Search CRC
Search this site
194 results found with an empty search
- Counter-FIMI as FIMI: Russian Narrative Manipulation and Reputational Hijacking
Key Takeaways Four days before Armenia’s 7 June 2026 parliamentary election, an article published by a Social Design Agency (SDA)-linked influence asset (Yerevan One) promoted a narrative framing European counter-FIMI efforts as electoral interference, censorship and an effort to “purge” Armenia’s information space. The article falsely cited the Cyfluence Research Center (CRC), referred to as “Cyfluence Research,” for allegations that Western funders and French authorities were coordinating information operations in Armenia. CRC made no such claim. According to leaked SDA documents, Yerevan One was designed to serve as a pro-Russian “news outlet” used to influence Armenia’s election and promote political actors and narratives favorable to Russia. The case highlights a distinct hostile influence technique: hijacking a legitimate think tank or research institute’s reputation and perceived credibility to support a malign narrative. Background A recent CRC blog examined OCCRP reporting on leaked documents linked to the Social Design Agency (SDA), a known Russian influence contractor. Among the leaked files was a document describing a plan to use various media outlets in order to target Armenian voters with pro-Russian messaging ahead of Armenia’s general elections. One of these dedicated outlets is Yerevan One (Erevan.One). Figure 1 - Erevan.One homepage (accessed 27 July 2026). The Interference-Inversion Narrative On 3 June 2026, four days before Armenia’s parliamentary election, Erevan.One published an article titled “Censorship Is Democracy: French Press Exposes Paris’s Interference in Armenia’s Elections” (translated from Russian). The article alleged that French and European actors were financing organizations that supplied information about so-called “malicious disinformation campaigns” and supported a “purge of the information space.” This narrative is founded on the alleged misuse and weaponization of counter-disinformation investigations by Western actors. In that context, it cast VIGINUM, the French state service whose primary mission is to detect and characterize foreign information manipulation and interference (FIMI), as a vehicle for externally imposed censorship in Armenia. To further justify these claims, the Erevan.One article cites “evidence” from select sources. Coincidentally, it went as far as mentioning our organization (mentioned in the article as “Cyfluence Research”) to its support allegations of European interference. The article falsely implied that the CRC, together with a French media outlet (France-Soir) have reported on the alleged European and US-led “malicious campaigns”. Figure 2 – The Erevan.One article alleging European electoral interference under the guise of counter-disinformation. Figure 3 - Excerpt from the Erevan.One article falsely presenting “Cyfluence Research” as support for an allegation about European and US funding. The article’s selection of sources suggests a case of source conflation. A France-Soir opinion article published on 4 May 2026 advanced similar allegations.[1] It listed a CRC blog from 2025, which covered a VIGINUM report on the Russian threat actor Storm-1516, among its sources. However, the cited blog did not concern Armenia, VIGINUM activity in Armenia, or the funding of Armenian NGOs. Erevan.One’s framing (i.e. “According to France-Soir and Cyfluence Research”) converted a bibliographic citation into a direct institutional endorsement. This could be the result of careless manual drafting, automated summarization, or AI-assisted content generation. Needless to say, the aforementioned claims made by Erevan.One are obviously false. The Cyfluence Research Center did not produce any analysis or statement supporting the article’s allegations at any point. This type of misattribution aligns with DISARM Technique T0161.002: Statement Incorrectly Presented as Made by Individual or Institution. Figure 4 - Concluding passage from the Erevan.One article asserting that France-Soir had reported French interference in the recent Armenian elections. Erevan.One and SDA-Linked Influence Campaigns An OCCRP investigation based on leaked documents clearly linked Erevan.One to a wider media infrastructure associated with the Social Design Agency (SDA), a Russian influence (or “cognitive strikes”) contractor sanctioned by the US, the UK, and the EU. Figure 5 - Excerpt from the investigation report mentioning SDA operational asset "Yerevan One" (Erevan.One). (Courtesy of OCCRP) According to OCCRP, a document contained in the leak placed erevan.one within a group of 12 media outlets targeting audiences across Armenia, Central Asia, and the wider post-Soviet space. A separate file described Yerevan One as an outlet focused on the Armenian diaspora in Russia and outlined plans to use it during Armenia’s election campaign. The documented objective was to undermine attitudes toward Armenia’s authorities and Prime Minister Nikol Pashinyan, while cultivating support for actors favoring a closer relationship with Moscow. An EK Strategic Communications Center’s report on Russian interference in Armenia reached a similar assessment. It identified erevan.one as a “documented covert Kremlin proxy platform” affiliated with the SDA, placing it within an operational infrastructure that included Russian state media, regional proxy outlets, Telegram networks, and anonymous social media accounts. According to the report, this influence infrastructure proliferated and amplified narratives portraying European integration as a threat to Armenia’s sovereignty, security, economy, and national identity. Figure 6 - Excerpt from a report classifying Erevan.one as a documented covert proxy platform attributed to the SDA. (Courtesy of EK Strategic Communication Center) OCCRP appropriately cautions that the authorship of every individual document in the leaked archive cannot always be assigned conclusively to the SDA. However, current evidence places Yerevan One within an influence infrastructure connected to the SDA and that plans existed to deploy the outlet in support of Russian strategic objectives surrounding Armenia’s election. Turning Influence Defense Into “Foreign Interference” Whether deliberate or incidental, Erevan.One’s misleading citing of CRC served several mutually reinforcing narrative functions: Authority laundering - Referencing an established European research center made the false allegations appear to rest on independent analysis. Narrative inversion - Instead of presenting hostile influence campaign (HIC) detection and monitoring as a defensive activity, the article reframed the identification of FIMI efforts as devices of censorship and foreign interference. By doing so, it turned respected research institutions into malign actors. Meanwhile, the outlet actually identified as part of a foreign influence infrastructure (Erevan.One) is presented as the defender of free democratic discourse. Reputational smearing - By injecting the CRC into a narrative about covert and hostile European intervention, the article attached fabricated claims to the organization. The observed messaging seen in this specific case match the overall narratives spread by Russian proxies and Russia-aligned actors. The pre-emptive promotion of “Western interference” narratives seems to have been intended to weaken confidence in the election and Armenia’s relationship with Europe. Borrowed Legitimacy and Forced Association In a previous blog, we examined different models of credibility abuse by hostile influence actors, including the exploitation of legitimacy associated with news organizations, OSINT platforms, research institutes, and other authoritative entities (see DISARM Technique T0097.204: Think Tank Persona). These operations frequently imitate reputable institutions or create pseudo-research organizations whose visual identity and analytical language make political messaging appear credible. The erevan.one article exhibits usage of a different technique. In this case, threat actors did not impersonate the CRC or create a counterfeit website. Instead, they simply inserted the organization’s name into a narrative, while assigning it a supportive role. The observed misattribution can be seen as forced association: the unauthorized incorporation of a legitimate institution into a malign narrative to appropriate its authority, alter public perceptions of its work, or both. Conclusion and Implications Influence defense practitioners and cognitive security stakeholders should incorporate reputational abuse and forced associated into existing analytical frameworks. Ongoing brand monitoring should examine not only the frequency of mentions but also the context, narratives and claims attached to them. Suspicious references should be documented immediately (through screenshots, URL archiving, etc.). Threat researchers should map the velocity and reach of narratives across platforms and influence assets. Public correction should be quick and deliberate. Defenders need to establish an authoritative record without reproducing or amplifying unfounded allegations. If possible, this step should be accompanied by removal demands and appropriate legal action. Protecting the information environment requires defending not only platforms, data, and narratives, but also personal and organizational identities and reputations. Threat actors continue to impersonate credible media outlets and abuse legitimacy in order to target vulnerable audiences in pursuit of their strategic goals. [References:] France-Soir. Macron choisit le Premier ministre des Arméniens ? Les services secrets français accusés d’ingérence. [online] Published 25 July 2026. Available at: https://www.francesoir.fr/opinions-tribunes/macron-choisit-le-premier-ministre-des-armeniens-les-services-secrets-francais erevan.one, “Цензура — это демократия: французская пресса вскрыла вмешательство Парижа в выборы Армении”, 3 June 2026. https://web.archive.org/web/20260727111815/https://erevan.one/42960-cenzura-jeto-demokratija-francuzskaja-pressa-vskryla-vmeshatelstvo-parizha-v-vybory-armenii.html EK Strategic Communications Center, The Kremlin’s 2026 Election Campaign in Armenia, 5 June 2026. https://ekstrategies.org/articles/the-kremlins-2026-election-campaign-in-armenia Organized Crime and Corruption Reporting Project, Leaked Documents Reveal Russian ‘Cognitive Strikes’ Against the West, Including Islamophobic ‘Pig Head’ Attacks in Paris, 24 May 2026. https://www.occrp.org/en/investigation/leaked-documents-reveal-russian-cognitive-strikes-against-the-west-including-islamophobic-pig-head-attacks-in-paris Cyfluence Research Center, Borrowed Legitimacy: Three Models of Credibility Abuse in Influence Operations, 15 June 2026. https://www.cyfluence-research.org/post/borrowed-legitimacy-three-models-of-credibility-abuse-in-influence-operations Cyfluence Research Center (CRC), Behind the Curtain: Leaked SDA Files, Russian Influence Operations, and Defensive Cyfluence, June 1, 2026; updated June 14, 2026.https://www.cyfluence-research.org/post/behind-the-curtain-leaked-dsa-files-russian-influence-operations-and-defensive-cyfluence Financial Post, Russia’s “Wiki Warfare” Tries to Distort Reality, Documents Show, June 23, 2026. https://financialpost.com/pmn/business-pmn/russias-wiki-warfare-tries-to-distort-reality-documents-show
- Cyber based influence campaigns 20th - 26th July 2026 Report
[Introduction] Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW). Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc. During the 20th to the 26th of July 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities. [Contents] [Introduction] [Report Highlights] [Report Summary] [State Actors] Tiktok Commission Preliminary Finds TikTok in Breach of DSA for Failing to Ensure Safe Accounts for Minors Russia Russia Concocts Ukrainian Torture Moscow Exploits Poland-Ukraine Dispute Over OUN and UPA Legacy Ukraine Russian Propaganda Spreading Fakes About Death of US Senator Lindsey Graham Russian Propaganda Uses AI to Spread Fake Cardboard Protest Images China Taiwan Officials Warn Beijing Is Turning Taiwan's Political Divisions into Distrust [AI Related Articles] Commission Publishes Guidelines on Transparency Obligations for AI Systems In Chinese, AI Speaks Fluent Propaganda The Mass Production of AI Personas Weighing In on World Affairs Voters Are Being Inundated by a Barrage of AI-Generated Election Ads [General Reports] 2020 Election Denial Is Back World Cup Ends, Bogus Claims Don't French Parliament Greenlights Social Media Ban for Under-15s The Pro-Trump Ad Boycott that Never Happened [CRC Glossary] [ Report Highlights] Russia launched a coordinated cognitive warfare campaign against the Poland-Ukraine alliance, deploying GRU-linked operations to pay Ukrainian refugees to hold destabilising protests in Poland, FSB-released purported archival documents amplifying historical grievances, and coordinated Google Maps vandalism, prompting Poland's Foreign Minister to state Moscow was waging a full-scale cognitive war against Poland. A Russian influence operation spread a fabricated Human Rights Watch report falsely claiming President Zelensky ordered the torture and killing of 43 anti-draft protesters in Lviv, with the disinformation originating from the Foundation to Battle Injustice, an organisation assessed to be controlled by Russian intelligence. Russian propaganda falsely claimed US Senator Lindsey Graham was killed in Kyiv by a Russian Iskander missile strike; he died in Washington DC on July 11th from aortic dissection. The campaign deployed a fabricated CNN article and digitally manipulated imagery to signal Russia's capacity to target Western politicians and deter allied support for Ukraine. In the five days following President Trump's July 16th national address revisiting 2020 election fraud claims, posts on X claiming the 2020 election was rigged or stolen surged by 214 per cent, accumulating 77.7 million views, and the number of individual accounts actively disseminating the narrative increased by 295 per cent to 218,000. Beijing is systematically weaponising Taiwan's political divisions through Mazu religious temple networks, subsidised mainland visits, and targeted digital campaigns to erode Taiwanese trust in the United States, with electoral data confirming CCP influence operations have already shifted voting patterns in key districts. A NewsGuard audit found that leading AI chatbots reproduce pro-China false claims at significantly higher rates when prompted in Mandarin than in English, creating a language-dependent vulnerability that exposes Chinese-language users to disproportionate levels of CCP-aligned disinformation through mainstream AI tools. A Graphika investigation documented over 300 accounts across YouTube, Facebook, TikTok, and X deploying AI-generated personas to spread anti-Western and pro-China commentary on geopolitics and world affairs, with more than 140 YouTube channels hosting deepfakes impersonating journalists and academics including Rachel Maddow. The European Commission published binding AI Act transparency guidelines requiring disclosure of AI-generated content and deepfakes from August 2nd 2026, and issued preliminary DSA findings that TikTok violated platform safety obligations by setting minor accounts to publicly visible by default and recommending minor-generated content to a global audience. [ Report Summary] A Russian influence campaign spread a fabricated Human Rights Watch report claiming Zelensky ordered the torture of 43 anti-draft protesters in Lviv. The false narrative originated from the Foundation to Battle Injustice, an organisation assessed to be controlled by Russian intelligence. Russia exploited the Poland-Ukraine dispute over the OUN and UPA historical legacy through a GRU-linked campaign paying Ukrainian refugees to hold destabilising protests, FSB releases of purported archival documents, and coordinated Google Maps vandalism. Poland's Foreign Minister stated Moscow was waging a full-scale cognitive war against Poland. Russian propaganda falsely claimed Senator Graham was killed in Kyiv by a Russian Iskander missile strike, when he died in Washington DC on July 11th from aortic dissection. The campaign used a fabricated CNN article and digitally manipulated photographs, aimed at deterring allied support for Ukraine. Russian propaganda outlets shared an AI-generated image falsely depicting a protest rally in Lviv in which participants wearing balaclavas hold a cardboard sign reading 'Cut down TRCs like cardboard', a reference to draft recruitment centres. AI detection service AI or Not assessed the image as artificially generated with 93 per cent probability. Taiwanese officials and researchers warn that Beijing weaponises Taiwan's political divisions through Mazu religious temple networks, subsidised trips to mainland China, and targeted digital campaigns to erode Taiwanese trust in the United States. Electoral data found that neighborhoods near urban temples showed greater shifts toward opposition candidates in 2018-2020. The European Commission issued preliminary DSA findings that TikTok violated platform safety obligations by allowing minor users to set accounts as publicly visible by default and by recommending content from users aged 16-17 to all platform users globally through the For You Feed. TikTok is required to restrict default account visibility for minors and cease global distribution of minor-generated content. The European Commission published guidelines on AI Act Article 50 transparency obligations, effective August 2nd 2026, requiring providers to inform users during direct AI interaction and add machine-readable marks to AI-generated content, with deployers required to disclose deepfakes, AI-generated public interest content, and emotion recognition systems. A NewsGuard audit found that leading AI chatbots reproduce pro-China false claims at significantly higher rates when queries are submitted in Mandarin than when identical topics are raised in English, indicating a language-dependent vulnerability in AI models' handling of politically sensitive content. A Graphika investigation documented over 300 assets across YouTube, Facebook, TikTok, and X deploying AI-generated personas to distribute commentary on geopolitics and world affairs. More than 140 YouTube channels hosted deepfakes impersonating journalists and academics, including Rachel Maddow and Col. Douglas Macgregor, with anti-Western and pro-China narratives recurring across discussions of the Russia-Ukraine conflict, Iran tensions, and the South China Sea. Multiple US election races in the 2026 midterm cycle feature AI-generated attack ads depicting candidates in fabricated scenarios, ranging from deepfake hotel footage to exaggerated cartoon villains. The trend raises concerns about voter manipulation through synthetic media, particularly among older demographics unfamiliar with AI generation technology. A NewsGuard analysis found that in the five days following US President Trump's July 16 address revisiting 2020 election fraud claims, posts on X claiming the 2020 election was rigged surged by 214 per cent, accumulating 77.7 million views. The number of individual accounts advancing stolen-election claims increased by 295 per cent to 218,000 accounts within the five-day window. Following Spain's defeat of Argentina in the 2026 FIFA World Cup final on July 19th, a fresh wave of viral false claims emerged. NewsGuard tracked at least 14 provably false claims circulating since the tournament began in June 2026, illustrating how major sporting events are routinely exploited as disinformation vectors. France became the first European Union country to approve a blanket social media ban for children under 15, with the law taking effect September 1st, 2026 for new account creation and enforcement on existing accounts beginning January 2027. All users must verify their age using privacy regulator-approved methods, and cell phones are also banned from high schools. NewsGuard debunked the viral claim that Coca-Cola and General Motors pulled advertising from NBC and ABC after the networks did not broadcast President Trump's July 16 election security address. NewsGuard identified Chevrolet commercials airing on both networks on July 19th, and both General Motors and Coca-Cola confirmed to NewsGuard on July 20th that no advertising withdrawal had occurred. [State Actors] Tiktok Commission Preliminary Finds TikTok in Breach of DSA for Failing to Ensure Safe Accounts for Minors A finding published by the European Commission states that preliminary findings under the Digital Services Act determined that TikTok violated platform safety obligations by allowing minor users to set their accounts as publicly visible by default and by recommending content from users aged 16 to 17 to all platform users globally through the For You Feed, with TikTok required to restrict minor account defaults so that content is visible only to accepted followers and to cease recommending minor-generated content to a global audience. The preliminary finding represents the most significant DSA enforcement action against TikTok since it was designated a Very Large Online Platform in 2023. If confirmed following TikTok's response period, the platform faces financial penalties of up to six per cent of its global annual turnover under DSA enforcement provisions. The European Commission separately opened formal DSA proceedings against TikTok in 2024 over its recommendation algorithms and alleged addictive design features; those proceedings remain ongoing and are independent of the current preliminary finding on minor account safety. Source: European Commission. Commission preliminary finds TikTok in breach of Digital Services Act for failing to ensure safe accounts for minors. [online] Published 24 July 2026. Available at: https://digital-strategy.ec.europa.eu/en/news/commission-preliminary-finds-tiktok-breach-digital-services-act-failing-ensure-safe-accounts-minors Top Of Page Russia Russia Concocts Ukrainian Torture A report published by NewsGuard states that a Russian influence campaign is spreading a fabricated Human Rights Watch report claiming that 43 anti-draft protesters in Lviv were tortured to death on the orders of President Zelensky, with the false claim originating from the Foundation to Battle Injustice, an organisation assessed to be controlled by Russian intelligence. The Foundation to Battle Injustice has been linked to multiple previous Russian-backed disinformation operations targeting Western audiences. By attributing the fabricated narrative to an entity designed to mimic the name and format of a legitimate international human rights body, the operation sought to exploit the credibility typically associated with organisations such as Human Rights Watch, enabling initial amplification through pro-Kremlin media ecosystems before independent fact-checkers could issue rebuttals. Source: NewsGuard. Russia Concocts Ukrainian Torture Footage to Feed Kremlin Narrative. [online] Published 22 July 2025. Available at: https://www.newsguardrealitycheck.com/p/russia-concocts-ukrainian-torture Top Of Page Moscow Exploits Poland-Ukraine Dispute Over OUN and UPA Legacy An analysis published by The Jamestown Foundation states that Russia exploited the Poland-Ukraine diplomatic dispute over the contested legacy of the Organisation of Ukrainian Nationalists and the Ukrainian Insurgent Army to conduct a coordinated cognitive warfare campaign, including GRU-linked operations paying Ukrainian refugees $100-$200 to hold destabilising protests in Poland, FSB-released purported archival documents amplifying the historical dispute, and coordinated digital vandalism of Google Maps across Poland, with Polish Foreign Minister Sikorski explicitly stating that Moscow was waging a full-scale cognitive war against Poland. The operation marks an escalation in Russia's use of pre-existing historical fault lines as cognitive warfare instruments against NATO-adjacent states. The OUN and UPA legacy represents one of the deepest points of tension in Polish-Ukrainian relations, making it a high-yield target for operations designed simultaneously to destabilise Polish domestic support for Ukrainian refugees, undermine Warsaw's backing for Kyiv, and fracture a strategically critical alliance on Russia's western flank at a moment when both countries are cooperating closely on defence and border security. Source: Jamestown Foundation. Moscow Exploits Poland–Ukraine Dispute Over OUN and UPA Legacy. [online] Published 22 July 2026. Available at: https://jamestown.org/moscow-exploits-poland-ukraine-dispute-over-oun-and-upa-legacy/ Top Of Page Ukraine Russian Propaganda Spreading Fakes About Death of US Senator Lindsey Graham A fact-check published by Ukrinform states that Russian propaganda outlets spread fabricated claims that US Senator Lindsey Graham was killed in Kyiv by a Russian Iskander missile strike targeting a drone facility, when in fact he died in Washington DC on July 11th from aortic dissection, with the campaign including a fabricated CNN article and digitally manipulated photographs of a Kyiv library renamed in his honour, designed to create the impression that Russia can target Western politicians and deter allied support for Ukraine. Senator Graham had been among the most prominent voices in the United States Senate advocating for continued military and financial assistance to Ukraine. The campaign's use of a fabricated CNN article, a format that presents false claims in the visual style of breaking news, and digitally altered imagery was designed to circulate rapidly on social media before platform moderation or journalistic verification could intervene, compressing the available window for correction and maximising exposure of the deterrence narrative to Western political audiences. Source: Ukrinform. Russian propaganda spreading fakes about death of U.S. Senator Lindsey Graham. [online] Published 19 July 2026. Available at: https://www.ukrinform.net/rubric-factcheck/4145861-russian-propaganda-spreading-fakes-about-death-of-us-senator-lindsey-graham.html Top Of Page Russian Propaganda Uses AI to Spread Fake Cardboard Protest Images A fact-check published by Ukrinform states that Russian propaganda outlets spread an AI-generated image falsely depicting a protest rally in Lviv in which participants wearing balaclavas hold a cardboard sign reading 'Cut down TRCs like cardboard', a reference to draft recruitment centers, with AI detection service AI or Not assessing the image as artificially generated with 93 percent probability, exploiting ongoing tensions surrounding Ukraine's military mobilisation. The fabricated image forms part of a recurring Russian information operation aimed at manufacturing visual evidence of anti-conscription sentiment within Ukraine for consumption by both domestic Ukrainian audiences and Western observers, intended to convey that opposition to mobilisation is broader than official reporting reflects. The use of AI generation enables low-cost, scalable production of synthetic protest imagery with sufficient visual plausibility to circulate on social media platforms before detection tools can flag it, exploiting the speed asymmetry between disinformation production and fact-checking response that characterises the current information environment. Source: Ukrinform. Russian propaganda uses AI to spread fake “cardboard protest” images. [online] Published 23 July 2026. Available at: https://www.ukrinform.net/rubric-factcheck/4147206-russian-propaganda-uses-ai-to-spread-fake-cardboard-protest-images.html Top Of Page China Taiwan Officials Warn Beijing Is Turning Taiwan's Political Divisions into Distrust A report published by The Epoch Times states that Taiwanese officials and researchers warn that Beijing is weaponising Taiwan's political divisions through religious networks, subsidised visits to mainland China, and digital campaigns to erode Taiwanese trust in the United States rather than build affinity toward China, with electoral data showing CCP influence operations have already shifted voting patterns in Kaohsiung and research finding that frequent users of China-based social media show elevated distrust of the US and increased identification with mainland China. Unlike earlier CCP influence operations in Taiwan that sought to build affirmative pro-mainland sentiment, the strategy identified by officials focuses primarily on eroding Taiwanese confidence in the United States as a credible and reliable security guarantor. Research cited in the report found that Taiwanese social media users with higher exposure to mainland Chinese platforms exhibited measurably lower trust in the US-Taiwan security relationship, indicating the operation is reshaping Taiwan's strategic calculus without requiring any positive identification with the mainland, a more operationally efficient objective that is also harder for Taiwanese authorities to counter through straightforward pro-democracy messaging. Source: The Epoch Times. Taiwan Officials Warn Beijing Is Turning Taiwan’s Political Divisions Into Distrust. [online] Published 28 July 2026. Available at: https://www.theepochtimes.com/china/taiwan-officials-warn-beijing-is-turning-taiwans-political-divisions-into-distrust-6067510 Top Of Page [AI Related Articles] Commission Publishes Guidelines on Transparency Obligations for AI Systems A guidelines published by the European Commission state that Article 50 transparency obligations under the EU AI Act take effect on August 2nd, 2026, requiring providers to design AI systems that inform users when they are interacting with AI and to add machine-readable marks to AI-generated or manipulated content, with deployers required to disclose deepfakes, AI-generated public interest content lacking human editorial control, and emotion recognition systems, a framework the Commission states will reduce the risk of deception and manipulation through synthetic media. The transparency obligation applies to any AI system generating or manipulating audio, image, video, or text content where the output could reasonably be mistaken for human-produced material, with specific exemptions for authorised law enforcement and national security applications. The machine-readable marking requirement is intended to work alongside automated platform detection tools, enabling social media and news distribution systems to flag synthetic content at scale, a mechanism the Commission characterises as necessary given the volume of AI-generated material that makes manual disclosure verification impractical across contemporary digital information ecosystems. Source: European Commission. Commission publishes guidelines on transparency obligations for providers and deployers of certain AI systems. [online] Published 20 July 2026. Available at: https://digital-strategy.ec.europa.eu/en/news/commission-publishes-guidelines-transparency-obligations-providers-and-deployers-certain-ai-systems Top Of Page In Chinese, AI Speaks Fluent Propaganda A report published by NewsGuard states that leading AI chatbots reproduce pro-China false claims at significantly higher rates when prompted in Mandarin than in English, indicating a language-dependent vulnerability that exposes Chinese-language users to disproportionate levels of CCP-aligned disinformation through mainstream AI tools. The audit tested chatbots from multiple providers on a range of politically sensitive topics including the Uyghur detention camps, the Tiananmen Square events of 1989, and Taiwan's political status. The report noted a particularly sharp deterioration in source quality for one audited model, which cited Russian state-affiliated media in every response to queries about the Russia-Ukraine conflict, a finding NewsGuard described as a significant regression from an earlier audit cycle in which the same model cited Russian state sources in only four per cent of equivalent responses, suggesting a measurable worsening of AI model reliability on contested geopolitical topics. Source: NewsGuard. In Chinese, AI Speaks Fluent Propaganda. [online] Published 21 July 2026. Available at: https://www.newsguardrealitycheck.com/p/in-chinese-ai-speaks-fluent-propaganda Top Of Page The Mass Production of AI Personas Weighing In on World Affairs A report published by Graphika states that an investigation into more than 300 accounts across YouTube, Facebook, TikTok, and X uncovered a network of AI-generated personas producing geopolitical commentary, with over 140 YouTube channels using deepfakes impersonating journalists and academics to spread anti-Western and pro-China narratives on the Russia-Ukraine conflict, Iran tensions, and the South China Sea, and more than 200 identified channels removed for violating platform terms of service. A single AI-generated persona was identified across 154 channels, predominantly producing finance and investment content, indicating a potential commercial monetisation motive operating alongside the geopolitical commentary function. While Graphika researchers could not definitively attribute the network to a single state or non-state actor, they noted that the consistent anti-Western and pro-China thematic framing across assets spanning multiple countries and languages is consistent with previously documented Chinese state-aligned influence infrastructure, and that YouTube's synthetic content disclosure labels, present on the identified videos, were absent on equivalent content distributed across other platforms in the network. Source: Graphika. Pundit by Prompt: The Mass Production of AI Personas Weighing In on World Affairs. [online] Published 21 July 2026. Available at: https://www.graphika.com/reports/pundit-by-prompt (Graphika) Top Of Page Voters Are Being Inundated by a Barrage of AI-Generated Election Ads A report published by Futurism states that multiple US election races in the 2026 midterm cycle feature AI-generated attack ads depicting candidates in fabricated scenarios, including deepfakes and cartoon-style caricatures, raising concerns about synthetic media manipulation of voters, particularly among older demographics unfamiliar with AI generation technology. The 2026 midterm cycle is the first US federal election in which AI-generated attack advertising has appeared at scale, with campaigns and affiliated political action committees using commercially available AI video generation tools to produce content that would previously have required professional production budgets. Several of the ads identified by Futurism carried no AI-generated content disclosure labels, and the Federal Election Commission has not issued binding rules on synthetic political advertising, creating a regulatory gap that currently allows AI-generated attack content to circulate in competitive races without mandatory transparency requirements. Source: Futurism. Voters Are Being Inundated by a Barrage of AI-Generated Conservative “Slop” Ads and Deepfakes. [online] Published 25 July 2026. Available at: https://futurism.com/artificial-intelligence/voters-elections-conservative-generative-ai-slop-ads-deepfakes Top Of Page [General Reports] 2020 Election Denial Is Back A report published by NewsGuard states that in the five days following President Trump's 16th July national address, posts on X claiming the 2020 US election was rigged or stolen surged by 214 per cent, reaching 77.7 million views, with the number of accounts advancing the narrative rising by 295 per cent from 55,100 to 218,000, and the content focused on Trump's claims that widespread fraud occurred in 2020 and that China acquired and exploited American voter data. Trump's address included a new allegation that China had acquired and exploited American voter data, a claim for which no supporting evidence was presented and which NewsGuard assessed as false. The 609,000 posts recorded in the five-day window following the address collectively accumulated more than 77.7 million views on X, with the platform's algorithmic amplification of content from high-follower accounts accelerating the narrative's reach beyond what organic sharing alone would have produced, representing, according to NewsGuard's tracking data, the largest single-event surge in 2020 election denial content since the certification of the election result in January 2021. Source: NewsGuard. 