Search CRC
Search this site
198 results found with an empty search
- Cyber based influence campaigns 13th – 19th July 2026 Report
[Introduction] Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW). Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc. During the 13th to the 19th July 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities. [Contents] [Introduction] [Report Highlights] [Report Summary] [State Actors] Russia EU Sanctions Expose Funding Mechanism Behind Pro-Russian Influencer Russia's New Decentralized Propaganda Infrastructure NATO Condemns Russia's Persistent Malicious Cyber Activities Targeting Allies Ukraine Despite Ukraine's Victories, False Narratives About The War Persist One Fake Photo Let Russian Propaganda Cast Doubt on the Kyiv Lavra Strike China Chinese Operation Disrupts Anti-CCP Events in the US and Europe Iran Iran's Faked Military Triumphs Anatomy of an Iran-Aligned Influence Network on X War in Gaza Digital Campaign Debunks Israel's Narrative About Gaza Ceasefire [AI Related Articles] xAI Sues Grok User Who Generated Estimated 3 Million Sexualized AI Images The Problem AI Content Moderation Cannot Solve YouTube Wiped 35 Million Subscribers Over AI Slop [General Reports] Sudden Death, Sudden Conspiracies 380 False Election Claims and Counting A Voter Guide to Trump's Election Claims State Officials, Election Experts Pan Trump Speech [Appendix - Frameworks to Counter Disinformation] A Year of Innovations in Counter-Disinformation Tooling France Plans to Triple Penalties for AI-Driven Election Disinformation AI Content Labelling Enforcement Begins in 24 Days [CRC Glossary] [ Report Highlights] NATO issued a formal condemnation on July 13th, 2026, of Russia's persistent malicious cyber activities targeting member states and partners, coinciding with EU sanctions on entities supporting information manipulation, signalling a coordinated Western escalatory response to Russian hybrid operations. The Jamestown Foundation exposed the dual-funding mechanism behind pro-Russian influencer Alexandra Jost: RT's parent TV-Novosti paid approximately EUR 1,840 monthly while the Kremlin-linked Presidential Foundation for Cultural Initiatives channelled additional grants, demonstrating the systematic financial architecture behind Moscow's English-language information operations. Graphika documented Chinese state-linked operation Spamouflage deploying a novel tactic on July 13th, 2026, distributing manipulated event flyers to disrupt anti-CCP gatherings in the US and Europe organised by Safeguard Defenders and pro-Tibet and Uyghur groups, marking an escalation toward direct transnational repression via coordinated inauthentic behaviour. NewsGuard's Reality Check confirmed that pro-Iran accounts posted an AI-generated video falsely depicting missiles striking a US Navy aircraft carrier, with multiple visual inconsistencies exposing the content as synthetically manufactured, a documented escalation in Iran's use of generative AI for false military triumph claims. xAI filed a lawsuit against a Grok user who generated an estimated 3 million sexualized AI images, including 23,000 minors, during 11 days, even as the Center for Countering Digital Hate documented the scale of the platform's systemic guardrail failures. False war narratives about Ukraine proliferated across algorithm-assisted echo chambers, with Forbes documenting how far-left and far-right voices converge on pro-Russian defeat narratives despite battlefield evidence to the contrary, and the Kyiv Independent revealing how a single AI-flagged image enabled Kremlin propagandists to weaponise Meta's own moderation system against accurate reporting. The EU DisinfoLab newsletter documented two new Russian FIMI infrastructure operations, Roska Bridge (exploiting Mastodon and Bluesky cross-posting automation to evade moderation) and Hahaganda (weaponised mockery across European networks), alongside France's proposal to triple criminal penalties for election disinformation and Canada's introduction of the Safe Social Media Act. A coordinated counter-narrative campaign launched July 16th 2026 under '#They Lied to You' challenged the international media framing of a Gaza ceasefire, with participants including journalists and civil defence workers documenting that Israeli military operations had expanded to 70% of Gaza's territory, exceeding the 53% stipulated in the ceasefire agreement. [ Report Summary] The EU sanctioned US citizen Alexandra Jost for disseminating disinformation about Russia's invasion of Ukraine, revealing a dual-funding structure from RT's parent company and Kremlin-linked cultural foundations. EU DisinfoLab documented two new Russian information manipulation operations exploiting decentralised social platforms and weaponised humour, alongside an EU Court ruling that RT sanctions apply to free streaming websites. The North Atlantic Council issued a formal statement condemning Russia's sustained cyber operations against NATO members and partners, committing to enhanced collective cyber defence and integrated countermeasures. A Forbes analysis documents how far-left and far-right voices converge on false narratives predicting Ukrainian defeat, serving Russian information warfare purposes through algorithm-assisted echo chambers despite contradictory battlefield evidence. Russian propagandists exploited a potentially AI-generated image of the burning Dormition Cathedral to construct a false staged-attack narrative, temporarily causing Meta to apply false-information labels to accurate reporting. Graphika documented Spamouflage deploying a novel tactic of distributing manipulated event flyers to disrupt anti-Communist Party gatherings organised by civil society groups in the US and Europe. Pro-Iran accounts posted AI-generated video falsely depicting missiles striking a US Navy aircraft carrier, with visual inconsistencies confirming the content as synthetically manufactured disinformation. ShadowGraph Intelligence documented a 21-account coordinated inauthentic behaviour network generating 48.6 million engagements and an estimated 5-10 billion views over six months, deploying fabricated quote overlays on video to spread pro-Iran, anti-US, and anti-Israel narratives on X. A coordinated counter-narrative campaign using '#They Lied to You' challenged international media framing of a Gaza ceasefire, with participants documenting that Israeli operations had expanded to 70% of Gaza's territory. xAI filed a lawsuit against a user who weaponised Grok to generate an estimated 3 million sexualized deepfake images, including 23,000 of minors, as the platform faces multiple lawsuits over systemic guardrail failures. A Rest of World analysis argues that AI content moderation fails to protect women from image-based abuse because it cannot account for consent or evaluate cultural context, calling for consent-based human moderation frameworks. YouTube's enforcement of its renamed 'inauthentic content' policy wiped 35 million subscribers from AI-generated channels, establishing a new standard requiring genuine human editorial judgment for content to qualify for distribution. NewsGuard documented how baseless conspiracy theories about Senator Lindsey Graham's death from cardiovascular disease spread immediately on social media, including false claims he was killed by Russian missiles. NewsGuard's tracking of false election claims reached 380 as President Trump fired two Democratic members of the US Election Assistance Commission, raising concerns about systematic dismantling of election integrity infrastructure. NewsGuard produced a voter guide fact-checking Trump's election security claims, finding that documents cited in a primetime speech did not support the assertions made about Chinese interference and noncitizen voter registration. State election officials and security experts dismissed Trump's primetime election fraud address as unsupported by evidence, documenting how federal dismantling of election security infrastructure compounds the threat from foreign influence operations. CheckFirst documented a year of advances in counter-disinformation infrastructure, including the IMS attribution framework, the Tutki OSINT training platform, and the CheckFirst Import Connector for monitoring the Pravda network. French Prime Minister Lecornu announced legislation to triple criminal penalties for disseminating false information during electoral periods, establishing a permanent public information commission and extending emergency judicial removal procedures. The EU AI Office confirmed the Code of Practice on AI-Generated Content as an adequate compliance mechanism under Article 50 of the EU AI Act, with binding deepfake labelling and disclosure obligations becoming enforceable on 2 August 2026. [State Actors] Russia EU Sanctions Expose Funding Mechanism Behind Pro-Russian Influencer An article published by The Jamestown Foundation states that the European Union sanctioned Alexandra Jost, a US citizen based in Russia operating the 'Sasha Meets Russia' social media account, for disseminating disinformation justifying Russia's invasion of Ukraine, with the sanctions revealing a dual funding structure: approximately EUR 1,840 monthly from TV-Novosti (RT's parent company) and grants channelled through the Russian Presidential Foundation for Cultural Initiatives via public relations agency Limitless. Jost's effectiveness as a Kremlin propaganda vector derives from her native English-speaking status and casual content format, which appear less overtly propagandistic than state media, while her rebuilt X account has accumulated 67,400 followers since April 2025, with individual posts generating between 20,000 and 1.9 million views. An article published by The Jamestown Foundation states that while EU sanctions increase operational costs for pro-Russian influencers, platform access rather than legal designation ultimately determines reach, as demonstrated by Jost's capacity to rebuild her following after earlier deplatforming. The analysis reveals that Russia allocated EUR 420 million in additional state media funding and EUR 16 million to pro-war cultural projects in 2023 alone, signalling an escalating Kremlin investment in English-language information operations designed to justify territorial occupation and delegitimise Western support for Ukraine through apparently organic civilian voices. Source: The Jamestown Foundation. EU Sanctions Expose Funding Mechanism Behind Pro-Russian Influencer. [online] Published 10 July 2026. Available at: https://jamestown.org/eu-sanctions-expose-funding-mechanism-behind-pro-russian-influencer/ Top Of Page Russia's New Decentralized Propaganda Infrastructure A newsletter published by EU DisinfoLab states that Russia's Foreign Information Manipulation and Interference operations have deployed two new sophisticated technical evasion tactics: 'Roska Bridge' weaponises decentralised social platforms Mastodon and Bluesky by exploiting the Brid.gy cross-posting service's functionality to automatically distribute pro-Kremlin propaganda while circumventing moderation, and 'Hahaganda' deploys coordinated psychological operations using weaponised mockery across European networks to reinforce disinformation narratives through humour. The EU Court of Justice simultaneously clarified that sanctions against Russia Today apply to free websites and streaming services, yet RT has already evaded these restrictions by establishing new accounts on X. A newsletter published by EU DisinfoLab states that democratic governments are strengthening enforcement responses to these operations: France's Prime Minister proposed legislation tripling criminal penalties for election disinformation and expanding expedited judicial content takedown procedures, Canada introduced the Safe Social Media Act (Bill C-34) establishing a Digital Safety Commission with powers to mandate deepfake labelling and enforce platform accountability, and the UK government implemented institutional boycotts of X following violent unrest. Research cited in the newsletter found that Meta's network contained over 634,000 fraudulent advertisements generating billions of impressions through media brand impersonation, while X's Community Notes mechanism was found to systematically under-moderate election disinformation. Source: Disinfo.eu (EU DisinfoLab). Disinfo Update 15/07/2026. [online] Published 15 July 2026. Available at: https://www.disinfo.eu/disinfo-update-15-07-2026/ Top Of Page NATO Condemns Russia's Persistent Malicious Cyber Activities Targeting Allies A statement published by NATO states that the North Atlantic Council formally condemned Russia's persistent malicious cyber activities targeting NATO member states, partners, and critical national infrastructure, noting that Russian cyber actors exploit state-sponsored infrastructure to conduct operations constituting a threat to Allied security. The statement references coordinated international responses including UK and EU sanctions against individuals and entities supporting Russian cyber operations, and commits NATO to employing its full operational spectrum to deter, defend against, and counter cyber threats. A statement published by NATO states that the alliance's collective cyber defence posture will be enhanced and cyber capabilities integrated across NATO operations in response to Russia's sustained targeting of Allied governments, infrastructure, and information systems. The condemnation, issued on the same date that the EU imposed sanctions on entities responsible for information manipulation activities, reflects a coordinated Western response positioning Russian cyber operations and information warfare as interconnected hybrid threats requiring aligned multilateral countermeasures. Source: NATO. Statement of Condemnation by the North Atlantic Council of Russia’s Malicious Cyber Activities. [online] Published 13 July 2026. Available at: https://www.nato.int/en/about-us/official-texts-and-resources/official-texts/2026/07/13/statement-of-condemnation-by-the-north-atlantic-council-of-russias-malicious-cyber-activities Top Of Page Ukraine Despite Ukraine's Victories, False Narratives About the War Persist An article published by Forbes states that false narratives predicting Ukrainian defeat persist across the political spectrum despite documented battlefield successes including Ukrainian drone campaigns that have degraded Russian oil refining capacity to 65% of seasonal consumption levels. Influential figures including academics, journalists, and former diplomats continue to argue that 'NATO expansionism led to the Russian invasion' or that Ukraine faces inevitable defeat, with these narratives converging across far-left and far-right perspectives despite their ideological differences. An article published by Forbes states that these convergent defeat narratives operate through 'algorithm-assisted echo chambers' that amplify pro-Russian framing to mainstream audiences, with the arguments lacking evidentiary support yet serving Russian information warfare purposes by normalising surrender as the only rational outcome. The analysis notes that Ukraine has successfully resisted what was described as the world's second-strongest military for over four years, a record that directly contradicts the defeat narratives still circulating in influential media and academic spaces, indicating these narratives function as sustained disinformation rather than evidence-based strategic assessment. Source: Forbes. Despite Ukraine’s Victories, False Narratives About the War Persist. [online] Published 16 July 2026. Available at: https://www.forbes.com/sites/marktemnycky/2026/07/16/despite-ukraines-victories-false-narratives-about-the-war-persist/ Top Of Page One Fake Photo Let Russian Propaganda Cast Doubt on the Kyiv Lavra Strike An investigation published by Kyiv Independent states that Russian propaganda platforms exploited a photograph of the Dormition Cathedral burning during Russia's 15 June 2026 missile strike, an image OpenAI's detection tools flagged as containing SynthID watermarks suggesting AI generation or editing, to construct a false narrative that Ukrainian photographers had staged the attack by setting up filming positions in advance. Pro-Kremlin accounts circulated the cathedral image alongside two AI-generated photographs falsely depicting journalists preparing the scene, causing Meta to initially restrict posts about the attack due to a technical error linking legitimate reporting to an AFP fact-check examining the AI-generated imagery. An investigation published by Kyiv Independent states that StopFake.org's Olga Yurkova explained the standard propaganda methodology: 'propagandists first establish a narrative and then create visual evidence' to support predetermined false conclusions, with AI-generated content enabling rapid production of fabricated visual 'proof' during critical moments when information environments are most contested. Meta subsequently removed the false-information labels after acknowledging the algorithmic error, a sequence that demonstrates how AI-generated disinformation can briefly weaponise platform safety systems against accurate reporting, creating a window of amplified confusion precisely when factual information about attacks on civilian and cultural infrastructure is most needed. Source: The Kyiv Independent. How One Fake Photo Let Russian Propaganda Cast Doubt on Kyiv Lavra Strike. [online] Published 7 July 2026. Available at: https://kyivindependent.com/how-one-fake-photo-let-russian-propaganda-cast-doubt-on-kyiv-lavra-strike/ Top Of Page China Chinese Operation Disrupts Anti-CCP Events in the US and Europe A report published by Graphika states that the Chinese state-linked influence operation Spamouflage deployed a novel disruption tactic in mid-2026, disseminating manipulated versions of event flyers across Facebook and X to interfere with anti-Communist Party of China events organised by Safeguard Defenders and pro-Tibet and Uyghur civil society groups in the US and Europe. The operation used inauthentic accounts to distribute the manipulated materials, representing the first documented instance of Spamouflage using this specific method to hinder event participation and obstruct civil society gatherings critical of Chinese government policies. A report published by Graphika states that this shift toward event disruption reflects an escalation in transnational repression tactics, as Chinese state actors move beyond diplomatic pressure and toward direct coordinated interference with diaspora civil society activities on Western soil. Analysts assess this tactic could extend to election interference and other forms of transnational repression, as the manipulation of event flyers, combined with coordinated inauthentic amplification, demonstrates a scalable method for sowing confusion and discouraging participation in events challenging Chinese Communist Party narratives without requiring the operational sophistication of more traditional influence operation infrastructure. Source: Graphika. Save the Date for Spamouflage. [online] Published 13 July 2026. Available at: https://www.graphika.com/reports/save-the-date-for-spamouflage Top Of Page Iran Iran's Faked Military Triumphs A briefing published by NewsGuard states that pro-Iran accounts posted an AI-generated video on multiple social media platforms falsely depicting missiles striking a US Navy aircraft carrier, with multiple visual inconsistencies pointing to the video's inauthenticity, including unnatural explosion dynamics and compositional artefacts characteristic of AI video generation. The fabricated footage circulated widely during a period of elevated US-Iran tensions, consistent with Iran's documented pattern of deploying synthetic media to claim false military triumphs and project deterrence capability beyond what its actual military operations have achieved. A briefing published by NewsGuard states that the dissemination of fabricated military victory footage reflects a broader Iranian information strategy documented in the 2025-2026 conflict period: IRGC-linked Telegram channels and state media amplify AI-generated imagery depicting false strikes on US military assets to maintain domestic morale and project international deterrence, even as independent verification systematically debunks the claims. The pattern indicates that synthetic media has become a primary instrument of Iranian strategic communication, enabling the regime to manufacture the appearance of military effectiveness in the information environment independently of operational outcomes on the ground. Source: NewsGuard Reality Check. Iran’s Faked Military Triumphs. [online] Published 16 July 2026. Available at: https://www.newsguardrealitycheck.com/p/irans-faked-military-triumphs Top Of Page Anatomy of an Iran-Aligned Influence Network on X A report published by ShadowGraph Intelligence states that a 21-account coordinated inauthentic behaviour network aligned with Iranian interests operated on X between 18 January and 18 July 2026, generating approximately 137,000 posts drawing 48.6 million engagements, with reverse-engineered impression modelling estimating 5 to 10 billion total views, equivalent to USD 30 to 65 million in earned media value at standard US news advertising rates. The three anchor accounts, @GBC_Press, @IRGC_Press, and @IRGC_Global, were batch-created within 40 minutes on 9 April 2026, with 15 of the 21 accounts created during March and April 2026, all carrying purchased blue verification, generic press branding, and identical 'West Asia' location designations constituting a shared manufactured fingerprint. A report published by ShadowGraph Intelligence states that the network's primary fabrication method involved overlaying manufactured quotes onto unrelated video footage: the flagship example saw @GBC_Press falsely attribute to Israeli Prime Minister Netanyahu a threat of 'sudden power outages, and train accidents' against Spain, a quote absent from the attached video, achieving 4.3 million views, while @IRGC_Global falsely attributed a nuclear threat statement to North Korean leader Kim Jong-Un drawing 4.4 million views. Author Travis Hawley, a former NSA and US Air Force Intelligence Officer, assessed Iran-alignment at high confidence based on content, branding, and regional placement, while explicitly noting that definitive state attribution would require legal process accessing platform registration records, a distinction that highlights the evidentiary limits of open-source attribution even in high-confidence cases of coordinated inauthentic behaviour. Source: Shadowgraph Intelligence. Iran-Aligned Influence Network on X. [online] Available at: https://shadowgraphintel.com/reports/iran-aligned-influence-network-on-x/ Top Of Page War in Gaza Digital Campaign Debunks Israel's Narrative About Gaza Ceasefire An article published by Middle East Monitor states that activists launched a coordinated social media campaign on July 16th, 2026, using the hashtag '#They Lied to You' in Arabic and English, mobilising journalists, humanitarian workers, children from Gaza, and international supporters to challenge the international media framing that a ceasefire had ended hostilities. Civil Defence spokesperson Mahmoud Basal stated, 'They lied to you when they said there was a ceasefire in Gaza; what kind of ceasefire is this when children are still being killed,' with participants sharing video content and written posts documenting continued deaths, displacement, and destruction. An article published by Middle East Monitor states that the campaign directly challenged official ceasefire claims by presenting ground-level evidence of ongoing Israeli military operations, with the Gaza Health Ministry reporting that ceasefire violations had killed 1,127 Palestinians and wounded 3,643 as of the reporting date. Participants emphasised that Israeli territorial control had expanded to 70% of Gaza's total area, exceeding the 53% stipulated in the ceasefire agreement, using the attention gap created by reduced international media coverage as a vector to reinvigorate global awareness of what the campaign described as a systematic misrepresentation of the conflict's status. Source: Middle East Monitor (MEMO). Digital Campaign Debunks Israel’s Narrative About Gaza Ceasefire. [online] Published 19 July 2026. Available at: https://www.middleeastmonitor.com/20260719-digital-campaign-debunks-israels-narrative-about-gaza-ceasefire/ Top Of Page [AI Related Articles] xAI Sues Grok User Who Generated Estimated 3 Million Sexualized AI Images An article published by Futurism states that xAI filed a lawsuit against Terry Wayne Harwood, a 67-year-old South Carolina resident, alleging he used Grok across multiple accounts to generate nonconsensual sexual deepfakes of minors and women by circumventing safety guardrails through modified prompts in a 'calculated scheme to weaponize Plaintiff's tool for criminal ends.' The lawsuit occurs within a broader crisis: the Center for Countering Digital Hate documented that for 11 days, Grok generated an estimated 3 million sexualized images, including 23,000 of children, with multiple additional lawsuits against xAI pending from Tennessee teenagers and other victims. An article published by Futurism states that while xAI reports suspending 52,222 accounts and making 73,604 reports to the National Center for Missing and Exploited Children in 2026, litigation against individual users does not address the underlying guardrail failures that enabled abuse at this scale, with law enforcement and child safety experts reporting that AI-generated child sexual abuse material has created overwhelming investigative challenges. The case illustrates a structural tension in AI enforcement: platform liability claims focus on user misuse while systemic model-level vulnerabilities that enabled mass generation of illegal content remain the proximate cause, a distinction with significant implications for both regulatory frameworks and platform accountability standards. Source: Futurism. Elon Musk’s xAI Sues Grok User Over Deepfakes. [online] Published 15 July 2026. Available at: https://futurism.com/artificial-intelligence/elon-musk-xai-sues-grok-user-deepfakes Top Of Page The Problem AI Content Moderation Cannot Solve An article published by Rest of World states that Meta's launch of Muse Image, an AI tool enabling manipulation of public Instagram users' photos without consent, exemplifies a fundamental flaw in automated content moderation: platforms define harmful content through Western-centric definitions focusing solely on explicit sexual content, while research from Chayn in Pakistan and diaspora communities reveals that everyday images including photos without headscarves, wedding videos, and pictures with male classmates are weaponised to damage women's reputations and relationships in ways current policies fail to recognise. Image-based abuse is documented as 'one of the fastest-growing forms of technology-facilitated gender-based violence,' yet AI moderation systems remain blind to the contextual harm of non-explicit images when deployed across different cultural environments. An article published by Rest of World states that the core limitation of AI content moderation is that 'AI cannot account for consent': while automated systems expedite content identification and removal, they cannot evaluate the contextual factors essential for protecting marginalised communities from targeted image-based harassment. The author argues that platforms must shift toward consent-based frameworks requiring trained human moderators capable of understanding cultural context and intent, an approach that would prove more effective across borders and languages than purely algorithmic solutions, and would address not just the content itself but the violation of autonomy inherent in unauthorised image sharing and AI-powered manipulation of individuals' likenesses. Source: Rest of World. The Problem AI Content Moderation Cannot Solve. [online] Published 16 July 2026. Available at: https://restofworld.org/2026/ai-content-moderation-consent-muse/ Top Of Page YouTube Wiped 35 Million Subscribers Over AI Slop An article published by TechTimes states that YouTube renamed its 'repetitious content' policy to 'inauthentic content' in July 2025 to better reflect that mass-produced content has always been ineligible for monetisation, with enforcement accelerating through 2026: the platform permanently terminated 11 channels and wiped content from 5 others in January 2026, erasing a combined 35 million subscribers and an estimated USD 10 million in annual advertising revenue. A Kapwing study of 15,000 trending channels found 278 producing exclusively AI-generated content with a combined 63 billion views and an estimated USD 117 million in annual revenue, illustrating the scale of the content category the enforcement actions are targeting. An article published by TechTimes states that YouTube's VP of Trust and Safety outlined three specific policy buckets determining eligibility for the YouTube Partner Program, with the new framework establishing that content must reflect 'genuine human editorial judgment' to qualify for distribution and monetisation, a standard that directly addresses the use of AI systems to generate high volumes of templated, repetitive content at industrial scale. While YouTube maintains a tool-agnostic stance on AI-assisted creation, the enforcement wave signals that platforms are developing operational frameworks distinguishing between AI tools that enhance human creativity and AI systems that replace human judgment entirely, with significant implications for the broader ecosystem of AI-generated information content. Source: Tech Times. YouTube Wiped 35M Subscribers Over AI Slop: Now It's Judging Your Taste. [online] Published 15 July 2026. Available at: https://www.techtimes.com/articles/320629/20260715/youtube-wiped-35m-subscribers-over-ai-slop-now-its-judging-your-taste.htm Top Of Page [General Reports] Sudden Death, Sudden Conspiracies A briefing published by NewsGuard states that Senator Lindsey Graham's death from a tear in his aorta due to arteriosclerotic cardiovascular disease triggered an immediate wave of baseless conspiracy theories across social media platforms, including false claims that Graham was killed by Russian missiles, a fabricated narrative that spread before official cause of death information was publicly confirmed. The speed and content of the conspiracy narratives demonstrate the established pattern by which sudden deaths of prominent figures generate coordinated disinformation within hours, exploiting the information vacuum before verified reporting reaches mass audiences. A briefing published by NewsGuard states that the Graham death conspiracy cycle illustrates how social media platforms' algorithmic amplification of emotionally resonant content enables false narratives to achieve significant reach before fact-checking responses can counteract them, with platform recommendation systems rewarding engagement-generating claims regardless of their verifiability. The episode is consistent with documented patterns in which sudden-death disinformation serves multiple functions: generating traffic for low-credibility outlets, testing the receptiveness of audiences to specific false narratives, and exploiting public grief to embed conspiratorial frameworks that persist beyond the immediate news cycle. Source: NewsGuard Reality Check. Sudden Death, Sudden Conspiracies. [online] Published 15 July 2026. Available at: https://www.newsguardrealitycheck.com/p/sudden-death-sudden-conspiracies Top Of Page 380 False Election Claims and Counting A briefing published by NewsGuard states that the organisation's tracker of false claims related to US elections reached 380 tracked narratives as President Trump fired two Democratic members of the US Election Assistance Commission on July 9th 2026, an action that raised significant concerns about the integrity of federal election oversight infrastructure. The tracker documents the persistent volume and diversity of false election narratives circulating in the US information environment, spanning claims about ballot integrity, voter fraud, foreign interference, and electoral system security. A briefing published by NewsGuard states that the removal of Election Assistance Commission members, career officials whose role includes certifying voting systems and providing technical assistance to states, represents the latest in a series of actions that election security experts characterize as a systematic dismantling of the federal infrastructure designed to identify and counter both domestic election disinformation and foreign influence operations targeting US elections. The context of 380 tracked false claims circulating simultaneously with institutional changes to election oversight bodies creates a compounding challenge for fact-checkers and election officials attempting to maintain public confidence in electoral processes ahead of the 2026 midterm elections. Source: NewsGuard's Reality Check. 