Runtime

AI PSYOPS Incident Verification and Effect Attribution Casebook

Report summary

The transition from analog psychological operations to precision, artificial intelligence-driven cognitive warfare represents a structural shift in the global information environment. Traditional mass propaganda required extensive logistical, financial, and personnel resources to identify population

Status
Research archive item
Category
Runtime
Length
7,425 words
Reading time
34 minutes
Report type
evaluation

Key topics

  • Runtime
  • AI
  • .NET
  • OSINT
  • Research Archive
  • Strategy
  • Audit
  • Architecture

Research provenance

Archive status
Research archive item
Content identity
sha256:cf03f95334e97bcb2e99eaec986dfebcd7f879ead083f12a787d725aac217bc9

For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.

This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.

Full report

On this page

The transition from analog psychological operations to precision, artificial intelligence-driven cognitive warfare represents a structural shift in the global information environment. Traditional mass propaganda required extensive logistical, financial, and personnel resources to identify populations, draft localized messaging, and disseminate materials across borders. The deployment of generative artificial intelligence, large language models (LLMs), and synthetic media has effectively collapsed the marginal cost of cognitive attacks to near zero, enabling rapid, scalable influence operations that evade traditional defense mechanisms1. The objective of these operations transcends individual deception; it deliberately targets the epistemic foundations of societies, eroding shared standards for truth, trust in democratic institutions, and the fundamental habits of judgment upon which decision-making relies3. The assessment of cognitive warfare requires a taxonomy that accounts for the "constitutive invisibility" of modern influence operations3. In these operations, the targeted individual experiences induced doubt, altered values, or shifting identity organically, unaware of external manipulation, resulting in a systemic crisis of discovery where cyber tools deliver the attack but the human meaning-making layer is the ultimate target3. To navigate this environment, analysts track operations across twelve theoretical AI PSYOPS categories: Synthetic Audio Spoofing, Generative Deepfake Video, Contextual Reassignment, Media Impersonation, LLM Grooming and Data Poisoning, Targeted Reputational Deepfakes, Synthetic Persona Networks, Automated Narrative Testing, Rapid-Response Battle Damage Fabrication, Spear-Phishing Deepfakes, Automated Cognitive Probing, and Synthetic Polling2. This report provides an exhaustive, cross-category casebook of twenty documented incidents spanning the spectrum of AI-driven psychological operations. A critical vulnerability in contemporary influence analysis is the conflation of digital metrics with psychological impact. Therefore, this analysis explicitly divorces metrics of distribution—such as reach, exposure, and attention—from cognitive and behavioral effects, including comprehension, credibility, belief change, and behavioral action7. In the context of cognitive security, digital impressions, viral sharing, and media coverage must never be treated as empirical evidence of persuasion or tangible behavior change10. Every case evaluates twenty distinct variables to isolate operational mechanics from strategic effects, strictly adhering to non-operational analysis standards.

Category I: Electoral Sabotage and Democratic Subversion

The deployment of synthetic media during sensitive electoral windows exploits the vulnerability of information moratoriums and rapid news cycles. These operations aim to induce voter paralysis, suppress turnout for specific candidates, or misdirect public consensus by injecting high-friction, unverified narratives into the electorate immediately before voting commences12. The 2023 Slovak parliamentary elections serve as a prime indicator of this threat vector. Two days prior to the election, an audio recording circulated depicting Progressive Slovakia party leader Michal Šimečka allegedly conversing with a journalist regarding election rigging and manipulating the Roma minority12. Deployed during a legally mandated election news moratorium, the artifact temporarily paralyzed media organizations, preventing immediate institutional debunking and allowing the synthetic audio to propagate unchallenged across social networks12.