2020 Election Denial Is Back. [online] Published 21 July 2026. Available at: https://www.newsguardrealitycheck.com/p/2020-election-denial-is-back Top Of Page World Cup Ends, Bogus Claims Don't A report published by NewsGuard states that Spain's victory over Argentina in the 2026 FIFA World Cup final on July 19th triggered a fresh wave of viral false claims, bringing to 14 the total number of provably false narratives NewsGuard has tracked since the tournament began in June 2026, illustrating how major international sporting events are routinely exploited as vectors for coordinated disinformation. The pattern reflects a consistent dynamic in which high-profile international sporting events function as disinformation amplification environments: peak audience engagement, intense emotional stakes, and dense social media activity create conditions in which fabricated narratives spread rapidly ahead of correction, and content posted within the first minutes after a major result can accumulate millions of views before fact-checkers can respond. NewsGuard noted that the false claims circulating the 2026 World Cup span a range of categories including fabricated match incidents, invented player conduct, and false reports of off-field events, with the majority achieving initial viral spread on social media before migrating to low-credibility news websites. Source: NewsGuard. World Cup Ends, Bogus Claims Don't. [online] Published 22 July 2026. Available at: https://www.newsguardrealitycheck.com/p/world-cup-ends-bogus-claims-dont Top Of Page French Parliament Greenlights Social Media Ban for Under-15s A report published by The Record states that France became the first European Union country to approve a blanket social media ban for children under 15, with the law taking effect September 1st, 2026 for new account creation, requiring all users to verify their age using regulator-approved methods, with critics including Amnesty International arguing that governments should instead regulate harmful engagement-based algorithms rather than implement blanket bans. Research into Australia's analogous ban, introduced in December 2025, found that significant numbers of teenagers remained on social media through circumvention methods including VPN use, accounts created by older contacts, and falsified date-of-birth entries. The French legislation mandates regulator-approved identity verification rather than self-declaration, which proponents argue is more enforceable than the Australian model; privacy advocates have raised concerns that identity-linked verification creates disproportionate data exposure for all users, including adults who must submit to the same process, and the European Commission has indicated it is evaluating a bloc-wide equivalent ban for users under 13. Source: The Record. French Parliament greenlights social media ban for under-15s. [online] Published 22 July 2026. Available at: https://therecord.media/france-social-media-ban-parliament Top Of Page The Pro-Trump Ad Boycott that Never Happened A fact-check published by NewsGuard states that the viral claim that Coca-Cola and General Motors withdrew advertising from NBC and ABC after the networks declined to air President Trump's July 16th election security address is false, with NewsGuard identifying Chevrolet commercials airing on both networks on July 19th and both General Motors and Coca-Cola confirming to NewsGuard on July 20th that no such withdrawal had taken place. The false boycott narrative followed a documented disinformation template in which a politically charged media event is rapidly followed by fabricated corporate response claims designed to cast the event in binary partisan terms before the named companies can publicly respond. The speed with which the General Motors and Coca-Cola claims circulated illustrates how the disinformation production cycle increasingly outpaces corporate communications, with both companies forced to issue formal denials to NewsGuard several days after the false claim had already achieved substantial social media penetration, a pattern NewsGuard has documented in multiple prior episodes involving major brands and controversial media coverage decisions. Source: NewsGuard. The Pro-Trump Ad Boycott That Never Happened. [online] Published 24 July 2026. Available at: https://www.newsguardrealitycheck.com/p/the-pro-trump-ad-boycott-that-never Top Of Page [CRC Glossary] The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult. To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence. As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website. Top Of Page
- Cyber based influence campaigns 13th – 19th July 2026 Report
[Introduction] Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW). Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc. During the 13th to the 19th July 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities. [Contents] [Introduction] [Report Highlights] [Report Summary] [State Actors] Russia EU Sanctions Expose Funding Mechanism Behind Pro-Russian Influencer Russia's New Decentralized Propaganda Infrastructure NATO Condemns Russia's Persistent Malicious Cyber Activities Targeting Allies Ukraine Despite Ukraine's Victories, False Narratives About The War Persist One Fake Photo Let Russian Propaganda Cast Doubt on the Kyiv Lavra Strike China Chinese Operation Disrupts Anti-CCP Events in the US and Europe Iran Iran's Faked Military Triumphs Anatomy of an Iran-Aligned Influence Network on X War in Gaza Digital Campaign Debunks Israel's Narrative About Gaza Ceasefire [AI Related Articles] xAI Sues Grok User Who Generated Estimated 3 Million Sexualized AI Images The Problem AI Content Moderation Cannot Solve YouTube Wiped 35 Million Subscribers Over AI Slop [General Reports] Sudden Death, Sudden Conspiracies 380 False Election Claims and Counting A Voter Guide to Trump's Election Claims State Officials, Election Experts Pan Trump Speech [Appendix - Frameworks to Counter Disinformation] A Year of Innovations in Counter-Disinformation Tooling France Plans to Triple Penalties for AI-Driven Election Disinformation AI Content Labelling Enforcement Begins in 24 Days [CRC Glossary] [ Report Highlights] NATO issued a formal condemnation on July 13th, 2026, of Russia's persistent malicious cyber activities targeting member states and partners, coinciding with EU sanctions on entities supporting information manipulation, signalling a coordinated Western escalatory response to Russian hybrid operations. The Jamestown Foundation exposed the dual-funding mechanism behind pro-Russian influencer Alexandra Jost: RT's parent TV-Novosti paid approximately EUR 1,840 monthly while the Kremlin-linked Presidential Foundation for Cultural Initiatives channelled additional grants, demonstrating the systematic financial architecture behind Moscow's English-language information operations. Graphika documented Chinese state-linked operation Spamouflage deploying a novel tactic on July 13th, 2026, distributing manipulated event flyers to disrupt anti-CCP gatherings in the US and Europe organised by Safeguard Defenders and pro-Tibet and Uyghur groups, marking an escalation toward direct transnational repression via coordinated inauthentic behaviour. NewsGuard's Reality Check confirmed that pro-Iran accounts posted an AI-generated video falsely depicting missiles striking a US Navy aircraft carrier, with multiple visual inconsistencies exposing the content as synthetically manufactured, a documented escalation in Iran's use of generative AI for false military triumph claims. xAI filed a lawsuit against a Grok user who generated an estimated 3 million sexualized AI images, including 23,000 minors, during 11 days, even as the Center for Countering Digital Hate documented the scale of the platform's systemic guardrail failures. False war narratives about Ukraine proliferated across algorithm-assisted echo chambers, with Forbes documenting how far-left and far-right voices converge on pro-Russian defeat narratives despite battlefield evidence to the contrary, and the Kyiv Independent revealing how a single AI-flagged image enabled Kremlin propagandists to weaponise Meta's own moderation system against accurate reporting. The EU DisinfoLab newsletter documented two new Russian FIMI infrastructure operations, Roska Bridge (exploiting Mastodon and Bluesky cross-posting automation to evade moderation) and Hahaganda (weaponised mockery across European networks), alongside France's proposal to triple criminal penalties for election disinformation and Canada's introduction of the Safe Social Media Act. A coordinated counter-narrative campaign launched July 16th 2026 under '#They Lied to You' challenged the international media framing of a Gaza ceasefire, with participants including journalists and civil defence workers documenting that Israeli military operations had expanded to 70% of Gaza's territory, exceeding the 53% stipulated in the ceasefire agreement. [ Report Summary] The EU sanctioned US citizen Alexandra Jost for disseminating disinformation about Russia's invasion of Ukraine, revealing a dual-funding structure from RT's parent company and Kremlin-linked cultural foundations. EU DisinfoLab documented two new Russian information manipulation operations exploiting decentralised social platforms and weaponised humour, alongside an EU Court ruling that RT sanctions apply to free streaming websites. The North Atlantic Council issued a formal statement condemning Russia's sustained cyber operations against NATO members and partners, committing to enhanced collective cyber defence and integrated countermeasures. A Forbes analysis documents how far-left and far-right voices converge on false narratives predicting Ukrainian defeat, serving Russian information warfare purposes through algorithm-assisted echo chambers despite contradictory battlefield evidence. Russian propagandists exploited a potentially AI-generated image of the burning Dormition Cathedral to construct a false staged-attack narrative, temporarily causing Meta to apply false-information labels to accurate reporting. Graphika documented Spamouflage deploying a novel tactic of distributing manipulated event flyers to disrupt anti-Communist Party gatherings organised by civil society groups in the US and Europe. Pro-Iran accounts posted AI-generated video falsely depicting missiles striking a US Navy aircraft carrier, with visual inconsistencies confirming the content as synthetically manufactured disinformation. ShadowGraph Intelligence documented a 21-account coordinated inauthentic behaviour network generating 48.6 million engagements and an estimated 5-10 billion views over six months, deploying fabricated quote overlays on video to spread pro-Iran, anti-US, and anti-Israel narratives on X. A coordinated counter-narrative campaign using '#They Lied to You' challenged international media framing of a Gaza ceasefire, with participants documenting that Israeli operations had expanded to 70% of Gaza's territory. xAI filed a lawsuit against a user who weaponised Grok to generate an estimated 3 million sexualized deepfake images, including 23,000 of minors, as the platform faces multiple lawsuits over systemic guardrail failures. A Rest of World analysis argues that AI content moderation fails to protect women from image-based abuse because it cannot account for consent or evaluate cultural context, calling for consent-based human moderation frameworks. YouTube's enforcement of its renamed 'inauthentic content' policy wiped 35 million subscribers from AI-generated channels, establishing a new standard requiring genuine human editorial judgment for content to qualify for distribution. NewsGuard documented how baseless conspiracy theories about Senator Lindsey Graham's death from cardiovascular disease spread immediately on social media, including false claims he was killed by Russian missiles. NewsGuard's tracking of false election claims reached 380 as President Trump fired two Democratic members of the US Election Assistance Commission, raising concerns about systematic dismantling of election integrity infrastructure. NewsGuard produced a voter guide fact-checking Trump's election security claims, finding that documents cited in a primetime speech did not support the assertions made about Chinese interference and noncitizen voter registration. State election officials and security experts dismissed Trump's primetime election fraud address as unsupported by evidence, documenting how federal dismantling of election security infrastructure compounds the threat from foreign influence operations. CheckFirst documented a year of advances in counter-disinformation infrastructure, including the IMS attribution framework, the Tutki OSINT training platform, and the CheckFirst Import Connector for monitoring the Pravda network. French Prime Minister Lecornu announced legislation to triple criminal penalties for disseminating false information during electoral periods, establishing a permanent public information commission and extending emergency judicial removal procedures. The EU AI Office confirmed the Code of Practice on AI-Generated Content as an adequate compliance mechanism under Article 50 of the EU AI Act, with binding deepfake labelling and disclosure obligations becoming enforceable on 2 August 2026. [State Actors] Russia EU Sanctions Expose Funding Mechanism Behind Pro-Russian Influencer An article published by The Jamestown Foundation states that the European Union sanctioned Alexandra Jost, a US citizen based in Russia operating the 'Sasha Meets Russia' social media account, for disseminating disinformation justifying Russia's invasion of Ukraine, with the sanctions revealing a dual funding structure: approximately EUR 1,840 monthly from TV-Novosti (RT's parent company) and grants channelled through the Russian Presidential Foundation for Cultural Initiatives via public relations agency Limitless. Jost's effectiveness as a Kremlin propaganda vector derives from her native English-speaking status and casual content format, which appear less overtly propagandistic than state media, while her rebuilt X account has accumulated 67,400 followers since April 2025, with individual posts generating between 20,000 and 1.9 million views. An article published by The Jamestown Foundation states that while EU sanctions increase operational costs for pro-Russian influencers, platform access rather than legal designation ultimately determines reach, as demonstrated by Jost's capacity to rebuild her following after earlier deplatforming. The analysis reveals that Russia allocated EUR 420 million in additional state media funding and EUR 16 million to pro-war cultural projects in 2023 alone, signalling an escalating Kremlin investment in English-language information operations designed to justify territorial occupation and delegitimise Western support for Ukraine through apparently organic civilian voices. Source: The Jamestown Foundation. EU Sanctions Expose Funding Mechanism Behind Pro-Russian Influencer. [online] Published 10 July 2026. Available at: https://jamestown.org/eu-sanctions-expose-funding-mechanism-behind-pro-russian-influencer/ Top Of Page Russia's New Decentralized Propaganda Infrastructure A newsletter published by EU DisinfoLab states that Russia's Foreign Information Manipulation and Interference operations have deployed two new sophisticated technical evasion tactics: 'Roska Bridge' weaponises decentralised social platforms Mastodon and Bluesky by exploiting the Brid.gy cross-posting service's functionality to automatically distribute pro-Kremlin propaganda while circumventing moderation, and 'Hahaganda' deploys coordinated psychological operations using weaponised mockery across European networks to reinforce disinformation narratives through humour. The EU Court of Justice simultaneously clarified that sanctions against Russia Today apply to free websites and streaming services, yet RT has already evaded these restrictions by establishing new accounts on X. A newsletter published by EU DisinfoLab states that democratic governments are strengthening enforcement responses to these operations: France's Prime Minister proposed legislation tripling criminal penalties for election disinformation and expanding expedited judicial content takedown procedures, Canada introduced the Safe Social Media Act (Bill C-34) establishing a Digital Safety Commission with powers to mandate deepfake labelling and enforce platform accountability, and the UK government implemented institutional boycotts of X following violent unrest. Research cited in the newsletter found that Meta's network contained over 634,000 fraudulent advertisements generating billions of impressions through media brand impersonation, while X's Community Notes mechanism was found to systematically under-moderate election disinformation. Source: Disinfo.eu (EU DisinfoLab). Disinfo Update 15/07/2026. [online] Published 15 July 2026. Available at: https://www.disinfo.eu/disinfo-update-15-07-2026/ Top Of Page NATO Condemns Russia's Persistent Malicious Cyber Activities Targeting Allies A statement published by NATO states that the North Atlantic Council formally condemned Russia's persistent malicious cyber activities targeting NATO member states, partners, and critical national infrastructure, noting that Russian cyber actors exploit state-sponsored infrastructure to conduct operations constituting a threat to Allied security. The statement references coordinated international responses including UK and EU sanctions against individuals and entities supporting Russian cyber operations, and commits NATO to employing its full operational spectrum to deter, defend against, and counter cyber threats. A statement published by NATO states that the alliance's collective cyber defence posture will be enhanced and cyber capabilities integrated across NATO operations in response to Russia's sustained targeting of Allied governments, infrastructure, and information systems. The condemnation, issued on the same date that the EU imposed sanctions on entities responsible for information manipulation activities, reflects a coordinated Western response positioning Russian cyber operations and information warfare as interconnected hybrid threats requiring aligned multilateral countermeasures. Source: NATO. Statement of Condemnation by the North Atlantic Council of Russia’s Malicious Cyber Activities. [online] Published 13 July 2026. Available at: https://www.nato.int/en/about-us/official-texts-and-resources/official-texts/2026/07/13/statement-of-condemnation-by-the-north-atlantic-council-of-russias-malicious-cyber-activities Top Of Page Ukraine Despite Ukraine's Victories, False Narratives About the War Persist An article published by Forbes states that false narratives predicting Ukrainian defeat persist across the political spectrum despite documented battlefield successes including Ukrainian drone campaigns that have degraded Russian oil refining capacity to 65% of seasonal consumption levels. Influential figures including academics, journalists, and former diplomats continue to argue that 'NATO expansionism led to the Russian invasion' or that Ukraine faces inevitable defeat, with these narratives converging across far-left and far-right perspectives despite their ideological differences. An article published by Forbes states that these convergent defeat narratives operate through 'algorithm-assisted echo chambers' that amplify pro-Russian framing to mainstream audiences, with the arguments lacking evidentiary support yet serving Russian information warfare purposes by normalising surrender as the only rational outcome. The analysis notes that Ukraine has successfully resisted what was described as the world's second-strongest military for over four years, a record that directly contradicts the defeat narratives still circulating in influential media and academic spaces, indicating these narratives function as sustained disinformation rather than evidence-based strategic assessment. Source: Forbes. Despite Ukraine’s Victories, False Narratives About the War Persist. [online] Published 16 July 2026. Available at: https://www.forbes.com/sites/marktemnycky/2026/07/16/despite-ukraines-victories-false-narratives-about-the-war-persist/ Top Of Page One Fake Photo Let Russian Propaganda Cast Doubt on the Kyiv Lavra Strike An investigation published by Kyiv Independent states that Russian propaganda platforms exploited a photograph of the Dormition Cathedral burning during Russia's 15 June 2026 missile strike, an image OpenAI's detection tools flagged as containing SynthID watermarks suggesting AI generation or editing, to construct a false narrative that Ukrainian photographers had staged the attack by setting up filming positions in advance. Pro-Kremlin accounts circulated the cathedral image alongside two AI-generated photographs falsely depicting journalists preparing the scene, causing Meta to initially restrict posts about the attack due to a technical error linking legitimate reporting to an AFP fact-check examining the AI-generated imagery. An investigation published by Kyiv Independent states that StopFake.org's Olga Yurkova explained the standard propaganda methodology: 'propagandists first establish a narrative and then create visual evidence' to support predetermined false conclusions, with AI-generated content enabling rapid production of fabricated visual 'proof' during critical moments when information environments are most contested. Meta subsequently removed the false-information labels after acknowledging the algorithmic error, a sequence that demonstrates how AI-generated disinformation can briefly weaponise platform safety systems against accurate reporting, creating a window of amplified confusion precisely when factual information about attacks on civilian and cultural infrastructure is most needed. Source: The Kyiv Independent. How One Fake Photo Let Russian Propaganda Cast Doubt on Kyiv Lavra Strike. [online] Published 7 July 2026. Available at: https://kyivindependent.com/how-one-fake-photo-let-russian-propaganda-cast-doubt-on-kyiv-lavra-strike/ Top Of Page China Chinese Operation Disrupts Anti-CCP Events in the US and Europe A report published by Graphika states that the Chinese state-linked influence operation Spamouflage deployed a novel disruption tactic in mid-2026, disseminating manipulated versions of event flyers across Facebook and X to interfere with anti-Communist Party of China events organised by Safeguard Defenders and pro-Tibet and Uyghur civil society groups in the US and Europe. The operation used inauthentic accounts to distribute the manipulated materials, representing the first documented instance of Spamouflage using this specific method to hinder event participation and obstruct civil society gatherings critical of Chinese government policies. A report published by Graphika states that this shift toward event disruption reflects an escalation in transnational repression tactics, as Chinese state actors move beyond diplomatic pressure and toward direct coordinated interference with diaspora civil society activities on Western soil. Analysts assess this tactic could extend to election interference and other forms of transnational repression, as the manipulation of event flyers, combined with coordinated inauthentic amplification, demonstrates a scalable method for sowing confusion and discouraging participation in events challenging Chinese Communist Party narratives without requiring the operational sophistication of more traditional influence operation infrastructure. Source: Graphika. Save the Date for Spamouflage. [online] Published 13 July 2026. Available at: https://www.graphika.com/reports/save-the-date-for-spamouflage Top Of Page Iran Iran's Faked Military Triumphs A briefing published by NewsGuard states that pro-Iran accounts posted an AI-generated video on multiple social media platforms falsely depicting missiles striking a US Navy aircraft carrier, with multiple visual inconsistencies pointing to the video's inauthenticity, including unnatural explosion dynamics and compositional artefacts characteristic of AI video generation. The fabricated footage circulated widely during a period of elevated US-Iran tensions, consistent with Iran's documented pattern of deploying synthetic media to claim false military triumphs and project deterrence capability beyond what its actual military operations have achieved. A briefing published by NewsGuard states that the dissemination of fabricated military victory footage reflects a broader Iranian information strategy documented in the 2025-2026 conflict period: IRGC-linked Telegram channels and state media amplify AI-generated imagery depicting false strikes on US military assets to maintain domestic morale and project international deterrence, even as independent verification systematically debunks the claims. The pattern indicates that synthetic media has become a primary instrument of Iranian strategic communication, enabling the regime to manufacture the appearance of military effectiveness in the information environment independently of operational outcomes on the ground. Source: NewsGuard Reality Check. Iran’s Faked Military Triumphs. [online] Published 16 July 2026. Available at: https://www.newsguardrealitycheck.com/p/irans-faked-military-triumphs Top Of Page Anatomy of an Iran-Aligned Influence Network on X A report published by ShadowGraph Intelligence states that a 21-account coordinated inauthentic behaviour network aligned with Iranian interests operated on X between 18 January and 18 July 2026, generating approximately 137,000 posts drawing 48.6 million engagements, with reverse-engineered impression modelling estimating 5 to 10 billion total views, equivalent to USD 30 to 65 million in earned media value at standard US news advertising rates. The three anchor accounts, @GBC_Press, @IRGC_Press, and @IRGC_Global, were batch-created within 40 minutes on 9 April 2026, with 15 of the 21 accounts created during March and April 2026, all carrying purchased blue verification, generic press branding, and identical 'West Asia' location designations constituting a shared manufactured fingerprint. A report published by ShadowGraph Intelligence states that the network's primary fabrication method involved overlaying manufactured quotes onto unrelated video footage: the flagship example saw @GBC_Press falsely attribute to Israeli Prime Minister Netanyahu a threat of 'sudden power outages, and train accidents' against Spain, a quote absent from the attached video, achieving 4.3 million views, while @IRGC_Global falsely attributed a nuclear threat statement to North Korean leader Kim Jong-Un drawing 4.4 million views. Author Travis Hawley, a former NSA and US Air Force Intelligence Officer, assessed Iran-alignment at high confidence based on content, branding, and regional placement, while explicitly noting that definitive state attribution would require legal process accessing platform registration records, a distinction that highlights the evidentiary limits of open-source attribution even in high-confidence cases of coordinated inauthentic behaviour. Source: Shadowgraph Intelligence. Iran-Aligned Influence Network on X. [online] Available at: https://shadowgraphintel.com/reports/iran-aligned-influence-network-on-x/ Top Of Page War in Gaza Digital Campaign Debunks Israel's Narrative About Gaza Ceasefire An article published by Middle East Monitor states that activists launched a coordinated social media campaign on July 16th, 2026, using the hashtag '#They Lied to You' in Arabic and English, mobilising journalists, humanitarian workers, children from Gaza, and international supporters to challenge the international media framing that a ceasefire had ended hostilities. Civil Defence spokesperson Mahmoud Basal stated, 'They lied to you when they said there was a ceasefire in Gaza; what kind of ceasefire is this when children are still being killed,' with participants sharing video content and written posts documenting continued deaths, displacement, and destruction. An article published by Middle East Monitor states that the campaign directly challenged official ceasefire claims by presenting ground-level evidence of ongoing Israeli military operations, with the Gaza Health Ministry reporting that ceasefire violations had killed 1,127 Palestinians and wounded 3,643 as of the reporting date. Participants emphasised that Israeli territorial control had expanded to 70% of Gaza's total area, exceeding the 53% stipulated in the ceasefire agreement, using the attention gap created by reduced international media coverage as a vector to reinvigorate global awareness of what the campaign described as a systematic misrepresentation of the conflict's status. Source: Middle East Monitor (MEMO). Digital Campaign Debunks Israel’s Narrative About Gaza Ceasefire. [online] Published 19 July 2026. Available at: https://www.middleeastmonitor.com/20260719-digital-campaign-debunks-israels-narrative-about-gaza-ceasefire/ Top Of Page [AI Related Articles] xAI Sues Grok User Who Generated Estimated 3 Million Sexualized AI Images An article published by Futurism states that xAI filed a lawsuit against Terry Wayne Harwood, a 67-year-old South Carolina resident, alleging he used Grok across multiple accounts to generate nonconsensual sexual deepfakes of minors and women by circumventing safety guardrails through modified prompts in a 'calculated scheme to weaponize Plaintiff's tool for criminal ends.' The lawsuit occurs within a broader crisis: the Center for Countering Digital Hate documented that for 11 days, Grok generated an estimated 3 million sexualized images, including 23,000 of children, with multiple additional lawsuits against xAI pending from Tennessee teenagers and other victims. An article published by Futurism states that while xAI reports suspending 52,222 accounts and making 73,604 reports to the National Center for Missing and Exploited Children in 2026, litigation against individual users does not address the underlying guardrail failures that enabled abuse at this scale, with law enforcement and child safety experts reporting that AI-generated child sexual abuse material has created overwhelming investigative challenges. The case illustrates a structural tension in AI enforcement: platform liability claims focus on user misuse while systemic model-level vulnerabilities that enabled mass generation of illegal content remain the proximate cause, a distinction with significant implications for both regulatory frameworks and platform accountability standards. Source: Futurism. Elon Musk’s xAI Sues Grok User Over Deepfakes. [online] Published 15 July 2026. Available at: https://futurism.com/artificial-intelligence/elon-musk-xai-sues-grok-user-deepfakes Top Of Page The Problem AI Content Moderation Cannot Solve An article published by Rest of World states that Meta's launch of Muse Image, an AI tool enabling manipulation of public Instagram users' photos without consent, exemplifies a fundamental flaw in automated content moderation: platforms define harmful content through Western-centric definitions focusing solely on explicit sexual content, while research from Chayn in Pakistan and diaspora communities reveals that everyday images including photos without headscarves, wedding videos, and pictures with male classmates are weaponised to damage women's reputations and relationships in ways current policies fail to recognise. Image-based abuse is documented as 'one of the fastest-growing forms of technology-facilitated gender-based violence,' yet AI moderation systems remain blind to the contextual harm of non-explicit images when deployed across different cultural environments. An article published by Rest of World states that the core limitation of AI content moderation is that 'AI cannot account for consent': while automated systems expedite content identification and removal, they cannot evaluate the contextual factors essential for protecting marginalised communities from targeted image-based harassment. The author argues that platforms must shift toward consent-based frameworks requiring trained human moderators capable of understanding cultural context and intent, an approach that would prove more effective across borders and languages than purely algorithmic solutions, and would address not just the content itself but the violation of autonomy inherent in unauthorised image sharing and AI-powered manipulation of individuals' likenesses. Source: Rest of World. The Problem AI Content Moderation Cannot Solve. [online] Published 16 July 2026. Available at: https://restofworld.org/2026/ai-content-moderation-consent-muse/ Top Of Page YouTube Wiped 35 Million Subscribers Over AI Slop An article published by TechTimes states that YouTube renamed its 'repetitious content' policy to 'inauthentic content' in July 2025 to better reflect that mass-produced content has always been ineligible for monetisation, with enforcement accelerating through 2026: the platform permanently terminated 11 channels and wiped content from 5 others in January 2026, erasing a combined 35 million subscribers and an estimated USD 10 million in annual advertising revenue. A Kapwing study of 15,000 trending channels found 278 producing exclusively AI-generated content with a combined 63 billion views and an estimated USD 117 million in annual revenue, illustrating the scale of the content category the enforcement actions are targeting. An article published by TechTimes states that YouTube's VP of Trust and Safety outlined three specific policy buckets determining eligibility for the YouTube Partner Program, with the new framework establishing that content must reflect 'genuine human editorial judgment' to qualify for distribution and monetisation, a standard that directly addresses the use of AI systems to generate high volumes of templated, repetitive content at industrial scale. While YouTube maintains a tool-agnostic stance on AI-assisted creation, the enforcement wave signals that platforms are developing operational frameworks distinguishing between AI tools that enhance human creativity and AI systems that replace human judgment entirely, with significant implications for the broader ecosystem of AI-generated information content. Source: Tech Times. YouTube Wiped 35M Subscribers Over AI Slop: Now It's Judging Your Taste. [online] Published 15 July 2026. Available at: https://www.techtimes.com/articles/320629/20260715/youtube-wiped-35m-subscribers-over-ai-slop-now-its-judging-your-taste.htm Top Of Page [General Reports] Sudden Death, Sudden Conspiracies A briefing published by NewsGuard states that Senator Lindsey Graham's death from a tear in his aorta due to arteriosclerotic cardiovascular disease triggered an immediate wave of baseless conspiracy theories across social media platforms, including false claims that Graham was killed by Russian missiles, a fabricated narrative that spread before official cause of death information was publicly confirmed. The speed and content of the conspiracy narratives demonstrate the established pattern by which sudden deaths of prominent figures generate coordinated disinformation within hours, exploiting the information vacuum before verified reporting reaches mass audiences. A briefing published by NewsGuard states that the Graham death conspiracy cycle illustrates how social media platforms' algorithmic amplification of emotionally resonant content enables false narratives to achieve significant reach before fact-checking responses can counteract them, with platform recommendation systems rewarding engagement-generating claims regardless of their verifiability. The episode is consistent with documented patterns in which sudden-death disinformation serves multiple functions: generating traffic for low-credibility outlets, testing the receptiveness of audiences to specific false narratives, and exploiting public grief to embed conspiratorial frameworks that persist beyond the immediate news cycle. Source: NewsGuard Reality Check. Sudden Death, Sudden Conspiracies. [online] Published 15 July 2026. Available at: https://www.newsguardrealitycheck.com/p/sudden-death-sudden-conspiracies Top Of Page 380 False Election Claims and Counting A briefing published by NewsGuard states that the organisation's tracker of false claims related to US elections reached 380 tracked narratives as President Trump fired two Democratic members of the US Election Assistance Commission on July 9th 2026, an action that raised significant concerns about the integrity of federal election oversight infrastructure. The tracker documents the persistent volume and diversity of false election narratives circulating in the US information environment, spanning claims about ballot integrity, voter fraud, foreign interference, and electoral system security. A briefing published by NewsGuard states that the removal of Election Assistance Commission members, career officials whose role includes certifying voting systems and providing technical assistance to states, represents the latest in a series of actions that election security experts characterize as a systematic dismantling of the federal infrastructure designed to identify and counter both domestic election disinformation and foreign influence operations targeting US elections. The context of 380 tracked false claims circulating simultaneously with institutional changes to election oversight bodies creates a compounding challenge for fact-checkers and election officials attempting to maintain public confidence in electoral processes ahead of the 2026 midterm elections. Source: NewsGuard's Reality Check. 380 False Election Claims and Counting. [online] Published 15 July 2026. Available at: https://www.newsguardrealitycheck.com/p/380-false-election-claims-and-counting Top Of Page A Voter Guide to Trump's Election Claims A briefing published by NewsGuard states that an 18-month federal investigation led by former journalist John Solomon yielded no evidence supporting Trump administration claims that the 2020, 2022, or 2024 elections were compromised by fraud, while the administration's central allegation, that hundreds of thousands of noncitizens were registered across four states, contradicts state audits consistently finding only single- or double-digit numbers of such cases per state. Multiple courts unanimously rejected federal attempts to forcibly obtain state voter data, and state officials across party lines characterised the administration's actions as federal overreach. A briefing published by NewsGuard states that Trump's primetime address on election security rehashed previously debunked claims about alleged Chinese interference in the 2020 election without presenting new evidence, with election security experts including David Becker of the Center for Election Innovation and Research characterising the speech as delivering 'a dud' despite White House promises of a 'bombshell.' The guide documents the pattern of claims alongside expert assessments and official state-level rebuttals, providing a structured counter-narrative resource for voters seeking verified information about election integrity amid an intensifying domestic disinformation environment targeting public confidence in electoral institutions. Source: NewsGuard Reality Check. A Voter Guide to Trump’s Election Claims. [online] Published 17 July 2026. Available at: https://www.newsguardrealitycheck.com/p/a-voter-guide-to-trumps-election Top Of Page State Officials, Election Experts Pan Trump Speech An article published by CyberScoop states that state officials and election security experts uniformly rejected President Trump's July 17th 2026 primetime address on alleged election fraud, with David Becker of the Center for Election Innovation and Research stating 'The White House promised a bombshell and they delivered a dud', an assessment shared by Nevada Democratic Secretary of State Francisco Aguilar who pushed back forcefully against the federal administration's characterisation of state election systems as compromised. An 18-month federal investigation found zero evidence that the 2020, 2022, or 2024 elections were compromised by the fraud categories described in the speech. An article published by CyberScoop states that the Trump administration's removal of all three Election Assistance Commission commissioners and systematic dismantling of federal election security infrastructure, including elimination of CISA's election security initiatives and cessation of state-level threat intelligence sharing, has created structural vulnerabilities that foreign actors are already exploiting through information environment manipulation. Election officials characterised the concurrent actions, spreading unsubstantiated fraud narratives while removing the institutional infrastructure designed to counter actual foreign interference, as compounding threats to electoral integrity that operate through different mechanisms but produce a common outcome: reduced public confidence in the legitimacy of democratic processes. Source: CyberScoop. State Officials, Election Experts Pan Trump Speech: ‘This Is What Desperation Looks Like’. [online] Published 17 July 2026. Available at: https://cyberscoop.com/state-officials-election-experts-pan-trump-voter-fraud-speech-call-it-desperation/ Top Of Page [Appendix - Frameworks to Counter Disinformation] A Year of Innovations in Counter-Disinformation Tooling An article published by CheckFirst states that the organisation adopted the Information Manipulation Set (IMS) framework alongside EU DisinfoLab, Viginum, Cassini, and other partners to standardise documentation, attribution, and response to coordinated disinformation campaigns, an approach that enabled investigations including into Roska Bridge, a pro-Russian IMS exploiting decentralised platforms, and novel OSINT work mapping Russian intelligence units through medal symbols and insignia analysis. The IMS framework represents an advance in the counter-disinformation field's capacity to attribute campaigns to specific actor networks rather than documenting individual incidents in isolation. An article published by CheckFirst states that the organisation also strengthened educational and community counter-disinformation infrastructure through the Tutki specialised OSINT training platform, deployed in Armenian and French contexts to equip journalists and civil society with skills for recognising foreign information manipulation, alongside the launch of the CheckFirst Import Connector on OpenCTI for automated monitoring of the Pravda disinformation network, joining the Internet Watch Foundation, and establishing ObSINT as a Finnish NGO. These operational developments reflect an expanding ecosystem of specialised counter-disinformation organisations building shared infrastructure and technical capacity to monitor, attribute, and respond to information manipulation at the speed required to counter modern automated FIMI operations. Source: CheckFirst. CheckFirst’s 6th Birthday: A Year of Innovations. [online] Published 16 July 2026. Available at: https://checkfirst.network/checkfirsts-6th-birthday-a-year-of-innovations/ Top Of Page France Plans to Triple Penalties for AI-Driven Election Disinformation An article published by The Next Web states that French Prime Minister Sebastien Lecornu announced legislation scheduled for Council of Ministers review in late July 2026 to triple criminal penalties for producing false information content during electoral periods, characterised by Lecornu as a 'sacred' time for democracy, with additional provisions extending emergency judicial content removal procedures to all local elections and establishing a permanent public information commission to alert media, judges, and citizens when electoral interference is detected. The bill builds on France's 2018 disinformation law and responds to concerns about AI-driven manipulation and foreign interference ahead of the presidential campaign. An article published by The Next Web states that critics raise fundamental questions about defining falsity and state authority over political speech, noting that 'vague standards and state-appointed bodies risk chilling legitimate speech, especially during the charged weeks of a campaign,' with France's prior experience of court-constrained content removal orders, including orders requiring removal within one hour that were subsequently limited by constitutional courts, demonstrating that content-regulation statutes frequently encounter judicial limits. The legislation's final wording will determine whether the proposed commission functions as a warning mechanism or becomes an instrument of speech control, a distinction with significant implications for the balance between disinformation countermeasures and press freedom protections that organisations including Reporters Without Borders have flagged as a core tension in European regulatory approaches. Source: The Next Web. France Plans to Triple Penalties for AI-Driven Election Disinformation. [online] Published 9 July 2026. Available at: https://thenextweb.com/news/france-plans-to-triple-penalties-for-ai-driven-election-disinformation Top Of Page AI Content Labelling Enforcement Begins in 24 Days An article published by TechTimes states that the EU AI Act's Article 50 transparency obligations will become enforceable across all 27 member states on 2 August 2026, imposing binding disclosure requirements on chatbots, deepfakes, and AI-generated content constituting the first such binding framework in any G7 jurisdiction, with signatories to the Code of Practice receiving a presumption of regulatory conformity that reduces the evidentiary burden under national market surveillance enforcement. Companies wishing to appear on the initial list of Code of Practice signatories must submit by July 22nd 2026, ahead of the August enforcement date. An article published by TechTimes states that deployers of AI systems generating or manipulating content constituting a deepfake, defined as AI-generated or manipulated material depicting real or realistic people in ways that could appear authentic, must disclose the synthetic origin clearly at first exposure using standardised icons and machine-readable metadata, with non-compliance carrying fines of up to EUR 15 million or 3% of global annual turnover. The Code establishes shared technical standards for watermarking, detection, and labelling across the EU's information ecosystem at a moment when AI-generated content has reached sufficient volume and sophistication, demonstrated by documented deepfake surges during political events in June and July 2026, to constitute a systemic threat requiring binding regulatory frameworks rather than voluntary industry standards. Source: TechTimes. AI Content Labeling Enforcement Begins in 24 Days as EU Clears Compliance Code. [online] Published 9 July 2026. Available at: https://www.techtimes.com/articles/319996/20260709/ai-content-labeling-enforcement-begins-24-days-eu-clears-compliance-code.htm Top Of Page [CRC Glossary] The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult. To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence. As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website. Top Of Page
- Coloring the Protest: PRC-Aligned Narratives and Indonesia’s June 2026 Protest Wave
Indonesia's June 2026 protest wave, driven by university students, women's groups, and civic actors reacting to economic pressure, fuel and food costs, and criticism of the Free Nutritious Meals Programme was locally rooted, but its meaning was quickly contested online. This report documents how a cluster of pro-PRC influencer accounts moved to reframe the demonstrations as a U.S.-, NED-, and Soros-backed "color revolution" aimed at destabilizing Indonesia and countering China's regional influence. Using narrative intelligence tools, CRC researchers identified 187 relevant posts generating over 1.2 million views, concentrated in two coordinated surges (June 6–7 and June 14–15) that tracked closely with key moments in the protest cycle. Four accounts @angeloinchina, @NuryVittachi, @BrianJBerletic, and @PeterCronau drove the bulk of this activity, mutually amplifying one another and receiving support from a network of 37 accounts, 45% of which displayed bot-like behavior. Notably, this was not an isolated incident: the same accounts pushed similar claims during Indonesia's 2025 protest cycle and timed a parallel revival of "Tiananmen was Western-backed" narratives to coincide with the June 4th memorial period, pointing to a recurring, deliberate playbook rather than spontaneous commentary. While open-source evidence does not support claims that the protests were foreign-made or externally funded, the report argues that Indonesia as Southeast Asia's largest economy and a longtime adherent of a non-aligned foreign policy, remains a key target for narratives seeking to shape public and policymaker perceptions amid intensifying U.S.-China strategic competition. [Download PDF Here]
- Cyber based influence campaigns 6th – 12th July 2026 Report
[Introduction] Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW). Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc. During the 6th to the 12th of July 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities. [Contents] [Introduction] [Report Highlights] [Report Summary] [State Actors] Russia Baltic States Summon Russian Envoys Over False Deportation Claims Russia's Attacks on Ukraine's Cultural Heritage Russia's FSB Launches Disinformation Campaign Ukraine Fake Photo Let Russian Propaganda Cast Doubt on Kyiv Lavra Strike Russia Is Building Fake Ukrainians Iran Regime Supporters and Opposition Share AI-Generated Images Fact-Checkers Exposed the Iranian State's Funeral Fraud [AI Related Articles] Viral AI Fakes Flood Social Media as Iran Mourns Khamenei Over 5,800 Arrests in Global Fraud Bust EU Confirms Code of Practice on AI-Generated Content AI Threats to the 2026 Midterms [General Reports] Member Of Committee Investigating Spyware Hacked with Pegasus Fake Trump Post Says Belgium Is 2 Weeks Away from Developing a Nuclear Bomb The West Can Learn from Ukraine's Success Against Russian Propaganda India Ran Separate Spying Campaigns Against Same Pakistani Police Force [Appendix - Frameworks to Counter Disinformation] Threat of Foreign Influence on U.S. Elections Remains as Federal Defenses Recede FTC First Amendment Fight Continues [CRC Glossary] [ Report Highlights] Russia deployed false deportation narratives against Baltic states, Lithuania, Latvia, and Estonia summoned Russian envoys after Moscow falsely alleged mass deportations of Russian speakers, with Lithuanian intelligence confirming this as a consistent Kremlin tactic for pressuring NATO members. Russia's missile strike on Kyiv Pechersk Lavra has destroyed its core FIMI narrative of Orthodox Church protection, with UNESCO verifying 536 cultural sites destroyed and estimated damage reaching EUR 4 billion direct and EUR 20 billion indirect losses. Iran's state funeral for Ali Khamenei generated a multi-layered disinformation operation: state broadcasters fabricated crowd estimates of up to 40 million, AFP Fact Check identified aerial footage as 99.7% likely AI-generated, and Tehran Municipality coercively mobilised attendance while local governors extracted over USD 570,000 from automobile manufacturers to fund roadside stations. AI-generated synthetic media flooded social media during the Khamenei funeral, exploited simultaneously by pro-regime actors and opposition networks using the same generative tools to manipulate competing narratives, demonstrating AI disinformation is no longer exclusively a top-down state instrument. INTERPOL's Operation First Light 2026 produced the largest coordinated enforcement action against fraud networks in the organisation's history, spanning 97 countries, resulting in 5,811 arrests and USD 293 million intercepted from social engineering scam networks. The European Commission confirmed its Code of Practice on AI-Generated Content as an adequate compliance mechanism under Article 50 of the EU AI Act, with transparency obligations for marking and labelling synthetic media becoming legally binding from 2 August 2026. The Brennan Center documented concurrent escalation of AI-enhanced Chinese, Russian, and Iranian election influence operations alongside systematic dismantlement of US federal election security infrastructure, including elimination of funding, cessation of state-level threat intelligence sharing, and failure to establish the Election Security Group. [ Report Summary] Lithuania, Latvia, and Estonia summoned Russian diplomats to formally reject Kremlin claims that Baltic governments were preparing mass deportations of Russian-speaking residents. Russia's June 2026 missile strike on the Kyiv Pechersk Lavra monastery has fatally undermined Moscow's core propaganda narrative of being the protector of the Orthodox Church. Russia's Federal Security Bureau distributed fabricated archival documents about the 1943 Volyn tragedy in a targeted operation to damage Ukraine-Poland strategic relations. Russian propaganda platforms exploited an image of the burning Dormition Cathedral, flagged as potentially AI-generated, to construct a false narrative that Ukrainian photographers had staged Russia's June 2026 attack on Kyiv Pechersk Lavra. Russian information operations deployed AI-generated synthetic personas posing as Ukrainian soldiers, rabbis, and civilians on TikTok, Facebook, and YouTube to spread narratives of corruption, ethnic exclusion, and military futility. Both pro-regime actors and Iranian opposition networks distributed AI-generated images of Ali Khamenei's state funeral, exploiting the same synthetic media tools to advance opposing political objectives. International fact-checkers documented three categories of Iranian state deception at Khamenei's July 2026 funeral: fabricated crowd size statistics, AI-generated aerial footage, and coercive forced attendance mechanisms. The week of Ali Khamenei's state funeral produced a significant surge of AI-generated video and image fabrications circulating across multiple platforms, with detection tools confirming the synthetic origins of viral content. INTERPOL's Operation First Light 2026, spanning 97 countries, resulted in 5,811 arrests and the interception of USD 293 million in assets from social engineering scams and associated money laundering networks. The European Commission confirmed its Code of Practice on AI-Generated Content as an adequate compliance mechanism under Article 50 of the EU AI Act, establishing voluntary standards for marking and labelling synthetic media ahead of binding legal obligations taking effect in August 2026. A fabricated post mimicking Donald Trump's Truth Social format falsely claimed Belgium was on the verge of nuclear weapons development, originating from an X account and finding no corroboration in any authentic Trump record. Pro-Kremlin networks circulated a doctored photograph depicting drug seizure bags labelled with Zelensky's image across 78 articles and thousands of posts in 13 languages, timed to coincide with the NATO Ankara Summit to undermine Zelensky's diplomatic credibility. An Atlantic Council analysis argues Ukraine's documented successes in countering Russian information operations, including AI-powered multilingual official communications, real-time disinformation dashboards, and media literacy investment, provide a transferable model for NATO allies. The Brennan Center documented concurrent escalation of Chinese, Russian, and Iranian AI-enhanced election influence operations alongside the Trump administration's systematic dismantlement of federal election security infrastructure established since 2016. SentinelOne discovered that Chinese (VANGUARD PANDA) and Indian (DISCOBEAN) state-linked hacking groups independently and simultaneously infiltrated Pakistan's Balochistan Police for over two years, accessing biometric, criminal, and citizen data, each apparently unaware of the other's presence, with China likely motivated by CPEC security concerns and India by the regional rivalry over Baloch separatism. Citizen Lab confirmed that Stelios Kouloglou, a PEGA Committee member investigating spyware abuses, was himself hacked with Pegasus twice during the committee's active drafting periods, the first confirmed such case, raising concerns about breached parliamentary privilege, with attribution unclear beyond overlap with an operator previously linked to targeting exiled Russian/Belarusian journalists. Katie Harbath argues that the 2026 US midterms face a "kaleidoscopic minefield" of AI-driven threats, including autonomous agents, world models, and platform creator-monetization incentives that reward engagement over accuracy, that outpace post-2018 detection playbooks, and calls for shifting to rapid-triage frameworks built for unknown, fast-evolving attack vectors rather than static threat-mapping. NewsGuard reports continued progress in its First Amendment lawsuit against the FTC following the agency's withdrawal of a documentary demand. At the same time, the Omnicom-Interpublic merger conditions prohibiting the media company from working with disinformation-rating services remains in force. [State Actors] Russia Baltic States Summon Russian Envoys Over False Deportation Claims A report published by Euronews states that Lithuania, Latvia, and Estonia summoned Russian envoys after Moscow alleged the three NATO member states were preparing mass deportations of Russian-speaking residents. Lithuania's Foreign Ministry described the claims as 'entirely false,' and an attempt to 'divert attention from its aggression against Ukraine,' while Estonia's Foreign Minister called them 'nothing more than unfounded Russian propaganda,' and Latvia demanded Russia 'immediately retract this false information.' A report published by Euronews states that Lithuanian intelligence assessments document Russia's consistent use of narratives accusing Baltic states of persecuting Russian speakers and glorifying Nazi collaborators, narratives that serve Moscow's strategic goal of justifying foreign policy positions and amplifying pressure on NATO members. The diplomatic row coincided with Russian escalation of missile and drone attacks on Ukrainian civilian infrastructure, indicating that the false deportation narrative was deployed as information cover for concurrent military operations. Source: Euronews. Baltic States Summon Russian Envoys Over False Deportation Claims. [online] Published 10 July 2026. Available at: https://www.euronews.com/my-europe/2026/07/10/baltic-states-summon-russian-envoys-over-false-deportation-claims Top Of Page Russia's Attacks on Ukraine's Cultural Heritage An analysis published by StopFake states that Russia's targeting of the Kyiv Pechersk Lavra monastery on June 15th 2026 has collapsed Moscow's central Foreign Information Manipulation and Interference (FIMI) narrative of portraying Russia as the protector of the Orthodox Church. The analysis documents that this propaganda strategy rested on the false appropriation of Ukrainian