380 False Election Claims and Counting. [online] Published 15 July 2026. Available at: https://www.newsguardrealitycheck.com/p/380-false-election-claims-and-counting Top Of Page A Voter Guide to Trump's Election Claims A briefing published by NewsGuard states that an 18-month federal investigation led by former journalist John Solomon yielded no evidence supporting Trump administration claims that the 2020, 2022, or 2024 elections were compromised by fraud, while the administration's central allegation, that hundreds of thousands of noncitizens were registered across four states, contradicts state audits consistently finding only single- or double-digit numbers of such cases per state. Multiple courts unanimously rejected federal attempts to forcibly obtain state voter data, and state officials across party lines characterised the administration's actions as federal overreach. A briefing published by NewsGuard states that Trump's primetime address on election security rehashed previously debunked claims about alleged Chinese interference in the 2020 election without presenting new evidence, with election security experts including David Becker of the Center for Election Innovation and Research characterising the speech as delivering 'a dud' despite White House promises of a 'bombshell.' The guide documents the pattern of claims alongside expert assessments and official state-level rebuttals, providing a structured counter-narrative resource for voters seeking verified information about election integrity amid an intensifying domestic disinformation environment targeting public confidence in electoral institutions. Source: NewsGuard Reality Check. A Voter Guide to Trump’s Election Claims. [online] Published 17 July 2026. Available at: https://www.newsguardrealitycheck.com/p/a-voter-guide-to-trumps-election Top Of Page State Officials, Election Experts Pan Trump Speech An article published by CyberScoop states that state officials and election security experts uniformly rejected President Trump's July 17th 2026 primetime address on alleged election fraud, with David Becker of the Center for Election Innovation and Research stating 'The White House promised a bombshell and they delivered a dud', an assessment shared by Nevada Democratic Secretary of State Francisco Aguilar who pushed back forcefully against the federal administration's characterisation of state election systems as compromised. An 18-month federal investigation found zero evidence that the 2020, 2022, or 2024 elections were compromised by the fraud categories described in the speech. An article published by CyberScoop states that the Trump administration's removal of all three Election Assistance Commission commissioners and systematic dismantling of federal election security infrastructure, including elimination of CISA's election security initiatives and cessation of state-level threat intelligence sharing, has created structural vulnerabilities that foreign actors are already exploiting through information environment manipulation. Election officials characterised the concurrent actions, spreading unsubstantiated fraud narratives while removing the institutional infrastructure designed to counter actual foreign interference, as compounding threats to electoral integrity that operate through different mechanisms but produce a common outcome: reduced public confidence in the legitimacy of democratic processes. Source: CyberScoop. State Officials, Election Experts Pan Trump Speech: ‘This Is What Desperation Looks Like’. [online] Published 17 July 2026. Available at: https://cyberscoop.com/state-officials-election-experts-pan-trump-voter-fraud-speech-call-it-desperation/ Top Of Page [Appendix - Frameworks to Counter Disinformation] A Year of Innovations in Counter-Disinformation Tooling An article published by CheckFirst states that the organisation adopted the Information Manipulation Set (IMS) framework alongside EU DisinfoLab, Viginum, Cassini, and other partners to standardise documentation, attribution, and response to coordinated disinformation campaigns, an approach that enabled investigations including into Roska Bridge, a pro-Russian IMS exploiting decentralised platforms, and novel OSINT work mapping Russian intelligence units through medal symbols and insignia analysis. The IMS framework represents an advance in the counter-disinformation field's capacity to attribute campaigns to specific actor networks rather than documenting individual incidents in isolation. An article published by CheckFirst states that the organisation also strengthened educational and community counter-disinformation infrastructure through the Tutki specialised OSINT training platform, deployed in Armenian and French contexts to equip journalists and civil society with skills for recognising foreign information manipulation, alongside the launch of the CheckFirst Import Connector on OpenCTI for automated monitoring of the Pravda disinformation network, joining the Internet Watch Foundation, and establishing ObSINT as a Finnish NGO. These operational developments reflect an expanding ecosystem of specialised counter-disinformation organisations building shared infrastructure and technical capacity to monitor, attribute, and respond to information manipulation at the speed required to counter modern automated FIMI operations. Source: CheckFirst. CheckFirst’s 6th Birthday: A Year of Innovations. [online] Published 16 July 2026. Available at: https://checkfirst.network/checkfirsts-6th-birthday-a-year-of-innovations/ Top Of Page France Plans to Triple Penalties for AI-Driven Election Disinformation An article published by The Next Web states that French Prime Minister Sebastien Lecornu announced legislation scheduled for Council of Ministers review in late July 2026 to triple criminal penalties for producing false information content during electoral periods, characterised by Lecornu as a 'sacred' time for democracy, with additional provisions extending emergency judicial content removal procedures to all local elections and establishing a permanent public information commission to alert media, judges, and citizens when electoral interference is detected. The bill builds on France's 2018 disinformation law and responds to concerns about AI-driven manipulation and foreign interference ahead of the presidential campaign. An article published by The Next Web states that critics raise fundamental questions about defining falsity and state authority over political speech, noting that 'vague standards and state-appointed bodies risk chilling legitimate speech, especially during the charged weeks of a campaign,' with France's prior experience of court-constrained content removal orders, including orders requiring removal within one hour that were subsequently limited by constitutional courts, demonstrating that content-regulation statutes frequently encounter judicial limits. The legislation's final wording will determine whether the proposed commission functions as a warning mechanism or becomes an instrument of speech control, a distinction with significant implications for the balance between disinformation countermeasures and press freedom protections that organisations including Reporters Without Borders have flagged as a core tension in European regulatory approaches. Source: The Next Web. France Plans to Triple Penalties for AI-Driven Election Disinformation. [online] Published 9 July 2026. Available at: https://thenextweb.com/news/france-plans-to-triple-penalties-for-ai-driven-election-disinformation Top Of Page AI Content Labelling Enforcement Begins in 24 Days An article published by TechTimes states that the EU AI Act's Article 50 transparency obligations will become enforceable across all 27 member states on 2 August 2026, imposing binding disclosure requirements on chatbots, deepfakes, and AI-generated content constituting the first such binding framework in any G7 jurisdiction, with signatories to the Code of Practice receiving a presumption of regulatory conformity that reduces the evidentiary burden under national market surveillance enforcement. Companies wishing to appear on the initial list of Code of Practice signatories must submit by July 22nd 2026, ahead of the August enforcement date. An article published by TechTimes states that deployers of AI systems generating or manipulating content constituting a deepfake, defined as AI-generated or manipulated material depicting real or realistic people in ways that could appear authentic, must disclose the synthetic origin clearly at first exposure using standardised icons and machine-readable metadata, with non-compliance carrying fines of up to EUR 15 million or 3% of global annual turnover. The Code establishes shared technical standards for watermarking, detection, and labelling across the EU's information ecosystem at a moment when AI-generated content has reached sufficient volume and sophistication, demonstrated by documented deepfake surges during political events in June and July 2026, to constitute a systemic threat requiring binding regulatory frameworks rather than voluntary industry standards. Source: TechTimes. AI Content Labeling Enforcement Begins in 24 Days as EU Clears Compliance Code. [online] Published 9 July 2026. Available at: https://www.techtimes.com/articles/319996/20260709/ai-content-labeling-enforcement-begins-24-days-eu-clears-compliance-code.htm Top Of Page [CRC Glossary] The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult. To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence. As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website. Top Of Page
- Cyber based influence campaigns 6th – 12th July 2026 Report
[Introduction] Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW). Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc. During the 6th to the 12th of July 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities. [Contents] [Introduction] [Report Highlights] [Report Summary] [State Actors] Russia Baltic States Summon Russian Envoys Over False Deportation Claims Russia's Attacks on Ukraine's Cultural Heritage Russia's FSB Launches Disinformation Campaign Ukraine Fake Photo Let Russian Propaganda Cast Doubt on Kyiv Lavra Strike Russia Is Building Fake Ukrainians Iran Regime Supporters and Opposition Share AI-Generated Images Fact-Checkers Exposed the Iranian State's Funeral Fraud [AI Related Articles] Viral AI Fakes Flood Social Media as Iran Mourns Khamenei Over 5,800 Arrests in Global Fraud Bust EU Confirms Code of Practice on AI-Generated Content AI Threats to the 2026 Midterms [General Reports] Member Of Committee Investigating Spyware Hacked with Pegasus Fake Trump Post Says Belgium Is 2 Weeks Away from Developing a Nuclear Bomb The West Can Learn from Ukraine's Success Against Russian Propaganda India Ran Separate Spying Campaigns Against Same Pakistani Police Force [Appendix - Frameworks to Counter Disinformation] Threat of Foreign Influence on U.S. Elections Remains as Federal Defenses Recede FTC First Amendment Fight Continues [CRC Glossary] [ Report Highlights] Russia deployed false deportation narratives against Baltic states, Lithuania, Latvia, and Estonia summoned Russian envoys after Moscow falsely alleged mass deportations of Russian speakers, with Lithuanian intelligence confirming this as a consistent Kremlin tactic for pressuring NATO members. Russia's missile strike on Kyiv Pechersk Lavra has destroyed its core FIMI narrative of Orthodox Church protection, with UNESCO verifying 536 cultural sites destroyed and estimated damage reaching EUR 4 billion direct and EUR 20 billion indirect losses. Iran's state funeral for Ali Khamenei generated a multi-layered disinformation operation: state broadcasters fabricated crowd estimates of up to 40 million, AFP Fact Check identified aerial footage as 99.7% likely AI-generated, and Tehran Municipality coercively mobilised attendance while local governors extracted over USD 570,000 from automobile manufacturers to fund roadside stations. AI-generated synthetic media flooded social media during the Khamenei funeral, exploited simultaneously by pro-regime actors and opposition networks using the same generative tools to manipulate competing narratives, demonstrating AI disinformation is no longer exclusively a top-down state instrument. INTERPOL's Operation First Light 2026 produced the largest coordinated enforcement action against fraud networks in the organisation's history, spanning 97 countries, resulting in 5,811 arrests and USD 293 million intercepted from social engineering scam networks. The European Commission confirmed its Code of Practice on AI-Generated Content as an adequate compliance mechanism under Article 50 of the EU AI Act, with transparency obligations for marking and labelling synthetic media becoming legally binding from 2 August 2026. The Brennan Center documented concurrent escalation of AI-enhanced Chinese, Russian, and Iranian election influence operations alongside systematic dismantlement of US federal election security infrastructure, including elimination of funding, cessation of state-level threat intelligence sharing, and failure to establish the Election Security Group. [ Report Summary] Lithuania, Latvia, and Estonia summoned Russian diplomats to formally reject Kremlin claims that Baltic governments were preparing mass deportations of Russian-speaking residents. Russia's June 2026 missile strike on the Kyiv Pechersk Lavra monastery has fatally undermined Moscow's core propaganda narrative of being the protector of the Orthodox Church. Russia's Federal Security Bureau distributed fabricated archival documents about the 1943 Volyn tragedy in a targeted operation to damage Ukraine-Poland strategic relations. Russian propaganda platforms exploited an image of the burning Dormition Cathedral, flagged as potentially AI-generated, to construct a false narrative that Ukrainian photographers had staged Russia's June 2026 attack on Kyiv Pechersk Lavra. Russian information operations deployed AI-generated synthetic personas posing as Ukrainian soldiers, rabbis, and civilians on TikTok, Facebook, and YouTube to spread narratives of corruption, ethnic exclusion, and military futility. Both pro-regime actors and Iranian opposition networks distributed AI-generated images of Ali Khamenei's state funeral, exploiting the same synthetic media tools to advance opposing political objectives. International fact-checkers documented three categories of Iranian state deception at Khamenei's July 2026 funeral: fabricated crowd size statistics, AI-generated aerial footage, and coercive forced attendance mechanisms. The week of Ali Khamenei's state funeral produced a significant surge of AI-generated video and image fabrications circulating across multiple platforms, with detection tools confirming the synthetic origins of viral content. INTERPOL's Operation First Light 2026, spanning 97 countries, resulted in 5,811 arrests and the interception of USD 293 million in assets from social engineering scams and associated money laundering networks. The European Commission confirmed its Code of Practice on AI-Generated Content as an adequate compliance mechanism under Article 50 of the EU AI Act, establishing voluntary standards for marking and labelling synthetic media ahead of binding legal obligations taking effect in August 2026. A fabricated post mimicking Donald Trump's Truth Social format falsely claimed Belgium was on the verge of nuclear weapons development, originating from an X account and finding no corroboration in any authentic Trump record. Pro-Kremlin networks circulated a doctored photograph depicting drug seizure bags labelled with Zelensky's image across 78 articles and thousands of posts in 13 languages, timed to coincide with the NATO Ankara Summit to undermine Zelensky's diplomatic credibility. An Atlantic Council analysis argues Ukraine's documented successes in countering Russian information operations, including AI-powered multilingual official communications, real-time disinformation dashboards, and media literacy investment, provide a transferable model for NATO allies. The Brennan Center documented concurrent escalation of Chinese, Russian, and Iranian AI-enhanced election influence operations alongside the Trump administration's systematic dismantlement of federal election security infrastructure established since 2016. SentinelOne discovered that Chinese (VANGUARD PANDA) and Indian (DISCOBEAN) state-linked hacking groups independently and simultaneously infiltrated Pakistan's Balochistan Police for over two years, accessing biometric, criminal, and citizen data, each apparently unaware of the other's presence, with China likely motivated by CPEC security concerns and India by the regional rivalry over Baloch separatism. Citizen Lab confirmed that Stelios Kouloglou, a PEGA Committee member investigating spyware abuses, was himself hacked with Pegasus twice during the committee's active drafting periods, the first confirmed such case, raising concerns about breached parliamentary privilege, with attribution unclear beyond overlap with an operator previously linked to targeting exiled Russian/Belarusian journalists. Katie Harbath argues that the 2026 US midterms face a "kaleidoscopic minefield" of AI-driven threats, including autonomous agents, world models, and platform creator-monetization incentives that reward engagement over accuracy, that outpace post-2018 detection playbooks, and calls for shifting to rapid-triage frameworks built for unknown, fast-evolving attack vectors rather than static threat-mapping. NewsGuard reports continued progress in its First Amendment lawsuit against the FTC following the agency's withdrawal of a documentary demand. At the same time, the Omnicom-Interpublic merger conditions prohibiting the media company from working with disinformation-rating services remains in force. [State Actors] Russia Baltic States Summon Russian Envoys Over False Deportation Claims A report published by Euronews states that Lithuania, Latvia, and Estonia summoned Russian envoys after Moscow alleged the three NATO member states were preparing mass deportations of Russian-speaking residents. Lithuania's Foreign Ministry described the claims as 'entirely false,' and an attempt to 'divert attention from its aggression against Ukraine,' while Estonia's Foreign Minister called them 'nothing more than unfounded Russian propaganda,' and Latvia demanded Russia 'immediately retract this false information.' A report published by Euronews states that Lithuanian intelligence assessments document Russia's consistent use of narratives accusing Baltic states of persecuting Russian speakers and glorifying Nazi collaborators, narratives that serve Moscow's strategic goal of justifying foreign policy positions and amplifying pressure on NATO members. The diplomatic row coincided with Russian escalation of missile and drone attacks on Ukrainian civilian infrastructure, indicating that the false deportation narrative was deployed as information cover for concurrent military operations. Source: Euronews. Baltic States Summon Russian Envoys Over False Deportation Claims. [online] Published 10 July 2026. Available at: https://www.euronews.com/my-europe/2026/07/10/baltic-states-summon-russian-envoys-over-false-deportation-claims Top Of Page Russia's Attacks on Ukraine's Cultural Heritage An analysis published by StopFake states that Russia's targeting of the Kyiv Pechersk Lavra monastery on June 15th 2026 has collapsed Moscow's central Foreign Information Manipulation and Interference (FIMI) narrative of portraying Russia as the protector of the Orthodox Church. The analysis documents that this propaganda strategy rested on the false appropriation of Ukrainian Christian heritage, systematically omitting that Prince Volodymyr was 'Prince of Kyiv' and that Moscow was founded 159 years after Kyiv, while UNESCO has verified destruction of 536 Ukrainian cultural sites and Ukraine's Ministry of Culture has recorded approximately 1,900 damaged heritage locations. An analysis published by StopFake states that Russia's escalating attacks on cultural infrastructure reflect battlefield desperation rather than strategic intent, functioning as demoralization tactics when conventional military objectives fail. Estimated direct losses to Ukraine's cultural heritage have reached EUR 4 billion, with indirect losses of EUR 20 billion, and the theft of over 35,000 museum exhibits, a scale of cultural destruction that has simultaneously destroyed the credibility of Russia's self-assigned identity as civilization's defender. Source: StopFake. Russia’s Attacks on Ukraine’s Cultural Heritage: A Nail in the Coffin of FIMI. [online] Published 8 July 2026. Available at: https://www.stopfake.org/en/russia-s-attacks-on-ukraine-s-cultural-heritage-a-nail-in-the-coffin-of-fimi/ Top Of Page Russia's FSB Launches Disinformation Campaign A report published by Ukrainska Pravda states that Russia's Federal Security Bureau (FSB) launched a disinformation operation designed to damage Ukraine-Poland strategic relations by publishing allegedly 'declassified' files in Russia Today that falsely accused Ukrainian Insurgent Army commander Dmytro Kliachkivskyi of ordering the killing of approximately 2,000 Poles in Volodymyr-Volynskyi during 1943. Ukraine's Center for Countering Disinformation confirmed the documents were fabricated, with FSB Director Alexander Bortnikov personally overseeing the operation and state media instructed to amplify the narrative. A report published by Ukrainska Pravda states that the strategic objective of the FSB operation was to 'destroy the strategic partnership through manipulation of the past' by exploiting Polish historical trauma around the Volyn tragedy to provoke emotional reactions and fracture the Ukraine-Poland alliance at a critical moment of military cooperation. The operation was accompanied by identified bot farm activity targeting Polish social media and a network of eleven individuals organising anti-Ukrainian rallies in Poland for Russian payment, revealing a coordinated multi-vector influence campaign. Source: Ukrainska Pravda. Russia's FSB Launchs Disinformation Campaign Using Fake Volyn Tragedy Documents. [online] Published 5 July 2026. Available at: https://www.pravda.com.ua/eng/news/2026/07/05/8042440/ Top Of Page Ukraine Fake Photo Let Russian Propaganda Cast Doubt on Kyiv Lavra Strike An investigation published by Kyiv Independent states that Russian propaganda platforms exploited a photograph of the Dormition Cathedral burning during Russia's 15 June 2026 missile strike, an image that OpenAI's detection tools flagged as containing SynthID watermarks suggesting AI generation or editing, to construct a false narrative that Ukrainian photographers had staged the attack by setting up filming positions in advance. Pro-Kremlin accounts circulated the cathedral image alongside two AI-generated photographs falsely depicting journalists preparing the scene, with accompanying text claiming: 'The third photo shows the resulting image taken by these photographers.' An investigation published by Kyiv Independent states that StopFake.org's Olga Yurkova explained the standard propaganda methodology at work: 'propagandists first establish a narrative and then create visual evidence' to support predetermined false conclusions. Meta initially restricted posts about the attack due to a technical error linking legitimate reporting to an AFP fact-check examining the AI-generated imagery, but subsequently removed the false-information labels after acknowledging the algorithmic mistake, a sequence that demonstrates how AI-generated disinformation can briefly weaponise platform safety systems against accurate reporting. Source: The Kyiv Independent. How One Questionable Photo Fueled Confusion Over Russia's Attack on Kyiv Lavra. [online] Published 7 July 2026. Available at: https://kyivindependent.com/how-one-fake-photo-let-russian-propaganda-cast-doubt-on-kyiv-lavra-strike/ Top Of Page Russia Is Building Fake Ukrainians An analysis published by Euromaidan Press states that Russian information operations deployed at least three AI-generated videos targeting Ukrainian audiences across TikTok, Facebook, and YouTube in May 2026, collectively accumulating millions of views: a synthetic soldier accusing politicians of 'building a third house on the French Riviera' while troops sacrificed (915,000 views on Facebook), an AI-generated rabbi claiming draft dodgers should lose Ukrainian citizenship while deploying antisemitic tropes (557,000 views on TikTok), and a fabricated soldier accusing President Zelenskyy of pursuing war until complete societal destruction (425,000 views on TikTok). An analysis published by Euromaidan Press states that the three videos advanced distinct but complementary narratives, political corruption and soldier exploitation; ethnic exclusivity and Jewish overreach; and autocratic indifference to civilian casualties, while coordinated artificial promotion through bot engagement amplified their reach simultaneously across TikTok, YouTube, Facebook, Telegram, and X. The campaign demonstrates a sophisticated industrial-scale fabrication strategy in which AI-generated synthetic personas impersonate Ukrainian community figures to delegitimise the state, fracture social cohesion, and undermine civilian support for military mobilisation from within. Source: Euromaidan Press. Russia Is Building Fake Ukrainians: One AI Video, Telling Ukrainians Their Soldiers Are Dying So Politicians Can Buy Villas, Got 900,000 Views. [online] Published 4 July 2026. Available at: https://euromaidanpress.com/2026/07/04/russia-is-building-fake-ukrainians-one-ai-video-telling-ukrainians-their-soldiers-are-dying-so-politicians-can-buy-villas-got-900000-views/ Top Of Page Iran Regime Supporters and Opposition Share AI-Generated Images A report published by France 24 states that both pro-regime actors and Iranian opposition networks distributed AI-generated images of Ali Khamenei's state funeral, exploiting the same synthetic media tools to advance opposing political objectives. Regime supporters posted fabricated images of massive crowds at the Grande Mosalla Mosque and Azadi Tower, accumulating over 100,000 views and picked up by African media outlets, while opposition networks distributed a fabricated image of dissident rapper Toomaj Salehi appearing to honour Khamenei, both categories confirmed as AI-generated through SynthID watermark analysis. A report published by France 24 states that the parallel deployment of AI-generated content by opposing sides of Iran's political conflict reveals a fundamental shift in information warfare: synthetic imagery has become a universally accessible tool that requires neither state resources nor technical expertise, enabling both authoritarian governments and their opponents to manipulate public perception of the same event with fabricated visual evidence. The Khamenei funeral case demonstrates that AI disinformation is no longer exclusively a top-down state instrument but has become a contested terrain where all parties manufacture crowd sizes, emotional reactions, and political moments to shape international and domestic narratives. Source: France 24. Regime Supporters and Opposition Share AI-Generated Images of Khamenei’s Funeral. [online] Published 8 July 2026. Available at: https://www.france24.com/en/middle-east/20260708-regime-supporters-opposition-share-ai-generated-images-khamenei-funeral Top Of Page Fact-Checkers Exposed the Iranian State's Funeral Fraud A report published by NCRI states that international fact-checkers documented three categories of Iranian state deception surrounding Ali Khamenei's July 2026 state funeral: state broadcaster IRIB escalated crowd size claims from 'several million' to 15-20 million by 5 July, then 40 million nationwide by 10 July, while Reuters drone footage showed 'hundreds of thousands'; AFP Fact Check identified a 33-second aerial video as 99.7% likely AI-generated; and France 24 detected 'a fabricated beige dome replacing a real blue dome' and 'banners displaying illegible gibberish instead of actual Persian text' in widely circulated footage. A report published by NCRI states that the Iranian state supplemented media fabrication with coercive physical mobilisation: Tehran Municipality cancelled all employee leave and mandated attendance, the SAIJA organisation and Hamshahri newspaper bused workers under threat, and local governors extracted over USD 570,000 from automobile manufacturers to finance roadside stations, while the Ministry distributed 50 million free loaves of bread to financially incentivise participation. The three-layer deception strategy fabricated statistics, AI-generated visual evidence, and forced attendance to generate authentic-looking crowd footage represents a comprehensive state-coordinated disinformation architecture designed to construct a false narrative of popular grief for both domestic control and international legitimacy. Source: National Council of Resistance of Iran (NCRI). Manufactured Grief: How Fact-Checkers Exposed the Iranian State’s Funeral Fraud. [online] Published 11 July 2026. Available at: https://www.ncr-iran.org/en/news/iran-a-world/manufactured-grief-how-fact-checkers-exposed-the-iranian-states-funeral-fraud/ Top Of Page [AI Related Articles] Viral AI Fakes Flood Social Media as Iran Mourns Khamenei A report published by France 24 states that the week of Ali Khamenei's state funeral in early July 2026 produced a significant surge of AI-generated video and image fabrications across multiple platforms, with SynthID watermark analysis confirming the synthetic origins of viral content including AI-generated footage of massive crowds at the Grande Mosalla Mosque and Azadi Tower (accumulating over 100,000 views and picked up by African media) and an X post claiming approximately 40 million people attended via an AI-generated video that circulated in multiple languages. A report published by France 24 states that the Khamenei funeral disinformation surge demonstrates how major political events create predictable windows of high-volume AI content generation, as both state actors and opposition networks exploit the same generative tools to manipulate narratives about contested events. Pakistan's IVerify identified crowds in funeral footage moving in 'unnatural, wave-like patterns resembling flowing water', a characteristic artifact of AI video generation, illustrating that while detection tools are advancing, the volume and velocity of synthetic content production consistently outpaces platform enforcement capacity. Source: France 24. Viral AI Fakes Flood Social Media as Iran Mourns Khamenei. [online] Published 8 July 2026. Available at: https://www.france24.com/en/viral-ai-fakes-flood-social-media-as-iran-mourns-khamenei-1 Top Of Page Over 5,800 Arrests in Global Fraud Bust A press release published by INTERPOL states that Operation First Light 2026, a coordinated anti-fraud initiative spanning 97 countries that ran from January to April 2026, resulted in 5,811 arrests, the interception of USD 293 million in assets, the blocking of 31,014 bank accounts, and the identification of 142,000 victims globally from social engineering scams and associated money laundering operations. The operation analysed 152,808 cases, solved 23,715, and issued 99 Notices and Diffusions, with INTERPOL's Global Rapid Intervention of Payments (I-GRIP) system deployed as a stop-payment mechanism to swiftly block illicit financial flows. A press release published by INTERPOL states that the operation targeted social engineering scams, techniques that exploit human trust rather than technical vulnerabilities to obtain money or confidential information, reflecting the growing convergence between influence operations and financial fraud, where manipulative narrative techniques are increasingly weaponised for economic gain at global scale. The scale of Operation First Light 2026, encompassing nearly 100 countries and resulting in the largest coordinated enforcement action against fraud networks in INTERPOL's history, signals a decisive shift toward treating AI-enabled social engineering as a transnational security threat requiring multilateral law enforcement response. Source: INTERPOL. Over 5,800 Arrests, USD 293 Million Intercepted in Global Fraud Bust. [online] Published 9 July 2026. Available at: https://www.interpol.int/News-and-Events/News/2026/Over-5-800-arrests-USD-293-million-intercepted-in-global-fraud-bust Top Of Page EU Confirms Code of Practice on AI-Generated Content A policy document published by the European Commission states that the Commission and AI Board confirmed the Code of Practice on AI-Generated Content as an adequate compliance tool under Article 50 of the EU AI Act, which mandates transparency in AI-generated content and addresses 'risks of deception and manipulation, fostering the integrity of the information ecosystem.' The Code requires AI providers to mark audio, image, video, and text outputs in machine-readable formats detectable as artificially generated, and requires deployers to disclose deepfakes and AI-generated text on matters of public interest, with transparency obligations becoming legally binding from 2 August 2026. A policy document published by the European Commission states that while adherence to the Code of Practice is currently voluntary, its confirmation as an adequate compliance mechanism reduces administrative burden for signatories across EU Member States and establishes an industry-wide technical baseline for watermarking, detection, and labelling of synthetic media. The Commission's action comes at a moment when AI-generated content has reached sufficient scale and sophistication, demonstrated by the Khamenei funeral disinformation surge in the same week, to constitute a systemic threat to the information ecosystem that voluntary standards alone cannot address. Source: European Commission. Code of Practice on Transparency of AI-Generated Content. [online] Published 10 June 2026. Available at: https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content Top Of Page AI Threats to the 2026 Midterms Digital security strategist Katie Harbath identifies the AI threat landscape for the 2026 US midterm elections as a rapidly shifting kaleidoscopic minefield in which known threats such as deepfakes are relatively well-mapped, but novel and unnamed threat vectors are emerging faster than existing frameworks can track. Harbath highlights as particular unknowns: AI agents capable of acting autonomously on a voter's behalf; world models capable of simulating political scenarios; and the ways AI systems respond to political information inputs. She argues that playbooks developed since 2018, built to detect established attack patterns, are structurally inadequate for the next generation of threats. The piece also identifies how creator monetization programmes on social platforms now provide financial incentives for engagement-maximizing content regardless of accuracy, compounding the risk from state-sponsored influence operations by creating an aligned commercial infrastructure that amplifies divisive or false material. Harbath advocates shifting from threat-mapping to rapid-triage frameworks designed for unknown attack vectors. Source: Anchor Change. Kaleidoscopic Minefield: Election Playbook. [online] Published 28 October 2025. Available at: https://anchorchange.substack.com/p/kaleidoscopic-minefield-election-playbook Top Of Page [General Reports] Member Of Committee Investigating Spyware Hacked with Pegasus The Citizen Lab at the University of Toronto published forensic evidence confirming that Stelios Kouloglou, a former member of the European Parliament who sat on the PEGA Committee (the body tasked with investigating abuses of Pegasus and other commercial spyware), was himself hacked with NSO Group's Pegasus spyware on two separate occasions while the committee was active. The first infection occurred on 21 October 2022, coinciding with the committee's preparation of its draft report and upcoming hearings. The second infection occurred in June-July 2023 during the committee's final drafting period, approximately two months before the PEGA Committee adopted its first report. The attackers would have had access to confidential documents and committee deliberations, potentially breaching EU parliamentary privilege. Attribution remains uncertain: researchers found no indication of Greek government involvement but identified overlaps with an operator previously documented targeting Russian- and Belarusian-speaking exiled journalists in Europe. This is the first publicly confirmed case of a PEGA Committee member being hacked with Pegasus during the committee's operation. Source: Citizen Lab. Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus. [online] Published 3 July 2026. Available at: https://citizenlab.ca/research/member-of-committee-investigating-spyware-hacked-with-pegasus/ Top Of Page Fake Trump Post Says Belgium Is 2 Weeks Away from Developing a Nuclear Bomb A fact-check published by Lead Stories states that a fabricated post mimicking Donald Trump's Truth Social format falsely claimed that 'Belgium is 2 weeks away from developing a nuclear bomb,' originating from the @dogeofficialceo account on X on 7 July 2026. Lead Stories verified through manual review of Trump's Truth Social account, the Trump Truth archive, Google News, and Yahoo News that no authentic post from Trump's verified accounts contained the claim, noting that 'had the president actually made such a post, major news outlets would have widely reported it.' A fact-check published by Lead Stories states that the fabricated Trump nuclear post was published on the same day as the NATO Ankara Summit opened, a timing pattern consistent with coordinated influence operations designed to inject destabilising false narratives into major geopolitical events at moments of maximum media attention. The use of a convincingly formatted social media mockup to impersonate a sitting head of state on a nuclear proliferation claim represents an escalating category of disinformation that exploits both platform format conventions and audience familiarity with political figures' communication styles to generate credibility for fabricated content. Source: Lead Stories. Fact Check: Fake Trump Post Does NOT Say Belgium Is ‘2 Weeks Away’ From Developing A Nuclear Bomb. [online] Published 10 July 2026. Available at: https://leadstories.com/hoax-alert/2026/07/fact-check-fake-trump-post-says-belgium-is-2-weeks-away-from-developing-a-nuclear-bomb.html Top Of Page The West Can Learn from Ukraine's Success Against Russian Propaganda An analysis published by Atlantic Council states that Ukraine's documented successes in countering Russian information operations include deployment of an AI tool producing Ministry of Foreign Affairs statements in 30 languages with embedded unforgeable digital signatures, systems to counter Russia's network of thousands of fake websites, real-time disinformation dashboards for journalists, civil society, and government bodies, and media literacy investment through the Diia digital app, all anchored in 'laws promoting open data and transparency firmly rooted in democratic values. An analysis published by Atlantic Council states that NATO should adopt a 'whole-of-government and society approach' involving coalition-building across sectors, drawing from Ukraine's experience demonstrating that democracies can counter propaganda through technological innovation coupled with ethical safeguards rather than censorship. The analysis argues that the structural advantage of autocracies their natural tendency to weaponise information makes counter-disinformation investment a core democratic security priority, and that Ukraine's war-accelerated capability development offers Western governments a tested operational model at a moment when Russian information operations are targeting NATO member states directly. Source: Atlantic Council. The West Can Learn from Ukraine’s Success Against Russian Propaganda. [online] Published 2 July 2026. Available at: https://www.atlanticcouncil.org/blogs/ukrainealert/the-west-can-learn-from-ukraines-success-against-russian-propaganda/ Top Of Page India Ran Separate Spying Campaigns Against Same Pakistani Police Force SentinelOne researchers found that two separate, unconnected state-linked hacking groups, one tied to China (tracked as VANGUARD PANDA) and one tied to India (tracked as DISCOBEAN), independently conducted parallel cyber espionage operations against Pakistan's Balochistan Police for more than two years, from February 2024 to April 2026. The compromised systems held criminal records, biometric and fingerprint data, personnel files, hotel and tenant registration records linked to national identity systems, and citizen complaints. China's motivation appears tied to monitoring threats to its nationals and infrastructure connected to the China-Pakistan Economic Corridor (CPEC). India's motivation is likely linked to the bilateral rivalry and Pakistan's accusation that India backs the Baloch separatist insurgency. The simultaneous but independently run campaigns against the same target illustrate how a single police database can become the focus of competing foreign intelligence collection without either state being aware of the other's access. Source: The Record. China, India Ran Separate Spying Campaigns Against Same Pakistani Police Force. [online] Published 10 July 2026. Available at: https://therecord.media/china-india-ran-separate-spy-campaigns-against-same-police-force Top Of Page [Appendix - Frameworks to Counter Disinformation] Threat of Foreign Influence on U.S. Elections Remains as Federal Defenses Recede A report published by Brennan Center for Justice states that three nation-states are actively targeting U.S. elections with AI-enhanced tools: China's Golaxy Labs pays individuals to impersonate Western journalists while using AI to enhance message targeting; Russia's Social Design Agency hacked Bluesky user accounts and organised false-flag vandalism in Europe; and Iran is producing AI-enhanced video content and deploying fake news websites with AI-generated influencers. Simultaneously, the Trump administration has eliminated federal election security funding, ceased sharing threat intelligence with states, and failed to establish the Election Security Group. A report published by Brennan Center for Justice states that the combination of increasing foreign actor sophistication, leveraging AI to increase campaign volume, believability, and reach, with the simultaneous dismantlement of federal coordination infrastructure creates significant intelligence gaps for state election officials attempting to identify and respond to ongoing influence operations. The Center notes that while the diversity of the U.S. electoral system and prior security investments make direct interference with vote-casting technically challenging, the receding of federal defences represents a structural vulnerability that foreign actors are already exploiting through information environment manipulation rather than direct electoral system attacks. Source: Brennan Center for Justice. Threat of Foreign Influence on U.S. Elections Remain as Federal Defenses Recede. [online] Published 2 July 2026. Available at: https://www.brennancenter.org/our-work/research-reports/threat-foreign-influence-us-elections-remain-federal-defenses-recede Top Of Page FTC First Amendment Fight Continues A newsletter published by NewsGuard states that the company's First Amendment lawsuit against the Federal Trade Commission and its chairman Andrew Ferguson, challenging FTC conditioning of the Omnicom-Interpublic merger on prohibiting the combined entity from subscribing to any service that assesses the 'veracity of news reporting or other politically or ideologically contested facts', achieved a partial victory when the FTC dropped its demand for documents and ended its investigation, though the merger condition itself forbidding Omnicom from working with NewsGuard remains in force. A newsletter published by NewsGuard states that the FTC's condition targets the company 'with the precision of a laser beam' by using government power to prevent NewsGuard from producing journalism that the Trump administration and some of its supporters in the media do not like, characterising the action as an unprecedented use of merger review authority to censor First Amendment-protected editorial judgments about news source reliability. The case has broader implications for the disinformation detection sector: if upheld, the merger condition would establish a precedent permitting federal agencies to use commercial regulatory power to suppress organisations whose core function is assessing the accuracy of information. Source: NewsGuard's Reality Check. Our First Amendment Fight Continues. [online] Published 3 July 2026. Available at: https://www.newsguardrealitycheck.com/p/our-first-amendment-fight-continues Top Of Page [CRC Glossary] The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult. To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence. As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website. Top Of Page
