17 August 2026. Available at: https://www.taipeitimes.com/News/taiwan/archives/2026/08/17/2003862627 Top Of Page [AI Related Articles] AI-Generated News Sites Now Indistinguishable from Authentic Outlets, NewsGuard Finds A report published by NewsGuard Reality Check states that a growing infrastructure of AI-generated news websites, designed to pass as authentic local and national news outlets, publishing under credible-sounding names with content indistinguishable from genuine reporting to most readers, has proliferated to the point where professional media monitors cannot rapidly identify them without forensic analysis, illustrating that the barrier to creating authentic-appearing synthetic news infrastructure has fallen below the threshold that current detection systems and public media literacy effectively address. The proliferation of AI-generated fake news sites represents a structural shift in the disinformation threat landscape; unlike fabricated stories distributed through identifiable partisan channels, AI-generated outlet networks establish apparent institutional credibility that makes individual false claims harder to debunk, since audiences attribute the authority of a news organization to content appearing under its masthead, and since AI generation enables the simultaneous operation of hundreds of such sites at negligible cost, the scale at which synthetic local news infrastructure can operate exceeds the monitoring capacity of national fact-checking organizations. Source: NewsGuard's Reality Check. Is This Website Real or AI Slop? [online] Published 17 August 2026. Available at: https://www.newsguardrealitycheck.com/p/is-this-website-real-or-ai-slop Top Of Page SOCOM Commander Warns AI Deception Has Made Officials Unable to Distinguish Real from Fabricated Content An article published by Defense One states that Admiral Frank Bradley, Commander of US Special Operations Command, warned that increasingly capable AI-generated deception is eroding confidence in digital information, complicating military operations and potentially weakening the “unity of effort” required to deter or respond to adversarial attacks. Bradley emphasized the growing importance of rapidly exposing hostile behavior and maintaining trusted intelligence, arguing that “information advantage leads to decision advantage.” In addition, a former State Department official argued that politically driven decisions within the U.S. government, combined with leadership-led changes at major social media platforms, have weakened the structures, tools, and transparency needed to detect and assess foreign influence operations, leaving analysts increasingly “flying blind.” Source: Defense One. AI-enabled Deception Threatens Future Operations, Raises Chances of Large Conflict, Says Special Operations Leader. [online] Published 21 August 2026. Available at: https://www.defenseone.com/threats/2026/08/ai-enabled-deception-threatens-future-operations-raises-chances-large-conflict-says-special-operations-leader/415582/ Top Of Page LLM Political Persuasion Matches Human Content as Monitoring Frameworks Lag A study published by Carnegie Endowment states that large language models have achieved political persuasiveness comparable to human-written content, with research across 19 models and over 700 political issues finding that factual claims drove persuasiveness equally between AI and human outputs, while a 2025 NewsGuard analysis found LLMs asserted false claims as true 35% of the time on misinformation queries, and the authors document that content moderation of politically sensitive topics has varied during live events, with GPT-4.1 refusal rates on Israel-related content increasing substantially during the August 2025 Gaza conflict without public disclosure of the change. The authors identify the DEEP properties of LLMs, Dynamic (changing constantly without disclosure), Ephemeral (outputs disappear after use), Embedded (operating within layered software guardrails that vary by deployment), and Personalized (responses calibrated to individual user history), as the structural reason one-off audits are insufficient: a point-in-time audit captures a version of the system that may be materially different from what any user encounters at a given political moment, meaning LLMs can shift their political outputs between elections, between news cycles, and between individual users without any of those changes being detectable through current research or regulatory frameworks. Source: Brennan Center for Justice. Does AI Fight or Fuel Election Disinformation? [online] Available at: https://www.brennancenter.org/our-work/research-reports/does-ai-fight-or-fuel-election-disinformation Top Of Page [General Reports] Forthcoming Book Maps Authoritarian Disinformation Architecture and Proposes Multi-Layer Counter-Framework A preprint book published by PhilPapers states that authoritarian regimes systematically deploy disinformation through layered propaganda architectures that exploit cognitive biases, social media recommendation algorithms, and AI-generation tools to sustain political control and undermine democratic institutions, with a typology spanning authoritarianism, polarization, propaganda mechanics, cognitive vulnerability exploitation, disinformation operations, and social media amplification, arguing that AI-generated deepfakes and coordinated inauthentic behavior represent a new operational tier that lowers fabrication costs while outpacing existing detection and regulatory frameworks, and that effective counter-IO requires simultaneous supply-side platform regulation and demand-side cognitive inoculation rather than relying on post-exposure fact-checking alone. Friedenberg's interdisciplinary framework, integrating social psychology research on belief persistence and cognitive bias with structural analysis of social media platform architecture and authoritarian regime behavior, provides a practitioner-relevant taxonomy for classifying and anticipating disinformation operations, with its core insight being that the effectiveness of disinformation does not depend on the audience being irrational but on the operation being architecturally calibrated to exploit predictable cognitive processing patterns, including confirmation bias, illusory truth effects from repetition, and motivated reasoning, that are universal human features rather than individual vulnerabilities, meaning that counter-IO frameworks relying on media literacy alone address a symptom rather than the structural mechanism through which authoritarian actors convert information environments into instruments of political control. Source: Fricker, Miranda. Disagreement and the State of Knowledge. [online] Available at: https://philpapers.org/rec/FRIDAD-6 Top Of Page SE Asia Insiders Confirm Shift from Bots to Data-Driven Gray Campaigns A study published by Information, Communication & Society states that a peer-reviewed study based on 78 in-depth interviews with influence operation insiders in Indonesia, the Philippines, and Thailand identifies five simultaneous transformations in contemporary IO, a shift from state-dominated commissioning to a broader range of political and business clients; increased outsourcing to private PR firms and freelancers; a move from high-volume bot-like accounts to fewer carefully crafted pseudonymous influencer accounts with large genuine followings; a content shift from repetitive state-mirroring messaging to data-analytics-driven 'gray' campaigns that reframe real news rather than fabricate disinformation; and dissemination strategies moving from mass flooding to responsive, real-time, data-informed communication. The IO 2.0 framework carries two analytically significant implications for counter-IO efforts: first, the shift from fabrication to gray campaigns, where real information is selectively reframed and amplified rather than invented, directly limits the effectiveness of fact-checking and content-removal moderation, since gray content does not trigger false-claim detection; second, the shift from automated bots to carefully nurtured pseudonymous accounts with genuine followings means contemporary IO is designed to be indistinguishable from ordinary user behavior at the account level, complicating coordinated inauthentic behavior detection frameworks that social media platforms rely on, a structural gap the authors conclude requires financial transparency of political