MetricFinding
Artifact or event existenceVerified. Audio file published and amplified on social platforms12.
Content statusAI use was confirmed. Synthetic audio deepfake overlaid on static imagery12.
CoordinationNetworked distribution; rapidly amplified by rival political networks and Telegram channels12.
Actor identityUnattributed origin; initially amplified by extremist and pro-Russian networks13.
Sponsorship or directionUnproven; suspected domestic partisan actors or aligned foreign elements13.
IntentDefame target candidate, depress liberal voter turnout, and sow doubts regarding election integrity12.
OutputSynthetic audio deepfake file12.
DistributionFacebook, Instagram, Telegram, and domestic messaging forums15.
AvailabilityHighly accessible across public social media spheres15.
ReachHundreds of thousands of potential voters within the Slovak information space12.
ExposureHigh algorithmic impression rates recorded across multiple platforms12.
AttentionHigh. Sparked mainstream media discussions post-moratorium and dominated digital discourse12.
RecallHigh short-term recall due to the inflammatory nature of the content immediately prior to the vote.
ComprehensionTarget audiences correctly understood the narrative that the candidate was corrupt12.
CredibilityHigh initial credibility among predisposed partisan voters; actively disputed by digital forensics post-election15.
Belief or attitudeInsufficient empirical data to isolate the deepfake's unique impact on long-term political ideology separate from existing bias.
IntentionUnmeasured. Likely reinforced existing voting intentions among adversarial constituencies without shifting neutral intent.
BehaviorAbsent verified behavior change. While the pro-Russian candidate won, direct causal linkage between the deepfake and altered ballot-casting behavior remains unverified16.
Operational outcomeSuccessful exploitation of the media moratorium, generating widespread narrative confusion12.
Strategic effectDemonstrated the efficacy of deploying synthetic media in constrained legal windows to bypass institutional fact-checking12.

The subsequent incident involving a synthetic voice clone of United States President Joe Biden illustrates the democratization of synthetic audio spoofing. In January 2024, thousands of New Hampshire voters received a robocall featuring an AI-generated clone of Biden's voice. The artifact utilized his known catchphrases to falsely advise constituents against voting in the primary election, suggesting their votes should be saved for the general election17. The operation resulted in unprecedented federal regulatory action and highlighted the speed at which domestic actors can leverage commercial generative tools.

MetricFinding
Artifact or event existenceVerified. Thousands of robocalls intercepted and logged by telecommunications networks17.
Content statusAI use was confirmed. Voice clone generated via commercial synthetic audio software17.
CoordinationCentralized distribution via a telecom provider (Lingo Telecom)18.
Actor identitySteve Kramer (political consultant)17.
Sponsorship or directionIndependent action. Actor claimed the intent was an act of civil disobedience to spur AI regulation17.
IntentOstensibly to raise awareness regarding AI dangers; functionally to deter voter participation17.
OutputAI-generated voice recording delivered via automated telephony18.
DistributionDirect-to-consumer phone calls spoofing a known political operative's caller ID18.
AvailabilityDirected push-communication; targets did not seek out the artifact17.
ReachThousands of targeted New Hampshire voter phone numbers18.
ExposureHigh relative to the target list; successful call connections established17.
AttentionExtensive national media coverage and regulatory scrutiny18.
RecallHigh among recipients and the general public following mass media reporting.
ComprehensionClear understanding of the directive to withhold votes17.
CredibilityModerate to low. Promptly flagged as anomalous by sophisticated voters, though convincing in tone17.
Belief or attitudeNo evidence of altered democratic beliefs.
IntentionUnverified impact on intention to vote.
BehaviorAbsent. Turnout remained robust, and the targeted candidate won via write-in. No validated evidence of voter suppression17.
Operational outcomeTactical failure in vote suppression; tactical success in generating media spectacle17.
Strategic effectCatalyzed Federal Communications Commission (FCC) regulatory penalties ($6 million fine) and accelerated legislation against AI telephony spoofing19.

Electoral subversion extends beyond advanced Western democracies. Ahead of the January 2024 national elections in Bangladesh, a deepfake video emerged depicting independent candidate Abdullah Nahod Nigar explicitly stating her withdrawal from the electoral race22. This represents a highly specific application of identity-based deepfakes, seeking to manipulate public perception by falsely attributing actions to individuals to discourage voter participation22.