- Iran War Post-MoU: From Cyfluence Operations to STRATCOM Efforts
Key Takeaways A new report by cyber-influence threat intelligence firm Intercept9500 examines how cyber, influence, economic, and kinetic actions operated as interconnected components of the Iran War. The report also highlights practical lessons for counter-Cyfluence and Influence Defense, including the need for rapid pre-bunking and response to narrative attacks, as well as the pre-conflict development of defensive capabilities and procedures to protect civilian infrastructure from both kinetic and hybrid threats. The recently-signed U.S.–Iran Memorandum of Understanding has led to a reduction in cyfluence attacks. At the same time, renewed kinetic attacks against civilian shipping and military assets have tested the agreement’s longevity. A CRC narrative intelligence analysis mapped key Iranian strategic communication assets on X/Twitter, primarily senior officials and state media channels, alongside their recent activity patterns, reach, and dominant narratives. Iran’s post-MoU messaging and overt influence activity continue to offer a valuable case study in how influence efforts persist, shift, and adapt across the conflict’s most recent stages. Recap Since the outbreak of the Iran War in February 2026, the conflict has extended far beyond conventional military exchanges. It has included cyberattacks (such as hack-and-leak operations, infrastructure disruption, broadcast interruption, and message application hijacking), extensive internet restrictions, the proliferation of synthetic propaganda and coordinated information disorder, and STRATCOM messaging. CRC threat researchers have previously examined this convergence of military disciplines and offensive vectors in a recent report titled The Deployment of Hybrid Threats and Cyfluence Operations in the Iran War. In the report, we documented how cyber, cognitive, and physical actions were combined to impact military institutions, national infrastructure, political leadership, and public perceptions. The Islamabad MoU On June 17-18, the United States and the Islamic Republic of Iran officially signed the Islamabad Memorandum of Understanding (MoU), agreeing on a 60-day framework intended to cement the ceasefire, reopen the doubly blockaded Strait of Hormuz, and enable negotiations on sanctions, Iran’s nuclear program, and wider regional security settlements.[1] This MoU entered into effect despite important (and high-profile) disagreements between U.S. and Iranian interpretations of its provisions, resulting in some critics even describing it as “dead on arrival”. Perhaps unsurprisingly, the MoU did not put an everlasting end to the conflict. It did, however, temporarily move the conflict from a high-intensity open warfare toward arduous negotiations, confrontational statements, and a continued contestation of the information domain. For now, the apparent result is a confusing dynamic featuring constant crisis management, posturing and re-posturing. Developments Since the MoU As of mid-July, Iranian attacks on commercial shipping in the Strait of Hormuz have renewed, prompting retaliatory U.S. military action against Iranian targets. Subsequently, Iran launched missile and drone strikes against American military assets and allies in the region. Iran continues to frame its control of the strait as a source of strategic leverage, while claiming sovereignty over the important maritime routes.[2] On July 8, President Trump declared the ceasefire effectively over, although diplomatic contacts continued. By July 12, the conflict had returned to direct widescale military exchanges, with the Strait of Hormuz again emerging as both a military chokepoint and an instrument of economic coercion. On July 13, President Trump, together with key American administration officials and the U.S. Central Command, declared the reinstatement of the naval blockade against Iran. Figure 1 - Posts published by official U.S. accounts on X. Left: A @WhiteHouse post, reposted by @POTUS, quoting President Trump’s declaration that “the ceasefire is over”; Right: @CENTCOM’s July 12 announcement of a “third round of strikes” against Iran following the IRGC’s targeting of a container ship in the Strait of Hormuz. (Courtesy of X) Figure 2 - Posts published by official U.S. accounts on X: a statement by President Trump, reposted by @WhiteHouse, and a U.S. Central Command announcement confirming the resumption of the naval blockade against Iran. (Courtesy of X) Regarding offensive cyfluence actions, public reporting since June 18 does not yet provide evidence of new operations. However, the current lack of positive evidence does not mean that cyber-influence efforts have ceased. Iranian efforts targeting the information environment are persistent. Iranian officials, state media, aligned commentators, and associated proxies have continued competing to define the narrative following the signing of the MoU agreement (i.e. a humiliating and expected U.S. surrender), as well as the reasoning for the current re-escalation, and the legitimacy of Iran’s military actions against affected Arab nations. Iranian Narrative Adaptation After the MoU The signing of the MoU required Iranian messaging to balance several potentially conflicting objectives: presenting the agreement as an Iranian achievement, denying that Tehran had capitulated, maintaining deterrence, preserving the legitimacy of the “Resistance Axis” (including Hezbollah in Lebanon and the Houthis in Yemen), and preparing domestic and foreign audiences for renewed confrontation. Initial Iranian statements emphasized conditional compliance. Tehran thus presented the agreement as a mechanism for acknowledging Iranian sovereignty and securing U.S. and Israeli concessions while retaining the right to respond to any violations. On the other hand, Iran’s supreme leader made his reservations about the agreement known, approving it due to Iranian national interests and the preservation of the wider resistance project. Later on, as tensions mounted, Iranian messaging shifted toward blaming the U.S. for the agreement’s imminent failure. This narrative essentially bridged the two alternating and competing positions of diplomatic engagement and military escalation. And by doing so, Iran portrayed itself as having accepted negotiations while framing renewed hostilities as a legitimate response to the American administration’s insincerity and aggression. Following Ayatollah Ali Khamenei’s funeral ceremonies, online discourse and media coverage saw a sharp increase in attention to Iranian threats against American and other Western leaders. Iranian revenge rhetoric, accompanied by imagery targeting President Donald Trump and other key political figures generated major traction on social media. A reported Israeli intelligence warning of a possible Iranian assassination plot against President Trump added to the perceived threat narrative. Trump himself responded by publicly warning that any successful attack would trigger overwhelming U.S. retaliation. Figure 3 - Coverage by CNN and Fox News on X regarding recent Iranian death threats against U.S. and Israeli leaders, and an Israeli intelligence warning of an alleged Iranian assassination plot. (Courtesy of X) Media coverage of the Iranian state-sanctioned threats and alleged intelligence disclosures, together with official statements, were joined by online influencers amplifying escalatory or conspiratorial narratives. Almost instantaneously, Iranian promises of revenge by means of assassination became a prominent theme of online discourse. Figure 4 - Posts by influencer Laura Loomer addressing Iranian assassination threats, questioning President Trump’s claim of successful regime change, and suggesting a possible connection to Senator Lindsey Graham’s sudden death. (Courtesy of X) Narrative Intelligence Analysis A CRC analysis of the most influential Iranian officials and state media accounts on X/Twitter (between dates June 10 – July 12, 2026) maps the extent of Iran’s overt messaging and narrative control efforts, by tracking its leading strategic communication assets, during this timeframe. Figure 5 - Activity graph showing top 10 Iranian officials and state media accounts on X/Twitter (timeframe: June 10 to July 12, 2026). Figure 6 - Graph showing impressions per day for the top 10 Iranian officials and state media accounts on X/Twitter (timeframe: June 10 to July 12, 2026). The two graphs above depict posting activity and impressions metrics for leading Iranian strategic communication assets on X/twitter. The selected time window allows us to assess STRATCOM efforts velocity and impact, before and after the signing of the MoU agreement. The table below shows an aggregated summary of reach and engagement metrics for the top 10 Iranian officials or state media accounts considered as STRATCOM assets (as of July 12, 2026). Figure 7 – A summary of the top 10 leading Iranian STRATCOM assets active on X/Twitter, including aggregated impressions metrics (timeframe June 10 to July 12, 2026). According to our analysis of Iranian communications throughout recent weeks, two amplification models appear to operate in parallel. State media outlets drove volume, publishing hundreds of posts with relatively low average reach. On the other hand, Iranian senior officials posted far less but attracted far more attention. Foreign Minister Araghchi’s 18 posts generated over 18 million impressions, exceeding the reach of IRNA or Press TV despite their much higher output. State media therefore sustained distribution, while viral reach came from a small number of high-profile officials. Dominant Narratives Using automated classification of content published by the most prominent Iranian X accounts since the signing of the MoU, CRC analysts identified three dominant narratives: The first - centered on the death of former Supreme Leader Ayatollah Khamenei, portraying it as martyrdom and honorable sacrifice while reinforcing the legitimacy of his son and successor, Mojtaba Khamenei. The second - accused the United States of repeatedly violating the MoU and emphasized Iran’s claimed exclusive sovereignty over the Strait of Hormuz. The third - focused on deterrence, retaliation, and revenge, combining official threats with visual depictions of “the Iranian public” demanding retribution in an effort to present these messages as organic, popular sentiment. Figure 8 - Top 3 narratives appearing in posts by Iranian officials and state media outlets on X/Twitter. Implications for Cyfluence Research Since the start of the Iran War, threat analysts and researchers have begun to map, correlate and monitor the diverse – and perhaps unprecedented – usage of hybrid threats, including cyfluence attacks, carried out by the combatting sides. A new report by cyber threat intelligence firm Intercept9500, titled Iranian Hybrid Warfare During Operation Epic Fury, provides a valuable multi-dimensional review of offensive operations. Following an earlier Intercept9500 Preliminary Analysis published in May 2026, it complements the CRC’s abovementioned research by examining the overall Iranian response to the U.S.–Israeli military campaign. Interestingly, the report posits that Iran effectively inverted the “conventional hybrid hierarchy”. Instead of deploying offensive influence and cyber operations to support a kinetic main effort, Tehran prioritized the cognitive and cyber domains, due to its calculation of its own comparative strengths and weaknesses. By doing so, Iran managed to gain greater opportunities to deny its adversaries from achieving their strategic objectives. To that extent, cyber activity was primarily designed and leveraged for visibility, narrative dissemination, and cognitive impact. Moreover, the strategic and operational models presented in the report place hostile influence operations and offensive cyber capabilities as part of an integrated cyfluence ecosystem. Figure 9 – Iranian Cyfluence Operational Model during the Iran War. (Courtesy of Intercept9500)[3] Conclusion The Iran War remains a valuable case study for hybrid-threat researchers, cyfluence analysts, and Influence Defense stakeholders. It highlights the role of the strategic and operational fusion of kinetic actions, cyber capabilities, economic coercion, information control, diplomatic posturing, and strategic communication in modern warfare. Given that the increased integration of these various elements has already created a highly complex and dynamic global threat landscape, additional research into both offensive applications and defensive countermeasures should be encouraged. For Influence Defense practitioners and stakeholders, the existing (and still expanding) body of evidence and operational insights is a valuable resource. A methodological examination of how hybrid threats manifest during high-intensity conflict could directly inform pre-emptive and proactive capacity building, helping to protect against emerging threats, especially in other regions currently at risk. CRC report raises several noteworthy takeaways for defenders, such as the need to pre-bunk and respond rapidly to narrative attacks, while establishing defensive capabilities, coordination mechanisms, and protection procedures before a crisis emerges. This point is particularly important for civilian infrastructure and private sector entities, which are increasingly exposed to both kinetic and hybrid threats. Lastly, we should be mindful of a basic working assumption: the valuable lessons learned from this conflict are not limited to the current combatants. Other major actors, including China and Russia, will surely draw their own conclusions. Likewise, different hacktivist groups, proxy organizations, and small-scale threat actors will likely be quicker to adapt, modifying their approach and TTPs accordingly. Ultimately, it is the application of those lessons that will determine how cyfluence capabilities and hybrid threats will be deployed in future conflicts. The CRC continues to monitor the developments and will report on relevant findings. [References:] Deutsche Welle (DW). What’s in the 14-Point US-Iran Peace Plan? [online] Published 19 June 2026. Available at: https://www.dw.com/en/whats-in-the-14-point-us-iran-peace-plan/a-77595563 Associated Press. Iran, USA and United Arab Emirates Attack. [online] Published 24 June 2026. Available at: https://apnews.com/article/iran-usa-united-arab-emirates-attack-0764d17c09370a8c5cf1e8197a8878ab Intercept9500, “Iranian Hybrid Warfare During Operation Epic Fury: Preliminary Analysis While the Situation is Still Unfolding” 15 June 2026. Available online: https://media.licdn.com/dms/document/media/v2/D4D1FAQFygKagA-vnDQ/feedshare-document-sanitized-pdf/B4DZ9THlLlGkA8-/0/1783805925198?e=1784451600&v=beta&t=H0YeCibL2_7qxMeO4zYcEN13cJFG6gqSYtZ9E7PJY7E
- Cyber based influence campaigns 29th June – 5th July 2026 Report
[Introduction] Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW). Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc. During the 29th June - 5th July of June 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities. [Contents] [Introduction] [Report Highlights] [Report Summary] [State Actors] Russia RIA Novosti Falsely Claims Lithuanian History Textbook Glorifies Hitler's Collaborators Russia Uses Mockery and Parody to Amplify Disinformation Across Europe Russia's Information War Against Ukraine's EU Future Threatens All of Europe Russian IMS Exploits Mastodon and Bluesky Architecture to Launder Sanctioned Media RT Launches @RT_on_X Account Russia Deploys FPV Drones Ukraine Moscow Deploys FIMI to Conceal Battlefield Russian Channels Strip Context from Lula's G7 Statements China China Enacts Transnational Repression Law Chinese Network Deploys 294 Fake Dating Profiles on Meta [AI Related Articles] AI-Generated Images Exploit World Cup Coverage to Spread Political Disinformation Coordinated Deepfake Ad Campaigns Impersonate Football Stars AI-Generated Hypersexualised Content Targets World Cup Fandoms Across Seven Countries [General Reports] Domestic and Chinese Influence Networks Simultaneously Target Philippine Facebook Pages Finland Nuclear Weapons Disinformation and Australian Fake News Network Documented Google GTIG and FBI Disrupt NetNut Proxy Botnet Controlling Two Million Devices AI Deepfakes, Bots, and Sockpuppet Networks HAARP Conspiracy Surges to 134,000 Mentions [Appendix - Frameworks to Counter Disinformation] EU AI Act Code of Practice Signatories Ahead of August Enforcement Consumer Deepfake Detection Market Expands [CRC Glossary] [ Report Highlights] StopFake documents Russia's 'Hahaganda' strategy deploying fabricated mockery, AI deepfakes, and nine fake Charlie Hebdo covers distributed across 13 languages to undermine Ukrainian institutional credibility without direct factual contestation. A joint EEAS-CCD report cited by StopFake documents 244,000 publications on Ukraine's EU accession generating 1.39 billion views, with over 2,600 sources displaying inauthentic coordination deploying four country-adapted narratives portraying membership as costly and conflicting. Revelum documents at least 10,000 deepfake scam ads impersonating six football players over 12 months, with volumes surging 413% for Luis Diaz and 1,700% for Neymar during the 2026 World Cup, using identical templates pointing to centralised operations. DFRLab found a Philippine domestic state-aligned network and China's Spamouflage simultaneously targeting the same Filipino activist Facebook pages with opposing objectives, showing unrelated state actors can exploit identical platform gaps with a compounding effect. Google GTIG, the FBI, Lumen, and Shadowserver disrupted NetNut/Popa, a residential proxy botnet controlling 2 million compromised devices that served 316 distinct threat clusters in a single week across cybercriminal and espionage operations. Euronews confirmed AI-generated synthetic media campaigns across six platforms in three languages during the 2026 World Cup, with one fabricated image reaching 3 million views before debunking, illustrating the amplification gap cognitive warfare operations are designed to exploit. EUvsDisinfo documents Russia's use of FPV drones as dual-use instruments delivering both explosives and propaganda leaflets into frontline communities simultaneously, integrating kinetic and cognitive warfare in a single technological vector with Kherson as the primary documented case study. [ Report Summary] StopFake finds RIA Novosti's claim that a Lithuanian history textbook glorifies Hitler's collaborators is false; the textbook describes LAF activities without glorification and includes a dedicated Holocaust section that RIA Novosti systematically omitted. StopFake documents Russia's 'Hahaganda' strategy deploying fabricated mockery, AI-generated deepfakes, and nine fake Charlie Hebdo covers across 13 languages to delegitimise Ukrainian leadership without direct factual contestation. StopFake cites a joint EEAS-CCD report documenting 244,000 publications on Ukraine's EU accession generating 1.39 billion views, with over 2,600 sources displaying inauthentic coordination deploying four country-adapted narratives portraying membership as costly, conflicting, and elite-driven. CheckFirst documents 'Roska Bridge,' a Russian IMS using Brid.gy to automatically synchronise EU-sanctioned media content across Mastodon and Bluesky in monthly burst operations across 10 instances, with CIB indicators linking it structurally to the Pravda Network. NewsGuard documents RT's @RT_on_X account accumulating 6 million views within five days of its 25 June 2026 debut in apparent evasion of EU sanctions, with the European Commission confirming sanctions cover all transmission and distribution channels including platforms and apps. EUvsDisinfo documents Russia's use of FPV drones as dual-use instruments delivering both explosives and propaganda leaflets into frontline communities simultaneously, integrating kinetic and cognitive warfare in a single technological vector with Kherson as the primary documented case study. StopFake documents Russia's use of FIMI to conceal military setbacks through false territorial claims, logistical denial despite documented supply chain degradation, and a propaganda fracture in which Kremlin-aligned correspondents contradicted official civilian-targeting narratives. StopFake identifies Russian channels extracting Lula's 'everyone is tired' remark from its G7 context, which also referenced Putin's supporters and called for UN diplomacy, to fabricate a false claim that Western backers specifically are seeking to end support for Ukraine. AEI/ISW documents the PRC's enactment of an ambiguous overseas ethnic unity law, PLA-Russia joint aerial exercises near South Korea and Japan on 27th June 2026, and Japan's discovery of PRC counterfeit USB drives containing state-linked malware that compromised defence systems between March 2024 and February 2025. NewsGuard identifies 294 coordinated Threads accounts using AI-generated profiles of attractive women targeting Taiwanese men, exhibiting CIB indicators including identical posting schedules and inaccurate Taiwan details, assessed as primed to deploy political content ahead of Taiwan's November 2026 local elections. Euronews documented AI-generated synthetic media campaigns across six platforms in three languages during World Cup 2026, including fake images of Starmer and Netanyahu at matches, with one fabricated image accumulating 3 million views before debunking, illustrating the amplification velocity gap cognitive warfare operations exploit. Revelum documents at least 10,000 deepfake scam ads impersonating six football players over 12 months, with volumes surging 413% for Luis Diaz and 1,700% for Neymar during the 2026 World Cup, using identical narrative templates and urgency language pointing to centralised operations with scalable infrastructure. EDMO documents widespread unlabelled AI-generated hypersexualised content targeting World Cup fandoms across seven countries, monetised through platform revenue programmes, with investigations revealing the same infrastructure used in dual operation for far-right political propaganda distribution. DFRLab identified a Philippine domestic state-aligned network and China's Spamouflage simultaneously targeting the same Filipino activist Facebook pages with opposing objectives, demonstrating that unrelated state actors can exploit identical platform vulnerabilities simultaneously with compounding effect. The Disinformation Observer documents a false viral claim fabricating that 'President Sipila' approved nuclear weapons storage in Finland, and an Australian CIB operation run by Vietnamese operators impersonating established news brands on Facebook to drive advertising revenue. Google GTIG, the FBI, Lumen, and Shadowserver disrupted NetNut/Popa, a residential proxy botnet controlling approximately 2 million compromised devices that served 316 distinct threat clusters in one week spanning cybercriminal and espionage operations, with the FBI seizing the netnut.com domain. Memesita reports the 2026 World Cup has attracted coordinated operations using AI deepfakes, bot amplification, and sockpuppet networks blending fabricated political content with sports commentary, while noting the secondary Liar's Dividend risk of deepfake proliferation enabling dismissal of genuine evidence as AI-generated. HAARP conspiracy mentions surged from 16,200 to 134,000 in one week as Venezuelan earthquakes killed at least 1,450 and a European heatwave killed hundreds, with viral posts falsely attributing both to US ionospheric weaponization, a claim directly refuted by HAARP's director and incompatible with seismic data. Providers and deployers of generative AI systems subject to EU AI Act Article 50 have until 22 July 2026 at 18:00 CEST to sign the Code of Practice on Transparency, with signatories receiving presumption of conformity before enforcement begins on 2 August 2026. Biometric Update reports three new deepfake detection product launches in June 2026, Scam.ai/Qualcomm's Halo, Bitdefender's RealCheck for 14 countries, and South Korea's KISA funding 11 new research projects, driven by Deloitte projections of USD 40 billion in US generative AI fraud losses by 2027. [State Actors] Russia RIA Novosti Falsely Claims Lithuanian History Textbook Glorifies Hitler's Collaborators A fact-check published by StopFake states that RIA Novosti alleged a Lithuanian 10th-grade history textbook glorifies Hitler's collaborators and ignores Nazi ties and antisemitism, a claim StopFake's analysis finds to be materially false through textual evidence and historical context. The textbook describes Lithuanian Activists' Front (LAF) activities in approximately two paragraphs without portraying any figures as heroes, acknowledges both independence aspirations and the movement's Nazi connections, and does not characterise Kazys Skirpa -- the principal figure referenced by RIA Novosti, as heroic, presenting him solely in the context of anti-Soviet resistance during a period when Lithuania had already been occupied under the Molotov-Ribbentrop Pact framework. A fact-check published by StopFake states that the textbook also contains a dedicated section titled 'The Holocaust in Nazi-Occupied Europe,' complete with death camp maps, statistical data by country, and explicit documentation of Lithuanian Jewish victims, as well as a direct statement that various European nationals 'participated in one way or another in arrests, deportations, and executions', content RIA Novosti did not reference in its coverage. StopFake's analysis identifies this pattern of selective omission as the operational core of the false claim, finding that the textbook does not glorify collaborators but rather documents a contested historical period with contextual material that RIA Novosti systematically suppressed, situating the fabrication within a broader pattern of Russian state media weaponising European historical sensitivities to generate political pressure and undermine Baltic credibility in EU and NATO contexts. Source: StopFake. RIA Novosti Fake News: Lithuanian History Textbook Glorifies Hitler’s Collaborators. [online] Published 24 June 2026. Available at: https://www.stopfake.org/en/ria-novosti-fake-news-lithuanian-history-textbook-glorifies-hitler-x27-s-collaborators/ Top Of Page Russia Uses Mockery and Parody to Amplify Disinformation Across Europe An analysis published by StopFake states that Russia has developed a coordinated disinformation strategy termed 'Hahaganda', deploying mockery, satire, and parody as tactical instruments to delegitimise targets without requiring direct persuasion, to undermine institutional trust through systematic ridicule rather than factual contestation. The analysis documents three primary operational channels: AI-generated image manipulation and deepfake video production, institutional impersonation through fabricated content attributed to credible outlets such as Charlie Hebdo, and the deployment of synthetic videos depicting Ukrainian military personnel as desperate or coerced, all distributed through a standard pattern in which Telegram channels seed content that propagates across Facebook, TikTok, and X. An analysis published by StopFake states that Hahaganda operates by exploiting confirmation bias within target audiences already sceptical of Ukrainian governance, producing a false impression of widespread international condemnation and enabling coordinated narratives to circulate as apparent organic sentiment rather than as identifiable propaganda. Documented examples include at least nine fabricated Charlie Hebdo covers attacking President Zelenskyy, which prompted a Paris court complaint by the publication in May 2025, and a January 2026 deepfake video depicting a purported Ukrainian warehouse commander that spread across 13 or more languages, with the teleMarafon Facebook account alone publishing over 50 AI-generated videos since October 2023 formatted to resemble news broadcasts. StopFake assesses Hahaganda as a significant evolution in Russian information operations, enabling attribution-resistant narrative amplification that is structurally difficult for platform moderation systems to detect given the use of satirical framing to obscure coordinated political intent. Source: StopFake. Hahaganda: How Russia Seeks to Reinforce Disinformation Narratives in Europe Through Mockery and Parody. [online] Published 30 June 2026. Available at: https://www.stopfake.org/en/hahaganda-how-russia-seeks-to-reinforce-disinformation-narratives-in-europe-through-mockery-and-parody/ Top Of Page Russia's Information War Against Ukraine's EU Future Threatens All of Europe An article published by StopFake states that a joint analytical report by the European External Action Service and Ukraine's Centre for Countering Disinformation documented how Russian Foreign Information Manipulation and Interference (FIMI) operations are systematically targeting Ukraine's path towards European Union membership, with monitors observing approximately 244,000 publications on Ukraine's EU accession between January 2025 and May 2026 generating a combined 1.39 billion views, with over 2,600 sources displaying inauthentic behaviour patterns including synchronised dissemination and coordinated amplification responses. The article identifies four core destructive narratives deployed across EU member states and Ukrainian audiences: that EU accession prolongs conflict, that Ukraine is corrupt and incompatible with European values, that EU membership is costly and risky for both parties, and that European countries pursue hidden territorial or economic interests in Ukraine, with country-specific adaptations targeting Germany via economic anxieties, France via corruption narratives, and Poland through historical sensitivities and anti-refugee framing. An article published by StopFake states that the report identifies a structural escalation in Russia's approach, finding that Moscow is no longer relying only on individual falsehoods but instead deploying generative AI, coordinated inauthentic behaviour networks, and cross-platform amplification to exhaust audiences and normalise distrust at scale, with narratives tested in the Ukrainian information space subsequently adapted for EU audiences before being reintroduced into Ukraine to create the false impression of European loss of confidence in Kyiv. StopFake situates this campaign as a direct threat not only to Ukraine's accession trajectory but to European institutional integrity itself, arguing that operations designed to degrade trust in Ukraine's compatibility with European values simultaneously corrode the foundations of democratic solidarity within EU member states, requiring not only Ukrainian countermeasures but a structural framework for shared analytical intelligence between Kyiv and European institutions as a condition of the enlargement process. Source: StopFake. Russia’s Information War Against Ukraine’s European Future Is a Threat to Europe Itself. [online] Published 1 July 2026. Available at: https://www.stopfake.org/en/russia-s-information-war-against-ukraine-s-european-future-is-a-threat-to-europe-itself/ Top Of Page Russian IMS Exploits Mastodon and Bluesky Architecture to Launder Sanctioned Media An investigation published by CheckFirst states that a Russian information manipulation set (IMS) dubbed 'Roska Bridge' has been exploiting architectural vulnerabilities in decentralised social platforms since at least September 2025, using the Brid.gy service as a technical gateway to automatically synchronise content from EU-sanctioned Russian media outlets, including Pravda Network, Russia Today, and Sputnik, across Mastodon and Bluesky simultaneously. The investigation documents operations across 10 Mastodon instances, including mastodon.social, which has over 870,000 users, with hundreds of coordinated accounts executing content in monthly burst cycles, posting intensively before disappearing and being replaced, a pattern CheckFirst identifies as a clear indicator of Coordinated Inauthentic Behaviour (CIB). An investigation published by CheckFirst states that Roska Bridge's geographic and narrative targeting encompasses Ukraine, France, Germany, and the United States with anti-Western and anti-Ukrainian propaganda, while simultaneously promoting Max, a Russian state-backed messenger that requires Russian phone numbers, indicating that the operation runs parallel domestic and Western audience targeting tracks from shared infrastructure. CheckFirst identifies structural linkage between Roska Bridge and the Pravda Network through synchronised identical publications, suggesting these are not independent actors but components of a coordinated Russian influence infrastructure designed to route sanctioned state media content into platforms, Mastodon and Bluesky, that lack the sanctions-compliance infrastructure