Christian heritage, systematically omitting that Prince Volodymyr was 'Prince of Kyiv' and that Moscow was founded 159 years after Kyiv, while UNESCO has verified destruction of 536 Ukrainian cultural sites and Ukraine's Ministry of Culture has recorded approximately 1,900 damaged heritage locations. An analysis published by StopFake states that Russia's escalating attacks on cultural infrastructure reflect battlefield desperation rather than strategic intent, functioning as demoralization tactics when conventional military objectives fail. Estimated direct losses to Ukraine's cultural heritage have reached EUR 4 billion, with indirect losses of EUR 20 billion, and the theft of over 35,000 museum exhibits, a scale of cultural destruction that has simultaneously destroyed the credibility of Russia's self-assigned identity as civilization's defender. Source: StopFake. Russia’s Attacks on Ukraine’s Cultural Heritage: A Nail in the Coffin of FIMI. [online] Published 8 July 2026. Available at: https://www.stopfake.org/en/russia-s-attacks-on-ukraine-s-cultural-heritage-a-nail-in-the-coffin-of-fimi/ Top Of Page Russia's FSB Launches Disinformation Campaign A report published by Ukrainska Pravda states that Russia's Federal Security Bureau (FSB) launched a disinformation operation designed to damage Ukraine-Poland strategic relations by publishing allegedly 'declassified' files in Russia Today that falsely accused Ukrainian Insurgent Army commander Dmytro Kliachkivskyi of ordering the killing of approximately 2,000 Poles in Volodymyr-Volynskyi during 1943. Ukraine's Center for Countering Disinformation confirmed the documents were fabricated, with FSB Director Alexander Bortnikov personally overseeing the operation and state media instructed to amplify the narrative. A report published by Ukrainska Pravda states that the strategic objective of the FSB operation was to 'destroy the strategic partnership through manipulation of the past' by exploiting Polish historical trauma around the Volyn tragedy to provoke emotional reactions and fracture the Ukraine-Poland alliance at a critical moment of military cooperation. The operation was accompanied by identified bot farm activity targeting Polish social media and a network of eleven individuals organising anti-Ukrainian rallies in Poland for Russian payment, revealing a coordinated multi-vector influence campaign. Source: Ukrainska Pravda. Russia's FSB Launchs Disinformation Campaign Using Fake Volyn Tragedy Documents. [online] Published 5 July 2026. Available at: https://www.pravda.com.ua/eng/news/2026/07/05/8042440/ Top Of Page Ukraine Fake Photo Let Russian Propaganda Cast Doubt on Kyiv Lavra Strike An investigation published by Kyiv Independent states that Russian propaganda platforms exploited a photograph of the Dormition Cathedral burning during Russia's 15 June 2026 missile strike, an image that OpenAI's detection tools flagged as containing SynthID watermarks suggesting AI generation or editing, to construct a false narrative that Ukrainian photographers had staged the attack by setting up filming positions in advance. Pro-Kremlin accounts circulated the cathedral image alongside two AI-generated photographs falsely depicting journalists preparing the scene, with accompanying text claiming: 'The third photo shows the resulting image taken by these photographers.' An investigation published by Kyiv Independent states that StopFake.org's Olga Yurkova explained the standard propaganda methodology at work: 'propagandists first establish a narrative and then create visual evidence' to support predetermined false conclusions. Meta initially restricted posts about the attack due to a technical error linking legitimate reporting to an AFP fact-check examining the AI-generated imagery, but subsequently removed the false-information labels after acknowledging the algorithmic mistake, a sequence that demonstrates how AI-generated disinformation can briefly weaponise platform safety systems against accurate reporting. Source: The Kyiv Independent. How One Questionable Photo Fueled Confusion Over Russia's Attack on Kyiv Lavra. [online] Published 7 July 2026. Available at: https://kyivindependent.com/how-one-fake-photo-let-russian-propaganda-cast-doubt-on-kyiv-lavra-strike/ Top Of Page Russia Is Building Fake Ukrainians An analysis published by Euromaidan Press states that Russian information operations deployed at least three AI-generated videos targeting Ukrainian audiences across TikTok, Facebook, and YouTube in May 2026, collectively accumulating millions of views: a synthetic soldier accusing politicians of 'building a third house on the French Riviera' while troops sacrificed (915,000 views on Facebook), an AI-generated rabbi claiming draft dodgers should lose Ukrainian citizenship while deploying antisemitic tropes (557,000 views on TikTok), and a fabricated soldier accusing President Zelenskyy of pursuing war until complete societal destruction (425,000 views on TikTok). An analysis published by Euromaidan Press states that the three videos advanced distinct but complementary narratives, political corruption and soldier exploitation; ethnic exclusivity and Jewish overreach; and autocratic indifference to civilian casualties, while coordinated artificial promotion through bot engagement amplified their reach simultaneously across TikTok, YouTube, Facebook, Telegram, and X. The campaign demonstrates a sophisticated industrial-scale fabrication strategy in which AI-generated synthetic personas impersonate Ukrainian community figures to delegitimise the state, fracture social cohesion, and undermine civilian support for military mobilisation from within. Source: Euromaidan Press. Russia Is Building Fake Ukrainians: One AI Video, Telling Ukrainians Their Soldiers Are Dying So Politicians Can Buy Villas, Got 900,000 Views. [online] Published 4 July 2026. Available at: https://euromaidanpress.com/2026/07/04/russia-is-building-fake-ukrainians-one-ai-video-telling-ukrainians-their-soldiers-are-dying-so-politicians-can-buy-villas-got-900000-views/ Top Of Page Iran Regime Supporters and Opposition Share AI-Generated Images A report published by France 24 states that both pro-regime actors and Iranian opposition networks distributed AI-generated images of Ali Khamenei's state funeral, exploiting the same synthetic media tools to advance opposing political objectives. Regime supporters posted fabricated images of massive crowds at the Grande Mosalla Mosque and Azadi Tower, accumulating over 100,000 views and picked up by African media outlets, while opposition networks distributed a fabricated image of dissident rapper Toomaj Salehi appearing to honour Khamenei, both categories confirmed as AI-generated through SynthID watermark analysis. A report published by France 24 states that the parallel deployment of AI-generated content by opposing sides of Iran's political conflict reveals a fundamental shift in information warfare: synthetic imagery has become a universally accessible tool that requires neither state resources nor technical expertise, enabling both authoritarian governments and their opponents to manipulate public perception of the same event with fabricated visual evidence. The Khamenei funeral case demonstrates that AI disinformation is no longer exclusively a top-down state instrument but has become a contested terrain where all parties manufacture crowd sizes, emotional reactions, and political moments to shape international and domestic narratives. Source: France 24. Regime Supporters and Opposition Share AI-Generated Images of Khamenei’s Funeral. [online] Published 8 July 2026. Available at: https://www.france24.com/en/middle-east/20260708-regime-supporters-opposition-share-ai-generated-images-khamenei-funeral Top Of Page Fact-Checkers Exposed the Iranian State's Funeral Fraud A report published by NCRI states that international fact-checkers documented three categories of Iranian state deception surrounding Ali Khamenei's July 2026 state funeral: state broadcaster IRIB escalated crowd size claims from 'several million' to 15-20 million by 5 July, then 40 million nationwide by 10 July, while Reuters drone footage showed 'hundreds of thousands'; AFP Fact Check identified a 33-second aerial video as 99.7% likely AI-generated; and France 24 detected 'a fabricated beige dome replacing a real blue dome' and 'banners displaying illegible gibberish instead of actual Persian text' in widely circulated footage. A report published by NCRI states that the Iranian state supplemented media fabrication with coercive physical mobilisation: Tehran Municipality cancelled all employee leave and mandated attendance, the SAIJA organisation and Hamshahri newspaper bused workers under threat, and local governors extracted over USD 570,000 from automobile manufacturers to finance roadside stations, while the Ministry distributed 50 million free loaves of bread to financially incentivise participation. The three-layer deception strategy fabricated statistics, AI-generated visual evidence, and forced attendance to generate authentic-looking crowd footage represents a comprehensive state-coordinated disinformation architecture designed to construct a false narrative of popular grief for both domestic control and international legitimacy. Source: National Council of Resistance of Iran (NCRI). Manufactured Grief: How Fact-Checkers Exposed the Iranian State’s Funeral Fraud. [online] Published 11 July 2026. Available at: https://www.ncr-iran.org/en/news/iran-a-world/manufactured-grief-how-fact-checkers-exposed-the-iranian-states-funeral-fraud/ Top Of Page [AI Related Articles] Viral AI Fakes Flood Social Media as Iran Mourns Khamenei A report published by France 24 states that the week of Ali Khamenei's state funeral in early July 2026 produced a significant surge of AI-generated video and image fabrications across multiple platforms, with SynthID watermark analysis confirming the synthetic origins of viral content including AI-generated footage of massive crowds at the Grande Mosalla Mosque and Azadi Tower (accumulating over 100,000 views and picked up by African media) and an X post claiming approximately 40 million people attended via an AI-generated video that circulated in multiple languages. A report published by France 24 states that the Khamenei funeral disinformation surge demonstrates how major political events create predictable windows of high-volume AI content generation, as both state actors and opposition networks exploit the same generative tools to manipulate narratives about contested events. Pakistan's IVerify identified crowds in funeral footage moving in 'unnatural, wave-like patterns resembling flowing water', a characteristic artifact of AI video generation, illustrating that while detection tools are advancing, the volume and velocity of synthetic content production consistently outpaces platform enforcement capacity. Source: France 24. Viral AI Fakes Flood Social Media as Iran Mourns Khamenei. [online] Published 8 July 2026. Available at: https://www.france24.com/en/viral-ai-fakes-flood-social-media-as-iran-mourns-khamenei-1 Top Of Page Over 5,800 Arrests in Global Fraud Bust A press release published by INTERPOL states that Operation First Light 2026, a coordinated anti-fraud initiative spanning 97 countries that ran from January to April 2026, resulted in 5,811 arrests, the interception of USD 293 million in assets, the blocking of 31,014 bank accounts, and the identification of 142,000 victims globally from social engineering scams and associated money laundering operations. The operation analysed 152,808 cases, solved 23,715, and issued 99 Notices and Diffusions, with INTERPOL's Global Rapid Intervention of Payments (I-GRIP) system deployed as a stop-payment mechanism to swiftly block illicit financial flows. A press release published by INTERPOL states that the operation targeted social engineering scams, techniques that exploit human trust rather than technical vulnerabilities to obtain money or confidential information, reflecting the growing convergence between influence operations and financial fraud, where manipulative narrative techniques are increasingly weaponised for economic gain at global scale. The scale of Operation First Light 2026, encompassing nearly 100 countries and resulting in the largest coordinated enforcement action against fraud networks in INTERPOL's history, signals a decisive shift toward treating AI-enabled social engineering as a transnational security threat requiring multilateral law enforcement response. Source: INTERPOL. Over 5,800 Arrests, USD 293 Million Intercepted in Global Fraud Bust. [online] Published 9 July 2026. Available at: https://www.interpol.int/News-and-Events/News/2026/Over-5-800-arrests-USD-293-million-intercepted-in-global-fraud-bust Top Of Page EU Confirms Code of Practice on AI-Generated Content A policy document published by the European Commission states that the Commission and AI Board confirmed the Code of Practice on AI-Generated Content as an adequate compliance tool under Article 50 of the EU AI Act, which mandates transparency in AI-generated content and addresses 'risks of deception and manipulation, fostering the integrity of the information ecosystem.' The Code requires AI providers to mark audio, image, video, and text outputs in machine-readable formats detectable as artificially generated, and requires deployers to disclose deepfakes and AI-generated text on matters of public interest, with transparency obligations becoming legally binding from 2 August 2026. A policy document published by the European Commission states that while adherence to the Code of Practice is currently voluntary, its confirmation as an adequate compliance mechanism reduces administrative burden for signatories across EU Member States and establishes an industry-wide technical baseline for watermarking, detection, and labelling of synthetic media. The Commission's action comes at a moment when AI-generated content has reached sufficient scale and sophistication, demonstrated by the Khamenei funeral disinformation surge in the same week, to constitute a systemic threat to the information ecosystem that voluntary standards alone cannot address. Source: European Commission. Code of Practice on Transparency of AI-Generated Content. [online] Published 10 June 2026. Available at: https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content Top Of Page AI Threats to the 2026 Midterms Digital security strategist Katie Harbath identifies the AI threat landscape for the 2026 US midterm elections as a rapidly shifting kaleidoscopic minefield in which known threats such as deepfakes are relatively well-mapped, but novel and unnamed threat vectors are emerging faster than existing frameworks can track. Harbath highlights as particular unknowns: AI agents capable of acting autonomously on a voter's behalf; world models capable of simulating political scenarios; and the ways AI systems respond to political information inputs. She argues that playbooks developed since 2018, built to detect established attack patterns, are structurally inadequate for the next generation of threats. The piece also identifies how creator monetization programmes on social platforms now provide financial incentives for engagement-maximizing content regardless of accuracy, compounding the risk from state-sponsored influence operations by creating an aligned commercial infrastructure that amplifies divisive or false material. Harbath advocates shifting from threat-mapping to rapid-triage frameworks designed for unknown attack vectors. Source: Anchor Change. Kaleidoscopic Minefield: Election Playbook. [online] Published 28 October 2025. Available at: https://anchorchange.substack.com/p/kaleidoscopic-minefield-election-playbook Top Of Page [General Reports] Member Of Committee Investigating Spyware Hacked with Pegasus The Citizen Lab at the University of Toronto published forensic evidence confirming that Stelios Kouloglou, a former member of the European Parliament who sat on the PEGA Committee (the body tasked with investigating abuses of Pegasus and other commercial spyware), was himself hacked with NSO Group's Pegasus spyware on two separate occasions while the committee was active. The first infection occurred on 21 October 2022, coinciding with the committee's preparation of its draft report and upcoming hearings. The second infection occurred in June-July 2023 during the committee's final drafting period, approximately two months before the PEGA Committee adopted its first report. The attackers would have had access to confidential documents and committee deliberations, potentially breaching EU parliamentary privilege. Attribution remains uncertain: researchers found no indication of Greek government involvement but identified overlaps with an operator previously documented targeting Russian- and Belarusian-speaking exiled journalists in Europe. This is the first publicly confirmed case of a PEGA Committee member being hacked with Pegasus during the committee's operation. Source: Citizen Lab. Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus. [online] Published 3 July 2026. Available at: https://citizenlab.ca/research/member-of-committee-investigating-spyware-hacked-with-pegasus/ Top Of Page Fake Trump Post Says Belgium Is 2 Weeks Away from Developing a Nuclear Bomb A fact-check published by Lead Stories states that a fabricated post mimicking Donald Trump's Truth Social format falsely claimed that 'Belgium is 2 weeks away from developing a nuclear bomb,' originating from the @dogeofficialceo account on X on 7 July 2026. Lead Stories verified through manual review of Trump's Truth Social account, the Trump Truth archive, Google News, and Yahoo News that no authentic post from Trump's verified accounts contained the claim, noting that 'had the president actually made such a post, major news outlets would have widely reported it.' A fact-check published by Lead Stories states that the fabricated Trump nuclear post was published on the same day as the NATO Ankara Summit opened, a timing pattern consistent with coordinated influence operations designed to inject destabilising false narratives into major geopolitical events at moments of maximum media attention. The use of a convincingly formatted social media mockup to impersonate a sitting head of state on a nuclear proliferation claim represents an escalating category of disinformation that exploits both platform format conventions and audience familiarity with political figures' communication styles to generate credibility for fabricated content. Source: Lead Stories. Fact Check: Fake Trump Post Does NOT Say Belgium Is ‘2 Weeks Away’ From Developing A Nuclear Bomb. [online] Published 10 July 2026. Available at: https://leadstories.com/hoax-alert/2026/07/fact-check-fake-trump-post-says-belgium-is-2-weeks-away-from-developing-a-nuclear-bomb.html Top Of Page The West Can Learn from Ukraine's Success Against Russian Propaganda An analysis published by Atlantic Council states that Ukraine's documented successes in countering Russian information operations include deployment of an AI tool producing Ministry of Foreign Affairs statements in 30 languages with embedded unforgeable digital signatures, systems to counter Russia's network of thousands of fake websites, real-time disinformation dashboards for journalists, civil society, and government bodies, and media literacy investment through the Diia digital app, all anchored in 'laws promoting open data and transparency firmly rooted in democratic values. An analysis published by Atlantic Council states that NATO should adopt a 'whole-of-government and society approach' involving coalition-building across sectors, drawing from Ukraine's experience demonstrating that democracies can counter propaganda through technological innovation coupled with ethical safeguards rather than censorship. The analysis argues that the structural advantage of autocracies their natural tendency to weaponise information makes counter-disinformation investment a core democratic security priority, and that Ukraine's war-accelerated capability development offers Western governments a tested operational model at a moment when Russian information operations are targeting NATO member states directly. Source: Atlantic Council. The West Can Learn from Ukraine’s Success Against Russian Propaganda. [online] Published 2 July 2026. Available at: https://www.atlanticcouncil.org/blogs/ukrainealert/the-west-can-learn-from-ukraines-success-against-russian-propaganda/ Top Of Page India Ran Separate Spying Campaigns Against Same Pakistani Police Force SentinelOne researchers found that two separate, unconnected state-linked hacking groups, one tied to China (tracked as VANGUARD PANDA) and one tied to India (tracked as DISCOBEAN), independently conducted parallel cyber espionage operations against Pakistan's Balochistan Police for more than two years, from February 2024 to April 2026. The compromised systems held criminal records, biometric and fingerprint data, personnel files, hotel and tenant registration records linked to national identity systems, and citizen complaints. China's motivation appears tied to monitoring threats to its nationals and infrastructure connected to the China-Pakistan Economic Corridor (CPEC). India's motivation is likely linked to the bilateral rivalry and Pakistan's accusation that India backs the Baloch separatist insurgency. The simultaneous but independently run campaigns against the same target illustrate how a single police database can become the focus of competing foreign intelligence collection without either state being aware of the other's access. Source: The Record. China, India Ran Separate Spying Campaigns Against Same Pakistani Police Force. [online] Published 10 July 2026. Available at: https://therecord.media/china-india-ran-separate-spy-campaigns-against-same-police-force Top Of Page [Appendix - Frameworks to Counter Disinformation] Threat of Foreign Influence on U.S. Elections Remains as Federal Defenses Recede A report published by Brennan Center for Justice states that three nation-states are actively targeting U.S. elections with AI-enhanced tools: China's Golaxy Labs pays individuals to impersonate Western journalists while using AI to enhance message targeting; Russia's Social Design Agency hacked Bluesky user accounts and organised false-flag vandalism in Europe; and Iran is producing AI-enhanced video content and deploying fake news websites with AI-generated influencers. Simultaneously, the Trump administration has eliminated federal election security funding, ceased sharing threat intelligence with states, and failed to establish the Election Security Group. A report published by Brennan Center for Justice states that the combination of increasing foreign actor sophistication, leveraging AI to increase campaign volume, believability, and reach, with the simultaneous dismantlement of federal coordination infrastructure creates significant intelligence gaps for state election officials attempting to identify and respond to ongoing influence operations. The Center notes that while the diversity of the U.S. electoral system and prior security investments make direct interference with vote-casting technically challenging, the receding of federal defences represents a structural vulnerability that foreign actors are already exploiting through information environment manipulation rather than direct electoral system attacks. Source: Brennan Center for Justice. Threat of Foreign Influence on U.S. Elections Remain as Federal Defenses Recede. [online] Published 2 July 2026. Available at: https://www.brennancenter.org/our-work/research-reports/threat-foreign-influence-us-elections-remain-federal-defenses-recede Top Of Page FTC First Amendment Fight Continues A newsletter published by NewsGuard states that the company's First Amendment lawsuit against the Federal Trade Commission and its chairman Andrew Ferguson, challenging FTC conditioning of the Omnicom-Interpublic merger on prohibiting the combined entity from subscribing to any service that assesses the 'veracity of news reporting or other politically or ideologically contested facts', achieved a partial victory when the FTC dropped its demand for documents and ended its investigation, though the merger condition itself forbidding Omnicom from working with NewsGuard remains in force. A newsletter published by NewsGuard states that the FTC's condition targets the company 'with the precision of a laser beam' by using government power to prevent NewsGuard from producing journalism that the Trump administration and some of its supporters in the media do not like, characterising the action as an unprecedented use of merger review authority to censor First Amendment-protected editorial judgments about news source reliability. The case has broader implications for the disinformation detection sector: if upheld, the merger condition would establish a precedent permitting federal agencies to use commercial regulatory power to suppress organisations whose core function is assessing the accuracy of information. Source: NewsGuard's Reality Check. Our First Amendment Fight Continues. [online] Published 3 July 2026. Available at: https://www.newsguardrealitycheck.com/p/our-first-amendment-fight-continues Top Of Page [CRC Glossary] The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult. To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence. As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website. Top Of Page
- Iran War Post-MoU: From Cyfluence Operations to STRATCOM Efforts
Key Takeaways A new report by cyber-influence threat intelligence firm Intercept9500 examines how cyber, influence, economic, and kinetic actions operated as interconnected components of the Iran War. The report also highlights practical lessons for counter-Cyfluence and Influence Defense, including the need for rapid pre-bunking and response to narrative attacks, as well as the pre-conflict development of defensive capabilities and procedures to protect civilian infrastructure from both kinetic and hybrid threats. The recently-signed U.S.–Iran Memorandum of Understanding has led to a reduction in cyfluence attacks. At the same time, renewed kinetic attacks against civilian shipping and military assets have tested the agreement’s longevity. A CRC narrative intelligence analysis mapped key Iranian strategic communication assets on X/Twitter, primarily senior officials and state media channels, alongside their recent activity patterns, reach, and dominant narratives. Iran’s post-MoU messaging and overt influence activity continue to offer a valuable case study in how influence efforts persist, shift, and adapt across the conflict’s most recent stages. Recap Since the outbreak of the Iran War in February 2026, the conflict has extended far beyond conventional military exchanges. It has included cyberattacks (such as hack-and-leak operations, infrastructure disruption, broadcast interruption, and message application hijacking), extensive internet restrictions, the proliferation of synthetic propaganda and coordinated information disorder, and STRATCOM messaging. CRC threat researchers have previously examined this convergence of military disciplines and offensive vectors in a recent report titled The Deployment of Hybrid Threats and Cyfluence Operations in the Iran War. In the report, we documented how cyber, cognitive, and physical actions were combined to impact military institutions, national infrastructure, political leadership, and public perceptions. The Islamabad MoU On June 17-18, the United States and the Islamic Republic of Iran officially signed the Islamabad Memorandum of Understanding (MoU), agreeing on a 60-day framework intended to cement the ceasefire, reopen the doubly blockaded Strait of Hormuz, and enable negotiations on sanctions, Iran’s nuclear program, and wider regional security settlements.[1] This MoU entered into effect despite important (and high-profile) disagreements between U.S. and Iranian interpretations of its provisions, resulting in some critics even describing it as “dead on arrival”. Perhaps unsurprisingly, the MoU did not put an everlasting end to the conflict. It did, however, temporarily move the conflict from a high-intensity open warfare toward arduous negotiations, confrontational statements, and a continued contestation of the information domain. For now, the apparent result is a confusing dynamic featuring constant crisis management, posturing and re-posturing. Developments Since the MoU As of mid-July, Iranian attacks on commercial shipping in the Strait of Hormuz have renewed, prompting retaliatory U.S. military action against Iranian targets. Subsequently, Iran launched missile and drone strikes against American military assets and allies in the region. Iran continues to frame its control of the strait as a source of strategic leverage, while claiming sovereignty over the important maritime routes.