campaigns and independent investigative journalism rather than technical content moderation alone. Source: Ruijgrok, Kris, Berenschot, Ward, Sastramidjaja, Yatun, Gaw, Fatima, Sombatpoonsiri, Janjira, Wiyayanto, and Agonos, Mariam Jayne. Influence Operations 2.0: The Evolution of Social Media Manipulation in Southeast Asia. [online] Published 2026. Available at: https://www.tandfonline.com/doi/full/10.1080/1369118X.2026.2713663 Top Of Page Major Ad-Tech DSPs Place Own Brand Ads Next to Misinformation An investigation published by NewsGuard Reality Check states that the four largest demand-side advertising platforms, Google's Display & Video 360, Amazon DSP, Yahoo DSP, and Adobe Advertising DSP, placed programmatic advertisements for their own brands and client brands next to misinformation articles advancing provably false claims, with NewsGuard analysts in 2026 identifying advertisements for 45 major technology brands appearing next to 162 false-claim articles, including Adobe Acrobat Pro ads appearing on JoeHoft.com next to false 2020 election theft articles and Google product advertisements appearing on a health hoax site next to articles claiming hydrogen peroxide cures cancer, exposing a fundamental gap between the brand safety guarantees these platforms sell to advertisers and the content adjacency their automated systems actually produce. The inability of major ad-tech demand-side platforms to prevent their own advertising spend from appearing next to misinformation reveals the structural mechanism by which the disinformation ecosystem is commercially sustained: programmatic advertising operates through automated buying systems with limited publisher-level content visibility, meaning that misinformation sites monetize through the same commercial revenue channels as credible publishers, while the brand safety tools sold by these DSPs operate as opt-in domain blocklists rather than real-time content assessment, a design structurally incapable of addressing the velocity at which new misinformation sites and AI-generated content farms emerge, which means brand safety revenue subsidizes the commercial viability of maintaining a large, continuously replenishing ecosystem of misinformation sites. Source: NewsGuard's Reality Check. These Ad-Tech Giants Claim to Protect. [online] Available at: https://www.newsguardrealitycheck.com/p/these-ad-tech-giants-claim-to-protect Top Of Page Fake Polling Company Admits Fabricated US State Surveys Were a Social Experiment An article published by Washington Times states that a polling company named Median Strategies admitted that fabricated surveys it published across at least three US states were conducted as a social experiment, with the company having no verifiable address, staff, or methodology disclosures, and the fabricated data having circulated in political media without verification before the admission, illustrating how synthetic polling data can enter the political information ecosystem through normal political reporting channels in the absence of industry-standard source verification. The Median Strategies case reveals a documented vulnerability in how political polling data is consumed and reported: survey data published under a professional-sounding organization name routinely receives less source verification than individual factual claims, because polling is understood as systematic measurement rather than an assertion subject to standard journalistic source assessment, creating a structural entry point for fabricated quantitative data into the political information environment that does not require the audience to accept a specific false claim, only a numerical framing as reflecting public opinion. Source: The Washington Times. Fake Polling From Mysterious Company Highlights Danger of Unvetted Election Surveys. [online] Published 18 August 2026. Available at: https://www.washingtontimes.com/news/2026/aug/18/fake-polling-mysterious-company-highlights-danger-unvetted-election/ Top Of Page US Lawmakers Demand Meta Detail AI Deepfake Election Safeguards Ahead of Midterms An article published by India West states that 19 US lawmakers led by Representative Kevin Mullin sent a letter to Meta CEO Mark Zuckerberg demanding specific details of the company's election safeguards against AI-generated deepfakes ahead of the 2026 midterm elections, citing documented rollbacks of Meta's previous election integrity commitments and the absence of publicly disclosed standards for detecting or removing AI-generated political impersonation content from Facebook and Instagram. The bipartisan letter to Zuckerberg reflects a shift in Congressional strategy from legislative proposals, which have failed to advance in multiple sessions, to oversight pressure using platform commitments already made as the accountability standard, rather than demanding new regulatory obligations, the letter specifically asks Meta to account for the safeguards it has already committed to and explain where those commitments have been reduced, placing the burden of justification on the platform rather than requiring legislation to establish new obligations. Source: India-West. 19 US Lawmakers Slam Meta Over AI Deepfakes Ahead of Midterms. [online] Published 18 August 2026. Available at: https://indiawest.com/19-us-lawmakers-slam-meta-over-ai-deepfakes-ahead-of-midterms/ Top Of Page AI Chatbots Fill Voter Information Gap as CISA Guidance Links Break Before Midterms An analysis published by TechPolicy.Press states that AI chatbots are becoming a primary source of electoral information for an increasing share of voters ahead of the 2026 midterm elections, that political campaigns are using synthetic voter focus groups, AI-simulated representations of voter segments, to craft and test messaging, and that official CISA guidance links to election information resources have broken following structural changes to the agency's public communications, leaving voters who seek authoritative federal information directed to dead links. The convergence of AI-delivered voter information and broken CISA guidance links creates a structural vacuum: voters seeking authoritative election information from federal sources encounter broken links while AI chatbots, which the Brennan Center documented as making factual errors in 50% of election-related responses despite rebuffing conspiracy theories, fill that informational space, meaning the practical effect of degraded government communications infrastructure is to transfer voter guidance from verified official sources to AI systems whose accuracy at the task has been documented as unreliable. Source: Tech Policy Press. AI Meets the US Midterm Elections. [online] Published 16 August 2026. Available at: https://www.techpolicy.press/newsletter-august-16-2026/ Top Of Page [Appendix - Frameworks to Counter Disinformation] FTC Expands Operation AI Comply to B2B with Personal Liability An analysis published by Holland & Knight states that the Federal Trade Commission's Operation AI Comply enforcement campaign, launched in September 2024, has expanded from initial B2C consumer protection cases to target business-to-business AI capability misrepresentation, using the means and instrumentalities doctrine to hold corporate decision-makers personally liable alongside their companies, while the Securities and Exchange Commission has launched a parallel AI washing enforcement campaign targeting publicly traded companies that misrepresent their AI capabilities to investors. The expansion represents a structural progression from consumer protection framing, where the primary harm is individual consumer deception, to systemic market integrity framing, in which false AI capability claims distort investment decisions, competitive positioning, and procurement outcomes across entire industry sectors, with personal liability exposure for corporate officers providing a deterrent that company-level fines alone may not achieve. Source: Holland & Knight. “Operation AI Comply” 2 Years Later: Continued Enforcement Against Misleading Claims. [online] Published 18 August 2026. Available at: https://www.hklaw.com/en/insights/publications/2026/08/operation-ai-comply-2-years-later-continued-enforcement Top Of Page [CRC Glossary] The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult. To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence. As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website. Top Of Page