MetricFinding
Artifact or event existenceVerified. Video surfaced on public social media ecosystems23.
Content statusAI use was confirmed. Deep generative methods utilized to manipulate the candidate's likeness and speech23.
CoordinationDisseminated by networked partisan accounts attempting to suppress opposition momentum23.
Actor identityUnattributed digital operatives23.
Sponsorship or directionInferred domestic political factions seeking to benefit the ruling disposition23.
IntentSuppress voter turnout for the specific candidate by manufacturing false resignation22.
OutputDeepfake video file23.
DistributionFacebook and regional digital sharing networks23.
AvailabilityWidely accessible in targeted electoral constituencies23.
ReachTens of thousands of regional voters23.
ExposureAchieved significant algorithmic spread before fact-checker intervention23.
AttentionGenerated confusion among the electorate and required immediate debunking by campaign staff22.
RecallModerate; quickly superseded by post-election developments.
ComprehensionHighly effective; the message of withdrawal was unambiguous22.
CredibilityHigh initial credibility due to the low digital literacy context of the target environment23.
Belief or attitudeInduced temporary belief in the candidate's capitulation among exposed voters.
IntentionLikely intended to dissuade supporters from visiting polling stations.
BehaviorAbsent verified behavior change. Candidate lost by a narrow margin, but empirical attribution of vote-loss directly to the deepfake is unverified23.
Operational outcomeDisrupted campaign operations, forcing resources into crisis communication22.
Strategic effectNormalized synthetic media as a viable tool for localized voter suppression in emerging democracies14.

During Taiwan's 2024 presidential elections, cognitive warfare escalated to include synthetic media campaigns targeting cross-strait relations. Operations featured fabricated polling data and deepfake videos portraying current President Ching-te Lai praising the opposition Kuomintang (KMT) party25. The Taiwanese information environment, highly resilient due to continuous exposure to adversarial interference, provides a crucial baseline for observing cognitive defense mechanisms against AI influence.

MetricFinding
Artifact or event existenceVerified. Synthetic videos and fabricated data sets were detected in the wild25.
Content statusAI use was confirmed. Deepfakes utilized to manipulate the politician's statements25.
CoordinationNetworked distribution across cross-strait information platforms25.
Actor identityUnattributed, assessed by researchers to align with Chinese information operations25.
Sponsorship or directionAlleged state-sponsored interference targeting Taiwanese sovereignty25.
IntentConfuse Democratic Progressive Party (DPP) supporters and artificially boost KMT legitimacy25.
OutputDeepfake video and synthetic textual data (polls)25.
DistributionTaiwanese social media platforms, Line groups, and YouTube25.
AvailabilityReadily available to the Taiwanese digital public25.
ReachBroad national reach across the voting populace25.
ExposureSignificant impressions, actively contested by Taiwanese civil society25.
AttentionHigh. Triggered national security alerts and rapid counter-messaging25.
RecallHigh, contextualized as part of broader external interference efforts.
ComprehensionThe fabricated endorsement was clearly understood25.
CredibilityLow to moderate. Taiwan's highly resilient cognitive defense ecosystem quickly identified anomalies25.
Belief or attitudeNo verified shift in fundamental cross-strait ideological attitudes.
IntentionAttempted to shift voter intentions toward the opposition.
BehaviorAbsent. The targeted candidate ultimately secured the presidency. No evidence of widespread behavior change25.
Operational outcomeFailed to achieve the desired electoral disruption25.
Strategic effectAccelerated Taiwan's investment in AI literacy and rapid-response verification networks.

Returning to the 2023 Slovak election, a precursor to the Šimečka incident occurred one week prior to voting. The extremist media outlet Kulturblog released an audio deepfake falsely portraying then-President Zuzana Čaputová endorsing Milan Mazurek, a candidate from the far-right Republic Movement13. This operation highlighted the utility of manufacturing endorsements from highly trusted institutional figures to legitimize fringe political movements.

MetricFinding
Artifact or event existenceVerified. Audio disseminated via extremist channels13.
Content statusAI use was confirmed. Synthetic audio cloning13.
CoordinationDistributed by a specific media outlet with known personnel ties to the benefiting political party13.
Actor identityKulturblog (extremist media outlet)13.
Sponsorship or directionDomestic partisan actors13.
IntentLegitimize a fringe candidate by manufacturing an endorsement from a highly trusted institutional figure13.
OutputSynthetic audio clip13.
DistributionTelegram and secondary social media platforms13.
AvailabilityHigh availability within closed and semi-closed partisan networks13.
ReachPrimarily reached right-wing ideological silos before crossing into mainstream monitoring13.
ExposureModerate impression count13.
AttentionGarnered attention primarily from digital forensics and election watchdogs13.
RecallModerate. Overshadowed by the subsequent Šimečka deepfake incident13.
ComprehensionNarrative easily understood by the audience13.
CredibilityLow outside of deeply entrenched echo chambers; the political misalignment was overtly suspicious13.
Belief or attitudeInsufficient evidence of attitude shift among mainstream voters.
IntentionAttempted to drive undecided voters toward the far-right.
BehaviorAbsent verified behavior change. No measurable shift in physical voting behavior attributable to this specific file.
Operational outcomeMinor tactical success in energizing the extremist base, failure in mainstream persuasion13.
Strategic effectDemonstrated the democratization of voice-cloning technology among low-tier partisan actors12.