[2] On July 8, President Trump declared the ceasefire effectively over, although diplomatic contacts continued. By July 12, the conflict had returned to direct widescale military exchanges, with the Strait of Hormuz again emerging as both a military chokepoint and an instrument of economic coercion. On July 13, President Trump, together with key American administration officials and the U.S. Central Command, declared the reinstatement of the naval blockade against Iran. Figure 1 - Posts published by official U.S. accounts on X. Left: A @WhiteHouse post, reposted by @POTUS, quoting President Trump’s declaration that “the ceasefire is over”; Right: @CENTCOM’s July 12 announcement of a “third round of strikes” against Iran following the IRGC’s targeting of a container ship in the Strait of Hormuz. (Courtesy of X) Figure 2 - Posts published by official U.S. accounts on X: a statement by President Trump, reposted by @WhiteHouse, and a U.S. Central Command announcement confirming the resumption of the naval blockade against Iran. (Courtesy of X) Regarding offensive cyfluence actions, public reporting since June 18 does not yet provide evidence of new operations. However, the current lack of positive evidence does not mean that cyber-influence efforts have ceased. Iranian efforts targeting the information environment are persistent. Iranian officials, state media, aligned commentators, and associated proxies have continued competing to define the narrative following the signing of the MoU agreement (i.e. a humiliating and expected U.S. surrender), as well as the reasoning for the current re-escalation, and the legitimacy of Iran’s military actions against affected Arab nations. Iranian Narrative Adaptation After the MoU The signing of the MoU required Iranian messaging to balance several potentially conflicting objectives: presenting the agreement as an Iranian achievement, denying that Tehran had capitulated, maintaining deterrence, preserving the legitimacy of the “Resistance Axis” (including Hezbollah in Lebanon and the Houthis in Yemen), and preparing domestic and foreign audiences for renewed confrontation. Initial Iranian statements emphasized conditional compliance. Tehran thus presented the agreement as a mechanism for acknowledging Iranian sovereignty and securing U.S. and Israeli concessions while retaining the right to respond to any violations. On the other hand, Iran’s supreme leader made his reservations about the agreement known, approving it due to Iranian national interests and the preservation of the wider resistance project. Later on, as tensions mounted, Iranian messaging shifted toward blaming the U.S. for the agreement’s imminent failure. This narrative essentially bridged the two alternating and competing positions of diplomatic engagement and military escalation. And by doing so, Iran portrayed itself as having accepted negotiations while framing renewed hostilities as a legitimate response to the American administration’s insincerity and aggression. Following Ayatollah Ali Khamenei’s funeral ceremonies, online discourse and media coverage saw a sharp increase in attention to Iranian threats against American and other Western leaders. Iranian revenge rhetoric, accompanied by imagery targeting President Donald Trump and other key political figures generated major traction on social media. A reported Israeli intelligence warning of a possible Iranian assassination plot against President Trump added to the perceived threat narrative. Trump himself responded by publicly warning that any successful attack would trigger overwhelming U.S. retaliation. Figure 3 - Coverage by CNN and Fox News on X regarding recent Iranian death threats against U.S. and Israeli leaders, and an Israeli intelligence warning of an alleged Iranian assassination plot. (Courtesy of X) Media coverage of the Iranian state-sanctioned threats and alleged intelligence disclosures, together with official statements, were joined by online influencers amplifying escalatory or conspiratorial narratives. Almost instantaneously, Iranian promises of revenge by means of assassination became a prominent theme of online discourse. Figure 4 - Posts by influencer Laura Loomer addressing Iranian assassination threats, questioning President Trump’s claim of successful regime change, and suggesting a possible connection to Senator Lindsey Graham’s sudden death. (Courtesy of X) Narrative Intelligence Analysis A CRC analysis of the most influential Iranian officials and state media accounts on X/Twitter (between dates June 10 – July 12, 2026) maps the extent of Iran’s overt messaging and narrative control efforts, by tracking its leading strategic communication assets, during this timeframe. Figure 5 - Activity graph showing top 10 Iranian officials and state media accounts on X/Twitter (timeframe: June 10 to July 12, 2026). Figure 6 - Graph showing impressions per day for the top 10 Iranian officials and state media accounts on X/Twitter (timeframe: June 10 to July 12, 2026). The two graphs above depict posting activity and impressions metrics for leading Iranian strategic communication assets on X/twitter. The selected time window allows us to assess STRATCOM efforts velocity and impact, before and after the signing of the MoU agreement. The table below shows an aggregated summary of reach and engagement metrics for the top 10 Iranian officials or state media accounts considered as STRATCOM assets (as of July 12, 2026). Figure 7 – A summary of the top 10 leading Iranian STRATCOM assets active on X/Twitter, including aggregated impressions metrics (timeframe June 10 to July 12, 2026). According to our analysis of Iranian communications throughout recent weeks, two amplification models appear to operate in parallel. State media outlets drove volume, publishing hundreds of posts with relatively low average reach. On the other hand, Iranian senior officials posted far less but attracted far more attention. Foreign Minister Araghchi’s 18 posts generated over 18 million impressions, exceeding the reach of IRNA or Press TV despite their much higher output. State media therefore sustained distribution, while viral reach came from a small number of high-profile officials. Dominant Narratives Using automated classification of content published by the most prominent Iranian X accounts since the signing of the MoU, CRC analysts identified three dominant narratives: The first - centered on the death of former Supreme Leader Ayatollah Khamenei, portraying it as martyrdom and honorable sacrifice while reinforcing the legitimacy of his son and successor, Mojtaba Khamenei. The second - accused the United States of repeatedly violating the MoU and emphasized Iran’s claimed exclusive sovereignty over the Strait of Hormuz. The third - focused on deterrence, retaliation, and revenge, combining official threats with visual depictions of “the Iranian public” demanding retribution in an effort to present these messages as organic, popular sentiment. Figure 8 - Top 3 narratives appearing in posts by Iranian officials and state media outlets on X/Twitter. Implications for Cyfluence Research Since the start of the Iran War, threat analysts and researchers have begun to map, correlate and monitor the diverse – and perhaps unprecedented – usage of hybrid threats, including cyfluence attacks, carried out by the combatting sides. A new report by cyber threat intelligence firm Intercept9500, titled Iranian Hybrid Warfare During Operation Epic Fury, provides a valuable multi-dimensional review of offensive operations. Following an earlier Intercept9500 Preliminary Analysis published in May 2026, it complements the CRC’s abovementioned research by examining the overall Iranian response to the U.S.–Israeli military campaign. Interestingly, the report posits that Iran effectively inverted the “conventional hybrid hierarchy”. Instead of deploying offensive influence and cyber operations to support a kinetic main effort, Tehran prioritized the cognitive and cyber domains, due to its calculation of its own comparative strengths and weaknesses. By doing so, Iran managed to gain greater opportunities to deny its adversaries from achieving their strategic objectives. To that extent, cyber activity was primarily designed and leveraged for visibility, narrative dissemination, and cognitive impact. Moreover, the strategic and operational models presented in the report place hostile influence operations and offensive cyber capabilities as part of an integrated cyfluence ecosystem. Figure 9 – Iranian Cyfluence Operational Model during the Iran War. (Courtesy of Intercept9500)[3] Conclusion The Iran War remains a valuable case study for hybrid-threat researchers, cyfluence analysts, and Influence Defense stakeholders. It highlights the role of the strategic and operational fusion of kinetic actions, cyber capabilities, economic coercion, information control, diplomatic posturing, and strategic communication in modern warfare. Given that the increased integration of these various elements has already created a highly complex and dynamic global threat landscape, additional research into both offensive applications and defensive countermeasures should be encouraged. For Influence Defense practitioners and stakeholders, the existing (and still expanding) body of evidence and operational insights is a valuable resource. A methodological examination of how hybrid threats manifest during high-intensity conflict could directly inform pre-emptive and proactive capacity building, helping to protect against emerging threats, especially in other regions currently at risk. CRC report raises several noteworthy takeaways for defenders, such as the need to pre-bunk and respond rapidly to narrative attacks, while establishing defensive capabilities, coordination mechanisms, and protection procedures before a crisis emerges. This point is particularly important for civilian infrastructure and private sector entities, which are increasingly exposed to both kinetic and hybrid threats. Lastly, we should be mindful of a basic working assumption: the valuable lessons learned from this conflict are not limited to the current combatants. Other major actors, including China and Russia, will surely draw their own conclusions. Likewise, different hacktivist groups, proxy organizations, and small-scale threat actors will likely be quicker to adapt, modifying their approach and TTPs accordingly. Ultimately, it is the application of those lessons that will determine how cyfluence capabilities and hybrid threats will be deployed in future conflicts. The CRC continues to monitor the developments and will report on relevant findings. [References:] Deutsche Welle (DW). What’s in the 14-Point US-Iran Peace Plan? [online] Published 19 June 2026. Available at: https://www.dw.com/en/whats-in-the-14-point-us-iran-peace-plan/a-77595563 Associated Press. Iran, USA and United Arab Emirates Attack. [online] Published 24 June 2026. Available at: https://apnews.com/article/iran-usa-united-arab-emirates-attack-0764d17c09370a8c5cf1e8197a8878ab Intercept9500, “Iranian Hybrid Warfare During Operation Epic Fury: Preliminary Analysis While the Situation is Still Unfolding” 15 June 2026. Available online: https://media.licdn.com/dms/document/media/v2/D4D1FAQFygKagA-vnDQ/feedshare-document-sanitized-pdf/B4DZ9THlLlGkA8-/0/1783805925198?e=1784451600&v=beta&t=H0YeCibL2_7qxMeO4zYcEN13cJFG6gqSYtZ9E7PJY7E
- Cyber based influence campaigns 29th June – 5th July 2026 Report
[Introduction] Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW). Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc. During the 29th June - 5th July of June 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities. [Contents] [Introduction] [Report Highlights] [Report Summary] [State Actors] Russia RIA Novosti Falsely Claims Lithuanian History Textbook Glorifies Hitler's Collaborators Russia Uses Mockery and Parody to Amplify Disinformation Across Europe Russia's Information War Against Ukraine's EU Future Threatens All of Europe Russian IMS Exploits Mastodon and Bluesky Architecture to Launder Sanctioned Media RT Launches @RT_on_X Account Russia Deploys FPV Drones Ukraine Moscow Deploys FIMI to Conceal Battlefield Russian Channels Strip Context from Lula's G7 Statements China China Enacts Transnational Repression Law Chinese Network Deploys 294 Fake Dating Profiles on Meta [AI Related Articles] AI-Generated Images Exploit World Cup Coverage to Spread Political Disinformation Coordinated Deepfake Ad Campaigns Impersonate Football Stars AI-Generated Hypersexualised Content Targets World Cup Fandoms Across Seven Countries [General Reports] Domestic and Chinese Influence Networks Simultaneously Target Philippine Facebook Pages Finland Nuclear Weapons Disinformation and Australian Fake News Network Documented Google GTIG and FBI Disrupt NetNut Proxy Botnet Controlling Two Million Devices AI Deepfakes, Bots, and Sockpuppet Networks HAARP Conspiracy Surges to 134,000 Mentions [Appendix - Frameworks to Counter Disinformation] EU AI Act Code of Practice Signatories Ahead of August Enforcement Consumer Deepfake Detection Market Expands [CRC Glossary] [ Report Highlights] StopFake documents Russia's 'Hahaganda' strategy deploying fabricated mockery, AI deepfakes, and nine fake Charlie Hebdo covers distributed across 13 languages to undermine Ukrainian institutional credibility without direct factual contestation. A joint EEAS-CCD report cited by StopFake documents 244,000 publications on Ukraine's EU accession generating 1.39 billion views, with over 2,600 sources displaying inauthentic coordination deploying four country-adapted narratives portraying membership as costly and conflicting. Revelum documents at least 10,000 deepfake scam ads impersonating six football players over 12 months, with volumes surging 413% for Luis Diaz and 1,700% for Neymar during the 2026 World Cup, using identical templates pointing to centralised operations. DFRLab found a Philippine domestic state-aligned network and China's Spamouflage simultaneously targeting the same Filipino activist Facebook pages with opposing objectives, showing unrelated state actors can exploit identical platform gaps with a compounding effect. Google GTIG, the FBI, Lumen, and Shadowserver disrupted NetNut/Popa, a residential proxy botnet controlling 2 million compromised devices that served 316 distinct threat clusters in a single week across cybercriminal and espionage operations. Euronews confirmed AI-generated synthetic media campaigns across six platforms in three languages during the 2026 World Cup, with one fabricated image reaching 3 million views before debunking, illustrating the amplification gap cognitive warfare operations are designed to exploit. EUvsDisinfo documents Russia's use of FPV drones as dual-use instruments delivering both explosives and propaganda leaflets into frontline communities simultaneously, integrating kinetic and cognitive warfare in a single technological vector with Kherson as the primary documented case study. [ Report Summary] StopFake finds RIA Novosti's claim that a Lithuanian history textbook glorifies Hitler's collaborators is false; the textbook describes LAF activities without glorification and includes a dedicated Holocaust section that RIA Novosti systematically omitted. StopFake documents Russia's 'Hahaganda' strategy deploying fabricated mockery, AI-generated deepfakes, and nine fake Charlie Hebdo covers across 13 languages to delegitimise Ukrainian leadership without direct factual contestation. StopFake cites a joint EEAS-CCD report documenting 244,000 publications on Ukraine's EU accession generating 1.39 billion views, with over 2,600 sources displaying inauthentic coordination deploying four country-adapted narratives portraying membership as costly, conflicting, and elite-driven. CheckFirst documents 'Roska Bridge,' a Russian IMS using Brid.gy to automatically synchronise EU-sanctioned media content across Mastodon and Bluesky in monthly burst operations across 10 instances, with CIB indicators linking it structurally to the Pravda Network. NewsGuard documents RT's @RT_on_X account accumulating 6 million views within five days of its 25 June 2026 debut in apparent evasion of EU sanctions, with the European Commission confirming sanctions cover all transmission and distribution channels including platforms and apps. EUvsDisinfo documents Russia's use of FPV drones as dual-use instruments delivering both explosives and propaganda leaflets into frontline communities simultaneously, integrating kinetic and cognitive warfare in a single technological vector with Kherson as the primary documented case study. StopFake documents Russia's use of FIMI to conceal military setbacks through false territorial claims, logistical denial despite documented supply chain degradation, and a propaganda fracture in which Kremlin-aligned correspondents contradicted official civilian-targeting narratives. StopFake identifies Russian channels extracting Lula's 'everyone is tired' remark from its G7 context, which also referenced Putin's supporters and called for UN diplomacy, to fabricate a false claim that Western backers specifically are seeking to end support for Ukraine. AEI/ISW documents the PRC's enactment of an ambiguous overseas ethnic unity law, PLA-Russia joint aerial exercises near South Korea and Japan on 27th June 2026, and Japan's discovery of PRC counterfeit USB drives containing state-linked malware that compromised defence systems between March 2024 and February 2025. NewsGuard identifies 294 coordinated Threads accounts using AI-generated profiles of attractive women targeting Taiwanese men, exhibiting CIB indicators including identical posting schedules and inaccurate Taiwan details, assessed as primed to deploy political content ahead of Taiwan's November 2026 local elections. Euronews documented AI-generated synthetic media campaigns across six platforms in three languages during World Cup 2026, including fake images of Starmer and Netanyahu at matches, with one fabricated image accumulating 3 million views before debunking, illustrating the amplification velocity gap cognitive warfare operations exploit. Revelum documents at least 10,000 deepfake scam ads impersonating six football players over 12 months, with volumes surging 413% for Luis Diaz and 1,700% for Neymar during the 2026 World Cup, using identical narrative templates and urgency language pointing to centralised operations with scalable infrastructure. EDMO documents widespread unlabelled AI-generated hypersexualised content targeting World Cup fandoms across seven countries, monetised through platform revenue programmes, with investigations revealing the same infrastructure used in dual operation for far-right political propaganda distribution. DFRLab identified a Philippine domestic state-aligned network and China's Spamouflage simultaneously targeting the same Filipino activist Facebook pages with opposing objectives, demonstrating that unrelated state actors can exploit identical platform vulnerabilities simultaneously with compounding effect. The Disinformation Observer documents a false viral claim fabricating that 'President Sipila' approved nuclear weapons storage in Finland, and an Australian CIB operation run by Vietnamese operators impersonating established news brands on Facebook to drive advertising revenue. Google GTIG, the FBI, Lumen, and Shadowserver disrupted NetNut/Popa, a residential proxy botnet controlling approximately 2 million compromised devices that served 316 distinct threat clusters in one week spanning cybercriminal and espionage operations, with the FBI seizing the netnut.com domain. Memesita reports the 2026 World Cup has attracted coordinated operations using AI deepfakes, bot amplification, and sockpuppet networks blending fabricated political content with sports commentary, while noting the secondary Liar's Dividend risk of deepfake proliferation enabling dismissal of genuine evidence as AI-generated. HAARP conspiracy mentions surged from 16,200 to 134,000 in one week as Venezuelan earthquakes killed at least 1,450 and a European heatwave killed hundreds, with viral posts falsely attributing both to US ionospheric weaponization, a claim directly refuted by HAARP's director and incompatible with seismic data. Providers and deployers of generative AI systems subject to EU AI Act Article 50 have until 22 July 2026 at 18:00 CEST to sign the Code of Practice on Transparency, with signatories receiving presumption of conformity before enforcement begins on 2 August 2026. Biometric Update reports three new deepfake detection product launches in June 2026, Scam.ai/Qualcomm's Halo, Bitdefender's RealCheck for 14 countries, and South Korea's KISA funding 11 new research projects, driven by Deloitte projections of USD 40 billion in US generative AI fraud losses by 2027. [State Actors] Russia RIA Novosti Falsely Claims Lithuanian History Textbook Glorifies Hitler's Collaborators A fact-check published by StopFake states that RIA Novosti alleged a Lithuanian 10th-grade history textbook glorifies Hitler's collaborators and ignores Nazi ties and antisemitism, a claim StopFake's analysis finds to be materially false through textual evidence and historical context. The textbook describes Lithuanian Activists' Front (LAF) activities in approximately two paragraphs without portraying any figures as heroes, acknowledges both independence aspirations and the movement's Nazi connections, and does not characterise Kazys Skirpa -- the principal figure referenced by RIA Novosti, as heroic, presenting him solely in the context of anti-Soviet resistance during a period when Lithuania had already been occupied under the Molotov-Ribbentrop Pact framework. A fact-check published by StopFake states that the textbook also contains a dedicated section titled 'The Holocaust in Nazi-Occupied Europe,' complete with death camp maps, statistical data by country, and explicit documentation of Lithuanian Jewish victims, as well as a direct statement that various European nationals 'participated in one way or another in arrests, deportations, and executions', content RIA Novosti did not reference in its coverage. StopFake's analysis identifies this pattern of selective omission as the operational core of the false claim, finding that the textbook does not glorify collaborators but rather documents a contested historical period with contextual material that RIA Novosti systematically suppressed, situating the fabrication within a broader pattern of Russian state media weaponising European historical sensitivities to generate political pressure and undermine Baltic credibility in EU and NATO contexts. Source: StopFake. RIA Novosti Fake News: Lithuanian History Textbook Glorifies Hitler’s Collaborators. [online] Published 24 June 2026. Available at: https://www.stopfake.org/en/ria-novosti-fake-news-lithuanian-history-textbook-glorifies-hitler-x27-s-collaborators/ Top Of Page Russia Uses Mockery and Parody to Amplify Disinformation Across Europe An analysis published by StopFake states that Russia has developed a coordinated disinformation strategy termed 'Hahaganda', deploying mockery, satire, and parody as tactical instruments to delegitimise targets without requiring direct persuasion, to undermine institutional trust through systematic ridicule rather than factual contestation. The analysis documents three primary operational channels: AI-generated image manipulation and deepfake video production, institutional impersonation through fabricated content attributed to credible outlets such as Charlie Hebdo, and the deployment of synthetic videos depicting Ukrainian military personnel as desperate or coerced, all distributed through a standard pattern in which Telegram channels seed content that propagates across Facebook, TikTok, and X. An analysis published by StopFake states that Hahaganda operates by exploiting confirmation bias within target audiences already sceptical of Ukrainian governance, producing a false impression of widespread international condemnation and enabling coordinated narratives to circulate as apparent organic sentiment rather than as identifiable propaganda. Documented examples include at least nine fabricated Charlie Hebdo covers attacking President Zelenskyy, which prompted a Paris court complaint by the publication in May 2025, and a January 2026 deepfake video depicting a purported Ukrainian warehouse commander that spread across 13 or more languages, with the teleMarafon Facebook account alone publishing over 50 AI-generated videos since October 2023 formatted to resemble news broadcasts. StopFake assesses Hahaganda as a significant evolution in Russian information operations, enabling attribution-resistant narrative amplification that is structurally difficult for platform moderation systems to detect given the use of satirical framing to obscure coordinated political intent. Source: StopFake. Hahaganda: How Russia Seeks to Reinforce Disinformation Narratives in Europe Through Mockery and Parody. [online] Published 30 June 2026. Available at: https://www.stopfake.org/en/hahaganda-how-russia-seeks-to-reinforce-disinformation-narratives-in-europe-through-mockery-and-parody/ Top Of Page Russia's Information War Against Ukraine's EU Future Threatens All of Europe An article published by StopFake states that a joint analytical report by the European External Action Service and Ukraine's Centre for Countering Disinformation documented how Russian Foreign Information Manipulation and Interference (FIMI) operations are systematically targeting Ukraine's path towards European Union membership, with monitors observing approximately 244,000 publications on Ukraine's EU accession between January 2025 and May 2026 generating a combined 1.39 billion views, with over 2,600 sources displaying inauthentic behaviour patterns including synchronised dissemination and coordinated amplification responses. The article identifies four core destructive narratives deployed across EU member states and Ukrainian audiences: that EU accession prolongs conflict, that Ukraine is corrupt and incompatible with European values, that EU membership is costly and risky for both parties, and that European countries pursue hidden territorial or economic interests in Ukraine, with country-specific adaptations targeting Germany via economic anxieties, France via corruption narratives, and Poland through historical sensitivities and anti-refugee framing. An article published by StopFake states that the report identifies a structural escalation in Russia's approach, finding that Moscow is no longer relying only on individual falsehoods but instead deploying generative AI, coordinated inauthentic behaviour networks, and cross-platform amplification to exhaust audiences and normalise distrust at scale, with narratives tested in the Ukrainian information space subsequently adapted for EU audiences before being reintroduced into Ukraine to create the false impression of European loss of confidence in Kyiv. StopFake situates this campaign as a direct threat not only to Ukraine's accession trajectory but to European institutional integrity itself, arguing that operations designed to degrade trust in Ukraine's compatibility with European values simultaneously corrode the foundations of democratic solidarity within EU member states, requiring not only Ukrainian countermeasures but a structural framework for shared analytical intelligence between Kyiv and European institutions as a condition of the enlargement process. Source: StopFake. Russia’s Information War Against Ukraine’s European Future Is a Threat to Europe Itself. [online] Published 1 July 2026. Available at: https://www.stopfake.org/en/russia-s-information-war-against-ukraine-s-european-future-is-a-threat-to-europe-itself/ Top Of Page Russian IMS Exploits Mastodon and Bluesky Architecture to Launder Sanctioned Media An investigation published by CheckFirst states that a Russian information manipulation set (IMS) dubbed 'Roska Bridge' has been exploiting architectural vulnerabilities in decentralised social platforms since at least September 2025, using the Brid.gy service as a technical gateway to automatically synchronise content from EU-sanctioned Russian media outlets, including Pravda Network, Russia Today, and Sputnik, across Mastodon and Bluesky simultaneously. The investigation documents operations across 10 Mastodon instances, including mastodon.social, which has over 870,000 users, with hundreds of coordinated accounts executing content in monthly burst cycles, posting intensively before disappearing and being replaced, a pattern CheckFirst identifies as a clear indicator of Coordinated Inauthentic Behaviour (CIB). An investigation published by CheckFirst states that Roska Bridge's geographic and narrative targeting encompasses Ukraine, France, Germany, and the United States with anti-Western and anti-Ukrainian propaganda, while simultaneously promoting Max, a Russian state-backed messenger that requires Russian phone numbers, indicating that the operation runs parallel domestic and Western audience targeting tracks from shared infrastructure. CheckFirst identifies structural linkage between Roska Bridge and the Pravda Network through synchronised identical publications, suggesting these are not independent actors but components of a coordinated Russian influence infrastructure designed to route sanctioned state media content into platforms, Mastodon and Bluesky, that lack the sanctions-compliance infrastructure of major platforms, exploiting decentralisation's governance gap as a systematic distribution channel for content that cannot legally reach European audiences through conventional means. Source: Check First. Roska Bridge: How a Pro-Russian IMS Exploits Vulnerabilities of Decentralised Platforms to Spread Propaganda. [online] Published 1 July 2026. Available at: https://checkfirst.network/roska-bridge-how-a-pro-russian-ims-exploits-vulnerabilities-of-decentralised-platforms-to-spread-propaganda/ Top Of Page RT Launches @RT_on_X Account A report published by NewsGuard states that a new X account named @RT_on_X appears to be an attempt by Russian state outlet RT to bypass EU sanctions imposed following Russia's full-scale invasion of Ukraine, reaching European audiences who are legally barred from accessing RT content under EU regulations. The account debuted on 25 June 2026, accumulated 1,000 followers, and posted 631 times, with posts collectively garnering 6 million views within five days, an amplification rate consistent with coordinated boosting. NewsGuard identifies multiple indicators of RT affiliation: posts carry the official RT logo and the tagline 'Freedom over censorship, Truth over narrative,' content from the new account is routinely reposted on RT's official @RT_com account, which is itself blocked from European feeds, and the account is followed by RT's editor-in-chief, Margarita Simonyan. A report published by NewsGuard states that the European Commission, responding to NewsGuard's inquiry with a statement dated July 1st, 2026, confirmed that EU sanctions cover 'all means for transmission and distribution,' including 'platforms, websites and apps,' and that the Commission is in contact with national authorities regarding the @RT_on_X account's operations. NewsGuard assesses this case as consistent with RT's documented pattern of sanctions evasion through infrastructure substitution, with prior documented tactics including website cloning, third-party distribution agreements, and re-labelled content farms, and notes that X's current enforcement posture under Elon Musk's ownership has significantly reduced platform-level intervention against state-affiliated media accounts, creating a structural gap between EU regulatory requirements and platform compliance that Russian state media continue to exploit systematically. Source: NewsGuard Reality Check. RT Evades Sanctions. [online] Published 1 July 2026. Available at: https://www.newsguardrealitycheck.com/p/rt-evades-sanctions Top Of Page Russia Deploys FPV Drones An analysis published by EUvsDisinfo states that Russia has operationalised FPV (First Person View) drones as dual-use instruments in the war in Ukraine, using the same unmanned aerial vehicles both to drop explosives on civilian and military targets and to deliver propaganda leaflets into frontline communities, integrating physical violence with psychological pressure in a single technological vector. The analysis describes this as an intentional doctrinal combination: physical pressure derives from artillery, drone attacks, and infrastructure strikes that generate constant danger and exhaustion among affected populations, while information disruption operates through telecommunications collapse or restriction that simultaneously empties the information vacuum and fills it with propaganda channels, depriving communities of accurate situational awareness at moments of maximum vulnerability. An analysis published by EUvsDisinfo states that Kherson represents the most thoroughly documented case study, having experienced Russian occupation beginning March 2022, liberation nine months later, and continuous pressure from Russian forces positioned on the occupied eastern bank of the Dnipro River following their retreat, with residents subjected to documented torture, fabricated referendums on annexation, civilian disappearances, and child kidnappings during occupation, followed by ongoing drone and artillery attacks in the post-liberation period. EUvsDisinfo situates Russia's drone dual-use doctrine within the broader framework of cognitive warfare, assessing that the deliberate combination of kinetic and information instruments represents a tactical evolution designed to maximise psychological impact on civilian populations while minimising the resources required per target, and that the integration of AI-enabled drone production with systematic propaganda distribution points to an operational model that scales both the physical and cognitive warfare components simultaneously from shared infrastructure. Source: EUvsDisinfo. Explosives and Propaganda: Russia’s Dual-Use Drones. [online] Published 29 June 2026. Available at: https://euvsdisinfo.eu/explosives-and-propaganda-russias-dual-use-drones/ Top Of Page Ukraine Moscow Deploys FIMI to Conceal Battlefield An analysis published by StopFake states that Russia is deploying coordinated Foreign Information Manipulation and Interference (FIMI) operations to conceal military setbacks through three primary mechanisms: false territorial claims asserting the capture of locations that remain under Ukrainian control, logistical denial narratives minimising documented supply chain degradation, and threat escalation framing that