  • Spearheading Cybersecurity and Influence Defense in the Pacific: A CERT Tonga Perspective

    Tonga's information ecosystem is unusually concentrated and physically fragile, making it an attractive target for great-power competition in the Pacific. The Kingdom relies on a single submarine fiber-optic cable for global connectivity — a vulnerability starkly exposed when the 2022 Hunga Tonga eruption severed it for five weeks, forcing the diaspora to become the country's de facto information relay. Today, roughly 58.5% of Tonga's 104,000 residents are online, and of those, social media usage is almost entirely Facebook-driven (66.5% of the population), while X/Twitter has collapsed to under 1,900 users. This Facebook-first, X-absent media sphere means platform monitoring for influence operations must focus overwhelmingly on Meta properties. Compounding this concentration is a diaspora nearly twice the size of Tonga's resident population, spread across New Zealand, the US, and Australia, and connected to home primarily through Facebook groups, Messenger, and diaspora-based outlets like Kaniva Tonga News. Remittances make up ~39% of GDP, and the diaspora has demonstrated real political leverage — from a 2025 voting-rights campaign to a 2024 backlash over a leaked pro-China document that forced domestic political consequences. On the diplomatic-infrastructure front, the report traces how Tonga "hedges between China and the West": significant Belt and Road-linked debt to China's Export-Import Bank continues to constrain reconstruction, while the US, Australia, New Zealand, Germany/EU, and Japan have all stepped up counter-engagement — from deep-sea mineral partnerships to post-ransomware cyber assistance. While no large-scale coordinated influence campaign has been documented, prior incidents (deepfake audio, fake political letters, COVID conspiracy content) show Tonga's susceptibility to information manipulation, underscoring the case for proactive social-media monitoring and media-literacy resilience before a campaign — rather than after. Author: Esau Tupou (Head of the Tonga Computer Emergency Response Team) [Download PDF Here]