of major platforms, exploiting decentralisation's governance gap as a systematic distribution channel for content that cannot legally reach European audiences through conventional means. Source: Check First. Roska Bridge: How a Pro-Russian IMS Exploits Vulnerabilities of Decentralised Platforms to Spread Propaganda. [online] Published 1 July 2026. Available at: https://checkfirst.network/roska-bridge-how-a-pro-russian-ims-exploits-vulnerabilities-of-decentralised-platforms-to-spread-propaganda/ Top Of Page RT Launches @RT_on_X Account A report published by NewsGuard states that a new X account named @RT_on_X appears to be an attempt by Russian state outlet RT to bypass EU sanctions imposed following Russia's full-scale invasion of Ukraine, reaching European audiences who are legally barred from accessing RT content under EU regulations. The account debuted on 25 June 2026, accumulated 1,000 followers, and posted 631 times, with posts collectively garnering 6 million views within five days, an amplification rate consistent with coordinated boosting. NewsGuard identifies multiple indicators of RT affiliation: posts carry the official RT logo and the tagline 'Freedom over censorship, Truth over narrative,' content from the new account is routinely reposted on RT's official @RT_com account, which is itself blocked from European feeds, and the account is followed by RT's editor-in-chief, Margarita Simonyan. A report published by NewsGuard states that the European Commission, responding to NewsGuard's inquiry with a statement dated July 1st, 2026, confirmed that EU sanctions cover 'all means for transmission and distribution,' including 'platforms, websites and apps,' and that the Commission is in contact with national authorities regarding the @RT_on_X account's operations. NewsGuard assesses this case as consistent with RT's documented pattern of sanctions evasion through infrastructure substitution, with prior documented tactics including website cloning, third-party distribution agreements, and re-labelled content farms, and notes that X's current enforcement posture under Elon Musk's ownership has significantly reduced platform-level intervention against state-affiliated media accounts, creating a structural gap between EU regulatory requirements and platform compliance that Russian state media continue to exploit systematically. Source: NewsGuard Reality Check. RT Evades Sanctions. [online] Published 1 July 2026. Available at: https://www.newsguardrealitycheck.com/p/rt-evades-sanctions Top Of Page Russia Deploys FPV Drones An analysis published by EUvsDisinfo states that Russia has operationalised FPV (First Person View) drones as dual-use instruments in the war in Ukraine, using the same unmanned aerial vehicles both to drop explosives on civilian and military targets and to deliver propaganda leaflets into frontline communities, integrating physical violence with psychological pressure in a single technological vector. The analysis describes this as an intentional doctrinal combination: physical pressure derives from artillery, drone attacks, and infrastructure strikes that generate constant danger and exhaustion among affected populations, while information disruption operates through telecommunications collapse or restriction that simultaneously empties the information vacuum and fills it with propaganda channels, depriving communities of accurate situational awareness at moments of maximum vulnerability. An analysis published by EUvsDisinfo states that Kherson represents the most thoroughly documented case study, having experienced Russian occupation beginning March 2022, liberation nine months later, and continuous pressure from Russian forces positioned on the occupied eastern bank of the Dnipro River following their retreat, with residents subjected to documented torture, fabricated referendums on annexation, civilian disappearances, and child kidnappings during occupation, followed by ongoing drone and artillery attacks in the post-liberation period. EUvsDisinfo situates Russia's drone dual-use doctrine within the broader framework of cognitive warfare, assessing that the deliberate combination of kinetic and information instruments represents a tactical evolution designed to maximise psychological impact on civilian populations while minimising the resources required per target, and that the integration of AI-enabled drone production with systematic propaganda distribution points to an operational model that scales both the physical and cognitive warfare components simultaneously from shared infrastructure. Source: EUvsDisinfo. Explosives and Propaganda: Russia’s Dual-Use Drones. [online] Published 29 June 2026. Available at: https://euvsdisinfo.eu/explosives-and-propaganda-russias-dual-use-drones/ Top Of Page Ukraine Moscow Deploys FIMI to Conceal Battlefield An analysis published by StopFake states that Russia is deploying coordinated Foreign Information Manipulation and Interference (FIMI) operations to conceal military setbacks through three primary mechanisms: false territorial claims asserting the capture of locations that remain under Ukrainian control, logistical denial narratives minimising documented supply chain degradation, and threat escalation framing that recharacterises Ukrainian strikes on military infrastructure as attacks on civilians. The analysis documents repeated false declarations of victory in Kupyansk, which President Zelenskyy personally visited in November 2025 to refute, and three separate claims of liberating Mala Tokmachka throughout 2025-2026 while Ukrainian forces-maintained control, with Russian General Gerasimov declaring westward advances near Kupyansk as recently as May 16th, 2026, despite Ukrainian defensive positions holding. An analysis published by StopFake states that Russia's information operations to conceal battlefield conditions extended to economic and logistical matters, with official propaganda claiming supply conditions remained under control while simultaneous government decisions revealed operational stress: Belarus import increases, aviation kerosene export bans implemented on June 1st 2026, and diesel restrictions following Ukrainian drone strikes degrading the Crimea land corridor. The analysis documents a propaganda fracture in which Kremlin-aligned war correspondents acknowledged Ukrainian strikes targeted fuel tankers rather than civilians, directly contradicting official denial narratives, and identifies the Kremlin's development of image-of-victory messaging since February 2026, emphasising resistance to the West and business resilience under sanctions, as evidence that Russia's information operations are increasingly designed to manage domestic and international perception rather than to report conditions accurately. Source: StopFake. How Moscow Tries to Cover Up Its Failures on the Ukrainian Battlefield. [online] Published 1 July 2026. Available at: https://www.stopfake.org/en/how-moscow-tries-to-cover-up-its-failures-on-the-ukrainian-battlefield/ Top Of Page Russian Channels Strip Context from Lula's G7 Statements A fact-check published by StopFake states that Russian information channels extracted a selective quotation from Brazilian President Lula's remarks at a G7 summit meeting with Ukrainian President Zelensky on June 17th 2026, in which Lula stated 'everyone is tired' of the war, referencing supporters of Ukraine, supporters of Putin, and those financing both sides, and removed his explicit mention of Putin's supporters and his call for intensified diplomatic efforts through UN Security Council mechanisms, fabricating a false claim that Lula had specifically declared Western backers exhausted and seeking to withdraw support. StopFake's analysis identifies this as a textbook hostile influence operation employing selective quotation and context removal, designed to fracture the Western coalition by suggesting public fatigue justifies policy recalibration without requiring any actual change in Western government positions. A fact-check published by StopFake states that the manipulation exploits three intersecting cognitive vulnerabilities: anchoring bias, in which the factually accurate premise that fatigue exists lends false credibility to the distorted conclusion; confirmation bias among audiences predisposed to doubt Western commitment; and cognitive load effects that reduce the likelihood of audiences consulting full source materials in social media environments. Verification against Lula's official statements in Brazilian media, the Zelensky presidential office readout, and the G7 joint statement, which reaffirmed unwavering support for Ukraine including expanded air defense deliveries, confirmed that all three sources contradict the manipulated narrative, situating the operation within Russia's sustained effort to generate diplomatic pressure on Kyiv by manufacturing the appearance of Western exhaustion rather than contesting the substance of Western policy positions. Source: StopFake. Manipulation: Lula Said Ukraine’s Western Backers Are “Tired” and Want to End the War. [online] Published 23 June 2026. Available at: https://www.stopfake.org/en/manipulation-lula-said-ukraine-s-western-backers-are-tired-and-want-to-end-the-war/ Top Of Page China China Enacts Transnational Repression Law An update published by AEI and ISW states that the People's Republic of China enacted a new ethnic unity law effective 1 July 2026 creating ambiguous prosecution standards for overseas activity, with Taiwan's UK envoy warning of transnational repression risks and citing PRC's new London diplomatic facility with reported underground detention infrastructure, a development that analysts assess as an expansion of Beijing's coercive reach into diaspora communities under legally ambiguous domestic authority. The update also documents PLA and Russian joint aerial exercises conducted near South Korea and Japan on June 27th 2026, as coordinated military signaling, alongside the Chinese Coast Guard conducting three intrusive patrols around Taiwan's Pratas Island in June while maintaining continuous presence in Taiwan's eastern Exclusive Economic Zone. An update published by AEI and ISW states that Japan's Ground Self-Defence Force discovered PRC-manufactured counterfeit USB drives containing state-linked malware that had compromised secure Japanese defence systems between March 2024 and February 2025, representing a documented cyber-enabled intelligence operation against a key US treaty ally. The update identifies a strategic recalibration in PRC military signalling, with ADIZ incursions reduced to a pre-2024 baseline of 134 sorties in June versus over 300 previously, as evidence Beijing is shifting toward normalised coercion patterns designed to reduce threat desensitisation among Taiwanese and allied populations, a pattern ISW assesses as consistent with broader Chinese grey-zone strategy that maintains continuous military pressure while avoiding escalatory incidents that could consolidate Western political will against PRC regional objectives. Source: American Enterprise Institute (AEI) and Institute for the Study of War (ISW). China & Taiwan Update, July 2, 2026. [online] Published 2 July 2026. Available at: https://www.aei.org/articles/china-taiwan-update-july-2-2026/ Top Of Page Chinese Network Deploys 294 Fake Dating Profiles on Meta A report published by NewsGuard states that a network of 294 coordinated accounts on Meta's Threads platform, which launched in May 2026, features AI-generated profiles of attractive Asian women claiming to seek Taiwanese men as romantic partners, with the accounts exhibiting multiple indicators of coordinated inauthentic behaviour: identical posting schedules, systematically similar account handles, a consistent focus on targeting Taiwanese men, and inaccurate descriptions of Taiwan-specific cultural details that suggest non-Taiwanese operators. The operation bears the hallmarks of Chinese political influence campaigns, including a December 2025 operation that used fabricated attractive Japanese influencer accounts to promote pro-China territorial claims, with NewsGuard assessing the network as primed to inject political content at a strategically timed point ahead of Taiwan's November 2026 local elections. A report published by NewsGuard states that as of the publication date, the phony dating accounts had not yet begun posting overtly political content, a pattern consistent with Chinese influence operations that establish audience trust and follower bases through benign content before activating political messaging during peak electoral periods, a technique documented in multiple prior PRC operations across Facebook, Instagram, and X. NewsGuard situates the Threads operation within a broader pattern of Chinese influence activity that exploits the trust architecture of social connectivity platforms, where romantic and personal interest framing substantially reduces user scepticism compared to overtly political accounts, and identifies Meta Threads as an emerging target for PRC influence infrastructure that presents new moderation challenges given the platform's early-stage content enforcement systems and its integration with Instagram's audience base, which provides rapid follower scaling from existing social graph connections. Source: NewsGuard Reality Check. Fake Dating Profiles, Real Foreign Influence. [online] Published 2 July 2026. Available at: https://www.newsguardrealitycheck.com/p/fake-dating-profiles-real-foreign (newsguardrealitycheck.com). Top Of Page [AI Related Articles] AI-Generated Images Exploit World Cup Coverage to Spread Political Disinformation A fact-check published by Euronews states that coordinated campaigns exploiting 2026 World Cup coverage deployed AI-generated synthetic media across X, Facebook, Instagram, Threads, Reddit, and Bluesky in English, Spanish, and Russian, targeting multiple political audiences simultaneously using fabricated imagery designed to circulate within the high-engagement environment of a major global sporting event. Documented examples include falsely attributed images depicting UK Prime Minister Keir Starmer in Croatian fan attire and Israeli Prime Minister Netanyahu attending tournament matches, with the Starmer imagery derived from repurposed 2024 UEFA Championship footage, as well as a fabricated image of an Iranian player holding a pink backpack as tribute to casualties from a February 2026 airstrike, in which the depicted individual was not a member of Iran's squad, wore incorrect kit, and appeared in a stadium that did not match the actual match venue. A fact-check published by Euronews states that verification teams employed two primary methods: reverse image searching for source authenticity and OpenAI's SynthID watermark detection, a technical marker embedded in AI-generated or manipulated images confirming artificial origin. One fabricated image accumulated 3 million views before verification could achieve comparable reach, illustrating the fundamental asymmetry between disinformation amplification velocity and debunking capacity that cognitive warfare operations systematically exploit. Euronews assesses these campaigns as demonstrating a broader operational pattern in which major international sporting events serve as optimal disinformation vectors due to high ambient engagement, multilingual audience reach, reduced critical evaluation thresholds, and the availability of emotionally resonant imagery that can be easily manipulated to carry political narrative payloads alongside organic sports content. Source: Euronews. Fact Check: Were You Fooled by These AI-Generated Images of the World Cup? [online] Published 26 June 2026. Available at: https://www.euronews.com/my-europe/2026/06/26/fact-check-were-you-fooled-by-these-ai-generated-images-of-the-world-cup Top Of Page Coordinated Deepfake Ad Campaigns Impersonate Football Stars An investigation published by Revelum states that at least 10,000 deepfake scam advertisements impersonating professional football players were identified over 12 months, with 2,736 confirmed ads across six players and campaign intensity rising sharply during the 2026 World Cup, Luis Diaz experiencing a 413% surge in daily ad volume, Neymar a 1,700% increase from his baseline, and Cristiano Ronaldo reaching 8.1 ads per day during the tournament. The operations follow a standardised template that repeats across different players and countries: a fabricated local character, a delivery worker, teacher, or single mother, claims improbable financial returns through the targeted player's supposed investment app or platform, with player names, local currency, and media branding swapped while the narrative structure, psychological pressure elements, and urgency language remain identical. An investigation published by Revelum states that three consistent tactical elements appear across nearly all documented campaigns: fabricated authority narratives using local characters designed to interrupt user scrolling before critical evaluation occurs; borrowed credibility through fake news broadcasts mimicking legitimate national media aesthetics such as Colombia's Noticias Caracol or institutional bank notifications from entities including Banco Pichincha in Ecuador; and deliberate urgency manufacturing using the phrase 'This offer is only available for the next 72 hours' appearing verbatim across multiple campaigns. Revelum's analysis identifies the reuse of identical app names, Joker Jewels appearing in both James Rodriguez and Luis Diaz campaigns, shared narrative structures, and synchronised urgency tactics as evidence of centralised operations with significant advertising infrastructure budgets, and assesses the underlying deepfake tooling and social media network architecture as reusable across sectors and public figures well beyond football, representing a scalable threat to institutional trust and individual financial security. Source: Revelum. World Cup, World Scam: The Deepfake Ads Impersonating Football Stars During the 2026 FIFA World Cup. [online] Published 2 July 2026. Available at: https://revelum.ai/insights/world-cup-deepfake-scam-ads-2026/ Top Of Page AI-Generated Hypersexualised Content Targets World Cup Fandoms Across Seven Countries An analysis published by EDMO states that social media platforms experienced widespread distribution of unlabelled AI-generated images depicting hypersexualised female football supporters across multiple national team fandoms, with fact-checking organisations across Belgium, Germany, Argentina, Switzerland, Mexico, Spain, and Brazil identifying fabrications, indicating coordinated cross-platform distribution rather than isolated incidents. The primary monetisation mechanism identified by EDMO is platform revenue optimisation: content creators generate income through viral engagement on platform monetisation programmes before redirecting audiences to secondary platforms, including paid subscription services, with the synthetic content designed to attract engagement through sexual appeal while functioning as audience-capture infrastructure. An analysis published by EDMO states that investigations have documented a dual-use pattern in which AI-generated hypersexualised content serves both commercial monetisation objectives and political distribution ends, with prior documented cases showing the same infrastructure used to attract and lure users into networks that disseminate far-right nationalist political propaganda and xenophobia mixed with soft-core pornography. EDMO identifies measurable psychological and social harms from this content type, including unrealistic expectations among young male audiences and documented links to anxiety and depression among female audiences who do not conform to AI-generated beauty standards, and documents a platform enforcement asymmetry in which sexualised AI content is tolerated at scale while other forms of World Cup disinformation are removed, suggesting that inconsistent moderation policy creates structural opportunities for actors using synthetic sexual content as an influence operation delivery mechanism. Source: European Digital Media Observatory (EDMO). The World Cup of Hypersexualized Fakes? [online] Published 26 June 2026. Available at: https://edmo.eu/publications/the-world-cup-of-hypersexualized-fakes/ Top Of Page [General Reports] Domestic and Chinese Influence Networks Simultaneously Target Philippine Facebook Pages An investigation published by DFRLab states that two distinct coordinated inauthentic behaviour (CIB) networks simultaneously targeted the same Filipino activist Facebook pages in 2026 with opposing strategic objectives: a domestic state-aligned operation conducting red-tagging to publicly associate leftist organisations including the League of Filipino Students and Kilusang Mayo Uno with the Communist Party of the Philippines, while Chinese Spamouflage profiles used the identical activist pages as comment sections to distribute anti-Marcos government narratives and amplify political opposition messaging. The domestic operation was assessed with moderate confidence to be linked to the 2nd Civil-Military Operations Battalion of the Armed Forces of the Philippines, based on circumstantial evidence including military account engagement patterns and profiles displaying Civil-Military Operations insignia, with six interconnected Facebook pages created between February and April 2026 serving as content hubs. An investigation published by DFRLab states that the Chinese Spamouflage component, 50 profiles identified across the activist pages, part of a broader multi-platform operation attributed to Chinese law enforcement, employed AI-generated imagery and formulaic comments addressing government corruption, unverified claims about President Marcos's health, and political rivalries, with some accounts posting material calling for more Molotov cocktails during protest activity. DFRLab identifies the convergence as revealing a critical platform enforcement vulnerability: a single post by Kilusang Mayo Uno received simultaneous comments from both networks pursuing contradictory objectives, demonstrating that identical infrastructure and activist Facebook pages can be weaponised by uncoordinated state and foreign actors pursuing unrelated strategic goals, multiplicatively degrading information ecosystem integrity while the platform enforcement gap that allowed Meta's 2020-era takedown targets to reconstitute remains unaddressed. Source: Digital Forensic Research Lab (DFRLab). Two Coordinated Networks, One Domestic, One Foreign, Target the Same Philippine Facebook Pages. [online] Published 30 June 2026. Available at: https://dfrlab.org/2026/06/30/two-coordinated-networks-one-domestic-one-foreign-target-the-same-philippine-facebook-pages/ Top Of Page Finland Nuclear Weapons Disinformation and Australian Fake News Network Documented A digest published by The Disinformation Observer states that a false claim posted by an X account named Megatron_ron on June 27th 2026 asserted that 'President Sipila' approved importing and storing nuclear weapons in Finland, fabricating both the signatory's identity and the law's scope, as it was President Alexander Stubb who signed the amendment on June 26th 2026, and the law explicitly forbids manufacture and detonation of nuclear weapons, with the government stating no peacetime deployment is planned. The digest assesses the operation as exploiting a real parliamentary vote of 125 to 61 on June 17th to anchor false claims, using mushroom-cloud imagery and BREAKING framing for engagement amplification, in a context where only 18% of Finns support nuclear deployment domestically, representing a structurally exploitable public vulnerability that information operations can activate without requiring a credible underlying claim. A digest published by The Disinformation Observer states that the same reporting period documented an Australian coordinated inauthentic behaviour operation in which three Facebook pages impersonating The Australian, Australia Times, and The Australian Bulletin fabricated political stories from March 2026, with one post falsely claiming that politician Pauline Hanson collapsed in parliament and prompting genuine constituents to contact her office. Attribution identified 12 operators based in Vietnam and one in Indonesia managing the pages through Vietnamese page-management services FbTarget and Bee Up, with the pages having inherited audiences from prior life as soap-opera fan pages to lend false legitimacy, a case the digest classifies as financially motivated coordinated inauthentic behaviour with operators directing traffic for advertising revenue, illustrating how automation and AI-generated content have reduced production costs to a level that enables commercial actors to conduct sustained brand impersonation operations without ideological motivation. Source: The Disinformation Observer. This Week in Disinformation: 28 June 2026. [online] Published 28 June 2026. Available at: https://thedisinformationobserver.substack.com/p/this-week-in-disinformation-28-june (thedisinformationobserver.substack.com). Top Of Page Google GTIG and FBI Disrupt NetNut Proxy Botnet Controlling Two Million Devices A report published by BleepingComputer states that a coordinated operation involving Google's Threat Intelligence Group (GTIG), the FBI, Lumen Technologies, and The Shadowserver Foundation disrupted NetNut, also known as Popa, a residential proxy botnet controlling approximately 2 million compromised devices globally, including Android phones, smart TVs, and streaming boxes hijacked through trojanised applications and the Badbox 2.0 botnet. Google's analysis identified 316 distinct threat clusters using suspected NetNut exit nodes within a single week, encompassing both cybercriminal and espionage operations, with the service's robust reseller programme enabling whitelabelling that made it one of the largest proxy networks serving hundreds of threat actors seeking to route malicious traffic through residential IP addresses to obscure operational attribution. A report published by BleepingComputer states that enforcement actions included Google disabling command-and-control accounts on its infrastructure, using Google Play Protect to automatically warn users and disable infected applications, and the FBI seizing the netnut.com domain, while technical infrastructure details were distributed to law enforcement and cybersecurity researchers to enable ongoing monitoring. BleepingComputer notes that the disruption represents part of a broader systemic challenge: the proxy industry operates through interconnected reseller networks where operators purchase and redistribute botnet capacity, meaning disruption of a major provider typically forces threat actors to migrate to competing services rather than cease operations entirely, a structural limitation of infrastructure-level takedowns that leaves the underlying demand and operational incentives for residential proxy abuse unchanged. Source: BleepingComputer. NetNut Proxy Network Disrupted, 2 Million Infected Devices Cut Off. [online] Published 3 July 2026. Available at: https://www.bleepingcomputer.com/news/security/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off/ Top Of Page AI Deepfakes, Bots, and Sockpuppet Networks An analysis published by Memesita states that the 2026 FIFA World Cup has attracted coordinated disinformation operations using three primary AI-enabled tactics: synthetic media fabrications of players and officials designed to carry geopolitical narrative payloads, automated bot amplification systems disseminating false content across social platforms faster than fact-checking infrastructure can respond, and sockpuppet networks blending fabricated political grievances with legitimate sports commentary to evade detection. The analysis identifies the global audience scale of the tournament, spanning multiple geopolitical fault lines across North America, Europe, and the Middle East, as structurally optimal for influence operations seeking simultaneous multilingual reach and reduced critical evaluation thresholds among entertainment-focused audiences. An analysis published by Memesita states that the tournament environment creates a secondary vulnerability through what the article terms the Liar's Dividend: as deepfake synthetic media involving football players and officials becomes more widely circulated, actors gain increasing capacity to dismiss genuine documentation or evidence as AI-generated, creating conditions for epistemic collapse that undermine accountability mechanisms in both sports and political contexts. Memesita acknowledges significant uncertainty regarding conversion rates, noting that it is currently unclear how much of this disinformation successfully alters the perception of the tournament among casual viewers, a limitation that reflects the broader measurement challenge in assessing influence operation effectiveness, in which the volume and velocity of disinformation output can be quantified while the cognitive impact on target audiences remains difficult to isolate from ambient political conditions. Source: Memesita. 2026 World Cup Faces Surge in AI Disinformation and State Propaganda. [online] Published 3 July 2026. Available at: https://www.memesita.com/2026-world-cup-faces-surge-in-ai-disinformation-and-state-propaganda/ (memesita.com). Top Of Page HAARP Conspiracy Surges to 134,000 Mentions A report published by NewsGuard states that as devastating twin earthquakes struck Venezuela and extreme heat scorched Europe in late June 2026, mentions of HAARP, the High-frequency Active Auroral Research Program, a US ionospheric research facility in Alaska, surged from 16,200 to 134,000 per week, a roughly eightfold increase driven by viral social media posts attributing both natural disasters to deliberate US government weaponisation of weather and seismic conditions. A 25th June post on X from a Mexico-based account asserted that 'The United States used its HAARP system against Venezuela to destroy its infrastructure. To more easily plunder its oil,' accumulating 60,000 views and 1,000 likes, while a 28th June French-language TikTok video claimed HAARP was 'a project aimed at controlling natural phenomena such as tsunamis, heat, wind, rain, earthquakes, etc.' across multiple countries. A report published by NewsGuard states that HAARP director Jessica Matthews directly refuted the claims, stating the facility cannot generate or amplify weather events or earthquakes, with a University of Colorado-Boulder research scientist adding that HAARP's radio waves penetrate less than 1 centimetre into the ground while earthquakes typically originate miles below the surface, a physical incompatibility that directly contradicts the conspiracy's mechanism. The Venezuela earthquakes originated 6 and 13 miles below the surface, triggered by the shifting of the Caribbean and South American tectonic plates. NewsGuard situates the surge within a documented pattern in which catastrophic natural events reliably activate deep-state conspiracy frameworks, with HAARP serving as a persistent attribution target since its construction in the 1990s, a pattern that represents a structurally exploitable vulnerability in crisis information environments, where attribution pressure, grief, and political grievance combine to reduce critical evaluation thresholds precisely when accurate situational information is most consequential. Source: NewsGuard Reality Check. Blaming the Deep State for Earthquakes and Heatwaves. [online] Published 30 June 2026. Available at: https://www.newsguardrealitycheck.com/p/blaming-the-deep-state-for-earthquakes Top Of Page [Appendix - Frameworks to Counter Disinformation] EU AI Act Code of Practice Signatories Ahead of August Enforcement An article published by ActReady states that providers and deployers of generative AI systems subject to Article 50(2) or 50(4) of the EU AI Act have until 22 July 2026 at 18:00 CEST to sign the Code of Practice on Transparency of AI-Generated Content, with initial signatories receiving the presumption of conformity, a legal benefit that shifts the compliance burden by allowing organisations to reference the Code rather than independently constructing arguments demonstrating that their approach satisfies transparency requirements. The deadline is structurally significant because Article 50 transparency obligations become directly enforceable from August 2nd 2026, meaning organisations that sign after 22 July may not have the presumption established before enforcement begins and will not appear on the initial published signatory list. An article published by ActReady states that eligible parties include providers of generative AI systems capable of producing synthetic audio, image, video, or text, as well as deployers who use such systems to publish content on matters of public interest, including deepfakes and AI-generated text, and that practical implementation steps involve confirming organisational status as provider, deployer, or both, reviewing the Code's measures for operational feasibility, and integrating compliance work into August 2 readiness planning. ActReady situates the deadline within the broader context of the EU AI Act's phased enforcement schedule, noting that the Code of Practice represents a voluntary mechanism carrying a significant legal incentive, and that organisations already planning to sign have no regulatory or strategic reason to delay submission, a framing that positions the July 22nd deadline as a de facto obligation for any generative AI operator seeking to establish a favourable compliance baseline before the transparency regime becomes fully active. Source: ACT Ready. Want the Presumption of Conformity? You Have Until July 22: EU AI Act Code of Practice Signatory Deadline. [online] Published 22 June 2026. Available at: https://getactready.com/blog/eu-ai-act-code-of-practice-signatory-deadline-july-22 Top Of Page Consumer Deepfake Detection Market Expands An article published by Biometric Update states that three new deepfake detection products launched in June 2026 reflect an expanding market in which detection capability is shifting from enterprise-specific tools toward consumer-accessible platforms, driven by Deloitte projections of generative AI fraud losses reaching USD 40 billion in the United States by 2027. Scam.ai and Qualcomm released Halo, an on-device deepfake detection model for video conferencing on desktop that operates locally without cloud infrastructure and was specifically optimised for Qualcomm-powered devices, with Scam.ai co-founder Dennis Ng stating that on-device processing curbs attacks from the source by eliminating the latency and privacy exposure of cloud-based detection. At the same time, Bitdefender launched RealCheck for Android and iOS, a tool that analyses submitted videos to distinguish malicious deepfakes from satirical content and provides reports on the likelihood of manipulation and deceptive intent, available in 14 countries. An article published by Biometric Update states that South Korea's Korea Internet and Security Agency simultaneously announced 11 new research projects focused on deepfake detection and fraud suppression as part of broader efforts to enable safe personal data use in AI applications, situating the product launches within a government-industry co-investment pattern in which regulatory concern and commercial incentive are converging around detection infrastructure development. Biometric Update assesses these launches as evidence that deepfake detection is transitioning from a specialised enterprise security function toward a consumer necessity, a structural shift driven by the growing accessibility of voice-cloning and facial synthesis tools that have enabled large-scale fraud operations, including the coordinated investment scam deepfake campaigns documented targeting World Cup audiences during the same period, and that the absence of standardised detection benchmarks across national jurisdictions remains a significant gap in the emerging detection ecosystem. Source: Biometric Update. New deepfake detection product launches reflect expanding market. [online] Published 30 June 2026. Available at: https://www.biometricupdate.com/202606/new-deepfake-detection-product-launches-reflect-expanding-market Top Of Page [CRC Glossary] The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult. To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence. As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website. Top Of Page
- China’s Influence War on the EV Market
China’s Influence War on the EV Market: As economies digitize, cyber influence operations increasingly target financial systems, supply chains, and intellectual property. Emerging actors like "influence mercenaries" blur state and private aggression, as seen with China's robust response to Western tariffs on its EV market. Using state media, influencers, and bots, China counters criticism and promotes its economic dominance, showcasing the growing role of digital influence in global power dynamics.