recharacterises Ukrainian strikes on military infrastructure as attacks on civilians. The analysis documents repeated false declarations of victory in Kupyansk, which President Zelenskyy personally visited in November 2025 to refute, and three separate claims of liberating Mala Tokmachka throughout 2025-2026 while Ukrainian forces-maintained control, with Russian General Gerasimov declaring westward advances near Kupyansk as recently as May 16th, 2026, despite Ukrainian defensive positions holding. An analysis published by StopFake states that Russia's information operations to conceal battlefield conditions extended to economic and logistical matters, with official propaganda claiming supply conditions remained under control while simultaneous government decisions revealed operational stress: Belarus import increases, aviation kerosene export bans implemented on June 1st 2026, and diesel restrictions following Ukrainian drone strikes degrading the Crimea land corridor. The analysis documents a propaganda fracture in which Kremlin-aligned war correspondents acknowledged Ukrainian strikes targeted fuel tankers rather than civilians, directly contradicting official denial narratives, and identifies the Kremlin's development of image-of-victory messaging since February 2026, emphasising resistance to the West and business resilience under sanctions, as evidence that Russia's information operations are increasingly designed to manage domestic and international perception rather than to report conditions accurately. Source: StopFake. How Moscow Tries to Cover Up Its Failures on the Ukrainian Battlefield. [online] Published 1 July 2026. Available at: https://www.stopfake.org/en/how-moscow-tries-to-cover-up-its-failures-on-the-ukrainian-battlefield/ Top Of Page Russian Channels Strip Context from Lula's G7 Statements A fact-check published by StopFake states that Russian information channels extracted a selective quotation from Brazilian President Lula's remarks at a G7 summit meeting with Ukrainian President Zelensky on June 17th 2026, in which Lula stated 'everyone is tired' of the war, referencing supporters of Ukraine, supporters of Putin, and those financing both sides, and removed his explicit mention of Putin's supporters and his call for intensified diplomatic efforts through UN Security Council mechanisms, fabricating a false claim that Lula had specifically declared Western backers exhausted and seeking to withdraw support. StopFake's analysis identifies this as a textbook hostile influence operation employing selective quotation and context removal, designed to fracture the Western coalition by suggesting public fatigue justifies policy recalibration without requiring any actual change in Western government positions. A fact-check published by StopFake states that the manipulation exploits three intersecting cognitive vulnerabilities: anchoring bias, in which the factually accurate premise that fatigue exists lends false credibility to the distorted conclusion; confirmation bias among audiences predisposed to doubt Western commitment; and cognitive load effects that reduce the likelihood of audiences consulting full source materials in social media environments. Verification against Lula's official statements in Brazilian media, the Zelensky presidential office readout, and the G7 joint statement, which reaffirmed unwavering support for Ukraine including expanded air defense deliveries, confirmed that all three sources contradict the manipulated narrative, situating the operation within Russia's sustained effort to generate diplomatic pressure on Kyiv by manufacturing the appearance of Western exhaustion rather than contesting the substance of Western policy positions. Source: StopFake. Manipulation: Lula Said Ukraine’s Western Backers Are “Tired” and Want to End the War. [online] Published 23 June 2026. Available at: https://www.stopfake.org/en/manipulation-lula-said-ukraine-s-western-backers-are-tired-and-want-to-end-the-war/ Top Of Page China China Enacts Transnational Repression Law An update published by AEI and ISW states that the People's Republic of China enacted a new ethnic unity law effective 1 July 2026 creating ambiguous prosecution standards for overseas activity, with Taiwan's UK envoy warning of transnational repression risks and citing PRC's new London diplomatic facility with reported underground detention infrastructure, a development that analysts assess as an expansion of Beijing's coercive reach into diaspora communities under legally ambiguous domestic authority. The update also documents PLA and Russian joint aerial exercises conducted near South Korea and Japan on June 27th 2026, as coordinated military signaling, alongside the Chinese Coast Guard conducting three intrusive patrols around Taiwan's Pratas Island in June while maintaining continuous presence in Taiwan's eastern Exclusive Economic Zone. An update published by AEI and ISW states that Japan's Ground Self-Defence Force discovered PRC-manufactured counterfeit USB drives containing state-linked malware that had compromised secure Japanese defence systems between March 2024 and February 2025, representing a documented cyber-enabled intelligence operation against a key US treaty ally. The update identifies a strategic recalibration in PRC military signalling, with ADIZ incursions reduced to a pre-2024 baseline of 134 sorties in June versus over 300 previously, as evidence Beijing is shifting toward normalised coercion patterns designed to reduce threat desensitisation among Taiwanese and allied populations, a pattern ISW assesses as consistent with broader Chinese grey-zone strategy that maintains continuous military pressure while avoiding escalatory incidents that could consolidate Western political will against PRC regional objectives. Source: American Enterprise Institute (AEI) and Institute for the Study of War (ISW). China & Taiwan Update, July 2, 2026. [online] Published 2 July 2026. Available at: https://www.aei.org/articles/china-taiwan-update-july-2-2026/ Top Of Page Chinese Network Deploys 294 Fake Dating Profiles on Meta A report published by NewsGuard states that a network of 294 coordinated accounts on Meta's Threads platform, which launched in May 2026, features AI-generated profiles of attractive Asian women claiming to seek Taiwanese men as romantic partners, with the accounts exhibiting multiple indicators of coordinated inauthentic behaviour: identical posting schedules, systematically similar account handles, a consistent focus on targeting Taiwanese men, and inaccurate descriptions of Taiwan-specific cultural details that suggest non-Taiwanese operators. The operation bears the hallmarks of Chinese political influence campaigns, including a December 2025 operation that used fabricated attractive Japanese influencer accounts to promote pro-China territorial claims, with NewsGuard assessing the network as primed to inject political content at a strategically timed point ahead of Taiwan's November 2026 local elections. A report published by NewsGuard states that as of the publication date, the phony dating accounts had not yet begun posting overtly political content, a pattern consistent with Chinese influence operations that establish audience trust and follower bases through benign content before activating political messaging during peak electoral periods, a technique documented in multiple prior PRC operations across Facebook, Instagram, and X. NewsGuard situates the Threads operation within a broader pattern of Chinese influence activity that exploits the trust architecture of social connectivity platforms, where romantic and personal interest framing substantially reduces user scepticism compared to overtly political accounts, and identifies Meta Threads as an emerging target for PRC influence infrastructure that presents new moderation challenges given the platform's early-stage content enforcement systems and its integration with Instagram's audience base, which provides rapid follower scaling from existing social graph connections. Source: NewsGuard Reality Check. Fake Dating Profiles, Real Foreign Influence. [online] Published 2 July 2026. Available at: https://www.newsguardrealitycheck.com/p/fake-dating-profiles-real-foreign (newsguardrealitycheck.com). Top Of Page [AI Related Articles] AI-Generated Images Exploit World Cup Coverage to Spread Political Disinformation A fact-check published by Euronews states that coordinated campaigns exploiting 2026 World Cup coverage deployed AI-generated synthetic media across X, Facebook, Instagram, Threads, Reddit, and Bluesky in English, Spanish, and Russian, targeting multiple political audiences simultaneously using fabricated imagery designed to circulate within the high-engagement environment of a major global sporting event. Documented examples include falsely attributed images depicting UK Prime Minister Keir Starmer in Croatian fan attire and Israeli Prime Minister Netanyahu attending tournament matches, with the Starmer imagery derived from repurposed 2024 UEFA Championship footage, as well as a fabricated image of an Iranian player holding a pink backpack as tribute to casualties from a February 2026 airstrike, in which the depicted individual was not a member of Iran's squad, wore incorrect kit, and appeared in a stadium that did not match the actual match venue. A fact-check published by Euronews states that verification teams employed two primary methods: reverse image searching for source authenticity and OpenAI's SynthID watermark detection, a technical marker embedded in AI-generated or manipulated images confirming artificial origin. One fabricated image accumulated 3 million views before verification could achieve comparable reach, illustrating the fundamental asymmetry between disinformation amplification velocity and debunking capacity that cognitive warfare operations systematically exploit. Euronews assesses these campaigns as demonstrating a broader operational pattern in which major international sporting events serve as optimal disinformation vectors due to high ambient engagement, multilingual audience reach, reduced critical evaluation thresholds, and the availability of emotionally resonant imagery that can be easily manipulated to carry political narrative payloads alongside organic sports content. Source: Euronews. Fact Check: Were You Fooled by These AI-Generated Images of the World Cup? [online] Published 26 June 2026. Available at: https://www.euronews.com/my-europe/2026/06/26/fact-check-were-you-fooled-by-these-ai-generated-images-of-the-world-cup Top Of Page Coordinated Deepfake Ad Campaigns Impersonate Football Stars An investigation published by Revelum states that at least 10,000 deepfake scam advertisements impersonating professional football players were identified over 12 months, with 2,736 confirmed ads across six players and campaign intensity rising sharply during the 2026 World Cup, Luis Diaz experiencing a 413% surge in daily ad volume, Neymar a 1,700% increase from his baseline, and Cristiano Ronaldo reaching 8.1 ads per day during the tournament. The operations follow a standardised template that repeats across different players and countries: a fabricated local character, a delivery worker, teacher, or single mother, claims improbable financial returns through the targeted player's supposed investment app or platform, with player names, local currency, and media branding swapped while the narrative structure, psychological pressure elements, and urgency language remain identical. An investigation published by Revelum states that three consistent tactical elements appear across nearly all documented campaigns: fabricated authority narratives using local characters designed to interrupt user scrolling before critical evaluation occurs; borrowed credibility through fake news broadcasts mimicking legitimate national media aesthetics such as Colombia's Noticias Caracol or institutional bank notifications from entities including Banco Pichincha in Ecuador; and deliberate urgency manufacturing using the phrase 'This offer is only available for the next 72 hours' appearing verbatim across multiple campaigns. Revelum's analysis identifies the reuse of identical app names, Joker Jewels appearing in both James Rodriguez and Luis Diaz campaigns, shared narrative structures, and synchronised urgency tactics as evidence of centralised operations with significant advertising infrastructure budgets, and assesses the underlying deepfake tooling and social media network architecture as reusable across sectors and public figures well beyond football, representing a scalable threat to institutional trust and individual financial security. Source: Revelum. World Cup, World Scam: The Deepfake Ads Impersonating Football Stars During the 2026 FIFA World Cup. [online] Published 2 July 2026. Available at: https://revelum.ai/insights/world-cup-deepfake-scam-ads-2026/ Top Of Page AI-Generated Hypersexualised Content Targets World Cup Fandoms Across Seven Countries An analysis published by EDMO states that social media platforms experienced widespread distribution of unlabelled AI-generated images depicting hypersexualised female football supporters across multiple national team fandoms, with fact-checking organisations across Belgium, Germany, Argentina, Switzerland, Mexico, Spain, and Brazil identifying fabrications, indicating coordinated cross-platform distribution rather than isolated incidents. The primary monetisation mechanism identified by EDMO is platform revenue optimisation: content creators generate income through viral engagement on platform monetisation programmes before redirecting audiences to secondary platforms, including paid subscription services, with the synthetic content designed to attract engagement through sexual appeal while functioning as audience-capture infrastructure. An analysis published by EDMO states that investigations have documented a dual-use pattern in which AI-generated hypersexualised content serves both commercial monetisation objectives and political distribution ends, with prior documented cases showing the same infrastructure used to attract and lure users into networks that disseminate far-right nationalist political propaganda and xenophobia mixed with soft-core pornography. EDMO identifies measurable psychological and social harms from this content type, including unrealistic expectations among young male audiences and documented links to anxiety and depression among female audiences who do not conform to AI-generated beauty standards, and documents a platform enforcement asymmetry in which sexualised AI content is tolerated at scale while other forms of World Cup disinformation are removed, suggesting that inconsistent moderation policy creates structural opportunities for actors using synthetic sexual content as an influence operation delivery mechanism. Source: European Digital Media Observatory (EDMO). The World Cup of Hypersexualized Fakes? [online] Published 26 June 2026. Available at: https://edmo.eu/publications/the-world-cup-of-hypersexualized-fakes/ Top Of Page [General Reports] Domestic and Chinese Influence Networks Simultaneously Target Philippine Facebook Pages An investigation published by DFRLab states that two distinct coordinated inauthentic behaviour (CIB) networks simultaneously targeted the same Filipino activist Facebook pages in 2026 with opposing strategic objectives: a domestic state-aligned operation conducting red-tagging to publicly associate leftist organisations including the League of Filipino Students and Kilusang Mayo Uno with the Communist Party of the Philippines, while Chinese Spamouflage profiles used the identical activist pages as comment sections to distribute anti-Marcos government narratives and amplify political opposition messaging. The domestic operation was assessed with moderate confidence to be linked to the 2nd Civil-Military Operations Battalion of the Armed Forces of the Philippines, based on circumstantial evidence including military account engagement patterns and profiles displaying Civil-Military Operations insignia, with six interconnected Facebook pages created between February and April 2026 serving as content hubs. An investigation published by DFRLab states that the Chinese Spamouflage component, 50 profiles identified across the activist pages, part of a broader multi-platform operation attributed to Chinese law enforcement, employed AI-generated imagery and formulaic comments addressing government corruption, unverified claims about President Marcos's health, and political rivalries, with some accounts posting material calling for more Molotov cocktails during protest activity. DFRLab identifies the convergence as revealing a critical platform enforcement vulnerability: a single post by Kilusang Mayo Uno received simultaneous comments from both networks pursuing contradictory objectives, demonstrating that identical infrastructure and activist Facebook pages can be weaponised by uncoordinated state and foreign actors pursuing unrelated strategic goals, multiplicatively degrading information ecosystem integrity while the platform enforcement gap that allowed Meta's 2020-era takedown targets to reconstitute remains unaddressed. Source: Digital Forensic Research Lab (DFRLab). Two Coordinated Networks, One Domestic, One Foreign, Target the Same Philippine Facebook Pages. [online] Published 30 June 2026. Available at: https://dfrlab.org/2026/06/30/two-coordinated-networks-one-domestic-one-foreign-target-the-same-philippine-facebook-pages/ Top Of Page Finland Nuclear Weapons Disinformation and Australian Fake News Network Documented A digest published by The Disinformation Observer states that a false claim posted by an X account named Megatron_ron on June 27th 2026 asserted that 'President Sipila' approved importing and storing nuclear weapons in Finland, fabricating both the signatory's identity and the law's scope, as it was President Alexander Stubb who signed the amendment on June 26th 2026, and the law explicitly forbids manufacture and detonation of nuclear weapons, with the government stating no peacetime deployment is planned. The digest assesses the operation as exploiting a real parliamentary vote of 125 to 61 on June 17th to anchor false claims, using mushroom-cloud imagery and BREAKING framing for engagement amplification, in a context where only 18% of Finns support nuclear deployment domestically, representing a structurally exploitable public vulnerability that information operations can activate without requiring a credible underlying claim. A digest published by The Disinformation Observer states that the same reporting period documented an Australian coordinated inauthentic behaviour operation in which three Facebook pages impersonating The Australian, Australia Times, and The Australian Bulletin fabricated political stories from March 2026, with one post falsely claiming that politician Pauline Hanson collapsed in parliament and prompting genuine constituents to contact her office. Attribution identified 12 operators based in Vietnam and one in Indonesia managing the pages through Vietnamese page-management services FbTarget and Bee Up, with the pages having inherited audiences from prior life as soap-opera fan pages to lend false legitimacy, a case the digest classifies as financially motivated coordinated inauthentic behaviour with operators directing traffic for advertising revenue, illustrating how automation and AI-generated content have reduced production costs to a level that enables commercial actors to conduct sustained brand impersonation operations without ideological motivation. Source: The Disinformation Observer. This Week in Disinformation: 28 June 2026. [online] Published 28 June 2026. Available at: https://thedisinformationobserver.substack.com/p/this-week-in-disinformation-28-june (thedisinformationobserver.substack.com). Top Of Page Google GTIG and FBI Disrupt NetNut Proxy Botnet Controlling Two Million Devices A report published by BleepingComputer states that a coordinated operation involving Google's Threat Intelligence Group (GTIG), the FBI, Lumen Technologies, and The Shadowserver Foundation disrupted NetNut, also known as Popa, a residential proxy botnet controlling approximately 2 million compromised devices globally, including Android phones, smart TVs, and streaming boxes hijacked through trojanised applications and the Badbox 2.0 botnet. Google's analysis identified 316 distinct threat clusters using suspected NetNut exit nodes within a single week, encompassing both cybercriminal and espionage operations, with the service's robust reseller programme enabling whitelabelling that made it one of the largest proxy networks serving hundreds of threat actors seeking to route malicious traffic through residential IP addresses to obscure operational attribution. A report published by BleepingComputer states that enforcement actions included Google disabling command-and-control accounts on its infrastructure, using Google Play Protect to automatically warn users and disable infected applications, and the FBI seizing the netnut.com domain, while technical infrastructure details were distributed to law enforcement and cybersecurity researchers to enable ongoing monitoring. BleepingComputer notes that the disruption represents part of a broader systemic challenge: the proxy industry operates through interconnected reseller networks where operators purchase and redistribute botnet capacity, meaning disruption of a major provider typically forces threat actors to migrate to competing services rather than cease operations entirely, a structural limitation of infrastructure-level takedowns that leaves the underlying demand and operational incentives for residential proxy abuse unchanged. Source: BleepingComputer. NetNut Proxy Network Disrupted, 2 Million Infected Devices Cut Off. [online] Published 3 July 2026. Available at: https://www.bleepingcomputer.com/news/security/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off/ Top Of Page AI Deepfakes, Bots, and Sockpuppet Networks An analysis published by Memesita states that the 2026 FIFA World Cup has attracted coordinated disinformation operations using three primary AI-enabled tactics: synthetic media fabrications of players and officials designed to carry geopolitical narrative payloads, automated bot amplification systems disseminating false content across social platforms faster than fact-checking infrastructure can respond, and sockpuppet networks blending fabricated political grievances with legitimate sports commentary to evade detection. The analysis identifies the global audience scale of the tournament, spanning multiple geopolitical fault lines across North America, Europe, and the Middle East, as structurally optimal for influence operations seeking simultaneous multilingual reach and reduced critical evaluation thresholds among entertainment-focused audiences. An analysis published by Memesita states that the tournament environment creates a secondary vulnerability through what the article terms the Liar's Dividend: as deepfake synthetic media involving football players and officials becomes more widely circulated, actors gain increasing capacity to dismiss genuine documentation or evidence as AI-generated, creating conditions for epistemic collapse that undermine accountability mechanisms in both sports and political contexts. Memesita acknowledges significant uncertainty regarding conversion rates, noting that it is currently unclear how much of this disinformation successfully alters the perception of the tournament among casual viewers, a limitation that reflects the broader measurement challenge in assessing influence operation effectiveness, in which the volume and velocity of disinformation output can be quantified while the cognitive impact on target audiences remains difficult to isolate from ambient political conditions. Source: Memesita. 2026 World Cup Faces Surge in AI Disinformation and State Propaganda. [online] Published 3 July 2026. Available at: https://www.memesita.com/2026-world-cup-faces-surge-in-ai-disinformation-and-state-propaganda/ (memesita.com). Top Of Page HAARP Conspiracy Surges to 134,000 Mentions A report published by NewsGuard states that as devastating twin earthquakes struck Venezuela and extreme heat scorched Europe in late June 2026, mentions of HAARP, the High-frequency Active Auroral Research Program, a US ionospheric research facility in Alaska, surged from 16,200 to 134,000 per week, a roughly eightfold increase driven by viral social media posts attributing both natural disasters to deliberate US government weaponisation of weather and seismic conditions. A 25th June post on X from a Mexico-based account asserted that 'The United States used its HAARP system against Venezuela to destroy its infrastructure. To more easily plunder its oil,' accumulating 60,000 views and 1,000 likes, while a 28th June French-language TikTok video claimed HAARP was 'a project aimed at controlling natural phenomena such as tsunamis, heat, wind, rain, earthquakes, etc.' across multiple countries. A report published by NewsGuard states that HAARP director Jessica Matthews directly refuted the claims, stating the facility cannot generate or amplify weather events or earthquakes, with a University of Colorado-Boulder research scientist adding that HAARP's radio waves penetrate less than 1 centimetre into the ground while earthquakes typically originate miles below the surface, a physical incompatibility that directly contradicts the conspiracy's mechanism. The Venezuela earthquakes originated 6 and 13 miles below the surface, triggered by the shifting of the Caribbean and South American tectonic plates. NewsGuard situates the surge within a documented pattern in which catastrophic natural events reliably activate deep-state conspiracy frameworks, with HAARP serving as a persistent attribution target since its construction in the 1990s, a pattern that represents a structurally exploitable vulnerability in crisis information environments, where attribution pressure, grief, and political grievance combine to reduce critical evaluation thresholds precisely when accurate situational information is most consequential. Source: NewsGuard Reality Check. Blaming the Deep State for Earthquakes and Heatwaves. [online] Published 30 June 2026. Available at: https://www.newsguardrealitycheck.com/p/blaming-the-deep-state-for-earthquakes Top Of Page [Appendix - Frameworks to Counter Disinformation] EU AI Act Code of Practice Signatories Ahead of August Enforcement An article published by ActReady states that providers and deployers of generative AI systems subject to Article 50(2) or 50(4) of the EU AI Act have until 22 July 2026 at 18:00 CEST to sign the Code of Practice on Transparency of AI-Generated Content, with initial signatories receiving the presumption of conformity, a legal benefit that shifts the compliance burden by allowing organisations to reference the Code rather than independently constructing arguments demonstrating that their approach satisfies transparency requirements. The deadline is structurally significant because Article 50 transparency obligations become directly enforceable from August 2nd 2026, meaning organisations that sign after 22 July may not have the presumption established before enforcement begins and will not appear on the initial published signatory list. An article published by ActReady states that eligible parties include providers of generative AI systems capable of producing synthetic audio, image, video, or text, as well as deployers who use such systems to publish content on matters of public interest, including deepfakes and AI-generated text, and that practical implementation steps involve confirming organisational status as provider, deployer, or both, reviewing the Code's measures for operational feasibility, and integrating compliance work into August 2 readiness planning. ActReady situates the deadline within the broader context of the EU AI Act's phased enforcement schedule, noting that the Code of Practice represents a voluntary mechanism carrying a significant legal incentive, and that organisations already planning to sign have no regulatory or strategic reason to delay submission, a framing that positions the July 22nd deadline as a de facto obligation for any generative AI operator seeking to establish a favourable compliance baseline before the transparency regime becomes fully active. Source: ACT Ready. Want the Presumption of Conformity? You Have Until July 22: EU AI Act Code of Practice Signatory Deadline. [online] Published 22 June 2026. Available at: https://getactready.com/blog/eu-ai-act-code-of-practice-signatory-deadline-july-22 Top Of Page Consumer Deepfake Detection Market Expands An article published by Biometric Update states that three new deepfake detection products launched in June 2026 reflect an expanding market in which detection capability is shifting from enterprise-specific tools toward consumer-accessible platforms, driven by Deloitte projections of generative AI fraud losses reaching USD 40 billion in the United States by 2027. Scam.ai and Qualcomm released Halo, an on-device deepfake detection model for video conferencing on desktop that operates locally without cloud infrastructure and was specifically optimised for Qualcomm-powered devices, with Scam.ai co-founder Dennis Ng stating that on-device processing curbs attacks from the source by eliminating the latency and privacy exposure of cloud-based detection. At the same time, Bitdefender launched RealCheck for Android and iOS, a tool that analyses submitted videos to distinguish malicious deepfakes from satirical content and provides reports on the likelihood of manipulation and deceptive intent, available in 14 countries. An article published by Biometric Update states that South Korea's Korea Internet and Security Agency simultaneously announced 11 new research projects focused on deepfake detection and fraud suppression as part of broader efforts to enable safe personal data use in AI applications, situating the product launches within a government-industry co-investment pattern in which regulatory concern and commercial incentive are converging around detection infrastructure development. Biometric Update assesses these launches as evidence that deepfake detection is transitioning from a specialised enterprise security function toward a consumer necessity, a structural shift driven by the growing accessibility of voice-cloning and facial synthesis tools that have enabled large-scale fraud operations, including the coordinated investment scam deepfake campaigns documented targeting World Cup audiences during the same period, and that the absence of standardised detection benchmarks across national jurisdictions remains a significant gap in the emerging detection ecosystem. Source: Biometric Update. New deepfake detection product launches reflect expanding market. [online] Published 30 June 2026. Available at: https://www.biometricupdate.com/202606/new-deepfake-detection-product-launches-reflect-expanding-market Top Of Page [CRC Glossary] The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult. To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence. As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website. Top Of Page
- China’s Influence War on the EV Market
China’s Influence War on the EV Market: As economies digitize, cyber influence operations increasingly target financial systems, supply chains, and intellectual property. Emerging actors like "influence mercenaries" blur state and private aggression, as seen with China's robust response to Western tariffs on its EV market. Using state media, influencers, and bots, China counters criticism and promotes its economic dominance, showcasing the growing role of digital influence in global power dynamics.