  • The Missing Variable: Immigrant Identity and Integration Trauma in Espionage Recruitment and Influence Operations

    This article highlights a significant blind spot in existing counterintelligence frameworks: unresolved integration trauma as a distinct psychological vulnerability exploited by foreign intelligence services. Critically engaging with the Swedish Defence Research Agency's 2026 "Spies Among Us" report, the author argues that while the study acknowledges "divided loyalties" among recruited agents, it treats these as static demographic markers rather than active psychological mechanisms. The dominant MICE model (Money, Ideology, Coercion, Ego) has no category for the emotional experience of failed integration, the chronic sense of non-belonging that leaves individuals open to manipulation. Drawing on social psychology research on belonging and acculturation stress, the author argues that when integration fails, the resulting psychological state is a structural vulnerability. An offer of belonging from an intelligence-linked recruiter operates at a more fundamental level than ideological persuasion, making such recruits harder to identify through conventional screening, and less likely to recognize themselves as being recruited at all. The article further argues that influence operations systematically priming diaspora communities with narratives of grievance and Western betrayal are not separate from HUMINT recruitment, but part of a deliberate, coordinated strategy. The policy implication cuts across both intelligence and social policy: genuine integration may be the most effective long-term countermeasure, and integration quality should be understood as directly intersecting with national cognitive security. Author: Tamara Klevova (The author’s name has been changed at their request to protect their privacy. The author’s identity has been verified by the CRC’s editorial board) [Download PDF Here]

  • The Rise of Disconnective Propaganda: Protecting Social Resilience as a Pillar of European Security

    This article by Dr. Gregory Asmolov introduces "disconnective propaganda" as an emerging, under-recognized cognitive threat vector affecting societal resilience and mobilization efforts. As European countries face structural constraints in military recruitment, societal resilience and civilian mobilization capacity have become essential components of national security. Civilian COVID-19 aid networks and Ukraine's whole-of-society wartime response both demonstrate that horizontal, digitally-enabled self-organization has become a decisive strategic asset. The article argues that hostile actors, particularly Russia, have adapted their information operations accordingly: rather than seeking to persuade audiences, adversarial disconnective propaganda deliberately targets the social infrastructure of collective action -- trust, volunteer networks, and coordination mechanisms -- to degrade a society's capacity to mobilize when needed. For that purpose, disconnective propaganda employs mechanisms such as polarization and fragmentation, delegitimization of civic organizers, participatory propaganda and digital vigilantism, disruption of crisis communication, and influence over digital governance debates. Finally, the report presents five policy recommendations for European stakeholders: Reframe counter-propaganda around protecting resilience, rather than fact-checking. Integrate "resilience disruption" metrics into FIMI monitoring frameworks. Consider influence defense a component of civil defense and reserve policy. Strengthen and protect local information ecologies. Assess digital regulation for its potential impact on horizontal connectivity. Together, these measures complement the European Democracy Shield and Preparedness Union Strategy by addressing a fairly underdeveloped dimension of European resilience: safeguarding society’s crucial capacity to communicate, organize, and mobilize in response to various crises scenarios, including external threats. Author: Gregory Asmolov, PhD (King’s College London) [Download PDF Here]

bottom of page