Category II: Narrative Contamination and Epistemic Poisoning

Adversarial state and proxy networks continually evolve tactics to degrade the foundations of information reliability. Rather than merely presenting false information, contemporary operations seek to permanently poison the infrastructure of truth-seeking by grooming Large Language Models and generating pervasive cloned media environments4. The Russian disinformation network known as Pravda (or Portal Kombat) engaged in a campaign to flood the internet with pro-Kremlin falsehoods with the specific intent of manipulating the training data and real-time retrieval mechanisms of major AI chatbots6. By exploiting the Retrieval-Augmented Generation (RAG) pipelines of commercial models, the network ensures that users querying geopolitical events are served state-sponsored propaganda framed as objective machine output4.

MetricFinding
Artifact or event existenceVerified. Security audits confirmed the proliferation of fake sites and subsequent chatbot responses6.
Content statusAI use was confirmed. Exploited the architecture of Large Language Models (LLMs) via RAG pipelines6.
CoordinationMassive automated dissemination across a network of faux-news portals6.
Actor identityPravda / Portal Kombat6.
Sponsorship or directionRussian state-aligned networks6.
IntentExecute "LLM grooming" to ensure AI models hallucinate or cite Russian propaganda as objective truth6.
OutputAltered generative text outputs from major commercial AI chatbots6.
DistributionInfiltrated the data scraping and RAG pipelines of commercial AIs6.
AvailabilityAvailable to any global user querying affected AI models regarding geopolitical events6.
ReachPotentially billions of commercial AI users globally6.
ExposureHigh. Researchers found 10 major AI chatbots repeated these narratives 33% of the time6.
AttentionHigh alarm within the cybersecurity and AI safety communities6.
RecallIrrelevant for targets, as the deception occurs at the knowledge-retrieval layer4.
ComprehensionUsers comprehended the AI outputs as authoritative factual summaries4.
CredibilityExtremely high. Users implicitly trust major AI platform outputs more than random web links4.
Belief or attitudeStrong potential to alter beliefs due to the perceived neutrality of the AI source4.
IntentionUnmeasured.
BehaviorAbsent verified behavior change, though it alters information consumption habits by terminating verification.
Operational outcomeHighly successful epistemic contamination of commercial AI safety boundaries6.
Strategic effectHighlighted a critical vulnerability in the global epistemic infrastructure, forcing AI companies to overhaul data provenance4.

Operating alongside data-poisoning efforts is the Doppelgänger campaign. Active since at least May 2022, the Russian-aligned network utilizes generative AI and cybersquatting to clone legitimate Western news sites, including Le Monde, The Washington Post, and Der Spiegel. These cloned sites host synthetic articles designed to undermine Western support for Ukraine26. This constitutes a profound evolution in media impersonation, moving beyond isolated fake news posts into the creation of entirely simulated media environments.

MetricFinding
Artifact or event existenceVerified. Extensive forensic documentation of cloned infrastructure and thousands of fabricated articles26.
Content statusAI use was confirmed. Generative text utilized for article creation; synthetic profiles used for amplification26.
CoordinationHighly synchronized infrastructure utilizing automated bot amplification on Meta and X26.
Actor identitySocial Design Agency (SDA) and Structura National Technologies26.
Sponsorship or directionDirected by the Russian Presidential Administration28.
IntentFracture European/Transatlantic resolve, discredit Ukraine, and erode trust in Western media27.
OutputCloned domains, generative articles, and synthetic social media comments26.
DistributionTyposquatted URLs pushed via targeted social media advertising and bot swarms26.
AvailabilityUniversally accessible on the open web to users who click the deceptive links26.
ReachTransnational (targeted France, Germany, USA, Ukraine)27.
ExposureMillions of cumulative impressions driven by paid advertising and automated commenting28.
AttentionHigh institutional attention; resulted in massive platform takedowns and international sanctions28.
RecallLow artifact recall among general populations, high thematic recall regarding Ukraine fatigue.
ComprehensionClear narrative delivery utilizing localized languages27.
CredibilityTemporarily high when users failed to inspect URLs; degraded immediately upon forensic exposure26.
Belief or attitudeContributed to ambient informational fatigue, but isolated ideological shifts are difficult to empirically attribute32.
IntentionAimed to shift policy support away from military aid27.
BehaviorAbsent verified behavior change. Western aid continued despite the campaign27.
Operational outcomeSustained operational persistence despite massive digital platform countermeasures29.
Strategic effectForced fundamental shifts in Western cyber defense, resulting in US DOJ domain seizures and EU sanctions28.