- Digital Influence Vectors in Malaysia
Commissioned by the Friedrich Naumann Foundation For Freedom Malaysia in late 2025, as part of a Study on Perceptions of Geopolitics and Regional Issues, this dedicated CRC report examines how Chinese and Russian influence affects Malaysia’s digital information environment and public opinion. The report integrates the results of two recent national surveys, narrative intelligence findings, and a media environment analysis. It argues, that Malaysia is not necessarily undergoing authoritarian conversion. Instead, it is consistently exposed to foreign-driven anti-Western and authoritarian-aligned narratives which are embedded across state media, diplomatic channels, local outlets, social media platforms, and amplifier assets. In that context, the People's Republic of China (PRC) is the most prominent foreign actor, using a multi-layered influence architecture in an attempt to frame Beijing as Malaysia’s foremost economic and strategic partner. At the same time, Russian influence activity is also observed, albeit on a more limited scale. It relies mostly on diplomatic messaging, cultural institutions, individual influencers, and media partnerships promoting narratives around multipolarity, sovereignty, anti-Western sentiment, and closer Malaysia-Russia alignment. Survey data from the CRC and Merdeka Center provides important insights. It shows that although many Malaysians view the PRC as highly active and economically beneficial, a majority still holds China responsible for South China Sea tensions. For Malaysian and European influence defense stakeholders, the report highlights uneven cognitive resilience capacity across demographic groups, reinforcing the need for improved strategic communication deployment, as well as adoption of counter-FIMI detection, remediation and response capabilities in order to protect the crucial assets of democracy. This report was compiled in March 2026. [Download PDF Here]
- Cyber based influence campaigns 22nd – 28th June 2026 Report
[Introduction] Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW). Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc. During the 22nd to the 28th of June 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities. [Contents] [Introduction] [Report Highlights] [Report Summary] [Social Media Platforms] X False Claims about Alberta Government Published by X Influencer [State Actors] Russia Russia's Wiki Warfare Tries to Distort Reality, Documents Show Russia Intensifies Shadow War to Undermine Support for Ukraine Russia Expanding Soft Power in Georgia via Culture and Language Ukraine Russian Disinformation Takes Aim at Poland-Ukraine Rift Russia Tweaks Language to Deceive the West New EEAS-CCD Report Exposes Russian FIMI Targeting Ukraine's EU Future Russian False Military Claims as Battlefield Gains Slow China Countering Disinformation Could Anchor Australia-Japan Intelligence Cooperation Chinese Network Launches Hundreds of Fake Accounts to Influence the Next Taiwanese Election [AI Related Articles] Tracking AI-Enabled Misinformation Disinformation in 2026 Forum Documents How Influence Operations Scale Through AI Enhancement Big Brands Fund AI Slop Africa Is Not Ready for Malicious AI Swarms on Its Prime News Source [General Reports] Trust in Media 2026 Longtime Exxon Legacy of Climate Denial and Misinformation BLF Propaganda Efforts Under Akhtar Nadeem's Leadership Disinformation in the Western Balkans Disinformation Elicits Learning Biases [Appendix - Frameworks to Counter Disinformation] NewsGuard Launches First AI Chatbot Built to Deliver Trusted Journalism An Intelligence-Led Mission Approach for Australia-Japan Cooperation Evaluating Mexico's New Cybersecurity Plan The Opposite of America's AI Problem Is Happening in Brazil Cate Blanchett's Free Tool Helps Protect Identity from Being Deepfaked Youth Facing Disinformation [CRC Glossary] [ Report Highlights] Leaked files from Russia's Social Design Agency reveal Project 2026, a plan to build fake Wikipedia-style sites, phony think tanks, and fabricated media outlets to shape how AI models and search engines understand political issues, run with consultant-style performance targets and achieving up to 86 million views per fabricated story. The Kyiv Independent documents how Russia's Matryoshka bot network exploited an active political dispute between Poland and Ukraine over a UPA unit title on 22 June to spread fabricated claims invoking Nazism and a fake statement attributed to the Auschwitz-Birkenau Museum director, using false logos of Euronews, Der Spiegel, and ISW. A joint EEAS-CCD report documented Russian FIMI systematically targeting Ukraine's EU accession path, with approximately 244,000 publications generating 1.39 billion views between January 2025 and May 2026, deploying a structured network of state and state-linked assets to portray Ukraine as incompatible with European values and EU membership as costly and risky for both parties. NewsGuard identified a network of 294 coordinated Threads accounts posing as Taiwanese-targeted dating profiles in what researchers assess as pre-positioning ahead of Taiwan's November 2026 local elections, with 40% of accounts following naming patterns associated with a prior network that spread narratives critical of Taiwan's ruling Democratic Progressive Party. NewsGuard's June 2026 AI Tracking Center update documents 3,749 AI Content Farm news websites across 16 languages, 358 directly linked to Russia's Storm-1516 operation, and finds that leading AI chatbots now generate false claims in response to news prompts more than one-third of the time, nearly double the prior-year rate. An eLife study found that exposure to potentially unreliable information strengthened a positivity bias and increased reliance on credible sources, meaning disinformation alters not only what people believe but also the learning mechanisms through which they process subsequent information, increasing the weight placed on positive feedback from trusted sources. Brazil enters October 2026 elections with one of the world's most detailed AI election governance frameworks, including a deepfake ban, mandatory AI content labelling, and candidate-ranking restrictions, while Cate Blanchett presented the Human Consent Registry at the European Parliament on 24 June. Mexico unveiled a National Cybersecurity Plan specifically identifying AI-enabled disinformation as a primary threat. [ Report Summary] DisinfoWatch identified a U.S. based X account with 678,000 followers promoting unsupported claims against Alberta's provincial government, including assertions linking officials to criminal child trafficking, misleading claims about Premier Smith's role in vaccine-related employment policies, and a false claim that Albertans will never receive a genuine independence referendum, despite a provincial referendum being scheduled for October 19th, 2026. Leaked files from Russia's Social Design Agency reveal Project 2026, a plan to build fake Wikipedia-style sites, phony think tanks, and fabricated media outlets to shape how AI models and search engines understand political issues, run with consultant-style performance targets and achieving up to 86 million views per fabricated story. An Atlantic Council analysis documents Russia's expanding hybrid warfare campaign against Western democracies, combining sabotage, cyber operations, election interference, and weaponised migration in a sustained effort to undermine democratic institutions and weaken Western support for Ukraine, including the documented use of Telegram-recruited assets to conduct arson attacks at properties linked to UK Prime Minister Keir Starmer. A Jamestown Foundation analysis documents a Russian soft power offensive in Georgia conducted through cultural diplomacy, language promotion, and educational programmes, with Russian presidential representative Mikhail Shvydkoy's June 2026 Tbilisi visit framing Russian language initiatives and cultural events as a pathway to restore trust, which Georgian civil society figures assess as promoting narratives designed to normalize a shared Russian Georgian identity. The Kyiv Independent documents how Russia's Matryoshka bot network exploited an active political dispute between Poland and Ukraine over a UPA unit title on 22 June to spread fabricated claims invoking Nazism and a fake statement attributed to the Auschwitz-Birkenau Museum director, using false logos of Euronews, Der Spiegel, and ISW. A Kyiv Post analysis identifies how Russia systematically exploits ambiguous diplomatic language, deploying terms such as 'negotiations,' 'battlefield realities,' and 'neutrality' to reduce Western support for Ukraine while embedding demands for Ukrainian capitulation within the cognitive architecture of international diplomacy. A joint EEAS-CCD report documented Russian FIMI systematically targeting Ukraine's EU accession path, with approximately 244,000 publications generating 1.39 billion views between January 2025 and May 2026, deploying a structured network of state and state-linked assets to portray Ukraine as incompatible with European values and EU membership as costly and risky for both parties. EUvsDisinfo's ongoing disinformation review documents Kremlin-aligned channels promoting false claims of Russian military success, including persistent claims of capturing Kupyansk and Mala Tokmachka that contradicted open-source intelligence and Ukrainian authorities, as Russia's battlefield progress slowed and Ukrainian tactical momentum partially recovered. An ASPI Strategist analysis argues that countering Chinese state-linked disinformation targeting Japan should become a standing mission for Australia-Japan intelligence cooperation, following documented escalation in Beijing's overt influence operations against Tokyo since Prime Minister Takaichi took office in October 2025. NewsGuard identified a network of 294 coordinated Threads accounts displaying signs of inauthentic coordination, including synchronised posting patterns, AI-generated profile images, and naming conventions linked to a prior DPP-critical network, posing as Taiwanese-targeted dating profiles in what researchers assess as pre-positioning ahead of Taiwan's November 2026 local elections. NewsGuard's June 2026 AI Tracking Center update documents 3,749 AI Content Farm news websites across 16 languages, 358 directly linked to Russia's Storm-1516 operation, and finds that leading AI chatbots now generate false claims in response to news prompts more than one-third of the time, nearly double the prior-year rate. An international security forum analysis published on 27 June documents the structural evolution of state-sponsored influence operations as AI integration reshapes campaign architecture, finding that AI enhancement is reducing human resource requirements for large-scale disinformation while simultaneously increasing geographic targeting precision and narrative adaptability. NewsGuard Reality Check documented major brand advertisers including Adobe, Disney, Verizon, and Fox inadvertently funding AI content farms fabricating stories about the disappearance of Savannah Guthrie's 84-year-old mother, through programmatic advertising systems that place ads based on traffic volume rather than editorial standards, with fabricated articles amplified via a network of Facebook pages posting fake breaking-news graphics. Business Day documents that Africa's information environment faces a structurally unaddressed AI disinformation threat through synthetic audio distributed via radio and encrypted messaging platforms, with voice-cloning detection tools performing poorly on African-language audio and existing counter-disinformation frameworks focused almost entirely on text and video content. YouGov's Trust in Media 2026 survey finds trust declined for most of 48 measured U.S. news outlets, with sharply deepening partisan divides, 70% of respondents concerned about deepfakes spreading disinformation, and continued multi-generational fragmentation of the American information environment. An analysis in The Conversation examining the legacy of former ExxonMobil CEO Lee Raymond, who died on 9 June 2026, documents how under Raymond's leadership Exxon directed millions of dollars to climate denial organisations, with over 80% of paid editorial advertisements promoting scientific doubt during a period when the company's own scientists were producing accurate early warming models. A Jamestown Foundation profile of Akhtar Nadeem, also known as Gwahram Baloch, a senior BLF spokesperson and propagandist, documents the organisation's expanded media operations including the publications Ispar and Sarmachar, multilingual video content, and structured messaging addressing AI applications in Baloch armed operations. British Council research finds that young people in the Western Balkans often assess information credibility based on who shared it, familiarity with the source, and 'official-looking' signals rather than through verification, with information overload creating anxiety and distrust, and sharing behaviour driven by social belonging rather than genuine belief in the accuracy of what is being shared. An eLife study found that exposure to potentially unreliable information strengthened a positivity bias and increased reliance on credible sources, meaning disinformation alters not only what people believe but also the learning mechanisms through which they process subsequent information, increasing the weight placed on positive feedback from trusted sources. NewsGuard launched 'NewsGuard AI' on June 25th, the first AI chatbot drawing exclusively from 12,000 editorially vetted sources, backed by a 64,000 false claim guardrail and a 50-50 publisher revenue-sharing model, positioning it as a structural counter-architecture to the AI Content Farm ecosystem NewsGuard has simultaneously been cataloguing. A new ASPI report proposes a formal intelligence-led framework for Australia-Japan counter-disinformation cooperation, recommending dedicated mission leads in both countries' intelligence agencies, joint annual narrative-risk assessments, and crisis simulation exercises targeting Chinese and Russian state-linked information operations. Recorded Future analysis of Mexico's new National Cybersecurity Plan identifies ransomware, AI-enabled disinformation, hacktivism, and state-sponsored cyber activity as primary threats, with the 2026 FIFA World Cup co-hosted by Mexico expected to elevate risks across all four categories significantly. Anchor Change documents Brazil's October 2026 election regulatory framework as one of the world's most detailed, including a deepfake ban in campaign materials, mandatory AI content labelling, restrictions on AI systems recommending candidates, and a 90-day deadline to build a national enforcement tools catalogue, situating Brazil as a reference model for AI election governance. Cate Blanchett introduced the Human Consent Registry at the European Parliament on June 24th 2026, a free tool allowing individuals to record whether AI systems may use their name, image, voice, and other personal attributes, providing a practical consent mechanism in an environment where unauthorised deepfakes and synthetic likenesses have become pervasive. The Council of Europe's Monaco Presidency launched the 'Youth Facing Disinformation: Why Journalists Matter' programme, including a Strasbourg conference, year-long youth working groups, an audiovisual awareness campaign, and EUR 5,000 grants for youth-led projects addressing disinformation, media literacy, journalists' safety, and freedom of expression. [Social Media Platforms] X False Claims about Alberta Government Published by X Influencer An analysis published by DisinfoWatch states that a U.S.-based X account with 678,000 followers promoted a cluster of unsupported claims against Alberta's provincial government, asserting without evidence that the government is controlled by a criminal child-trafficking and money-laundering operation, that Premier Danielle Smith enabled the College of Physicians and Surgeons of Alberta to endanger children and punish unvaccinated health workers, and that Albertans will never receive a genuine independence referendum. DisinfoWatch's analysis identified these claims as presenting a false picture of Alberta's political, medical, and democratic institutions, noting that several allegations are presented without supporting evidence or documentation. An analysis published by DisinfoWatch states that the assertion that Albertans will never have an opportunity to vote on independence is not supported by the current public record; Alberta has scheduled a provincial referendum for 19 October 2026, including a question related to the process for a potential separation referendum. While citizen-led independence initiatives have faced legal and procedural challenges, DisinfoWatch notes that those obstacles do not in themselves demonstrate a coordinated effort to prevent a vote, and that the claims linking Premier Smith to COVID-19 vaccine employment policies are also misleading, as Alberta Health Services implemented and later rescinded those policies before Smith became premier. Source: DisinfoWatch. Florida-Based X Influencer Pushes Baseless Child-Trafficking Claim About Alberta Government. [online]. Published 22 June 2026. Available at: https://disinfowatch.org/disinfo/florida-based-x-influencer-pushes-baseless-child-trafficking-claim-about-alberta-government Top Of Page [State Actors] Russia Russia's Wiki Warfare Tries to Distort Reality, Documents Show An investigation published by Bloomberg states that leaked files from Russia's Social Design Agency (SDA), an entity sanctioned by the United States, the United Kingdom, and the European Union for directing Kremlin disinformation, reveal a plan called Project 2026, which sets out to construct a sprawling network of Wikipedia-style reference sites, phony think tanks, and fake media outlets designed to shape how people and AI language models understand key political issues. The 73 leaked files, spanning May 2023 to April 2026, show the operation is run with the structured discipline of a Western consulting firm, complete with performance targets, case studies, and opinion-tracking systems, a significant evolution beyond the quota-driven approach of earlier Kremlin troll farms. An investigation published by Bloomberg states that a September 2025 assessment of one SDA-produced fabricated story, claiming Ukrainian President Volodymyr Zelensky purchased his mother two apartments in Dubai's Burj Khalifa, showed the story reaching 86 million views, with 10 million attributable to 19 project contractors sharing it on social media. A second fake story about Armenian Prime Minister Pashinyan buying a French villa received 10.6 million views, with internal SDA chat logs documenting how it forced Pashinyan to publicly deny the allegations, demonstrating the operation's ability to translate manufactured narratives into real-world political pressure. Source: Bloomberg. Leaked Files Show Russia’s Plan to Influence AI and Search Results. [online] Published 23 June 2026. Available at: https://www.bloomberg.com/news/features/2026-06-23/leaked-files-show-russia-s-plan-to-influence-ai-and-search-results Top Of Page Russia Intensifies Shadow War to Undermine Support for Ukraine An analysis published by the Atlantic Council states that Russia is conducting an expanding hybrid warfare campaign against Western countries, combining acts of sabotage, cyber operations, election interference, and weaponised migration in a sustained effort to undermine democratic institutions, deepen social divisions, and weaken Western support for Ukraine. The analysis documents an incident in which a Ukrainian citizen was recruited through Telegram by a Russian-linked organiser and convicted in connection with arson attacks at properties linked to UK Prime Minister Keir Starmer, illustrating how Russian handlers use encrypted platforms to recruit and direct assets operating inside Western countries without direct personal contact. An analysis published by the Atlantic Council states that Western intelligence officials and NATO members have assessed Russia's activities as a coordinated campaign to challenge Western societies below the threshold of conventional warfare, combining disinformation operations with physical sabotage and cyber attacks in what analysts characterise as a deliberately ambiguous hybrid strategy. The analysis recommends that governments strengthen cooperation, improve resilience against hybrid threats, and treat disinformation and related influence operations as components of a sustained strategic campaign rather than isolated incidents, requiring doctrine, resources, and inter-agency coordination matched to the persistent, cross-domain nature of the threat. Source: Atlantic Council. Russia Intensifies Shadow War to Undermine Support for Ukraine. [online] Published 23 June 2026. Available at: https://www.atlanticcouncil.org/blogs/ukrainealert/russia-intensifies-shadow-war-to-undermine-support-for-ukraine/ (atlanticcouncil.org). Top Of Page Russia Expanding Soft Power in Georgia via Culture and Language A report published by the Jamestown Foundation states that Russia is expanding its soft power presence in Georgia through cultural diplomacy, language promotion, educational initiatives, and sponsored public events, with presidential representative Mikhail Shvydkoy visiting Tbilisi in June 2026 to lead Russian-sponsored cultural activities framed as a pathway to restore trust between the two countries. Russian officials presented these initiatives as grounded in shared history, language, and civilizational connection, terminology that critics and Georgian civil society figures assess as promoting narratives designed to increase Russian influence and reinforce the concept of a shared Russian Georgian identity. A report published by the Jamestown Foundation states that protests have accompanied several Russian-language and cultural events in Georgia, reflecting public concerns that such activities serve broader political objectives rather than purely cultural ones. The report identifies the promotion of the Russian language through competitions, educational programmes, and outreach to Georgian teachers and youth as a particularly significant dimension of the operation, documenting a pattern in which culturally coded soft power activities operate as a long-term influence infrastructure, gradually normalising pro-Russian narratives within Georgian society while maintaining plausible deniability as civilian cultural exchange. Source: The Jamestown Foundation. Russia Expanding Soft Power in Georgia via Culture and Language. [online] Published 25 June 2026. Available at: https://jamestown.org/russia-expanding-soft-power-in-georgia-via-culture-and-language/ Top Of Page Ukraine Russian Disinformation Takes Aim at Poland-Ukraine Rift A fact-check published by the Kyiv Independent states that the Matryoshka bot network deployed fake social media posts on 22 June 2026 exploiting a Polish Ukrainian political dispute over a military unit being granted a title honouring the World War II-era Ukrainian Insurgent Army (UPA), presenting the rift as evidence of rampant 'Nazism' among Ukrainian elites. The operation, detected by the Antibot4Navalny monitoring group, fabricated a statement by Piotr Cywinski, a Polish historian and director of the Auschwitz-Birkenau State Museum, falsely claiming he called for barring President Zelensky from Holocaust commemoration events. A fact-check published by the Kyiv Independent states that Matryoshka posts employed a signature technique of the operation: overlaying fabricated text on unrelated stock footage while attaching the logos of Euronews, Der Spiegel, and the Institute for the Study of War (ISW) to lend false credibility. The bot network generated approximately 30,000 views per post on X, though Antibot4Navalny noted that Matryoshka routinely inflates view counts, making authentic reach difficult to establish, a deliberate component of the operation's strategy to create the impression of organic widespread resonance for manufactured narratives targeting EU and NATO audiences. Source: Kyiv Independent. Fact Check: Russian Disinformation Takes Aim at Poland-Ukraine Rift. [online] Published 23 June 2026. Available at: https://kyivindependent.com/fact-check-russian-disinformation-takes-aim-at-poland-ukraine-rift/ Top Of Page Russia Tweaks Language to Deceive the West An analysis published by Kyiv Post states that Russia's use of the word 'negotiations' functions as a systematic cognitive warfare instrument, with Moscow openly stating readiness for 'talks' while simultaneously insisting on conditions amounting to Ukrainian capitulation, including permanent NATO exclusion, severe military limitations, and Ukrainian recognition of territories seized by illegal referendum. The analysis identifies how Russian officials deploy terms such as 'battlefield realities' and 'neutrality' to generate Western pressure on Kyiv while insulating Moscow from accountability for blocking any genuine ceasefire process. An analysis published by Kyiv Post states that the Kremlin's linguistic manipulation extends to framing Russian-installed collaborators in occupied Ukraine as 'separatists', a term that implies popular local agency rather than externally imposed occupation, and deploying the phrase 'special military operation' to deny the legal and moral character of a full-scale war of aggression. The analysis argues that Western actors who adopt Kremlin framing uncritically enable the information operation, as the repeated use of Russian-defined terms shapes the cognitive architecture within which policy options are evaluated, gradually shifting the perceived space of legitimate responses away from Ukrainian sovereignty. Source: Kyiv Post. OPINION: ‘Negotiations’ Are Traps – How Russia Tweaks Language to Deceive the West. [online] Published 28 June 2026. Available at: https://www.kyivpost.com/opinion/78980 (kyivpost.com). Top Of Page New EEAS-CCD Report Exposes Russian FIMI Targeting Ukraine's EU Future An article published by EUvsDisinfo states that a joint analytical report by the European External Action Service and Ukraine's Centre for Countering Disinformation documented how Russian Foreign Information Manipulation and Interference (FIMI) operations are systematically targeting Ukraine's path towards European Union membership, with monitors observing approximately 244,000 publications on Ukraine's accession between January 2025 and May 2026 generating a combined 1.39 billion views. The report identifies a structured network of state, state-linked, and aligned information assets promoting recurring narratives that portray Ukraine as incompatible with European values, depict accession as an elite-driven process detached from public interests, and frame EU membership as costly and risky for both parties. An article published by EUvsDisinfo states that Russia views Ukraine's integration into the EU as a direct threat to its regional influence, and has deployed coordinated information activities within a broader hybrid campaign that exploits fears related to corruption, security, identity, and economic costs through AI-enabled content production, cross-platform amplification, and information laundering. The report calls for closer cooperation between Ukraine, the EU, and international partners through information sharing, strategic communication, digital regulation, sanctions, and resilience-building initiatives, situating counter-FIMI policy as a structural requirement of the EU enlargement process rather than a peripheral security measure. Source: EUvsDisinfo. New EEAS-CCD Report Exposes Russian FIMI Targeting Ukraine’s EU Future. [online] Published 23 June 2026. Available at: https://euvsdisinfo.eu/new-eeas-ccd-report-exposes-russian-fimi-targeting-ukraines-eu-future/ (euvsdisinfo.eu). Top Of Page Russian False Military Claims as Battlefield Gains Slow A review published by EUvsDisinfo states that as Russia's battlefield gains have slowed and Ukraine has regained some tactical momentum, Kremlin-aligned information channels have increasingly promoted exaggerated or false claims of military success, including persistent claims of the capture of Ukrainian towns such as Kupyansk and Mala Tokmachka that persisted despite reports from Ukrainian authorities and open-source intelligence indicating both locations remained under Ukrainian control. At the same time, Russian information operations sought to shape perceptions of Ukrainian strikes on Russian military logistics and energy infrastructure by portraying them as attacks on civilians and evidence of Western escalation. A review published by EUvsDisinfo states that pro-Kremlin outlets portrayed Ukrainian strikes as targeting civilians and as evidence that Ukraine is unwilling to pursue peace, while some Russian officials simultaneously acknowledged that many strikes were aimed at military supply networks rather than civilian targets, demonstrating the internally inconsistent nature of the information campaign, which prioritises domestic audience management and Western perception shaping over factual coherence. The analysis situates these information efforts within a pattern of Russian operational communication increasingly designed to manage public perceptions of the war as Russia faces mounting casualties and diminishing battlefield returns, rather than to accurately inform either Russian or international audiences. Source: EUvsDisinfo. Still at War: Russia’s Disinformation Targeting Ukraine. [online] Published 25 June 2026. Available at: https://euvsdisinfo.eu/still-at-war-russias-disinformation-targeting-ukraine/ (euvsdisinfo.eu). Top Of Page China Countering Disinformation Could Anchor Australia-Japan Intelligence Cooperation An analysis published by ASPI's The Strategist states that Australia and Japan are both targets of state-linked disinformation campaigns designed to exploit historical grievances, domestic political divisions, and alliance anxieties, with Beijing ratcheting up its information operations against Japan significantly since Sanae Takaichi became Prime Minister in October 2025. The analysis documents an information offensive conducted through overt propaganda channels, including Chinese state media, as well as through networks of social media