- Cyber based influence campaigns 22nd – 28th June 2026 Report
[Introduction] Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW). Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc. During the 22nd to the 28th of June 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities. [Contents] [Introduction] [Report Highlights] [Report Summary] [Social Media Platforms] X False Claims about Alberta Government Published by X Influencer [State Actors] Russia Russia's Wiki Warfare Tries to Distort Reality, Documents Show Russia Intensifies Shadow War to Undermine Support for Ukraine Russia Expanding Soft Power in Georgia via Culture and Language Ukraine Russian Disinformation Takes Aim at Poland-Ukraine Rift Russia Tweaks Language to Deceive the West New EEAS-CCD Report Exposes Russian FIMI Targeting Ukraine's EU Future Russian False Military Claims as Battlefield Gains Slow China Countering Disinformation Could Anchor Australia-Japan Intelligence Cooperation Chinese Network Launches Hundreds of Fake Accounts to Influence the Next Taiwanese Election [AI Related Articles] Tracking AI-Enabled Misinformation Disinformation in 2026 Forum Documents How Influence Operations Scale Through AI Enhancement Big Brands Fund AI Slop Africa Is Not Ready for Malicious AI Swarms on Its Prime News Source [General Reports] Trust in Media 2026 Longtime Exxon Legacy of Climate Denial and Misinformation BLF Propaganda Efforts Under Akhtar Nadeem's Leadership Disinformation in the Western Balkans Disinformation Elicits Learning Biases [Appendix - Frameworks to Counter Disinformation] NewsGuard Launches First AI Chatbot Built to Deliver Trusted Journalism An Intelligence-Led Mission Approach for Australia-Japan Cooperation Evaluating Mexico's New Cybersecurity Plan The Opposite of America's AI Problem Is Happening in Brazil Cate Blanchett's Free Tool Helps Protect Identity from Being Deepfaked Youth Facing Disinformation [CRC Glossary] [ Report Highlights] Leaked files from Russia's Social Design Agency reveal Project 2026, a plan to build fake Wikipedia-style sites, phony think tanks, and fabricated media outlets to shape how AI models and search engines understand political issues, run with consultant-style performance targets and achieving up to 86 million views per fabricated story. The Kyiv Independent documents how Russia's Matryoshka bot network exploited an active political dispute between Poland and Ukraine over a UPA unit title on 22 June to spread fabricated claims invoking Nazism and a fake statement attributed to the Auschwitz-Birkenau Museum director, using false logos of Euronews, Der Spiegel, and ISW. A joint EEAS-CCD report documented Russian FIMI systematically targeting Ukraine's EU accession path, with approximately 244,000 publications generating 1.39 billion views between January 2025 and May 2026, deploying a structured network of state and state-linked assets to portray Ukraine as incompatible with European values and EU membership as costly and risky for both parties. NewsGuard identified a network of 294 coordinated Threads accounts posing as Taiwanese-targeted dating profiles in what researchers assess as pre-positioning ahead of Taiwan's November 2026 local elections, with 40% of accounts following naming patterns associated with a prior network that spread narratives critical of Taiwan's ruling Democratic Progressive Party. NewsGuard's June 2026 AI Tracking Center update documents 3,749 AI Content Farm news websites across 16 languages, 358 directly linked to Russia's Storm-1516 operation, and finds that leading AI chatbots now generate false claims in response to news prompts more than one-third of the time, nearly double the prior-year rate. An eLife study found that exposure to potentially unreliable information strengthened a positivity bias and increased reliance on credible sources, meaning disinformation alters not only what people believe but also the learning mechanisms through which they process subsequent information, increasing the weight placed on positive feedback from trusted sources. Brazil enters October 2026 elections with one of the world's most detailed AI election governance frameworks, including a deepfake ban, mandatory AI content labelling, and candidate-ranking restrictions, while Cate Blanchett presented the Human Consent Registry at the European Parliament on 24 June. Mexico unveiled a National Cybersecurity Plan specifically identifying AI-enabled disinformation as a primary threat. [ Report Summary] DisinfoWatch identified a U.S. based X account with 678,000 followers promoting unsupported claims against Alberta's provincial government, including assertions linking officials to criminal child trafficking, misleading claims about Premier Smith's role in vaccine-related employment policies, and a false claim that Albertans will never receive a genuine independence referendum, despite a provincial referendum being scheduled for October 19th, 2026. Leaked files from Russia's Social Design Agency reveal Project 2026, a plan to build fake Wikipedia-style sites, phony think tanks, and fabricated media outlets to shape how AI models and search engines understand political issues, run with consultant-style performance targets and achieving up to 86 million views per fabricated story. An Atlantic Council analysis documents Russia's expanding hybrid warfare campaign against Western democracies, combining sabotage, cyber operations, election interference, and weaponised migration in a sustained effort to undermine democratic institutions and weaken Western support for Ukraine, including the documented use of Telegram-recruited assets to conduct arson attacks at properties linked to UK Prime Minister Keir Starmer. A Jamestown Foundation analysis documents a Russian soft power offensive in Georgia conducted through cultural diplomacy, language promotion, and educational programmes, with Russian presidential representative Mikhail Shvydkoy's June 2026 Tbilisi visit framing Russian language initiatives and cultural events as a pathway to restore trust, which Georgian civil society figures assess as promoting narratives designed to normalize a shared Russian Georgian identity. The Kyiv Independent documents how Russia's Matryoshka bot network exploited an active political dispute between Poland and Ukraine over a UPA unit title on 22 June to spread fabricated claims invoking Nazism and a fake statement attributed to the Auschwitz-Birkenau Museum director, using false logos of Euronews, Der Spiegel, and ISW. A Kyiv Post analysis identifies how Russia systematically exploits ambiguous diplomatic language, deploying terms such as 'negotiations,' 'battlefield realities,' and 'neutrality' to reduce Western support for Ukraine while embedding demands for Ukrainian capitulation within the cognitive architecture of international diplomacy. A joint EEAS-CCD report documented Russian FIMI systematically targeting Ukraine's EU accession path, with approximately 244,000 publications generating 1.39 billion views between January 2025 and May 2026, deploying a structured network of state and state-linked assets to portray Ukraine as incompatible with European values and EU membership as costly and risky for both parties. EUvsDisinfo's ongoing disinformation review documents Kremlin-aligned channels promoting false claims of Russian military success, including persistent claims of capturing Kupyansk and Mala Tokmachka that contradicted open-source intelligence and Ukrainian authorities, as Russia's battlefield progress slowed and Ukrainian tactical momentum partially recovered. An ASPI Strategist analysis argues that countering Chinese state-linked disinformation targeting Japan should become a standing mission for Australia-Japan intelligence cooperation, following documented escalation in Beijing's overt influence operations against Tokyo since Prime Minister Takaichi took office in October 2025. NewsGuard identified a network of 294 coordinated Threads accounts displaying signs of inauthentic coordination, including synchronised posting patterns, AI-generated profile images, and naming conventions linked to a prior DPP-critical network, posing as Taiwanese-targeted dating profiles in what researchers assess as pre-positioning ahead of Taiwan's November 2026 local elections. NewsGuard's June 2026 AI Tracking Center update documents 3,749 AI Content Farm news websites across 16 languages, 358 directly linked to Russia's Storm-1516 operation, and finds that leading AI chatbots now generate false claims in response to news prompts more than one-third of the time, nearly double the prior-year rate. An international security forum analysis published on 27 June documents the structural evolution of state-sponsored influence operations as AI integration reshapes campaign architecture, finding that AI enhancement is reducing human resource requirements for large-scale disinformation while simultaneously increasing geographic targeting precision and narrative adaptability. NewsGuard Reality Check documented major brand advertisers including Adobe, Disney, Verizon, and Fox inadvertently funding AI content farms fabricating stories about the disappearance of Savannah Guthrie's 84-year-old mother, through programmatic advertising systems that place ads based on traffic volume rather than editorial standards, with fabricated articles amplified via a network of Facebook pages posting fake breaking-news graphics. Business Day documents that Africa's information environment faces a structurally unaddressed AI disinformation threat through synthetic audio distributed via radio and encrypted messaging platforms, with voice-cloning detection tools performing poorly on African-language audio and existing counter-disinformation frameworks focused almost entirely on text and video content. YouGov's Trust in Media 2026 survey finds trust declined for most of 48 measured U.S. news outlets, with sharply deepening partisan divides, 70% of respondents concerned about deepfakes spreading disinformation, and continued multi-generational fragmentation of the American information environment. An analysis in The Conversation examining the legacy of former ExxonMobil CEO Lee Raymond, who died on 9 June 2026, documents how under Raymond's leadership Exxon directed millions of dollars to climate denial organisations, with over 80% of paid editorial advertisements promoting scientific doubt during a period when the company's own scientists were producing accurate early warming models. A Jamestown Foundation profile of Akhtar Nadeem, also known as Gwahram Baloch, a senior BLF spokesperson and propagandist, documents the organisation's expanded media operations including the publications Ispar and Sarmachar, multilingual video content, and structured messaging addressing AI applications in Baloch armed operations. British Council research finds that young people in the Western Balkans often assess information credibility based on who shared it, familiarity with the source, and 'official-looking' signals rather than through verification, with information overload creating anxiety and distrust, and sharing behaviour driven by social belonging rather than genuine belief in the accuracy of what is being shared. An eLife study found that exposure to potentially unreliable information strengthened a positivity bias and increased reliance on credible sources, meaning disinformation alters not only what people believe but also the learning mechanisms through which they process subsequent information, increasing the weight placed on positive feedback from trusted sources. NewsGuard launched 'NewsGuard AI' on June 25th, the first AI chatbot drawing exclusively from 12,000 editorially vetted sources, backed by a 64,000 false claim guardrail and a 50-50 publisher revenue-sharing model, positioning it as a structural counter-architecture to the AI Content Farm ecosystem NewsGuard has simultaneously been cataloguing. A new ASPI report proposes a formal intelligence-led framework for Australia-Japan counter-disinformation cooperation, recommending dedicated mission leads in both countries' intelligence agencies, joint annual narrative-risk assessments, and crisis simulation exercises targeting Chinese and Russian state-linked information operations. Recorded Future analysis of Mexico's new National Cybersecurity Plan identifies ransomware, AI-enabled disinformation, hacktivism, and state-sponsored cyber activity as primary threats, with the 2026 FIFA World Cup co-hosted by Mexico expected to elevate risks across all four categories significantly. Anchor Change documents Brazil's October 2026 election regulatory framework as one of the world's most detailed, including a deepfake ban in campaign materials, mandatory AI content labelling, restrictions on AI systems recommending candidates, and a 90-day deadline to build a national enforcement tools catalogue, situating Brazil as a reference model for AI election governance. Cate Blanchett introduced the Human Consent Registry at the European Parliament on June 24th 2026, a free tool allowing individuals to record whether AI systems may use their name, image, voice, and other personal attributes, providing a practical consent mechanism in an environment where unauthorised deepfakes and synthetic likenesses have become pervasive. The Council of Europe's Monaco Presidency launched the 'Youth Facing Disinformation: Why Journalists Matter' programme, including a Strasbourg conference, year-long youth working groups, an audiovisual awareness campaign, and EUR 5,000 grants for youth-led projects addressing disinformation, media literacy, journalists' safety, and freedom of expression. [Social Media Platforms] X False Claims about Alberta Government Published by X Influencer An analysis published by DisinfoWatch states that a U.S.-based X account with 678,000 followers promoted a cluster of unsupported claims against Alberta's provincial government, asserting without evidence that the government is controlled by a criminal child-trafficking and money-laundering operation, that Premier Danielle Smith enabled the College of Physicians and Surgeons of Alberta to endanger children and punish unvaccinated health workers, and that Albertans will never receive a genuine independence referendum. DisinfoWatch's analysis identified these claims as presenting a false picture of Alberta's political, medical, and democratic institutions, noting that several allegations are presented without supporting evidence or documentation. An analysis published by DisinfoWatch states that the assertion that Albertans will never have an opportunity to vote on independence is not supported by the current public record; Alberta has scheduled a provincial referendum for 19 October 2026, including a question related to the process for a potential separation referendum. While citizen-led independence initiatives have faced legal and procedural challenges, DisinfoWatch notes that those obstacles do not in themselves demonstrate a coordinated effort to prevent a vote, and that the claims linking Premier Smith to COVID-19 vaccine employment policies are also misleading, as Alberta Health Services implemented and later rescinded those policies before Smith became premier. Source: DisinfoWatch. Florida-Based X Influencer Pushes Baseless Child-Trafficking Claim About Alberta Government. [online]. Published 22 June 2026. Available at: https://disinfowatch.org/disinfo/florida-based-x-influencer-pushes-baseless-child-trafficking-claim-about-alberta-government Top Of Page [State Actors] Russia Russia's Wiki Warfare Tries to Distort Reality, Documents Show An investigation published by Bloomberg states that leaked files from Russia's Social Design Agency (SDA), an entity sanctioned by the United States, the United Kingdom, and the European Union for directing Kremlin disinformation, reveal a plan called Project 2026, which sets out to construct a sprawling network of Wikipedia-style reference sites, phony think tanks, and fake media outlets designed to shape how people and AI language models understand key political issues. The 73 leaked files, spanning May 2023 to April 2026, show the operation is run with the structured discipline of a Western consulting firm, complete with performance targets, case studies, and opinion-tracking systems, a significant evolution beyond the quota-driven approach of earlier Kremlin troll farms. An investigation published by Bloomberg states that a September 2025 assessment of one SDA-produced fabricated story, claiming Ukrainian President Volodymyr Zelensky purchased his mother two apartments in Dubai's Burj Khalifa, showed the story reaching 86 million views, with 10 million attributable to 19 project contractors sharing it on social media. A second fake story about Armenian Prime Minister Pashinyan buying a French villa received 10.6 million views, with internal SDA chat logs documenting how it forced Pashinyan to publicly deny the allegations, demonstrating the operation's ability to translate manufactured narratives into real-world political pressure. Source: Bloomberg. Leaked Files Show Russia’s Plan to Influence AI and Search Results. [online] Published 23 June 2026. Available at: https://www.bloomberg.com/news/features/2026-06-23/leaked-files-show-russia-s-plan-to-influence-ai-and-search-results Top Of Page Russia Intensifies Shadow War to Undermine Support for Ukraine An analysis published by the Atlantic Council states that Russia is conducting an expanding hybrid warfare campaign against Western countries, combining acts of sabotage, cyber operations, election interference, and weaponised migration in a sustained effort to undermine democratic institutions, deepen social divisions, and weaken Western support for Ukraine. The analysis documents an incident in which a Ukrainian citizen was recruited through Telegram by a Russian-linked organiser and convicted in connection with arson attacks at properties linked to UK Prime Minister Keir Starmer, illustrating how Russian handlers use encrypted platforms to recruit and direct assets operating inside Western countries without direct personal contact. An analysis published by the Atlantic Council states that Western intelligence officials and NATO members have assessed Russia's activities as a coordinated campaign to challenge Western societies below the threshold of conventional warfare, combining disinformation operations with physical sabotage and cyber attacks in what analysts characterise as a deliberately ambiguous hybrid strategy. The analysis recommends that governments strengthen cooperation, improve resilience against hybrid threats, and treat disinformation and related influence operations as components of a sustained strategic campaign rather than isolated incidents, requiring doctrine, resources, and inter-agency coordination matched to the persistent, cross-domain nature of the threat. Source: Atlantic Council. Russia Intensifies Shadow War to Undermine Support for Ukraine. [online] Published 23 June 2026. Available at: https://www.atlanticcouncil.org/blogs/ukrainealert/russia-intensifies-shadow-war-to-undermine-support-for-ukraine/ (atlanticcouncil.org). Top Of Page Russia Expanding Soft Power in Georgia via Culture and Language A report published by the Jamestown Foundation states that Russia is expanding its soft power presence in Georgia through cultural diplomacy, language promotion, educational initiatives, and sponsored public events, with presidential representative Mikhail Shvydkoy visiting Tbilisi in June 2026 to lead Russian-sponsored cultural activities framed as a pathway to restore trust between the two countries. Russian officials presented these initiatives as grounded in shared history, language, and civilizational connection, terminology that critics and Georgian civil society figures assess as promoting narratives designed to increase Russian influence and reinforce the concept of a shared Russian Georgian identity. A report published by the Jamestown Foundation states that protests have accompanied several Russian-language and cultural events in Georgia, reflecting public concerns that such activities serve broader political objectives rather than purely cultural ones. The report identifies the promotion of the Russian language through competitions, educational programmes, and outreach to Georgian teachers and youth as a particularly significant dimension of the operation, documenting a pattern in which culturally coded soft power activities operate as a long-term influence infrastructure, gradually normalising pro-Russian narratives within Georgian society while maintaining plausible deniability as civilian cultural exchange. Source: The Jamestown Foundation. Russia Expanding Soft Power in Georgia via Culture and Language. [online] Published 25 June 2026. Available at: https://jamestown.org/russia-expanding-soft-power-in-georgia-via-culture-and-language/ Top Of Page Ukraine Russian Disinformation Takes Aim at Poland-Ukraine Rift A fact-check published by the Kyiv Independent states that the Matryoshka bot network deployed fake social media posts on 22 June 2026 exploiting a Polish Ukrainian political dispute over a military unit being granted a title honouring the World War II-era Ukrainian Insurgent Army (UPA), presenting the rift as evidence of rampant 'Nazism' among Ukrainian elites. The operation, detected by the Antibot4Navalny monitoring group, fabricated a statement by Piotr Cywinski, a Polish historian and director of the Auschwitz-Birkenau State Museum, falsely claiming he called for barring President Zelensky from Holocaust commemoration events. A fact-check published by the Kyiv Independent states that Matryoshka posts employed a signature technique of the operation: overlaying fabricated text on unrelated stock footage while attaching the logos of Euronews, Der Spiegel, and the Institute for the Study of War (ISW) to lend false credibility. The bot network generated approximately 30,000 views per post on X, though Antibot4Navalny noted that Matryoshka routinely inflates view counts, making authentic reach difficult to establish, a deliberate component of the operation's strategy to create the impression of organic widespread resonance for manufactured narratives targeting EU and NATO audiences. Source: Kyiv Independent. Fact Check: Russian Disinformation Takes Aim at Poland-Ukraine Rift. [online] Published 23 June 2026. Available at: https://kyivindependent.com/fact-check-russian-disinformation-takes-aim-at-poland-ukraine-rift/ Top Of Page Russia Tweaks Language to Deceive the West An analysis published by Kyiv Post states that Russia's use of the word 'negotiations' functions as a systematic cognitive warfare instrument, with Moscow openly stating readiness for 'talks' while simultaneously insisting on conditions amounting to Ukrainian capitulation, including permanent NATO exclusion, severe military limitations, and Ukrainian recognition of territories seized by illegal referendum. The analysis identifies how Russian officials deploy terms such as 'battlefield realities' and 'neutrality' to generate Western pressure on Kyiv while insulating Moscow from accountability for blocking any genuine ceasefire process. An analysis published by Kyiv Post states that the Kremlin's linguistic manipulation extends to framing Russian-installed collaborators in occupied Ukraine as 'separatists', a term that implies popular local agency rather than externally imposed occupation, and deploying the phrase 'special military operation' to deny the legal and moral character of a full-scale war of aggression. The analysis argues that Western actors who adopt Kremlin framing uncritically enable the information operation, as the repeated use of Russian-defined terms shapes the cognitive architecture within which policy options are evaluated, gradually shifting the perceived space of legitimate responses away from Ukrainian sovereignty. Source: Kyiv Post. OPINION: ‘Negotiations’ Are Traps – How Russia Tweaks Language to Deceive the West. [online] Published 28 June 2026. Available at: https://www.kyivpost.com/opinion/78980 (kyivpost.com). Top Of Page New EEAS-CCD Report Exposes Russian FIMI Targeting Ukraine's EU Future An article published by EUvsDisinfo states that a joint analytical report by the European External Action Service and Ukraine's Centre for Countering Disinformation documented how Russian Foreign Information Manipulation and Interference (FIMI) operations are systematically targeting Ukraine's path towards European Union membership, with monitors observing approximately 244,000 publications on Ukraine's accession between January 2025 and May 2026 generating a combined 1.39 billion views. The report identifies a structured network of state, state-linked, and aligned information assets promoting recurring narratives that portray Ukraine as incompatible with European values, depict accession as an elite-driven process detached from public interests, and frame EU membership as costly and risky for both parties. An article published by EUvsDisinfo states that Russia views Ukraine's integration into the EU as a direct threat to its regional influence, and has deployed coordinated information activities within a broader hybrid campaign that exploits fears related to corruption, security, identity, and economic costs through AI-enabled content production, cross-platform amplification, and information laundering. The report calls for closer cooperation between Ukraine, the EU, and international partners through information sharing, strategic communication, digital regulation, sanctions, and resilience-building initiatives, situating counter-FIMI policy as a structural requirement of the EU enlargement process rather than a peripheral security measure. Source: EUvsDisinfo. New EEAS-CCD Report Exposes Russian FIMI Targeting Ukraine’s EU Future. [online] Published 23 June 2026. Available at: https://euvsdisinfo.eu/new-eeas-ccd-report-exposes-russian-fimi-targeting-ukraines-eu-future/ (euvsdisinfo.eu). Top Of Page Russian False Military Claims as Battlefield Gains Slow A review published by EUvsDisinfo states that as Russia's battlefield gains have slowed and Ukraine has regained some tactical momentum, Kremlin-aligned information channels have increasingly promoted exaggerated or false claims of military success, including persistent claims of the capture of Ukrainian towns such as Kupyansk and Mala Tokmachka that persisted despite reports from Ukrainian authorities and open-source intelligence indicating both locations remained under Ukrainian control. At the same time, Russian information operations sought to shape perceptions of Ukrainian strikes on Russian military logistics and energy infrastructure by portraying them as attacks on civilians and evidence of Western escalation. A review published by EUvsDisinfo states that pro-Kremlin outlets portrayed Ukrainian strikes as targeting civilians and as evidence that Ukraine is unwilling to pursue peace, while some Russian officials simultaneously acknowledged that many strikes were aimed at military supply networks rather than civilian targets, demonstrating the internally inconsistent nature of the information campaign, which prioritises domestic audience management and Western perception shaping over factual coherence. The analysis situates these information efforts within a pattern of Russian operational communication increasingly designed to manage public perceptions of the war as Russia faces mounting casualties and diminishing battlefield returns, rather than to accurately inform either Russian or international audiences. Source: EUvsDisinfo. Still at War: Russia’s Disinformation Targeting Ukraine. [online] Published 25 June 2026. Available at: https://euvsdisinfo.eu/still-at-war-russias-disinformation-targeting-ukraine/ (euvsdisinfo.eu). Top Of Page China Countering Disinformation Could Anchor Australia-Japan Intelligence Cooperation An analysis published by ASPI's The Strategist states that Australia and Japan are both targets of state-linked disinformation campaigns designed to exploit historical grievances, domestic political divisions, and alliance anxieties, with Beijing ratcheting up its information operations against Japan significantly since Sanae Takaichi became Prime Minister in October 2025. The analysis documents an information offensive conducted through overt propaganda channels, including Chinese state media, as well as through networks of social media influencers, inauthentic accounts, and bots amplifying Beijing's narratives across the regional information environment. An analysis published by ASPI's The Strategist states that Beijing's reaction to Japan's May 2026 intelligence reforms demonstrates that even legitimate democratic governance measures will be contested in the information domain, with Chinese state media and diplomatic accounts coordinating campaigns to portray the reforms as destabilising. The analysis recommends that mission leads be appointed in Australia's Office of National Intelligence and Japan's newly established National Intelligence Agency, alongside a standing bilateral forum on information integrity producing annual narrative-risk assessments and crisis simulations, positioning counter-disinformation as a structural feature of the alliance rather than an ad hoc response to individual incidents. Source: Australian Strategic Policy Institute (ASPI). Countering Disinformation Could Anchor Australia–Japan Intelligence Cooperation. [online] Published 26 June 2026. Available at: https://www.aspistrategist.org.au/countering-disinformation-could-anchor-australia-japan-intelligence-cooperation/ Top Of Page Chinese Network Launches Hundreds of Fake Accounts to Influence the Next Taiwanese Election A report published by NewsGuard states that a network of 294 coordinated Threads accounts displaying multiple signs of inauthentic coordination, including similar naming conventions, synchronised posting patterns, identical profile content, and repurposed or AI-generated images, has been operating as attractive Asian women seeking relationships with Taiwanese men, with researchers assessing the accounts as positioned to build audiences and credibility ahead of Taiwan's November 2026 local elections. The network shares characteristics with previously identified China-linked influence operations targeting Taiwan, with 40% of accounts following naming patterns associated with a network that previously spread narratives critical of Taiwan's ruling Democratic Progressive Party. A report published by NewsGuard states that account location data, cultural inaccuracies in posts about Taiwan, and posting schedules aligned with standard working hours in China indicate the operators are likely based outside Taiwan. The analysis assesses the accounts as designed to establish relationships, collect audience information, and build online reach before potentially being deployed to amplify coordinated messaging around politically significant events, a well-documented tactic in which networks established as socially benign are repurposed for political influence operations once they have accrued sufficient followers and engagement history to avoid rapid platform detection. Source: NewsGuard Technologies. Chinese Network Launches Hundreds of Fake Dating Accounts to Influence the Next Taiwanese Election. [online] Published 24 June 2026. Available at: https://www.newsguardtech.com/special-reports/chinese-network-launches-hundreds-of-fake-dating-accounts-to-influence-the-next-taiwanese-election/ (newsguardtech.com). Top Of Page [AI Related Articles] Tracking AI-Enabled Misinformation A report published by NewsGuard states that its AI Tracking Center, updated 23 June 2026, has identified 3,749 AI Content Farm news and information websites operating across 16 languages, sites that use AI tools to produce substantial volumes of content without disclosure, presenting synthetic material as human-authored journalism. The center identifies 358 of these sites as directly linked to Storm-1516, a pro-Russian influence operation that creates fabricated content on sites designed to resemble local newspapers in the United States and Europe, targeting audiences unlikely to encounter mainstream fact-checking. A report published by NewsGuard states that an audit of the 10 leading generative AI tools found the rate of generating false claims in response to news prompts has nearly doubled, with AI chatbots now providing false information more than one-third of the time. NewsGuard confirmed specific instances, including an AI-edited image purportedly showing an Iranian missile (the original predating the March 2026 conflict) and images circulating as purported photographs of Venezuelan leader Nicolas Maduro that in fact depicted former Iraqi President Saddam Hussein from December 2003, illustrating the compounding risk created when AI models are trained on or cite content originating from adversarial AI Content Farms. Source: NewsGuard Technologies. Tracking AI-Enabled Misinformation: 3,749 AI Content Farm Sites (and Counting), Plus the Top False Claims Generated by Artificial Intelligence Tools. [online] Last updated 23 June 2026. Available at: https://www.newsguardtech.com/special-reports/ai-tracking-center/ (newsguardtech.com). Top Of Page Disinformation in 2026 Forum Documents How Influence Operations Scale Through AI Enhancement A report published by the Center for Foreign Interference Research states that a 25 June 2026 international security forum analysis revealed that the integration of artificial intelligence tools into influence operation architectures is producing a structural shift in how state-sponsored disinformation campaigns are designed and executed, with AI enabling smaller operational teams to produce higher volumes of contextually tailored content targeting multiple geographic markets simultaneously. The forum documentation identifies this as a departure from earlier volume-over-precision models, with AI enhancement allowing operators to embed narratives within organic public debates rather than relying on identifiable high-volume posting patterns that platform moderation tools are calibrated to detect. A report published by the Center for Foreign Interference Research states that the forum also documented coordinated foreign campaigns deliberately exploiting dormant inter-state conflicts and ethnic tensions across post-Soviet states to sow discord, a tactic that AI enhancement makes more scalable by enabling rapid localisation of destabilising narratives for different linguistic and cultural contexts within the same operational deployment. The forum findings position AI-augmented influence operations as a compounding threat in the run-up to the 2026 U.S. midterm elections and ongoing European electoral cycles, where reduced attribution confidence and increased content volume are simultaneously degrading the effectiveness of platform-level moderation responses. Source: Foreign Interference Research Center. Disinformation in 2026 Forum Documents How Influence Operations Scale Through AI Enhancement. [online] Published 25 June 2026. Available at: https://www.foreigninterference.org/post/disinformation-in-2026-forum-documents-how-influence-operations-scale-through-ai-enhancement (foreigninterference.org). Top Of Page Big Brands Fund AI Slop A report published by NewsGuard's Reality Check states that major brand advertisers including Adobe, Disney, Verizon, and Fox had advertisements running on AI-generated content farm websites publishing fabricated stories about the disappearance of Nancy Guthrie, the 84-year-old mother of Today show co-anchor Savannah Guthrie, sites that produced false claims about FBI breakthroughs, new evidence, and alleged family involvement in the case despite authorities having cleared relatives. The fake articles were engineered to capitalise on public interest in a high-profile missing-person case while generating advertising revenue through programmatic advertising systems that place brand ads on content regardless of veracity. A report published by NewsGuard's Reality Check states that traffic to the fabricated stories was amplified through a network of apparently connected Facebook pages that post fake breaking-news graphics directing users to AI-generated sites, and that the operation may be operated from Vietnam, though ownership could not be confirmed. NewsGuard identifies the case as illustrating a systemic business model in which AI content farms produce fabricated or misleading stories about high-profile topics to attract clicks and monetise audience attention through advertising, a model that is financially self-sustaining as long as programmatic ad systems route advertising budgets to content based on traffic volume rather than editorial standards. Source: NewsGuard Reality Check. Big Brands Fund AI Slop. [online] Published 22 June 2026. Available at: https://www.newsguardrealitycheck.com/p/big-brands-fund-ai-slop (newsguardrealitycheck.com). Top Of Page Africa Is Not Ready for Malicious AI Swarms on Its Prime News Source An analysis published by Business Day states that Africa's information environment faces growing risks from AI-enabled disinformation distributed through audio content on radio and encrypted messaging platforms, creating a significant gap in existing defences against emerging threats because global counter-disinformation efforts have largely focused on social media and text-based content while radio remains the primary news source for many Africans, particularly in rural communities, among women, and among people with limited digital access. Synthetic audio can exploit trusted communication channels to spread false narratives, influence elections, and create the illusion of public consensus in environments where voice-cloning technology is increasingly accessible. A report published by Business Day states that recent elections in Nigeria and Ghana demonstrated how misleading audio content circulates rapidly through WhatsApp and other peer-to-peer networks, bypassing traditional moderation and fact-checking mechanisms, and that investment in audio deepfake detection systems designed for African languages and acoustic environments remains limited, with voice-cloning models trained on limited African-language data harder to detect using standard tools built for English, French, and Mandarin. The analysis identifies the growing accessibility of voice-cloning technology as increasing the risk that political figures, community leaders, and public officials can be impersonated to manipulate public opinion, calling for governments, election bodies, media organisations, and fact-checking groups across Africa to strengthen resilience against audio-based disinformation as a priority. Source: Business Day. BIG READ | Africa Is Not Ready for ‘Malicious AI Swarms’ on Its Prime News Source. [online] Published 23 June 2026. Available at: https://www.businessday.co.za/lifestyle/2026-06-23-africas-dominant-news-source-is-underprepared-for-ai-disinformation Top Of Page [General Reports] Trust in Media 2026 A survey published by YouGov states that trust declined for most of the 48 news outlets measured in its 2026 Trust in Media survey, with only a handful making modest gains within the margin of error. The survey identifies sharply defined partisan divides as the dominant structural feature of American media trust, a pattern that limits the capacity of any single outlet or platform to serve as a shared factual reference point across the electorate, creating conditions that state and non-state disinformation actors systematically exploit to widen existing societal fractures. A survey published by YouGov states that 70% of respondents expressed concern that deepfakes would be used to spread disinformation, reflecting a broad awareness of synthetic media threats even as institutional mechanisms for labelling or detecting AI-generated content remain underdeveloped. The survey situates declining media trust within a broader pattern of information environment fragmentation in which generational differences in news consumption habits, platform preferences, and source authority create structurally separate information ecosystems, a condition that disinformation research identifies as increasing vulnerability to targeted influence operations by reducing the shared factual baseline needed to evaluate and reject false narratives collectively. Source: YouGov. Trust in Media 2026: Which News Sources Americans Use and Trust. [online] Published 29 June 2026. Available at: https://yougov.com/en-us/articles/55045-trust-in-media-2026-which-news-sources-americans-use-and-trust (yougov.com). Top Of Page Longtime Exxon Legacy of Climate Denial and Misinformation An article published by The Conversation states that former ExxonMobil CEO Lee Raymond, who died on June 9th 2026, at age 87, left a consequential legacy of spreading doubt about climate change despite his own company's internal scientists having produced some of the most accurate early models of human-caused global warming. Over 80% of Exxon's paid editorial-style advertisements during Raymond's tenure specifically promoted uncertainty and doubt about climate science, and Raymond's 1997 address to the World Petroleum Congress explicitly denied that the world was warming, denied the fossil fuel industry's causal role, and challenged the scientific consensus at a critical juncture in international climate policy formation. An article published by The Conversation states that under Raymond's leadership, Exxon directed millions of dollars to organisations promoting climate denial, establishing a pattern of corporate disinformation that continues to shape public discourse and policy contestation today. The analysis identifies a broad range of persistent narratives used to cast doubt on climate change or its causes, including claims that warming is primarily driven by natural factors, scepticism about links between emissions and extreme weather, and criticism of proposed solutions, and argues that inoculation strategies, critical thinking education, and prebunking are among the most evidence-supported tools for building public resilience to this form of corporate-origin disinformation. Source: The Conversation. Longtime Exxon CEO Lee Raymond’s Legacy of Climate Denial and Misinformation Lives On – A Psychologist Offers Ways to Counter It. [online] Published 22 June 2026. Available at: https://theconversation.com/longtime-exxon-ceo-lee-raymonds-legacy-of-climate-denial-and-misinformation-lives-on-a-psychologist-offers-ways-to-counter-it-285667 Top Of Page BLF Propaganda Efforts Under Akhtar Nadeem's Leadership A report published by the Jamestown Foundation profiled Akhtar Nadeem, also known as Gwahram Baloch, a senior figure and spokesperson for the Balochistan Liberation Front, as part of a broader analysis of how educated and middle-class activists have assumed more prominent leadership roles within the Baloch insurgency. Under Akhtar Nadeem's leadership, the organisation has expanded its propaganda efforts through the publications 'Ispar' and 'Sarmachar,' video content, multilingual messaging, and increasingly structured communication strategies addressing ideological themes, organisational developments, and the use of artificial intelligence in combat operations. A report published by the Jamestown Foundation states that the BLF's expanded media operations reflect a deliberate effort to modernise the organisation's outreach, strengthen its narrative position, and maintain relevance alongside its armed activities, following a strategic communication model in which insurgent groups use professional-grade media production to recruit internationally, shape foreign press coverage, and contest the Pakistani state's information environment. The profiling of Akhtar Nadeem illustrates a pattern identified across multiple insurgent movements in which the combination of educated leadership and sophisticated information operations produces a more durable and harder-to-isolate influence infrastructure than purely tactical communication approaches. Source: The Jamestown Foundation. Briefs Archive. [online] Available at: https://jamestown.org/briefs/ Top Of Page Disinformation in the Western Balkans A study published by the British Council states that young people in the Western Balkans often judge the credibility of information based on who shared it, familiarity with the source, and 'official-looking' signals rather than through detailed verification, reflecting a context in which checking information requires significant time and effort, leading many to rely on trusted friends, family members, influencers, or quick credibility cues, especially when confronted with large volumes of content. Researchers observed that sharing content does not always reflect genuine belief, with young people frequently sharing information for humour, social connection, or group belonging even when uncertain of its accuracy. A study published by the British Council states that information overload is creating confusion, anxiety, and increasing distrust in the Western Balkans information environment, with some participants reporting it has become increasingly difficult to determine what is true, and that the growing presence of AI-generated and manipulated content is further weakening traditional authenticity signals and increasing reliance on source identity and reputation. The research recommends improving media and information literacy, helping users recognise common credibility cues, supporting trustworthy journalism and fact-checking initiatives, and increasing platform transparency and accountability, framing youth information resilience as a structural requirement for democratic health in a region with significant vulnerability to both domestic and externally driven disinformation. Source: British Council. Next Generation What We Know: Mis/disinformation in the Western Balkans. [online] Published June 2026. Available at: https://www.britishcouncil.org/research-insight/next-generation-wwk-rfp-western-balkans Top Of Page Disinformation Elicits Learning Biases A study published by eLife states that an assessment of how people learn and update their beliefs when exposed to potentially false information found that while individuals generally learned more from credible sources, consistent with rational decision-making principles, they also showed important biases when confronted with unreliable information, including continuing to learn from sources known to be unreliable rather than ignoring them entirely. The study also found that exposure to misleading information increased reliance on trusted sources, leading participants to place greater weight on credible feedback than they otherwise would. A study published by eLife states that the presence of unreliable information strengthened a positivity bias, making people more likely to accept positive feedback while discounting negative feedback, and that this pattern suggests disinformation affects not only what people believe but also how they process and learn from subsequent information. By exploiting existing cognitive biases, including cognitive load effects from the effort of filtering non-credible sources, positivity bias, and motivated cognition, misleading information can alter decision-making processes even when people are consciously aware that some sources are untrustworthy, with significant implications for the design of counter-disinformation interventions that must address not just belief content but underlying learning mechanisms. Source: eLife. [Article 106073]. [online] Published 2026. Available at: https://elifesciences.org/articles/106073 (elifesciences.org). Top Of Page [Appendix - Frameworks to Counter Disinformation] NewsGuard Launches First AI Chatbot Built to Deliver Trusted Journalism An announcement published by NewsGuard states that the company launched 'NewsGuard AI' on June 25th, 2026, the first AI chatbot sourcing responses exclusively from 12,000 news and information websites whose editorial processes have been evaluated against nine apolitical journalistic standards. The system incorporates a guardrail trained on 64,000 documented false claims to suppress misinformation and is built on a revenue-sharing model in which publishers receive 50% of subscription fees generated from use of their content, positioning the platform as both a quality information tool and a mechanism to fund journalism from trusted sources. An announcement published by NewsGuard states that the chatbot is designed as a direct architectural response to the AI Content Farm ecosystem the company has simultaneously been cataloguing, in which 3,749 AI-generated content farms pollute the training data and citation pools that standard AI tools draw from. By restricting sourcing to verified publishers and explicitly excluding unreliable AI-generated content, NewsGuard AI represents a structural counter-model to the compounding feedback loop between adversarial content farms and AI hallucination that standard retrieval-augmented generation systems are currently unable to break. Source: NewsGuard Technologies. NewsGuard Launches First AI Chatbot Built to Deliver Trusted Journalism Only from Reliable News Websites. [online] Published 24 June 2026. Available at: https://www.newsguardtech.com/press/newsguard-launches-first-ai-chatbot-built-to-deliver-trusted-journalism-only-from-reliable-news-websites/ (newsguardtech.com). Top Of Page An Intelligence-Led Mission Approach for Australia-Japan Cooperation A report published by ASPI states that a new report for the Australia-Japan security relationship proposes that counter-disinformation be elevated into a standing intelligence mission co-led by Australia's Office of National Intelligence and Japan's newly established National Intelligence Agency, moving beyond ad hoc responses to individual influence operations toward a structural bilateral framework for countering Chinese and Russian state-linked disinformation targeting both countries and their shared strategic interests. The report identifies both Australia and Japan as sustained targets of state-linked information operations designed to exploit historical grievances, domestic political divisions, and alliance anxieties. A report published by ASPI states that the proposed Australia-Japan counter-disinformation framework would include an annual bilateral narrative-risk assessment identifying the most significant information operations threatening alliance cohesion, as well as crisis simulation exercises testing institutional responses to coordinated disinformation events, providing shared operational preparedness infrastructure that neither country currently has in place for the information domain. The report situates the recommendation within a documented escalation of Chinese disinformation operations against Japan since Prime Minister Takaichi's election in October 2025, with Beijing deploying overt state media channels, influencer networks, and inauthentic accounts in a campaign ASPI assesses as part of a broader Chinese strategy to contest Japan's role as a U.S. defence and security partner in the Indo-Pacific. Source: Australian Strategic Policy Institute (ASPI). From Common Threats to Narrative Defence. [online] Published June 2026. Available at: https://www.aspi.org.au/report/from-common-threats-to-narrative-defence Top Of Page Evaluating Mexico's New Cybersecurity Plan An analysis published by Recorded Future states that Mexico has unveiled a National Cybersecurity Plan to strengthen the country's cyber resilience and address threats including ransomware, disinformation, hacktivism, and state-sponsored cyber activity, following a series of cyber incidents affecting government institutions and critical sectors. Ransomware is identified as one of the most significant threats facing Mexican organisations, particularly in the government, healthcare, and financial sectors, and the 2026 FIFA World Cup co-hosted by Mexico is expected to increase cyber risks by creating a target-rich environment for ransomware groups, hacktivists, fraud actors, and disinformation networks. A report published by Recorded Future states that disinformation networks represent a specific risk category in Mexico's cybersecurity landscape, with foreign and domestic actors potentially exploiting major events to spread fabricated narratives that can undermine institutional trust and complicate emergency response. The analysis recommends adopting international cybersecurity standards, improving threat intelligence capabilities, conducting cyber incident exercises, strengthening public awareness and cyber hygiene, and deepening cooperation with international partners, particularly the United States, as Mexico implements new legislation and regulatory frameworks in advance of the FIFA World Cup and the October 2026 electoral period. Source: Recorded Future Insikt Group. Evaluating Mexico's New Cybersecurity Plan. [online] Published 25 June 2026. Available at: https://www.recordedfuture.com/research/mexico-new-cybersecurity-plan-evaluation Top Of Page The Opposite of America's AI Problem Is Happening in Brazil An article published by Anchor Change states that Brazil is entering its October 2026 elections with one of the world's most detailed regulatory frameworks for AI and online political content, including a ban on deepfakes in campaign materials, mandatory labelling of AI-generated content, restrictions on AI systems recommending or ranking candidates, and a blackout period for AI-altered content before voting. Brazil's electoral court has also created a permanent commission on AI in elections and established a 90-day deadline to build a national catalogue of enforcement tools, with a recent study identifying 18 AI-generated political profiles active in Brazil between January 2025 and April 2026, most of which did not disclose their AI nature. An article published by Anchor Change states that uncertainty around how some rules should be interpreted, particularly restrictions on ranking political candidates, has created challenges for AI companies, with some platforms potentially choosing to limit or suspend political AI features rather than risk penalties, raising concerns about reduced access to information during the election period. The analysis situates Brazil's approach within more than a decade of efforts to address online harms, election integrity, and platform accountability, identifying a growing tension between efforts to limit misleading or manipulated content and concerns that overly restrictive or unclear rules could discourage platforms from providing political information altogether, a tension likely to become a reference point for other democracies developing AI election governance frameworks. Source: Anchor Change. The Opposite of America’s AI Problem. [online] Published 25 June 2026. Available at: https://anchorchange.substack.com/p/the-opposite-of-americas-ai-problem (anchorchange.substack.com). Top Of Page Cate Blanchett's Free Tool Helps Protect Identity from Being Deepfaked An article published by CyberNews states that Australian actress Cate Blanchett introduced the Human Consent Registry at the European Parliament on June 24th 2026, a free tool that allows individuals to record whether AI systems may use their name, image, voice, and other personal attributes, or to define consent terms for specific uses, providing a practical mechanism for the growing demand for individual control over AI-generated representations in an environment where unauthorised deepfakes and synthetic likenesses have become pervasive. The platform is designed to be accessible to both individuals and third parties such as agents and managers, and is expected to expand to enable protection of artworks, characters, and brands. A report published by CyberNews states that the Human Consent Registry reflects the convergence of celebrity advocacy, legislative momentum, and public demand for AI identity protections, with governments and regulators in the European Union, Australia, Japan, and the United States increasingly responding to the harm associated with nonconsensual AI-generated content. The initiative addresses the intersection between individual consent rights and information integrity, while the registry's primary function is identity protection rather than disinformation countermeasures; the broader ecosystem of nonconsensual AI-generated representations creates risks for democratic discourse when synthetic media depicting real individuals is used to fabricate statements, manipulate public opinion, or undermine institutional trust. Source: Cybernews. Cate Blanchett Joins the Fight Against Deepfakes. [online] Published 25 June 2026. Available at: https://cybernews.com/ai-news/cate-blanchett-ai/ (cybernews.com). Top Of Page Youth Facing Disinformation An announcement published by the Council of Europe states that Monaco has launched the 'Youth Facing Disinformation: Why Journalists Matter' initiative as part of its 2026 Presidency of the Committee of Ministers, under the broader 'Journalists Matter' campaign for the safety and role of journalists in democratic societies. The programme aims to strengthen media and information literacy among young Europeans navigating an information environment where social media and AI tools blur the distinction between reliable information and misleading content, including through conferences, workshops, debates, and an audiovisual awareness campaign designed to engage young audiences on information overload, conspiracy theories, and disinformation. An announcement published by the Council of Europe states that a major conference in Strasbourg in November 2026 will bring together youth participants, journalists, experts, media organisations, and social media stakeholders to discuss challenges related to reliable information, and will launch year-long youth-led working groups focused on practical projects supporting quality journalism and strengthening resilience against disinformation. The programme includes a grants programme awarding up to four projects of EUR 5,000 each for youth-led initiatives addressing disinformation, media literacy, journalists' safety, and freedom of expression, positioning youth participation not merely as a communications target but as an active structural contributor to the development of information integrity solutions. Source: Council of Europe. Youth Facing Disinformation – Why Journalists Matter. [online] Published June 2026. Available at: https://www.coe.int/en/web/freedom-expression/youth-facing-disinformation-why-journalists-matter Top Of Page [CRC Glossary] The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult. To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence. As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website. Top Of Page
- How Dating Apps Became Vectors for Cyber Attacks and Influence Operations
In recent years, a growing number of documented cases have shown how dating-oriented platforms are consistently being exploited and weaponized by threat actors to deliver both cyber and cognitive threats. Dating platforms are inherently built around the promise of intimate connection through the sharing of personal information. This premise hints at why such platforms may be attractive to state and non-state actors seeking to identify, assess, and exploit potential targets. In this blog, we highlight various recurring uses of dating platforms in today’s hybrid threat landscape, spanning intelligence collection and recruitment, malware delivery, and hostile narrative manipulation. Figure 1 – Kill chain models integrating dating-oriented platforms. Dating Apps as Threat Channels Intelligence Collection and Recruitment According to a recent analysis by EUvsDisinfo, since Russia’s full-scale invasion in 2022, dating apps such as Tinder have reportedly been abused by different actors.[1] Recently, the Ukrainian Ministry of Defense has warned that inauthentic female personas, or accounts posing as law enforcement officials, initiate contact, build trust, collect personal information, and eventually shift toward blackmail or recruitment. The Security Service of Ukraine (SBU) identified similar methods involving fake profiles that gathered information before pressuring targets to cooperate. This kind of activity has also been reported outside Ukraine. Germany’s Military Counterintelligence Service (BAMAD) stated that Russian intelligence operatives used Tinder to target politicians and soldiers. In some cases, recruitment has moved beyond information collection. In July 2025, the SBU arrested a woman who was reportedly recruited through a dating platform and instructed to plant a bomb in a hotel. In November 2025, authorities arrested a man in Nikopol accused of passing Ukrainian defense positions to Russian artillery after being recruited in a similar manner. These recent cases exemplify a repeated pattern: dating apps increasingly serve as effective tools for identifying vulnerable individuals and, in some cases, recruiting them for intelligence purposes. Hostile Influence and Narrative Manipulation In recent years, dating platforms and forums have been increasingly exploited and integrated into influence attack chains. Observed cases have shown attackers utilize seemingly-innocent female personas on social media platforms and dedicated dating sites to garner exposure, proliferate narratives, or generate “source material” that could be leveraged for narrative manipulation. According to the EUvsDisinfo analysis, a fake Tinder account was used in Ukraine in 2018 as part of a campaign against a senior police official.[2] Manipulated screenshots of a private dating conversation were leaked online, triggering public reactions and damaging trust in law enforcement. Another operational model can be found in a recent report by NewsGuard, which uncovered an ongoing PRC-aligned threat activity cluster, targeting Taiwan ahead of the local election expected November 2026. The investigation provides details of “[a] network of 294 coordinated accounts on Meta’s Threads, which launched in May 2026”. NewsGuard’s findings suggest that the identified operational assets are mainly designed to leverage established trust for subsequent narrative amplification. In addition, these sockpuppets can be utilized to study the behavioral patterns of potential targets, before attackers craft and proliferate their political messaging. Figure 2 – An inauthentic Threads dating account targeting Taiwanese users, according to NewsGuard.[3] The overall effectiveness of such tactics stems from the credibility assigned to dating-based interactions. An inauthentic dating account can spread a narrative, illicit sensitive information, lure unsuspecting high-value targets, or social-engineer its way to malicious payload delivery. Malware Delivery The same psychological incentives and trust-based dynamics that make dating apps an effective channel for HUMINT recruitment can also make them effective malware delivery vectors. Research from the Center for Strategic and International Studies (CSIS) documented how the terrorist organization Hamas targeted Israeli soldiers through what local officials called “Operation Broken Heart”.[4] The MO was fairly simple. Threat actors used sockpuppets, pretending to be young attractive women on social media platforms and dating apps. They convinced targeted soldiers to download malicious apps onto their mobile devices. Hamas also reportedly developed fake dating apps specifically for this purpose. Once installed, the malware provided access to cameras, microphones, and location data of the victim’s device. Another similar instance can be found in a 2026 ESET research report.[5] Security researchers identified an Android app called GhostChat circulating in Pakistan. The app resembled a dating platform and presented users with multiple female profiles, each requiring exclusive access credentials. Once installed, the application operated in the background, collecting contacts, files, photographs, and other information from the victim’s device. ESET linked the app to a broader cyber-espionage infrastructure that included fake government websites and WhatsApp-focused scams. Figure 3 – The malicious GhostChat app requiring access codes to unlock chats Conclusion Within the context of sophisticated hybrid threats, such as hostile influence campaigns (HICs) and cyfluence attack chains, dating apps should be considered as largely-unmonitored digital spaces, allowing hybrid threat actors and cyber-criminals to easily exploit a wide array of attack surfaces. Based on current trends in the foreign information manipulation and interference (FIMI) threat landscape, we expect attempts by threat actors to move laterally across social media platforms to persist. Hostile actors are likely to increasingly turn to unmonitored apps, while continuing to operate under the cover of perceived trust and privacy. Influence defense practitioners and cognitive security stakeholders must consider that influence operations may increasingly take place in restricted online spaces that are difficult to monitor. It is therefore crucial to identify and deploy the needed sensors to support ongoing defensive efforts. [References:] EUvsDisinfo. Tough Love: Spies, Dating Apps, and the Dark Side of Online Intimacy. [online] Published 10 June 2026. Available at: https://euvsdisinfo.eu/tough-love-spies-dating-apps-and-the-dark-side-of-online-intimacy/ (euvsdisinfo.eu). NewsGuard Technologies. Chinese Network Launches Hundreds of Fake Dating Accounts to Influence the Next Taiwanese Election. [online] Published 2026. Available at: https://www.newsguardtech.com/special-reports/chinese-network-launches-hundreds-of-fake-dating-accounts-to-influence-the-next-taiwanese-election/ (newsguardtech.com). Center for Strategic and International Studies (CSIS). Understanding Hamas’s and Hezbollah’s Uses of Information Technology. [online] Published 31 July 2023. Available at: https://www.csis.org/analysis/understanding-hamass-and-hezbollahs-uses-information-technology (csis.org). ESET Research. Love? Actually: Fake Dating App Used as Lure in Targeted Spyware Campaign in Pakistan. [online] Published 28 January 2026. Available at: https://www.welivesecurity.com/en/eset-research/love-actually-fake-dating-app-used-lure-targeted-spyware-campaign-pakistan/ (welivesecurity.com).