A variation of this strategy focuses on regional influence through proxy writers. Moscow-based tech firm Structura National Technologies utilized generative AI chatbots to amplify stories written by localized proxy writers across South America, targeting regional discourse34. By pairing human "meatware" for contextual authenticity with AI software for scalable distribution, the network optimized narrative injection across the Global South.

MetricFinding
Artifact or event existenceVerified by U.S. State Department disclosures34.
Content statusAI use was confirmed. AI chatbots utilized for automated dissemination and narrative amplification34.
CoordinationHighly synchronized integration of human authors and AI distribution bots34.
Actor identityStructura National Technologies / Social Design Agency34.
Sponsorship or directionRussian Kremlin34.
IntentFoster anti-U.S. and pro-Russian sentiment in the Global South34.
OutputHigh-volume generative text and social media commentary34.
DistributionMajor social media platforms accessible in Latin America34.
AvailabilityAvailable to targeted demographic segments34.
ReachTransnational (Central and South America)34.
ExposureUnquantified officially, but assessed as high volume based on bot activity34.
AttentionGarnered U.S. federal sanctions and intelligence reports30.
RecallLow. The tactic relies on ambient volume rather than memorable individual artifacts.
ComprehensionNarratives were contextually localized for high comprehension34.
CredibilityHigh, as the content originated from seemingly organic local writers before AI amplification34.
Belief or attitudeLong-term ideological shift is unverified but represents the core objective34.
IntentionUnmeasured.
BehaviorAbsent verified behavior change.
Operational outcomeAchieved sustained information dominance in targeted digital sectors prior to disruption34.
Strategic effectIllustrated the hybrid model of AI operations: integrating organic local authors with automated synthetic distribution networks34.

Similarly targeting domestic discourse, a network identified by Recorded Future analysts as "CopyCop," aligned with the Russian government, shifted its focus to the 2024 US elections. The network utilized AI to generate political content and inauthentic websites, disseminating targeted narratives through a widespread architecture of YouTube videos35.

MetricFinding
Artifact or event existenceVerified. Network architecture and video content logged by intelligence analysts35.
Content statusAI use was inferred/alleged. Identified as utilizing generative AI for content scaling35.
CoordinationNetworked cross-platform coordination bridging fake websites to YouTube amplification35.
Actor identityCopyCop network35.
Sponsorship or directionRussian government-aligned35.
IntentInflame partisan tensions surrounding the 2024 U.S. elections35.
OutputYouTube videos and inauthentic web articles35.
DistributionYouTube and cybersquatted digital platforms35.
AvailabilityReadily accessible to standard internet users searching political terms35.
ReachTargeted at the U.S. electorate35.
ExposureHigh view counts on targeted YouTube distribution nodes35.
AttentionIdentified by commercial threat intelligence sectors35.
RecallModerate among specific algorithmic consumer silos.
ComprehensionStandard political narratives were easily comprehended35.
CredibilityModerate; disguised as standard domestic political commentary35.
Belief or attitudeReinforced prevailing domestic partisan divides.
IntentionUnmeasured.
BehaviorAbsent verified behavior change.
Operational outcomeSuccessfully established a bridgehead in video-based disinformation prior to detection35.
Strategic effectDemonstrated the efficacy of combining text-based generative sites with automated video pipelines to bypass single-platform moderation35.