influencers, inauthentic accounts, and bots amplifying Beijing's narratives across the regional information environment. An analysis published by ASPI's The Strategist states that Beijing's reaction to Japan's May 2026 intelligence reforms demonstrates that even legitimate democratic governance measures will be contested in the information domain, with Chinese state media and diplomatic accounts coordinating campaigns to portray the reforms as destabilising. The analysis recommends that mission leads be appointed in Australia's Office of National Intelligence and Japan's newly established National Intelligence Agency, alongside a standing bilateral forum on information integrity producing annual narrative-risk assessments and crisis simulations, positioning counter-disinformation as a structural feature of the alliance rather than an ad hoc response to individual incidents. Source: Australian Strategic Policy Institute (ASPI). Countering Disinformation Could Anchor Australia–Japan Intelligence Cooperation. [online] Published 26 June 2026. Available at: https://www.aspistrategist.org.au/countering-disinformation-could-anchor-australia-japan-intelligence-cooperation/ Top Of Page Chinese Network Launches Hundreds of Fake Accounts to Influence the Next Taiwanese Election A report published by NewsGuard states that a network of 294 coordinated Threads accounts displaying multiple signs of inauthentic coordination, including similar naming conventions, synchronised posting patterns, identical profile content, and repurposed or AI-generated images, has been operating as attractive Asian women seeking relationships with Taiwanese men, with researchers assessing the accounts as positioned to build audiences and credibility ahead of Taiwan's November 2026 local elections. The network shares characteristics with previously identified China-linked influence operations targeting Taiwan, with 40% of accounts following naming patterns associated with a network that previously spread narratives critical of Taiwan's ruling Democratic Progressive Party. A report published by NewsGuard states that account location data, cultural inaccuracies in posts about Taiwan, and posting schedules aligned with standard working hours in China indicate the operators are likely based outside Taiwan. The analysis assesses the accounts as designed to establish relationships, collect audience information, and build online reach before potentially being deployed to amplify coordinated messaging around politically significant events, a well-documented tactic in which networks established as socially benign are repurposed for political influence operations once they have accrued sufficient followers and engagement history to avoid rapid platform detection. Source: NewsGuard Technologies. Chinese Network Launches Hundreds of Fake Dating Accounts to Influence the Next Taiwanese Election. [online] Published 24 June 2026. Available at: https://www.newsguardtech.com/special-reports/chinese-network-launches-hundreds-of-fake-dating-accounts-to-influence-the-next-taiwanese-election/ (newsguardtech.com). Top Of Page [AI Related Articles] Tracking AI-Enabled Misinformation A report published by NewsGuard states that its AI Tracking Center, updated 23 June 2026, has identified 3,749 AI Content Farm news and information websites operating across 16 languages, sites that use AI tools to produce substantial volumes of content without disclosure, presenting synthetic material as human-authored journalism. The center identifies 358 of these sites as directly linked to Storm-1516, a pro-Russian influence operation that creates fabricated content on sites designed to resemble local newspapers in the United States and Europe, targeting audiences unlikely to encounter mainstream fact-checking. A report published by NewsGuard states that an audit of the 10 leading generative AI tools found the rate of generating false claims in response to news prompts has nearly doubled, with AI chatbots now providing false information more than one-third of the time. NewsGuard confirmed specific instances, including an AI-edited image purportedly showing an Iranian missile (the original predating the March 2026 conflict) and images circulating as purported photographs of Venezuelan leader Nicolas Maduro that in fact depicted former Iraqi President Saddam Hussein from December 2003, illustrating the compounding risk created when AI models are trained on or cite content originating from adversarial AI Content Farms. Source: NewsGuard Technologies. Tracking AI-Enabled Misinformation: 3,749 AI Content Farm Sites (and Counting), Plus the Top False Claims Generated by Artificial Intelligence Tools. [online] Last updated 23 June 2026. Available at: https://www.newsguardtech.com/special-reports/ai-tracking-center/ (newsguardtech.com). Top Of Page Disinformation in 2026 Forum Documents How Influence Operations Scale Through AI Enhancement A report published by the Center for Foreign Interference Research states that a 25 June 2026 international security forum analysis revealed that the integration of artificial intelligence tools into influence operation architectures is producing a structural shift in how state-sponsored disinformation campaigns are designed and executed, with AI enabling smaller operational teams to produce higher volumes of contextually tailored content targeting multiple geographic markets simultaneously. The forum documentation identifies this as a departure from earlier volume-over-precision models, with AI enhancement allowing operators to embed narratives within organic public debates rather than relying on identifiable high-volume posting patterns that platform moderation tools are calibrated to detect. A report published by the Center for Foreign Interference Research states that the forum also documented coordinated foreign campaigns deliberately exploiting dormant inter-state conflicts and ethnic tensions across post-Soviet states to sow discord, a tactic that AI enhancement makes more scalable by enabling rapid localisation of destabilising narratives for different linguistic and cultural contexts within the same operational deployment. The forum findings position AI-augmented influence operations as a compounding threat in the run-up to the 2026 U.S. midterm elections and ongoing European electoral cycles, where reduced attribution confidence and increased content volume are simultaneously degrading the effectiveness of platform-level moderation responses. Source: Foreign Interference Research Center. Disinformation in 2026 Forum Documents How Influence Operations Scale Through AI Enhancement. [online] Published 25 June 2026. Available at: https://www.foreigninterference.org/post/disinformation-in-2026-forum-documents-how-influence-operations-scale-through-ai-enhancement (foreigninterference.org). Top Of Page Big Brands Fund AI Slop A report published by NewsGuard's Reality Check states that major brand advertisers including Adobe, Disney, Verizon, and Fox had advertisements running on AI-generated content farm websites publishing fabricated stories about the disappearance of Nancy Guthrie, the 84-year-old mother of Today show co-anchor Savannah Guthrie, sites that produced false claims about FBI breakthroughs, new evidence, and alleged family involvement in the case despite authorities having cleared relatives. The fake articles were engineered to capitalise on public interest in a high-profile missing-person case while generating advertising revenue through programmatic advertising systems that place brand ads on content regardless of veracity. A report published by NewsGuard's Reality Check states that traffic to the fabricated stories was amplified through a network of apparently connected Facebook pages that post fake breaking-news graphics directing users to AI-generated sites, and that the operation may be operated from Vietnam, though ownership could not be confirmed. NewsGuard identifies the case as illustrating a systemic business model in which AI content farms produce fabricated or misleading stories about high-profile topics to attract clicks and monetise audience attention through advertising, a model that is financially self-sustaining as long as programmatic ad systems route advertising budgets to content based on traffic volume rather than editorial standards. Source: NewsGuard Reality Check. Big Brands Fund AI Slop. [online] Published 22 June 2026. Available at: https://www.newsguardrealitycheck.com/p/big-brands-fund-ai-slop (newsguardrealitycheck.com). Top Of Page Africa Is Not Ready for Malicious AI Swarms on Its Prime News Source An analysis published by Business Day states that Africa's information environment faces growing risks from AI-enabled disinformation distributed through audio content on radio and encrypted messaging platforms, creating a significant gap in existing defences against emerging threats because global counter-disinformation efforts have largely focused on social media and text-based content while radio remains the primary news source for many Africans, particularly in rural communities, among women, and among people with limited digital access. Synthetic audio can exploit trusted communication channels to spread false narratives, influence elections, and create the illusion of public consensus in environments where voice-cloning technology is increasingly accessible. A report published by Business Day states that recent elections in Nigeria and Ghana demonstrated how misleading audio content circulates rapidly through WhatsApp and other peer-to-peer networks, bypassing traditional moderation and fact-checking mechanisms, and that investment in audio deepfake detection systems designed for African languages and acoustic environments remains limited, with voice-cloning models trained on limited African-language data harder to detect using standard tools built for English, French, and Mandarin. The analysis identifies the growing accessibility of voice-cloning technology as increasing the risk that political figures, community leaders, and public officials can be impersonated to manipulate public opinion, calling for governments, election bodies, media organisations, and fact-checking groups across Africa to strengthen resilience against audio-based disinformation as a priority. Source: Business Day. BIG READ | Africa Is Not Ready for ‘Malicious AI Swarms’ on Its Prime News Source. [online] Published 23 June 2026. Available at: https://www.businessday.co.za/lifestyle/2026-06-23-africas-dominant-news-source-is-underprepared-for-ai-disinformation Top Of Page [General Reports] Trust in Media 2026 A survey published by YouGov states that trust declined for most of the 48 news outlets measured in its 2026 Trust in Media survey, with only a handful making modest gains within the margin of error. The survey identifies sharply defined partisan divides as the dominant structural feature of American media trust, a pattern that limits the capacity of any single outlet or platform to serve as a shared factual reference point across the electorate, creating conditions that state and non-state disinformation actors systematically exploit to widen existing societal fractures. A survey published by YouGov states that 70% of respondents expressed concern that deepfakes would be used to spread disinformation, reflecting a broad awareness of synthetic media threats even as institutional mechanisms for labelling or detecting AI-generated content remain underdeveloped. The survey situates declining media trust within a broader pattern of information environment fragmentation in which generational differences in news consumption habits, platform preferences, and source authority create structurally separate information ecosystems, a condition that disinformation research identifies as increasing vulnerability to targeted influence operations by reducing the shared factual baseline needed to evaluate and reject false narratives collectively. Source: YouGov. Trust in Media 2026: Which News Sources Americans Use and Trust. [online] Published 29 June 2026. Available at: https://yougov.com/en-us/articles/55045-trust-in-media-2026-which-news-sources-americans-use-and-trust (yougov.com). Top Of Page Longtime Exxon Legacy of Climate Denial and Misinformation An article published by The Conversation states that former ExxonMobil CEO Lee Raymond, who died on June 9th 2026, at age 87, left a consequential legacy of spreading doubt about climate change despite his own company's internal scientists having produced some of the most accurate early models of human-caused global warming. Over 80% of Exxon's paid editorial-style advertisements during Raymond's tenure specifically promoted uncertainty and doubt about climate science, and Raymond's 1997 address to the World Petroleum Congress explicitly denied that the world was warming, denied the fossil fuel industry's causal role, and challenged the scientific consensus at a critical juncture in international climate policy formation. An article published by The Conversation states that under Raymond's leadership, Exxon directed millions of dollars to organisations promoting climate denial, establishing a pattern of corporate disinformation that continues to shape public discourse and policy contestation today. The analysis identifies a broad range of persistent narratives used to cast doubt on climate change or its causes, including claims that warming is primarily driven by natural factors, scepticism about links between emissions and extreme weather, and criticism of proposed solutions, and argues that inoculation strategies, critical thinking education, and prebunking are among the most evidence-supported tools for building public resilience to this form of corporate-origin disinformation. Source: The Conversation. Longtime Exxon CEO Lee Raymond’s Legacy of Climate Denial and Misinformation Lives On – A Psychologist Offers Ways to Counter It. [online] Published 22 June 2026. Available at: https://theconversation.com/longtime-exxon-ceo-lee-raymonds-legacy-of-climate-denial-and-misinformation-lives-on-a-psychologist-offers-ways-to-counter-it-285667 Top Of Page BLF Propaganda Efforts Under Akhtar Nadeem's Leadership A report published by the Jamestown Foundation profiled Akhtar Nadeem, also known as Gwahram Baloch, a senior figure and spokesperson for the Balochistan Liberation Front, as part of a broader analysis of how educated and middle-class activists have assumed more prominent leadership roles within the Baloch insurgency. Under Akhtar Nadeem's leadership, the organisation has expanded its propaganda efforts through the publications 'Ispar' and 'Sarmachar,' video content, multilingual messaging, and increasingly structured communication strategies addressing ideological themes, organisational developments, and the use of artificial intelligence in combat operations. A report published by the Jamestown Foundation states that the BLF's expanded media operations reflect a deliberate effort to modernise the organisation's outreach, strengthen its narrative position, and maintain relevance alongside its armed activities, following a strategic communication model in which insurgent groups use professional-grade media production to recruit internationally, shape foreign press coverage, and contest the Pakistani state's information environment. The profiling of Akhtar Nadeem illustrates a pattern identified across multiple insurgent movements in which the combination of educated leadership and sophisticated information operations produces a more durable and harder-to-isolate influence infrastructure than purely tactical communication approaches. Source: The Jamestown Foundation. Briefs Archive. [online] Available at: https://jamestown.org/briefs/ Top Of Page Disinformation in the Western Balkans A study published by the British Council states that young people in the Western Balkans often judge the credibility of information based on who shared it, familiarity with the source, and 'official-looking' signals rather than through detailed verification, reflecting a context in which checking information requires significant time and effort, leading many to rely on trusted friends, family members, influencers, or quick credibility cues, especially when confronted with large volumes of content. Researchers observed that sharing content does not always reflect genuine belief, with young people frequently sharing information for humour, social connection, or group belonging even when uncertain of its accuracy. A study published by the British Council states that information overload is creating confusion, anxiety, and increasing distrust in the Western Balkans information environment, with some participants reporting it has become increasingly difficult to determine what is true, and that the growing presence of AI-generated and manipulated content is further weakening traditional authenticity signals and increasing reliance on source identity and reputation. The research recommends improving media and information literacy, helping users recognise common credibility cues, supporting trustworthy journalism and fact-checking initiatives, and increasing platform transparency and accountability, framing youth information resilience as a structural requirement for democratic health in a region with significant vulnerability to both domestic and externally driven disinformation. Source: British Council. Next Generation What We Know: Mis/disinformation in the Western Balkans. [online] Published June 2026. Available at: https://www.britishcouncil.org/research-insight/next-generation-wwk-rfp-western-balkans Top Of Page Disinformation Elicits Learning Biases A study published by eLife states that an assessment of how people learn and update their beliefs when exposed to potentially false information found that while individuals generally learned more from credible sources, consistent with rational decision-making principles, they also showed important biases when confronted with unreliable information, including continuing to learn from sources known to be unreliable rather than ignoring them entirely. The study also found that exposure to misleading information increased reliance on trusted sources, leading participants to place greater weight on credible feedback than they otherwise would. A study published by eLife states that the presence of unreliable information strengthened a positivity bias, making people more likely to accept positive feedback while discounting negative feedback, and that this pattern suggests disinformation affects not only what people believe but also how they process and learn from subsequent information. By exploiting existing cognitive biases, including cognitive load effects from the effort of filtering non-credible sources, positivity bias, and motivated cognition, misleading information can alter decision-making processes even when people are consciously aware that some sources are untrustworthy, with significant implications for the design of counter-disinformation interventions that must address not just belief content but underlying learning mechanisms. Source: eLife. [Article 106073]. [online] Published 2026. Available at: https://elifesciences.org/articles/106073 (elifesciences.org). Top Of Page [Appendix - Frameworks to Counter Disinformation] NewsGuard Launches First AI Chatbot Built to Deliver Trusted Journalism An announcement published by NewsGuard states that the company launched 'NewsGuard AI' on June 25th, 2026, the first AI chatbot sourcing responses exclusively from 12,000 news and information websites whose editorial processes have been evaluated against nine apolitical journalistic standards. The system incorporates a guardrail trained on 64,000 documented false claims to suppress misinformation and is built on a revenue-sharing model in which publishers receive 50% of subscription fees generated from use of their content, positioning the platform as both a quality information tool and a mechanism to fund journalism from trusted sources. An announcement published by NewsGuard states that the chatbot is designed as a direct architectural response to the AI Content Farm ecosystem the company has simultaneously been cataloguing, in which 3,749 AI-generated content farms pollute the training data and citation pools that standard AI tools draw from. By restricting sourcing to verified publishers and explicitly excluding unreliable AI-generated content, NewsGuard AI represents a structural counter-model to the compounding feedback loop between adversarial content farms and AI hallucination that standard retrieval-augmented generation systems are currently unable to break. Source: NewsGuard Technologies. NewsGuard Launches First AI Chatbot Built to Deliver Trusted Journalism Only from Reliable News Websites. [online] Published 24 June 2026. Available at: https://www.newsguardtech.com/press/newsguard-launches-first-ai-chatbot-built-to-deliver-trusted-journalism-only-from-reliable-news-websites/ (newsguardtech.com). Top Of Page An Intelligence-Led Mission Approach for Australia-Japan Cooperation A report published by ASPI states that a new report for the Australia-Japan security relationship proposes that counter-disinformation be elevated into a standing intelligence mission co-led by Australia's Office of National Intelligence and Japan's newly established National Intelligence Agency, moving beyond ad hoc responses to individual influence operations toward a structural bilateral framework for countering Chinese and Russian state-linked disinformation targeting both countries and their shared strategic interests. The report identifies both Australia and Japan as sustained targets of state-linked information operations designed to exploit historical grievances, domestic political divisions, and alliance anxieties. A report published by ASPI states that the proposed Australia-Japan counter-disinformation framework would include an annual bilateral narrative-risk assessment identifying the most significant information operations threatening alliance cohesion, as well as crisis simulation exercises testing institutional responses to coordinated disinformation events, providing shared operational preparedness infrastructure that neither country currently has in place for the information domain. The report situates the recommendation within a documented escalation of Chinese disinformation operations against Japan since Prime Minister Takaichi's election in October 2025, with Beijing deploying overt state media channels, influencer networks, and inauthentic accounts in a campaign ASPI assesses as part of a broader Chinese strategy to contest Japan's role as a U.S. defence and security partner in the Indo-Pacific. Source: Australian Strategic Policy Institute (ASPI). From Common Threats to Narrative Defence. [online] Published June 2026. Available at: https://www.aspi.org.au/report/from-common-threats-to-narrative-defence Top Of Page Evaluating Mexico's New Cybersecurity Plan An analysis published by Recorded Future states that Mexico has unveiled a National Cybersecurity Plan to strengthen the country's cyber resilience and address threats including ransomware, disinformation, hacktivism, and state-sponsored cyber activity, following a series of cyber incidents affecting government institutions and critical sectors. Ransomware is identified as one of the most significant threats facing Mexican organisations, particularly in the government, healthcare, and financial sectors, and the 2026 FIFA World Cup co-hosted by Mexico is expected to increase cyber risks by creating a target-rich environment for ransomware groups, hacktivists, fraud actors, and disinformation networks. A report published by Recorded Future states that disinformation networks represent a specific risk category in Mexico's cybersecurity landscape, with foreign and domestic actors potentially exploiting major events to spread fabricated narratives that can undermine institutional trust and complicate emergency response. The analysis recommends adopting international cybersecurity standards, improving threat intelligence capabilities, conducting cyber incident exercises, strengthening public awareness and cyber hygiene, and deepening cooperation with international partners, particularly the United States, as Mexico implements new legislation and regulatory frameworks in advance of the FIFA World Cup and the October 2026 electoral period. Source: Recorded Future Insikt Group. Evaluating Mexico's New Cybersecurity Plan. [online] Published 25 June 2026. Available at: https://www.recordedfuture.com/research/mexico-new-cybersecurity-plan-evaluation Top Of Page The Opposite of America's AI Problem Is Happening in Brazil An article published by Anchor Change states that Brazil is entering its October 2026 elections with one of the world's most detailed regulatory frameworks for AI and online political content, including a ban on deepfakes in campaign materials, mandatory labelling of AI-generated content, restrictions on AI systems recommending or ranking candidates, and a blackout period for AI-altered content before voting. Brazil's electoral court has also created a permanent commission on AI in elections and established a 90-day deadline to build a national catalogue of enforcement tools, with a recent study identifying 18 AI-generated political profiles active in Brazil between January 2025 and April 2026, most of which did not disclose their AI nature. An article published by Anchor Change states that uncertainty around how some rules should be interpreted, particularly restrictions on ranking political candidates, has created challenges for AI companies, with some platforms potentially choosing to limit or suspend political AI features rather than risk penalties, raising concerns about reduced access to information during the election period. The analysis situates Brazil's approach within more than a decade of efforts to address online harms, election integrity, and platform accountability, identifying a growing tension between efforts to limit misleading or manipulated content and concerns that overly restrictive or unclear rules could discourage platforms from providing political information altogether, a tension likely to become a reference point for other democracies developing AI election governance frameworks. Source: Anchor Change. The Opposite of America’s AI Problem. [online] Published 25 June 2026. Available at: https://anchorchange.substack.com/p/the-opposite-of-americas-ai-problem (anchorchange.substack.com). Top Of Page Cate Blanchett's Free Tool Helps Protect Identity from Being Deepfaked An article published by CyberNews states that Australian actress Cate Blanchett introduced the Human Consent Registry at the European Parliament on June 24th 2026, a free tool that allows individuals to record whether AI systems may use their name, image, voice, and other personal attributes, or to define consent terms for specific uses, providing a practical mechanism for the growing demand for individual control over AI-generated representations in an environment where unauthorised deepfakes and synthetic likenesses have become pervasive. The platform is designed to be accessible to both individuals and third parties such as agents and managers, and is expected to expand to enable protection of artworks, characters, and brands. A report published by CyberNews states that the Human Consent Registry reflects the convergence of celebrity advocacy, legislative momentum, and public demand for AI identity protections, with governments and regulators in the European Union, Australia, Japan, and the United States increasingly responding to the harm associated with nonconsensual AI-generated content. The initiative addresses the intersection between individual consent rights and information integrity, while the registry's primary function is identity protection rather than disinformation countermeasures; the broader ecosystem of nonconsensual AI-generated representations creates risks for democratic discourse when synthetic media depicting real individuals is used to fabricate statements, manipulate public opinion, or undermine institutional trust. Source: Cybernews. Cate Blanchett Joins the Fight Against Deepfakes. [online] Published 25 June 2026. Available at: https://cybernews.com/ai-news/cate-blanchett-ai/ (cybernews.com). Top Of Page Youth Facing Disinformation An announcement published by the Council of Europe states that Monaco has launched the 'Youth Facing Disinformation: Why Journalists Matter' initiative as part of its 2026 Presidency of the Committee of Ministers, under the broader 'Journalists Matter' campaign for the safety and role of journalists in democratic societies. The programme aims to strengthen media and information literacy among young Europeans navigating an information environment where social media and AI tools blur the distinction between reliable information and misleading content, including through conferences, workshops, debates, and an audiovisual awareness campaign designed to engage young audiences on information overload, conspiracy theories, and disinformation. An announcement published by the Council of Europe states that a major conference in Strasbourg in November 2026 will bring together youth participants, journalists, experts, media organisations, and social media stakeholders to discuss challenges related to reliable information, and will launch year-long youth-led working groups focused on practical projects supporting quality journalism and strengthening resilience against disinformation. The programme includes a grants programme awarding up to four projects of EUR 5,000 each for youth-led initiatives addressing disinformation, media literacy, journalists' safety, and freedom of expression, positioning youth participation not merely as a communications target but as an active structural contributor to the development of information integrity solutions. Source: Council of Europe. Youth Facing Disinformation – Why Journalists Matter. [online] Published June 2026. Available at: https://www.coe.int/en/web/freedom-expression/youth-facing-disinformation-why-journalists-matter Top Of Page [CRC Glossary] The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult. To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence. As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website. Top Of Page
.png)