- Cyber based influence campaigns 15th - 21st June 2026 Report
[Introduction] Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW). Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc. During the 15th to the 21st of June 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities. [Contents] [Introduction] [Report Highlights] [Report Summary] [State Actors] Russia Russian Narrative Adaptation in the Global South Gallant Boar Exercise Falsely Framed as Kaliningrad Invasion The War in Ukraine Putin’s “Denazification” Narrative EU Expands Sanctions Targeting Russian Operations [AI Related Articles] AI-Generated Screenshots Involving Eric Trump Benchmark for Detecting AI-Generated Videos Deepfake Detection in the Post-Artifact Era Deepfakes and Disinformation Targeting West Papua Activists AI Deepfakes Proliferate in 2026 U.S. Midterm Elections Despite Regulatory Efforts [General Reports] False Claims About Hirings at the Obama Presidential Center Reuters Institute Digital News Report 2026 [Appendix - Frameworks to Counter Disinformation] EU Sanctions Over Interference in Moldova Danish Parliamentary Election with No Sign of Significant Disinformation [CRC Glossary] [ Report Highlights] According to an article by Atlantic Council, Russian President Vladimir Putin continues to frame the war against Ukraine through the goal of “denazification”, presenting it as a central war aim rather than a justification for territorial gains. A report by Public First examined AI’s societal perception in 2026 and its potential risks. According to an article by CyberNews, a controversy emerged after UFC commentator Daniel Cormier posted screenshots that allegedly showed messages from Eric Trump asking whether any fights were "rigged" for betting purposes. According to NewsGuard’s Reality Check, in the weeks leading up to the opening of the Obama Presidential Center in Chicago, several conservative social media accounts claimed that the Obama Foundation had hired only Black contractors to work on the project. Foreign Interference documents over 2,800 AI-generated deepfakes deployed in 2026 U.S. midterm election contexts despite the TAKE IT DOWN Act entering FTC enforcement and state-level AI disclosure laws. The Reuters Institute Digital News Report 2026 finds overall news trust at a record low of 37% across 48 surveyed countries, with social media and video networks surpassing all other sources as the primary global news channel for the first time. Weekly AI chatbot use for news rose to 10%, with AI-generated pink slime content farms set to proliferate further. An analysis published by EU vs. Disinfo monitored TikTok activity around Denmark’s March 2026 parliamentary election and found no evidence of large-scale Russian disinformation efforts. [ Report Summary] A study published by Post-Soviet Affairs examined how Russian state-sponsored media outlets adapt their messaging for different audiences across the Global South. According to an article by Atlantic Council, Russian President Vladimir Putin continues to frame the war against Ukraine through the goal of “denazification”, presenting it as a central war aim rather than a justification for territorial gains. EUvsDisinfo's weekly review documents Kremlin-aligned outlets reframing NATO's Gallant Boar 2026 exercise in the Suwalki Gap as offensive preparation for a Kaliningrad invasion, a false claim portraying Belarus as a peaceful victim of Ukrainian aggression, and Bulgaria's EU fiscal obligations recast as political punishment. The European Union has published that it has adopted a new package of sanctions against Russia in response to its war against Ukraine, hybrid activities, and human rights violations. According to an article by CyberNews, a controversy emerged after UFC commentator Daniel Cormier posted screenshots that allegedly showed messages from Eric Trump asking whether any fights were "rigged" for betting purposes. A paper published by The Digital Library introduced “Chameleon”, a new benchmark dataset that is designed to detect whether a video is AI-generated and trace generated videos back to their source materials. A review published in the Digital Library examined how advances in AI video generation have made synthetic videos increasingly realistic. According to an article by ABC News, West Papuan activists have raised concerns about the growing use of AI-generated content and online disinformation to undermine their advocacy. Foreign Interference documents over 2,800 AI-generated deepfakes deployed in 2026 U.S. midterm election contexts despite the TAKE IT DOWN Act entering FTC enforcement and state-level AI disclosure laws. The report finds that regulatory deterrence is outpaced by the low cost and high availability of AI content generation tools. The Reuters Institute Digital News Report 2026 finds overall news trust at a record low of 37% across 48 surveyed countries, with social media and video networks surpassing all other sources as the primary global news channel for the first time. Weekly AI chatbot use for news rose to 10%, with AI-generated pink slime content farms set to proliferate further. According to NewsGuard’s Reality Check, in the weeks leading up to the opening of the Obama Presidential Center in Chicago, several conservative social media accounts claimed that the Obama Foundation had hired only Black contractors to work on the project. The European Union announced it has imposed sanctions on six individuals accused of activities aimed at undermining Moldova’s sovereignty, independence, and democratic processes. An analysis published by EU vs. Disinfo monitored TikTok activity around Denmark’s March 2026 parliamentary election and found no evidence of large-scale Russian disinformation efforts. [State Actors] Russia Russian Narrative Adaptation in the Global South A study published by Post-Soviet Affairs examined how Russian state-sponsored media outlets, particularly RT and Sputnik, adapt their messaging for different audiences across the Global South. Focusing on narratives about multipolarity and neocolonialism, Russian messaging is not uniform but tailored to specific regional contexts. Through analysis of English, French, and Spanish-language content, the study showed that Russia adjusts its narratives to resonate with local historical experiences, political concerns, and existing beliefs. The most significant differences emerge between Africa and Latin America. French-language content aimed at African audiences places strong emphasis on colonial legacies, portraying France as a former colonial oppressor while presenting Russia as a supporter of sovereignty and a multipolar world order. In contrast, Spanish-language content targeting Latin America links neocolonialism more closely to US influence, capitalism, and interventionism, while often portraying China rather than Russia as the leading force behind a multipolar future. These adaptations draw on distinct regional memories and grievances to increase the narratives' appeal. Source: Taylor & Francis Online. [Article DOI: 10.1080/1060586X.2026.2690912]. [online journal article] Published 2026. Available at: https://www.tandfonline.com/doi/full/10.1080/1060586X.2026.2690912 (tandfonline.com). Top Of Page Gallant Boar Exercise Falsely Framed as Kaliningrad Invasion A weekly disinformation review published by EU vs Disinfo states that Kremlin-aligned outlets reframed NATO's Gallant Boar 2026 military exercise, a defensive training operation in the Suwalki Gap involving multiple allied forces, as an offensive preparation for an invasion of Russia's Kaliningrad exclave. The false narrative, widely circulated on Russian state media and amplified on Telegram, illustrates the Kremlin's consistent pattern of inverting the defensive character of NATO activities to sustain a warmongering West narrative among domestic and Global South audiences. A weekly disinformation review published by EUvsDisinfo states that Bulgaria's obligations under EU fiscal rules were simultaneously reframed as political punishment for the country's pro-EU governance, and that a false claim portraying Ukraine as planning a military assault on Belarus was introduced across pro-Kremlin channels during the reporting period. The review identifies the Belarus narrative as part of a coordinated effort to destabilise Minsk-Kyiv relations by attributing aggressive intent to Ukraine while obscuring Belarus's documented military buildup along its Ukrainian border since at least April 2026. Source: EUvsDisinfo. Warmongering NATO, Peaceful Belarus and Bulgaria’s Punishment. [online] Published 18 June 2025. Available at: https://euvsdisinfo.eu/warmongering-nato-peaceful-belarus-and-bulgarias-punishment/ (euvsdisinfo.eu). Top Of Page The War in Ukraine Putin’s “Denazification” Narrative According to an article by Atlantic Council, Russian President Vladimir Putin continues to frame the war against Ukraine through the goal of “denazification”, presenting it as a central war aim rather than a justification for territorial gains. This narrative reflects a broader rejection of Ukrainian statehood and helps explain the lack of progress in peace negotiations. The article traces the origins of the “Nazi Ukraine” narrative to Soviet-era portrayals of Ukrainian nationalist movements and argues that the Kremlin has revived and expanded this theme in the years leading up to and during the full-scale invasion. Russian state media and official rhetoric have consistently portrayed Ukrainian patriotism and independence as forms of extremism, while using the “denazification” concept to delegitimize Ukraine as a sovereign nation. This narrative has been challenged by international institutions and historians. Ukraine’s 2019 elections, where President Volodymyr Zelenskyy, a Russian-speaking Jewish candidate, won by a large margin, showed that the characterization of Ukraine as a Nazi state lacks support. The “denazification” narrative also functions as a powerful propaganda theme within Russia. Repeated references to an alleged Nazi threat have been used to justify the invasion and sustain public support for the war, despite the absence of credible evidence for such claims. Source: Atlantic Council. Putin’s Obsession With ‘Denazifying’ Ukraine Makes Peace Impossible. [online] Published 18 June 2026. Available at: https://www.atlanticcouncil.org/blogs/ukrainealert/putins-obsession-with-denazifying-ukraine-makes-peace-impossible/ (atlanticcouncil.org). Top Of Page EU Expands Sanctions Targeting Russian Operations The European Union has published that it has adopted a new package of sanctions against Russia in response to its war against Ukraine, hybrid activities, and human rights violations. The measures target 34 individuals and 47 entities linked to Russia’s military-industrial sector, energy exports, sanctions evasion networks, and influence operations. According to the EU, the sanctions are intended to reduce Russia’s ability to sustain the war, limit revenues from its “shadow fleet” of oil transport companies, and counter activities that threaten European security. A notable part of the package focuses on individuals and organizations accused of spreading narratives that support or justify Russia’s actions in Ukraine. The EU sanctioned several media figures, commentators, and public personalities whom it describes as involved in foreign information manipulation and interference. These individuals are accused of promoting narratives that justify the war, dehumanize Ukrainians, or distort historical events. The sanctions also include the Presidential Foundation for Cultural Initiatives and a senior Russian Orthodox Church bishop, both cited for their role in supporting pro-Kremlin messaging. The package additionally includes sanctions related to the persecution and death of opposition leader Alexei Navalny, as well as the renewal of restrictions connected to Russia’s annexation of Crimea. Source: European External Action Service (EEAS). Russia’s War of Aggression Against Ukraine: New EU Sanctions Target Energy Revenues, the Military-Industrial Complex, Propaganda and Human Rights Violations. [online] Published 18 June 2026. Available at: https://www.eeas.europa.eu/delegations/ukraine/russia%E2%80%99s-war-aggression-against-ukraine-new-eu-sanctions-target-energy-revenues-military-industrial_en (eeas.europa.eu). Top Of Page [AI Related Articles] AI-Generated Screenshots Involving Eric Trump According to an article by CyberNews, a controversy emerged ahead of the UFC Freedom 250 event after UFC commentator Daniel Cormier posted screenshots that allegedly showed messages from Eric Trump asking whether any fights were "rigged" for betting purposes. Cormier deleted the post within 15 minutes, while Eric Trump publicly denied ever communicating with him and stated that the screenshots were fake and AI-generated. According to later reporting, Trump also reiterated that he had never spoken to Cormier. Even so, the incident quickly sparked debate online, with some questioning why Cormier would share screenshots if the conversation never occurred, while others noted that screenshots alone are increasingly difficult to verify in an era of advanced AI-generated content. The discussion was further amplified by responses on X, including comments about the challenges of determining authenticity when digital content can be easily manipulated. Source: Cybernews. Eric Trump Claims Rigged UFC Event Texts Were Actually AI Deepfakes. [online] Published 15 June 2026. Available at: https://cybernews.com/news/eric-trump-ufc-polymarket-deepfake/ (cybernews.com). Top Of Page Benchmark for Detecting AI-Generated Videos The rapid advancement of AI video generation has made it easier to create highly realistic synthetic videos, raising concerns about fraud, privacy violations, and the misuse of fabricated content in public virtual spaces. A paper published in the Digital Library introduced “Chameleon”, a new benchmark dataset containing 1,700 AI-generated videos created using commercial closed-source models. Chameleon includes high-resolution videos with strong temporal and spatial consistency, making them more representative of real-world AI-generated content. The dataset is designed to evaluate two key challenges: detecting whether a video is AI-generated and tracing generated videos back to their source materials. To support this, the researchers collected real videos from domains vulnerable to manipulation and generated corresponding synthetic versions using text-to-video and image-to-video methods. This approach allows researchers not only to assess detection performance but also to investigate the origins of manipulated content. The authors argued that existing benchmarks no longer reflect the capabilities of modern video generation systems and that improved detection and source-tracing tools are needed to address challenges posed by increasingly realistic AI-generated videos. Source: Association for Computing Machinery (ACM). Proceedings of the 2024 ACM Conference on Fairness, Accountability, and Transparency (FAccT '24). [online] Published 2024. Available at: https://dl.acm.org/doi/full/10.1145/3805622.3810862 (dl.acm.org). Top Of Page Deepfake Detection in the Post-Artifact Era A review published in the Digital Library examined how advances in AI video generation have made synthetic videos increasingly realistic, with modern models capable of producing high-resolution, minute-long clips featuring coherent motion and complex scenes. As video quality improves, many of the visual artifacts that earlier detection systems relied on, such as facial inconsistencies, unnatural blinking, or frequency distortions, are disappearing, making it more difficult to distinguish AI-generated content from authentic footage. To address this challenge, the authors proposed a forensic framework based on five assumptions: physiological integrity, temporal coherence, geometric consistency, semantic consistency, and provenance signals. Comparing several detection approaches, they found that current evaluation benchmarks often focus on accuracy while giving less attention to trustworthiness, robustness, and real-world deployment. The review also highlights broader societal concerns associated with increasingly convincing synthetic media, including privacy violations, non-consensual deepfake content, and other forms of misuse. Therefore, future detection systems should move beyond searching for technical artifacts and instead combine multiple sources of evidence, stronger provenance mechanisms, and more comprehensive evaluation methods to improve resilience against rapidly evolving AI-generated video technologies. Source: Association for Computing Machinery (ACM). [Article in the Proceedings of the 2024 ACM Conference on Fairness, Accountability, and Transparency (FAccT ’24)]. [online] Published 2024. Available at: https://dl.acm.org/doi/full/10.1145/3810988.3812659 (dl.acm.org). Top Of Page Deepfakes and Disinformation Targeting West Papua Activists According to an article by ABC News, West Papuan activists have raised concerns about the growing use of AI-generated content and online disinformation to undermine their advocacy. Koteka Wenda, daughter of independence leader Benny Wenda, discovered a deepfake video falsely portraying her as criticizing a documentary about deforestation and indigenous land exploitation in West Papua. She warned that such content could mislead supporters and damage the credibility of activists. Another prominent activist, Veronica Koman, reported similar experiences, including manipulated videos falsely showing her praising the Indonesian government. The article highlighted broader concerns about information manipulation in Indonesia. An Amnesty International report argued that disinformation campaigns have increasingly been used to target government critics, discredit dissenting voices, and influence public debate (for further information, see W21 May Cyfluence Report). These tactics have become a significant tool for attacking critics online, while activists and human rights advocates describe them as part of a longer pattern of repression. Researchers have also documented previous coordinated online campaigns related to West Papua, including the use of misleading content and automated social media accounts to promote pro-government narratives and weaken activist voices. Activists argue that AI-generated deepfakes represent a new challenge in this information environment, making it harder for the public to distinguish authentic messages from fabricated ones. Source: ABC News. AI-generated content targeting West Papuan activists. [online] Published 21 June 2026. Available at: https://www.abc.net.au/news/2026-06-21/ai-generated-content-targeting-west-papuan-activists/106760046 (abc.net.au). Top Of Page AI Deepfakes Proliferate in 2026 U.S. Midterm Elections Despite Regulatory Efforts A report published by Foreign Interference states that AI-generated deepfakes targeting the 2026 U.S. midterm elections have proliferated significantly despite federal and state-level regulatory interventions, with tracking indicating over 2,800 documented cases of synthetic media deployed to manipulate electoral discourse across social media platforms. The report identifies that the TAKE IT DOWN Act, signed into law in May 2025 with FTC enforcement beginning 19 May 2026, has not materially reduced production volumes due to the low cost and high availability of AI content generation tools accessible to both state and non-state actors. A report published by Foreign Interference states that the supply-side economics of AI deepfake production -- where a single actor can generate thousands of synthetic media assets at near-zero marginal cost -- have outpaced the deterrent capacity of existing legislation and platform enforcement mechanisms. The report notes that despite New York State's AI influencer disclosure law taking effect on 9 June 2026 and the EU Code of Practice on AI-generated content marking published 10 June 2026, the global regulatory patchwork creates arbitrage opportunities for foreign and domestic influence operators to route production through unregulated jurisdictions while targeting regulated audiences. Source: Foreign Interference Research Center. AI Deepfakes Proliferate in 2026 U.S. Midterm Elections Despite Regulatory Efforts. [online] Published 2026. Available at: https://foreigninterference.org/post/ai-deepfakes-proliferate-in-2026-u-s-midterm-elections-despite-regulatory-efforts (foreigninterference.org). Top Of Page [General Reports] False Claims About Hirings at the Obama Presidential Center According to NewsGuard’s Reality Check, in the weeks leading up to the opening of the Obama Presidential Center in Chicago, several conservative social media accounts claimed that the Obama Foundation had hired only Black contractors to work on the project. These posts framed the alleged hiring practices as racial discrimination and linked them to broader criticism of diversity, equity, and inclusion (DEI) initiatives. The claims gained significant attention online, accumulating hundreds of thousands of views. However, available information does not support the assertion that only Black contractors were involved in the project. The center’s construction was managed by Lakeside Alliance, a joint venture that includes leaders and member companies from diverse backgrounds. Publicly available records and company information indicate that both Black-owned and non-Black-owned firms participated in the project. Confusion around unpaid subcontractor disputes appears to have been combined with inaccurate claims about contractor demographics. According to Lakeside Alliance’s latest published report, 40% of subcontracts were awarded to minority-owned businesses, indicating that a majority of contracts went to other companies. Source: NewsGuard Reality Check. False Claims of Racism at the Obama Administration / Related Viral Misinformation Debunked. [online] Published 2023. Available at: https://www.newsguardrealitycheck.com/p/false-claims-of-racism-at-the-obama (newsguardrealitycheck.com). Top Of Page Reuters Institute Digital News Report 2026 A report published by Reuters Institute for the Study of Journalism states that overall news trust across 48 surveyed countries has fallen to a record low of 37%, with 38 of 48 countries recording declining trust in news over the past year. For the first time in the survey's history, social media and video networks surpassed all other sources as the most widely used channel for news globally, with 54% of audiences now reaching news primarily through social and video platforms, representing a 13-percentage point gain over television since 2020. The report states that weekly use of AI chatbots for news rose from 7% in 2025 to 10% in 2026, with growth concentrated in Asia, Africa, Latin America, and Southern and Eastern Europe -- regions with historically weaker institutional media infrastructure and higher vulnerability to AI-generated disinformation. The report warns that AI-powered pink slime content farms are set to proliferate further as platforms struggle to distinguish synthetic from legitimate news content, raising structural risk that the architecture of public information ecosystems will increasingly reward low-cost synthetic production over credible editorial standards. Source: Reuters Institute for the Study of Journalism. Digital News Report 2026. [online] Published 2026. Available at: https://reutersinstitute.politics.ox.ac.uk/digital-news-report/2026 (reutersinstitute.politics.ox.ac.uk). Top Of Page [Appendix - Frameworks to Counter Disinformation] EU Sanctions Over Interference in Moldova The European Union announced it has imposed sanctions on six individuals accused of activities aimed at undermining Moldova’s sovereignty, independence, and democratic processes. According to the EU, the individuals were involved in Russian-funded efforts to influence Moldova’s September 2025 parliamentary elections, including vote-buying schemes and coordinated influence campaigns. Some of those sanctioned are linked to organizations and political networks associated with businessman Ilan Shor and the Russia-based NGO Evrazia. With these additions, EU restrictive measures now apply to 29 individuals and five entities connected to activities viewed as destabilizing Moldova. The sanctions include asset freezes and travel bans Among those listed are political figures and Russian nationals accused of organizing election-related activities, facilitating illicit funding, and coordinating influence operations. These efforts included the dissemination of propaganda, the mobilization of local networks, and attempts to shape voter behavior through coordinated campaigns. The sanctions also cite the use of religious and community structures to support political messaging and collect personal data. Source: European External Action Service (EEAS). Republic of Moldova: Council lists six individuals for actions destabilising the country. [online] Published 16 June 2026. Available at: https://www.eeas.europa.eu/delegations/moldova/republic-moldova-council-lists-six-individuals-actions-destabilising-country_en (eeas.europa.eu). Top Of Page Danish Parliamentary Election with No Sign of Significant Disinformation According to Danish authorities and independent analyses, there was no major foreign disinformation campaign targeting Denmark’s March 2026 parliamentary election. An analysis published by EU vs. Disinfo monitored TikTok activity across more than 40 political and media channels, specifically looking for coordinated inauthentic behavior, bot networks, and AI-amplified influence operations. While election-related content increased as expected, investigators found no evidence of large-scale Russian disinformation efforts or systematic bot activity aimed at influencing public opinion. The findings suggested that Denmark’s resilience against disinformation stems from several factors, including high public trust in government and media, free press, broad political consensus on key issues such as support for Ukraine, and proactive warnings from Danish intelligence services. Additionally, it showed that Russian influence operations are selective rather than universal, with resources directed toward countries where political divisions make influence campaigns more likely to succeed. As a result, Denmark may have been viewed as a low-return target compared with countries facing greater polarization and weaker information resilience. Source: EUvsDisinfo. The dog that didn’t bark: What the Danish election reveals about Russian influence operations. [online] Published 27 May 2026. Available at: https://euvsdisinfo.eu/the-dog-that-didnt-bark-what-the-danish-election-reveals-about-russian-influence-operations/ (euvsdisinfo.eu). Top Of Page [CRC Glossary] The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult. To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence. As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website. Top Of Page
- Cyber based influence campaigns 08th - 14th June 2026 Report
[Introduction] Cyber-based hostile influence campaigns are aimed at influencing target audiences by promoting information and/or disinformation over the internet, sometimes combined with cyber-attacks which enhance their effect (hence force Cyfluence, as opposed to cyber-attacks that aim to steal information, extort money, etc.) Such hostile influence campaigns and operations can be considered an epistemological branch of Information Operations (IO) or Information Warfare (IW). Typically, and as customary during the last decade, the information is spread throughout various internet platforms, which are the different elements of the hostile influence campaign, and as such, connectivity and repetitiveness of content between several elements are the main core characteristics of influence campaigns. Hostile influence campaigns, much like Cyber-attacks, have also become a tool for rival nations and corporations to damage reputation or achieve various business, political or ideological goals. Much like in the cyber security arena, PR professionals and government agencies are responding to negative publicity and disinformation shared over the news and social media. We use the term cyber based hostile influence campaigns, as we include in this definition also cyber-attacks aimed at influencing (such as hack and leak during election time), while we exclude of this term other types of more traditional kinds of influence such as diplomatic, economic, military etc. During the 08th to the 14th of June 2026, we observed, collected and analyzed endpoints of information related to cyber based hostile influence campaigns (including Cyfluence attacks). The following report is a summary of what we regard as the main events. Some of the mentioned campaigns have to do with social media and news outlets solemnly, while others leverage cyber-attack capabilities. [Contents] [Introduction] [Report Highlights] [Report Summary] [Social Media Platforms] YouTube YouTube Channels Linked to Sanctioned Iranian Entities [State Actors] Russia Russian Narratives Target NATO Unity and Baltic Security Georgia’s Balancing Act Between Western Partnerships and Non-Western Ties Misinformation Targeting Macron Ahead of World Cup Fact-Checking Claims Made by Putin at SPIEF FIMI Operations Targeting Armenia’s 2026 Elections The War in Ukraine Russian Distorted Messaging on Canada–Ukraine Partnership ODNI Release Revives Claims About Ukrainian Biolabs The Russia–Ukraine Conflict in the Media Battlefield China AI-Generated Influence Campaigns Target U.S. Technology Debates Autism Misunderstandings and Information Challenges in Chinese Communities Iran Iran’s Evolving Information Strategy AI Chatbots Show Greater Vulnerability to False Claims About the Iran War [AI Related Articles] German Court Holds Google Liable for False AI-Generated Search Overviews [General Reports] False Claims About California's 2026 Primary Elections BlackCore Linked to Digital Interference Campaigns Across Multiple Countries [Appendix - Frameworks to Counter Disinformation] NATO Exercise Examines Responses to Information Campaigns During Crises Democratic Preparations for Election Interference and Information Threats Workshop on Hybrid Threats, Disinformation, and Cyber Influence in Somalia [CRC Glossary] [ Report Highlights] According to a report by The Jamestown Foundation, the possibility of a Russian attack on the Baltic states remains uncertain, but a growing Russian narrative that questions NATO’s willingness and ability to defend its members is perceived. According to NewsGuard’s Reality Check, as the World Cup begins in North America, a widely shared online narrative falsely claimed that French football star Kylian Mbappé had accused French President Emmanuel Macron of years of sexual harassment. According to an article by Stop Fake, during a meeting with international news agencies at the St. Petersburg International Economic Forum, Vladimir Putin made several misleading claims regarding the war in Ukraine, Russian military operations, European energy policy, and regional politics. According to an article by Disinfo Watch, a recently declassified slide deck from the U.S. ODNI has drawn attention for reviving debate around long-standing claims about U.S.-supported laboratories in Ukraine. OpenAI reported the disruption of two clusters of ChatGPT accounts that were allegedly used to support covert online influence activities linked to actors likely originating from China. An essay published in The Journal of Autistic Culture argued that public understanding of autism in many Chinese communities is shaped by a combination of misconceptions and inaccurate information. As stated in an article by CFR, Iran has developed a highly effective online communication strategy that relies on humor, memes, and AI-generated content rather than traditional propaganda. As published by EEAS, a workshop held in Nairobi focused on strengthening Somalia’s ability to address hybrid threats, disinformation, and foreign interference. [ Report Summary] A report by the Tech Transparency Project found that YouTube hosted and displayed advertisements on dozens of channels connected to Iranian individuals, organizations, and government entities subject to U.S. sanctions. According to a report by The Jamestown Foundation, the possibility of a Russian attack on the Baltic states remains uncertain, but a growing Russian narrative that questions NATO’s willingness and ability to defend its members is perceived. According to an article by The Jamestown Foundation, Georgia’s ruling Georgian Dream party has expressed interest in restoring the suspended U.S.-Georgia strategic partnership while insisting that improved relations should not require changes to its domestic or foreign policies. According to NewsGuard’s Reality Check, as the World Cup begins in North America, a widely shared online narrative falsely claimed that French football star Kylian Mbappé had accused French President Emmanuel Macron of years of sexual harassment. According to an article by Stop Fake, during a meeting with international news agencies at the St. Petersburg International Economic Forum, Vladimir Putin made several misleading claims regarding the war in Ukraine, Russian military operations, European energy policy, and regional politics. Research by the EEAS and CheckFirst found that Armenia’s 2026 parliamentary elections became a major target for foreign information manipulation campaigns, particularly from Kremlin-linked networks. As published in a DisinfoWatch analysis, a statement by Russian state media outlet TASS criticized a new Canada–Ukraine drone production arrangement and framed it as evidence of Canada’s growing involvement in the war. According to an article by Disinfo Watch, a recently declassified slide deck from the U.S. ODNI has drawn attention for reviving debate around long-standing claims about U.S.-supported laboratories in Ukraine. A paper published in the International Journal of Social and Economic Development examined how the Russia–Ukraine war is represented in modern media. OpenAI reported the disruption of two clusters of ChatGPT accounts that were allegedly used to support covert online influence activities linked to actors likely originating from China. An essay published in The Journal of Autistic Culture argued that public understanding of autism in many Chinese communities is shaped by a combination of misconceptions and inaccurate information. As stated in an article by CFR, Iran has developed a highly effective online communication strategy that relies on humor, memes, and AI-generated content rather than traditional propaganda. A May 2026 audit by NewsGuard found that leading AI chatbots were more likely to repeat false claims related to the Iran war than misinformation on other news topics. According to The Decoders’ publication, a German court ruled that Google can be held directly responsible for false statements generated by its AI search overviews, finding that these summaries are Google's own content rather than traditional search results. As published in NewsGuard’s Reality Check, following California's June 2026 primary elections, several conservative figures, including President Donald Trump, claimed that the results were being manipulated to benefit Democratic candidates. As published by Reuters, France’s digital interference watchdog Viginum reported that the Israeli-linked influence firm BlackCore is suspected of conducting digital interference operations in political campaigns in France, New York City, Scotland, Angola, and Togo. As published by the Financial Times, NATO recently conducted a simulation in Poland to test how allied countries might respond to information campaigns during major crises. According to a Politico article, Senate Democrats are preparing legal and communications strategies for a range of potential election-related disruptions ahead of the midterm elections. As published by EEAS, a workshop held in Nairobi focused on strengthening Somalia’s ability to address hybrid threats, disinformation, and foreign interference. [Social Media Platforms] YouTube YouTube Channels Linked to Sanctioned Iranian Entities A report by the Tech Transparency Project (TTP) found that YouTube hosted and displayed advertisements on dozens of channels connected to Iranian individuals, organizations, and government entities subject to U.S. sanctions. According to the investigation, 56 channels were associated with Treasury-designated sanctioned actors, while 28 others were linked to the Iranian government. YouTube may be providing services to sanctioned entities and potentially generating revenue from their content, although TTP could not determine whether the channels themselves received a share of advertising income. Following media inquiries, Google stated that it is committed to sanctions compliance and removed many of the identified channels. Among the channels identified were accounts linked to organizations and individuals connected to Iran’s Islamic Revolutionary Guard Corps (IRGC), sanctioned businesses, banks, state media outlets, government ministries, and senior political figures. The investigation also noted that some of the identified media outlets have previously been sanctioned by the United States for activities including propaganda, distorted reporting, or other actions cited by U.S. authorities. However, the central focus is not the content of the channels, but the broader question of whether YouTube's platform and advertising infrastructure are being used by entities that U.S. sanctions are intended to restrict. The findings raise questions about YouTube’s compliance with sanctions regulations and the effectiveness of safeguards designed to prevent sanctioned actors from using the platform. Source: Tech Transparency Project. YouTube Profits Off U.S.-Sanctioned Iranians Amid Middle East Conflict. [online] Published 11 June 2026. Available at: https://www.techtransparencyproject.org/articles/youtube-profits-off-u.s.-sanctioned-iranians-amid-middle-east-conflict (techtransparencyproject.org). (campaignforaccountability.org) Top Of Page [State Actors] Russia Russian Narratives Target NATO Unity and Baltic Security According to a report by The Jamestown Foundation, the possibility of a Russian attack on the Baltic states remains uncertain. Still, a growing Russian narrative that questions NATO’s willingness and ability to defend its members is perceived. Senior Russian officials have argued that if a conflict were to occur, the Baltic states would be responsible for provoking it and therefore could not rely on NATO’s collective defense commitments. The article also described a broader pattern of Russian statements and media activity concerning the Baltic region. Remarks by Russian officials and claims circulated by Russia’s Foreign Intelligence Service alleged that Latvia is involved in preparations for attacks against Russia. Latvian experts quoted in the text argued that these claims are unsupported and are part of an effort to portray the Baltic states as participants in a conflict rather than potential targets of Russian pressure. Russian state and state-affiliated media outlets amplified these narratives, while channels targeting Baltic audiences further spread them. Source: Jamestown Foundation. Moscow Tells Baltics NATO Will Not Come to Their Rescue. [online] Published 6 June 2026. Available at: https://jamestown.org/moscow-tells-baltics-nato-will-not-come-to-their-rescue/ (jamestown.org). Top Of Page Georgia’s Balancing Act Between Western Partnerships and Non-Western Ties According to an article by The Jamestown Foundation, Georgia’s ruling Georgian Dream party has expressed interest in restoring the suspended U.S.-Georgia strategic partnership while insisting that improved relations should not require changes to its domestic or foreign policies. At the same time, Tbilisi has expanded cooperation with the People’s Republic of China and maintained engagement with Iran and Russia, prompting increased scrutiny from Washington. Recent U.S. legislative initiatives and official statements have focused on concerns regarding foreign influence and Georgia’s broader political trajectory. The debate has increasingly extended into the information sphere as U.S. officials and critics of the Georgian government have raised concerns that growing ties with China, Russia, and Iran could increase external influence in Georgia. Georgian Dream argued that such claims exaggerate the scale and significance of these relationships, and the government continues to present itself as a defender of national sovereignty against outside pressure, even as it seeks renewed engagement with Washington. At the same time, foreign actors, including Iranian representatives, have become more visible participants in Georgia’s public discourse, contributing to competing narratives about the country’s direction and international partnerships. As a result, Tbilisi faces the challenge of balancing its pursuit of diversified foreign relations with maintaining trust with its traditional Western partners. Source: Jamestown Foundation. Georgian Dream Seeking U.S. Reset While Resisting Requisite Reforms. [online] Published 6 June 2026. Available at: https://jamestown.org/georgian-dream-seeking-u-s-reset-while-resisting-requisite-reforms/ (jamestown.org). Top Of Page Misinformation Targeting Macron Ahead of World Cup According to NewsGuard’s Reality Check, as the World Cup begins in North America, a widely shared online narrative falsely claimed that French football star Kylian Mbappé had accused French President Emmanuel Macron of years of sexual harassment. The story circulated through a video and article designed to resemble content from Eurosport and gained significant attention on social media, generating millions of views in multiple languages within days. The content originated from a website impersonating Eurosport rather than the legitimate broadcaster. The purported article was falsely attributed to a Eurosport journalist, who publicly rejected the claim and confirmed that neither he nor Eurosport had any connection to the story. The accompanying audio, presented as Mbappé’s voice, showed signs of manipulation, including unnatural speech patterns and inaccuracies that cast doubt on its authenticity. No credible evidence was presented to support the allegations against Macron. Researchers cited in the article linked the campaign to a network previously associated with anti-Macron narratives, particularly in response to France’s support for Ukraine. Source: NewsGuard Reality Check. Russia Plays Dirty at the World Cup. [online] Published 6 June 2026. Available at: https://www.newsguardrealitycheck.com/p/russia-plays-dirty-at-the-world-cup (newsguardrealitycheck.com). Top Of Page Fact-Checking Claims Made by Putin at SPIEF According to an article by Stop Fake, during a meeting with international news agencies at the St. Petersburg International Economic Forum (SPIEF), Vladimir Putin made several claims regarding the war in Ukraine, Russian military operations, European energy policy, and regional politics. The article argues that a number of these statements were inaccurate or misleading when compared with publicly available data and official records. The article challenged Putin’s claims about the extent of Russian territorial control in Ukraine, the scale of desertion in the Ukrainian Armed Forces, and the condition of Ukraine’s air defense network. For example, while Ukraine faces shortages in air defense coverage and interceptor missiles, it continues to operate an integrated, multi-layered air defense system. The review also highlighted inconsistencies between Putin’s recent description of an Oreshnik missile strike near Bila Tserkva as a test against a non-military target and earlier Russian official statements that described the strike as a successful attack on military infrastructure. Additionally, Russia’s own actions contributed significantly to the decline in gas supplies, as opposed to Putin’s characterization of Europe’s reduction of Russian energy imports. Source: StopFake. «Просто ударили туда, где было удобно посмотреть результаты». 7 фейков Путина на встрече с руководителями зарубежных информагентств. [online] Published 8 June 2026. Available at: https://www.stopfake.org/ru/prosto-udarili-tuda-gde-bylo-udobno-posmotret-rezultaty-7-fejkov-putina-na-vstreche-s-rukovoditelyami-zarubezhnyh-informagentstv/ (stopfake.org). (stopfake.org) Top Of Page FIMI Operations Targeting Armenia’s 2026 Elections Research by the European External Action Service (EEAS) and CheckFirst found that Armenia’s 2026 parliamentary elections became a major target for foreign information manipulation campaigns, particularly from Kremlin-linked networks. Following Prime Minister Nikol Pashinyan’s efforts to strengthen ties with the European Union and reduce dependence on Russia, coordinated influence operations portrayed him as an EU puppet, an ally of Azerbaijan, or a leader working against Armenia’s interests. These narratives were spread across social media, messaging apps, and networks linked to Russian influence operations such as Overload, Pravda, and Storm-1516. The investigation documented a broad ecosystem of manipulated content, including AI-generated videos, fake news websites, impersonated media outlets, and coordinated social media activity. At least 72 websites connected to the Storm-1516 network were identified, many of which published false stories about Pashinyan and promoted pro-Russian narratives. French TikTok users searching for Pashinyan were exposed mainly to hostile content originating from Kremlin-linked actors, members of the Armenian diaspora, or Azerbaijani sources. Russian state-affiliated media and influence actors also amplified these narratives through French-language content and messaging platforms. Findings showed Russia conducted a multi-layered effort to influence Armenian public opinion and undermine support for pro-Western political leaders. Evidence from leaked documents and domain registration patterns suggested coordination between influence networks operating in Armenia and similar campaigns previously observed in Europe, and Researchers noted that actors from the Armenian diaspora and Azerbaijan contributed to the online criticism of Pashinyan. Source: CheckFirst. Noise Without Effect. [online PDF] Published June 2026. Available at: https://checkfirst.network/wp-content/uploads/2026/06/NOISE_WITHOUT_EFFECT_11.pdf (checkfirst.network). Top Of Page The War in Ukraine Russian Distorted Messaging on Canada–Ukraine Partnership As published in a DisinfoWatch analysis, a statement by Russian state media outlet TASS, quoting Foreign Ministry spokesperson Maria Zakharova, criticized a new Canada–Ukraine drone production arrangement and framed it as evidence of Canada’s growing involvement in the war. Even though the statement was based on a real Canadian government announcement, the report argues that Russian officials used this announcement to advance broader narratives portraying Canada as a direct participant in the conflict, questioning the legitimacy of Ukraine’s government, and suggesting that support for Ukraine makes foreign partners responsible for the war. The most notable element of the statement was a threat to publish the addresses of Canadian production facilities connected to the project. The analysis highlighted several recurring themes in Russian messaging, including describing Ukraine as the “Kiev regime”, portraying defensive military support as aggression, characterizing Ukrainian military activity as terrorism, and suggesting that Canada is profiting from the conflict. These claims are presented without evidence or omit key context about Russia’s invasion of Ukraine and appear intended to discourage support for Ukraine and increase pressure on Canadian organizations involved in defence cooperation. Source: DisinfoWatch. Russian Spokeswoman Threatens Canada Over Drone Manufacturing. [online] Published 9 June 2026. Available at: https://disinfowatch.org/disinfo/russian-spokeswoman-threatens-canada-over-drone-manufacuring/ (disinfowatch.org). Top Of Page ODNI Release Revives Claims About Ukrainian Biolabs According to an article by Disinfo Watch, a recently declassified slide deck from the U.S. Office of the Director of National Intelligence (ODNI), released under Director of National Intelligence Tulsi Gabbard, has drawn attention for reviving debate around long-standing claims about U.S.-supported laboratories in Ukraine. While the slides contain information about public health laboratories, biosafety programs, and international scientific cooperation, they present it in a way that could be interpreted as supporting allegations of biological weapons activity. The documents do not provide evidence of a biological weapons program but instead use language and framing that may encourage such conclusions. Attention is given to references to pathogen storage, laboratory networks, and connections between Ukrainian institutions and U.S. organizations. However, dangerous pathogens are commonly stored and studied in public health and veterinary laboratories for disease surveillance and research, and the presence of such facilities does not indicate the development of biological weapons. Following the release, Russian state media outlets cited the documents as support for their long-standing narrative about Ukrainian “biolabs,” despite the absence of direct evidence in the slides themselves. The significance of the release lies less in the information it contains and more in how that information is framed. The report noted that international organizations and public-health experts have previously stated that there is no credible public evidence of a U.S.-backed biological weapons program in Ukraine. Source: DisinfoWatch. Tulsi Gabbard Biolab Report Feeds Russian State Anti-Ukraine Media Narratives. [online] Published 16 June 2026. Available at: https://disinfowatch.org/disinfo/tulsi-gabbard-biolab-report-feeds-russian-state-anti-ukraine-media-narratives/ (disinfowatch.org). Top Of Page The Russia–Ukraine Conflict in the Media Battlefield A paper published in the International Journal of Social and Economic Development examined how the Russia–Ukraine war is represented in modern media. It argued that disinformation can play a role in warfare that is as significant as military force, as media narratives shape public understanding of the conflict and influence perceptions of reality. Drawing on the ideas of Carl von Clausewitz, we see how war becomes a media spectacle in which audiences form judgments based on information provided by the media. The research highlighted the risks associated with war reporting, particularly in an environment where audiences are vulnerable to misinformation. The political, technological, and psychological foundations of media coverage strongly affect the interpretation of war. Source: Indonesian Journal of Sociology, Education and Development (IJSED). [Article Title]. [online] Published 30 June 2021. Available at: http://ijsedjournal.com/index.php/ijsed/article/view/68/56 (ijsedjournal.com). Top Of Page China AI-Generated Influence Campaigns Target U.S. Technology Debates OpenAI reported the disruption of two clusters of ChatGPT accounts that were allegedly used to support covert online influence activities linked to actors likely originating from China. The accounts generated social media content designed to shape public discussions around U.S. technology and AI-related policies. The campaigns focused on existing public concerns, including the impact of AI data centers on electricity prices and debates surrounding U.S. trade and technology policies. The first campaign, referred to as "Data Center Bandwagon", produced comments and images claiming that AI data center expansion was driving up energy costs for American households. The second campaign, "Tech and Tariffs", generated content criticizing U.S. tariffs and promoting narratives about technological competition. OpenAI also linked this activity to a network of likely inauthentic social media accounts that spread false claims alleging that ChatGPT user data had been compromised. The campaigns did not achieve significant public reach beyond their own activity. However, they illustrate how foreign actors may use AI tools to participate in and influence legitimate public debates while concealing their identity and objectives. Source: OpenAI. PRC-linked Influence Operations Are Targeting AI Debates in the US. [online] Published 10 June 2026. Available at: https://openai.com/index/prc-linked-influence-operations-ai-debates/ (openai.com). Top Of Page Autism Misunderstandings and Information Challenges in Chinese Communities An essay published in The Journal of Autistic Culture argued that public understanding of autism in many Chinese communities is shaped by a combination of misconceptions, inaccurate information, and, in some cases, deliberately misleading claims. Cultural pressures related to competition and conformity can reinforce negative perceptions of autism. As a result, autism is frequently viewed through a deficit-based lens, and inaccurate narratives can become widely accepted and difficult to challenge. A major issue is the role of language, social media, and professional authority in shaping public perceptions. Chinese terms for autism are often interpreted literally, leading many people to associate autism with loneliness, emotional withdrawal, or temporary social difficulties rather than a lifelong neurodevelopmental condition. Social media platforms further amplify misleading claims, including stories suggesting that autism can be "cured" through increased social interaction. Furthermore, some medical and educational professionals continue to promote outdated classifications, unsupported theories, and commercialized treatments, including claims that autism can be cured through rehabilitation programs or traditional remedies. These misunderstandings have significant consequences, including discrimination, delayed diagnosis, and inadequate support for autistic individuals, particularly those with higher support needs. The author called for greater awareness of autism, as well as cultural stereotypes from outside Chinese communities. Source: Timpe, K. What are Intended as Systems of Support become Systems of Struggle. Ought: The Journal of Autistic Culture. [online] Vol. 3, Iss. 1, Article 8, 2021. Available at: https://scholarworks.gvsu.edu/ought/vol3/iss1/8 (scholarworks.gvsu.edu). Top Of Page Iran Iran’s Evolving Information Strategy As stated in an article by CFR, Iran has developed a highly effective online communication strategy that relies on humor, memes, and AI-generated content rather than traditional propaganda. Iranian officials and pro-Iranian content creators increasingly use internet culture, sarcastic social media exchanges, and AI-produced videos to respond to U.S. messaging and engage audiences. This content is designed to function as entertainment first and political messaging second, making it more difficult to counter through conventional responses. This approach presents a challenge because existing tools were largely developed to address covert influence operations or deceptive AI content. Openly published satire and AI-generated memes do not fit neatly into those categories, and traditional fact-checking or content labeling is often ineffective when the message is primarily humorous. Iranian content has achieved significant engagement online, so much so that other countries may study and adopt similar techniques. To respond, the author recommends improving threat monitoring, increasing transparency from AI companies, disrupting covert influence networks when they are identified, and strengthening the United States’ own public diplomacy and soft power. At the same time, the article argues that the United States should avoid conducting its own covert influence campaigns, as this could undermine public trust and ultimately damage democratic institutions. Source: Council on Foreign Relations (CFR). Iran’s Trolling Caught the U.S. Off Guard. Here’s How to Push Back. [online] Published 10 June 2026. Available at: https://www.cfr.org/articles/irans-trolling-caught-the-u-s-off-guard-heres-how-to-push-back (cfr.org). (cfr.org) Top Of Page AI Chatbots Show Greater Vulnerability to False Claims About the Iran War A May 2026 audit by NewsGuard found that leading AI chatbots were more likely to repeat false claims related to the Iran war than misinformation on other news topics. Across all tested claims, chatbots provided false responses in about 15 percent of cases, but that rate increased to 25 percent for prompts related to the Iran conflict. This may be due to coordinated influence efforts that generate large volumes of content around specific narratives, increasing the likelihood that AI systems encounter and repeat those claims. One of the most frequently repeated false stories claimed that Iran’s Islamic Revolutionary Guard Corps destroyed an Israeli military satellite communications center. In reality, the strike targeted a civilian commercial facility and was attributed to Hezbollah, not the IRGC. Ten of the eleven chatbots repeated at least part of the false claim when presented with leading prompts. Several models cited Iranian state-linked or pro-Iranian media outlets, including Tasnim News, Mehr News, and the Tehran Times, when generating inaccurate responses. The report also found that chatbots sometimes relied on state-controlled media from Iran, Russia, and China when answering news-related questions. Many AI systems still struggle to assess source credibility effectively, allowing false or misleading narratives to influence their outputs. While some models improved compared with previous audits, the findings highlight ongoing challenges in preventing AI tools from amplifying inaccurate information that originates from coordinated influence networks. Source: NewsGuard. Quarterly AI False Claim Monitor — May 2026: Quarterly Audit of the 11 Leading Generative AI Tools and Their Propensity to Repeat False Claims on Controversial Topics in the News. [online] Published 8 June 2026. Available at: https://www.newsguardtech.com/ai-monitor/may-2026/ (newsguardtech.com). (newsguardtech.com) Top Of Page [AI Related Articles] German Court Holds Google Liable for False AI-Generated Search Overviews According to The Decoders’ publication, a German court ruled that Google can be held directly responsible for false statements generated by its AI search overviews, finding that these summaries are Google's own content rather than traditional search results. The case involved AI-generated responses that incorrectly linked two publishing companies to scams, subscription traps, and other questionable business practices. According to the court, the AI combined information from unrelated sources, created connections that did not exist in the cited material, and presented them as factual claims. Because the AI generated new statements instead of simply displaying third-party content, the court concluded that Google bears responsibility for the accuracy of those claims. The ruling rejected Google's argument that users can verify AI summaries by checking the linked sources themselves. The court noted that the overviews are presented as complete, standalone answers and may contain claims that do not appear in any source. It also found that existing legal protections for search engines do not apply because AI overviews actively interpret, summarize, and generate content. As a result, victims of false statements should be able to seek legal remedies directly from Google, rather than from the websites referenced by the AI. Source: The Decoder. Landmark German Ruling Declares Google's AI Overviews Are Google's Own Words and Makes It Liable for False Answers. [online] Published 9 June 2026. Available at: https://the-decoder.com/landmark-german-ruling-declares-googles-ai-overviews-are-googles-own-words-and-makes-it-liable-for-false-answers/ (the-decoder.com). (the-decoder.com) Top Of Page [General Reports] False Claims About California's 2026 Primary Elections As published in NewsGuard’s Reality Check, following California's June 2026 primary elections, several conservative figures, including President Donald Trump, claimed that the results were being manipulated to benefit Democratic candidates. These allegations focused on the slow pace of vote counting and the large number of mail-in ballots, with critics arguing that late-counted votes unfairly changed the standings of Republican candidates in the gubernatorial and Los Angeles mayoral races. However, election officials and voting experts noted that California's counting process routinely extends beyond Election Day because state laws allow mail-in ballots to arrive after Election Day if postmarked on time. Mail-in ballots also tend to be counted later and have historically favored Democratic candidates, a pattern observed in previous elections. As a result, shifts in vote totals after Election Day are not, by themselves, evidence of fraud. The controversy reflects the continued spread of election-related misinformation and unsubstantiated fraud claims that have persisted since the 2020 U.S. presidential election. Source: NewsGuard Reality Check. Election Denial, California Edition. [online] Published 12 June 2026. Available at: https://www.newsguardrealitycheck.com/p/election-denial-california-edition (newsguardrealitycheck.com). Top Of Page BlackCore Linked to Digital Interference Campaigns Across Multiple Countries As published by Reuters, France’s digital interference watchdog, Viginum, reported that the Israeli-linked influence firm BlackCore is suspected of conducting digital interference operations not only in France’s 2025 municipal elections, but also in political campaigns in New York City, Scotland, Angola, and Togo. According to Viginum, the company allegedly used networks of fake or coordinated online accounts to target political figures and influence public debate, although investigators have not identified who may have commissioned these activities. French authorities said technical analysis connected BlackCore to an online smear campaign against candidates from the French left-wing party La France Insoumise. Similar tactics were reportedly observed in Scotland, where accounts linked to the operation targeted John Swinney and the Scottish National Party during election campaigns. The report highlighted growing concerns about the commercial market for influence operations, where private firms allegedly offer services designed to shape narratives and manipulate online discussions. While France has asked Israel for assistance in identifying those behind the campaigns, investigators say the sponsors remain unknown. BlackCore, which previously described itself as a company specializing in influence, cyber, and information warfare services, has not responded to requests for comment. Source: Reuters. Israeli Firm BlackCore Also Suspected of Meddling in NYC, Scotland Votes, French Official Says. [online] Published 11 June 2026. Available at: https://www.reuters.com/world/israeli-firm-blackcore-also-suspected-meddling-nyc-scotland-votes-french-2026-06-11/ (reuters.com). Top Of Page [Appendix - Frameworks to Counter Disinformation] NATO Exercise Examines Responses to Information Campaigns During Crises As published by the Financial Times, NATO recently conducted a simulation in Poland to test how allied countries might respond to information campaigns during major crises. Using a fictional scenario in which an authoritarian neighboring state launched a cyberattack on an energy grid, participants faced coordinated online messaging designed to exploit public fear, undermine trust in authorities, and create social divisions. Additional scenarios included a major flood and a cyberattack on the banking system. Ukrainian officials played the role of the hostile actor, using AI-generated content and social media campaigns to spread narratives blaming government incompetence and corruption while presenting the fictional adversary as a source of assistance. The exercise highlighted how coordinated messaging can be used during emergencies to influence public perceptions, complicate crisis response efforts, and challenge official communications. Participants countered these efforts with messages promoting public trust, social stability, and national unity. The idea drew heavily on Ukraine’s experience since Russia’s full-scale invasion and reflected broader efforts within NATO to improve resilience against hostile information activities. Participants noted that while simulations help strengthen coordination and preparedness, they cannot fully replicate the pace and complexity of real-world wartime environments, and Ukrainian officials emphasized that adversaries often adapt their narratives rapidly. Source: Financial Times. Nato narrowly beats Russia-style NATO rece enemy in cyber attack simulation. [online]. Available at: https://www.ft.com/content/cda17cca-a651-41c5-9ac7-75dcde998c66?syn-25a6b1a6=1 (ft.com). Top Of Page Democratic Preparations for Election Interference and Information Threats According to a Politico article, Senate Democrats are preparing legal and communications strategies for a range of potential election-related disruptions ahead of the midterm elections. In a recent tabletop exercise led by Senate Minority Leader Chuck Schumer, lawmakers and election experts discussed responses to scenarios such as ballot seizures, federal agents at polling places, and foreign influence operations. A key focus was coordinating messaging to counter misinformation that could undermine public confidence in election results. One scenario examined the impact of a foreign influence campaign using AI-generated deepfakes alongside efforts to suppress reporting on false narratives. Another explored how unsubstantiated claims of widespread election fraud could encourage armed citizens to monitor polling sites and potentially justify increased federal involvement at voting locations. The exercises reflect concerns among Democratic officials about election integrity and public confidence. Participants emphasized the need for rapid legal action and collaboration with state and local authorities to address misleading information and ensure that voters remain confident that elections will be conducted fairly and that legitimate votes will be counted. Source: Politico. How Senate Democrats Are Planning to Push Back on Potential Election Interference. [online] Published 11 June 2026. Available at: https://www.politico.com/news/2026/06/11/how-senate-democrats-are-planning-to-push-back-on-potential-election-interference-00957663 (politico.com). (美轮美换 The American Roulette). Top Of Page Workshop on Hybrid Threats, Disinformation, and Cyber Influence in Somalia As published by EEAS, a workshop held in Nairobi by the Ministry of Foreign Affairs and International Cooperation of Somalia, the European Union Delegation to Somalia, and partner organizations focused on strengthening Somalia’s ability to address hybrid threats, disinformation, and foreign interference. The initiative introduced participants to key principles of cyber diplomacy and cybersecurity, while building expertise in cyber resilience, critical information infrastructure protection, and the detection of influence operations in the digital space. The training also guided the EU’s legal and policy framework for cybersecurity, helping Somali institutions improve national strategies, legislation, governance, and coordination mechanisms. Source: European External Action Service (EEAS). Somalia Advances Cybersecurity and Cyber Diplomacy Through EU-Supported Training on Hybrid Threats. [online] Published 5 June 2026. Available at: https://www.eeas.europa.eu/eucap-som/somalia-advances-cybersecurity-and-cyber-diplomacy-through-eu-supported-training-hybrid-threats_en (eeas.europa.eu). Top Of Page [CRC Glossary] The nature and sophistication of the modern Information Environment is projected to continue to escalate in complexity. However, across academic publications, legal frameworks, policy debates, and public communications, the same concepts are often described in different ways, making collaboration, cooperation, and effective action more difficult. To ensure clarity and establish a consistent frame of reference, the CRC is maintaining a standard glossary to reduce ambiguity and promote terminological interoperability. Its scope encompasses foundational concepts, as well as emerging terms relating to Hostile Influence and Cyfluence. As a collaborative project maintained with input from the community of experts, the CRC Glossary is intended to reflect professional consensus. We encourage you to engage with this initiative and welcome contributions via the CRC website. Top Of Page
- Borrowed Legitimacy: Three Models of Credibility Abuse in Influence Operations
Several reports published recently have highlighted a noteworthy technique increasingly employed by hybrid threat actors in hostile influence campaigns (HICs). As most Influence Defense practitioners and researchers know, the effectiveness of HICs often depends not only on the proliferated content itself, but also on the perceived credibility of the entity producing it. While clear propaganda can be easier to identify, entities that resemble research institutes, news outlets, or open-source investigation platforms may be viewed as more trustworthy by targeted audiences. As a result, the inherent legitimacy associated with these institutions is increasingly exploited and used to increase the reach and impact of malign narratives. In this context, it is worth defining credibility as the perceived reliability of information; While legitimacy refers to the perceived authority or institutional standing of the actor producing it. This blog examines three different models of influence-driven entities that exploit borrowed legitimacy, highlights the similarities between them, and their operational importance to cognitive attack-chains. OSINT Investigation Platforms In April 2026, the FDD published a detailed report on a Qatar-linked influence operation called “Eekad”.[1] Active since 2020, Eekad presents itself as the Arab World’s first open-source intelligence (OSINT) platform. It operates across platforms including X/Twitter, YouTube, Facebook, and Instagram, producing content that mimics the conventions of OSINT work: satellite imagery analysis, social network visualizations, geolocation investigations, and debunking of viral content. Eekad's outputs are designed to appear credible and methodologically sound, regardless of the accuracy or integrity of the underlying analysis. Figure 1 – An EekadFacts network graph showing “proof” of Israeli-linked accounts, allegedly amplifying anti-Hamas content online. According to the FDD report, Eekad has repeatedly promoted misleading or false claims which were aligned with Qatari political interests: defending Qatar, targeting Saudi Arabia, the UAE, and Israel, and promoting the post-Assad Syrian government. Its Meta ads showed payments made in Qatari currency, with many ads removed for violating political advertising rules. The FDD analysis linked the operation to a professional PR firm and pointed to financial resources that appeared inconsistent with those of an independent investigative outlet of its stated size. Eekad derives much of its perceived credibility from its presentation of investigative methodology. Rather than simply making claims, it presents them through investigative methods and formats that resemble established OSINT practices. For many audiences, this can create an impression of legitimacy. The FDD report goes into granular detail, mapping Eekad’s connections to Qatari state-media, its associated technical assets, inauthentic amplification of its output, and the ways in which it seems to be embedded within a broader influence infrastructure. ‘Pink Slime’ and Impersonated News Outlets A second model is that of news outlets which look and function like normal media organizations. However, their published content is systematically shaped by a political or state figure operating in the background. The now-infamous Russian hostile influence campaign codenamed Operation Doppelgänger provides a clear example of this model.[2] Its core tactic was the coordinated creation of look-alike websites that visually mimicked legitimate European news outlets. These high-profile influence assets consistently published pro-Kremlin content that appeared to originate from trusted sources. Doppelgänger operators employed webpage cloning tactics, allowing them to impersonate dozens of reputable European news outlets, including prominent European outlets such as Der Spiegel and Bild, as well as major US publications including The Washington Post and Fox News. Doppelgänger relied on audiences, associating familiar journalistic brands with credibility and legitimacy. Figure 2 - A fake Spiegel article, attributed to Russian influence campaign Doppelganger (Courtesy of CORRECTIV).[3] A 2025 report by Logically Facts provides yet another example of trust abuse, in the form of an alleged “Pink Slime” network used to proliferate Russian propaganda through the Dubai-listed Big News Network FZ LLC (BNN) and its subsidiary entities (Midwest Radio Network and The Mainstream Media). This extensive network of “eNewspapers” is suspected of enabling sanction evasion for Russian state media outlets such as RT (formerly Russia Today).[4] A recent CRC investigation has mapped over 2,340 distinct domains linked to BNN’s infrastructure. Figure 3 - Big News Network eNewspapers, suspected of spreading reporting by the EU-sanctioned Russia state media outlet RT.[5] What these inauthentic news entities share is their reliance on familiar journalistic features to appear credible. Bylines, publication dates, editorial sections, and professional layouts can all contribute to an impression of legitimacy before the content is even seen. Research Institutes and Intellectuals A third model of credibility abuse consists of pseudo think tanks and research institutes that spread state-dictated narratives under the guise of analytical observations. Audiences exposed to the content generated by these seemingly independent entities might be unaware of the underlying agendas. The approach taken by the People’s Republic of China (PRC) regarding the South China Sea public discourse serves as a clear example of this technique in action. A recent CRC report mapped an emerging influence infrastructure comprised of multiple PRC-linked entities that present themselves as research organizations. However, these organizations consistently promote narratives that support Beijing’s territorial claims in the region. The discovered influence campaign was observed employing networks of amplification assets on X/Twitter to proliferate the PRC-aligned narratives accusing Western powers and other regional actors as the primary aggressors in the contested region, while diverting attention from repeated Chinese violations of international maritime law.[6] Figure 4 – X accounts linked to PRC-aligned research institutions forming an emerging influence infrastructure. Crucially, ongoing PRC influence operations continue to demonstrate a centrally coordinated approach, integrating both authentic and inauthentic behavior, together with civilian, academic, and state actors, within a multi-layered influence architecture. Inspired by Soviet and Russian political warfare doctrines, recently-identified PRC information manipulation and interference efforts highlight the growing operational complexity of modern cognitive threats. Figure 5 – A structural mapping of the emerging PRC-attributed influence infrastructure, consisting of three inter-connected activity clusters (content generators, amplifiers, and research institutions) The Operational Role of Exploited Credibility The above-mentioned models all exhibit the same operational logic. They maximize their efficacy by abusing pre-existing trust, the veneer of credible information outlets, and the perceived legitimacy assigned to inauthentic operational assets posing as trustworthy entities. “Independent” OSINT research teams, viewed as credible data verification platforms, are leveraged to spread misleading or biased narratives. Meanwhile, impersonation of legitimate and reputable news sources helps threat actors spread information disorder and sow distrust in media coverage. The employment of state-aligned research institutes and individual intellectuals provides a solid base of validity to multi-layered influence architectures. To counter these highly effective adversarial TTPs, counter-influence efforts must dissect documented cases of credibility abuse and apply scrutiny to all kinds of information sources, media outlets and research entities. Defensive measures, including cognitive resilience capacity building, must be scaled and adapted to better inform targeted audiences of novel cognitive threats as they emerge. Reinforcing societal resiliency means providing vulnerable information to consumers with basic awareness and sufficient tools to critically evaluate claims, fighting the common instinct to trust an outdated notion of legitimacy. [References:] Foundation for Defense of Democracies. Qatar Influence Operations: Unmasking a Suspected Network. [online] Published 27 April 2026. Available at: https://www.fdd.org/analysis/2026/04/27/qatar-influence-operations-unmasking-a-suspected-network/ (fdd.org) Cyfluence Research. Visibility as Victory: The Strategic Logic of Doppelgänger. [online] Published 12 May 2025. Available at: https://www.cyfluence-research.org/post/visibility-as-victory-the-strategic-logic-of-doppelg%C3%A4nger CORRECTIV. Inside Doppelganger: How Russia Uses EU Companies for Its Propaganda. [online] Published 22 July 2024. Available at: https://correctiv.org/en/fact-checking-en/2024/07/22/inside-doppelganger-how-russia-uses-eu-companies-for-its-propaganda/ (correctiv.org) Logically Facts. Behind the Network of Pink Slime Sites Sharing Sanctioned Content to EU Readers. [online] Published 28 May 2025. Available at: https://web.archive.org/web/20250528135617/https://www.logicallyfacts.com/en/analysis/behind-the-network-of-pink-slime-sites-sharing-sanctioned-content-to-eu-readers Big News Network. Big News Network – Global News Service, Web Directory. [online] Available at: https://www.bignewsnetwork.net/ Cyfluence Research Center (CRC). From Pseudo-Research to Narrative Superiority: Mapping an Emerging PRC Influence Campaign in the South China Sea. [online] Published 11 May 2026. Updated 12 May 2026. Available at: https://www.cyfluence-research.org/post/from-pseudo-research-to-narrativesuperiority-mapping-an-emerging-prc-influencecampaign-in-the-south
.png)