Storm-1516 further refined the use of fake news sites by launching a highly targeted character assassination campaign against US Vice President Kamala Harris. A site titled "KBSF-San Francisco News" featured an AI-generated video of a fabricated victim, "Alisha Brown," falsely accusing Harris of a 2011 hit-and-run6. The operation combined synthetic video, stolen medical imagery, and a fabricated institutional framework.

MetricFinding
Artifact or event existenceVerified. Website and video deployed and tracked by Microsoft researchers6.
Content statusAI use was confirmed. AI-generated testimonial video utilizing stolen medical imagery6.
CoordinationNetworked distribution; pushed by bots and inadvertently shared by prominent politicians6.
Actor identityStorm-15166.
Sponsorship or directionRussian state-aligned6.
IntentCharacter assassination of a prominent political figure ahead of the 2024 election6.
OutputSynthetic video and fabricated news articles6.
DistributionHosted on a cybersquatted domain (Iceland registry) and amplified via X and TikTok6.
AvailabilityAvailable to general digital audiences6.
ReachGlobal, focusing on the U.S. electorate6.
ExposureMillions of impressions driven by algorithmic trending hashtags (\#HitAndRunKamala)36.
AttentionHigh. Debunked rapidly by CBS News and local police departments36.
RecallModerate among political operatives; low retention among the general public post-debunking.
ComprehensionNarrative of a criminal cover-up was unambiguous36.
CredibilityBriefly moderate due to the use of a seemingly legitimate news outlet structure; collapsed upon verification36.
Belief or attitudeInsufficient evidence to demonstrate a persistent shift in candidate favorability ratings36.
IntentionUnmeasured.
BehaviorAbsent verified behavior change. No validated electoral shift resulted from this artifact.
Operational outcomeTemporary narrative injection achieved, but rapidly neutralized by OSINT and media verification36.
Strategic effectReaffirmed the tactical reliance of foreign actors on fabricated domestic personas to launder disinformation into adversarial information spaces6.

Category III: Geopolitical Escalation and Synthetic Shock

Synthetic media enables state and non-state actors to manufacture geopolitical crises out of whole cloth, projecting false threats to demoralize populations, strain diplomatic alliances, or deter public activity. These operations leverage the authority of international institutions or the visceral fear of terrorism. In early 2024, the Russian-aligned Storm-1679 network launched a campaign to disparage the International Olympic Committee (IOC) and deter spectators from the Paris Games. This included a sophisticated synthetic documentary narrated by an AI clone of actor Tom Cruise, alongside deepfake news clips warning of impending terrorism37. The operation weaponized celebrity familiarity and trusted news branding.

MetricFinding
Artifact or event existenceVerified. The documentary and fake news segments were archived by researchers37.
Content statusAI use was confirmed. Voice cloning (Tom Cruise) and deepfake news anchors (Euro News, E\! News)37.
CoordinationSustained, multi-platform release synchronized to coincide with Olympic milestones37.
Actor identityStorm-1679 (also linked to Operation Overload / Matryoshka)37.
Sponsorship or directionRussian state-aligned influence operations37.
IntentDemoralize the French public, defame the IOC, and foment public fear of violence37.
OutputSynthetic documentary and fabricated broadcast news clips37.
DistributionTelegram, X, and various video-hosting platforms37.
AvailabilityPublicly accessible; highly optimized for algorithmic recommendation38.
ReachGlobal, with a specific operational focus on European and American audiences37.
ExposureReached millions of impressions; inadvertently amplified by high-profile figures37.
AttentionGarnered significant media and government attention (VIGINUM reports)32.
RecallModerate to high among targeted digital clusters due to the novelty of the Hollywood persona38.
ComprehensionNarrative regarding Olympic insecurity was clearly understood37.
CredibilityModerately high initially due to the sophisticated brand spoofing of trusted outlets38.
Belief or attitudeMay have induced ambient anxiety, though widespread attitude shifts against the IOC are unproven37.
IntentionDesigned to induce the intention to cancel travel plans37.
BehaviorAbsent verified behavior change. The Paris Olympics experienced record attendance; the campaign failed to manifest physical deterrence37.
Operational outcomeAchieved narrative injection but failed to achieve kinetic or behavioral disruption37.
Strategic effectForced European intelligence agencies to permanently integrate synthetic media detection into physical event security protocols32.

A supplementary component of the Olympic disruption effort occurred in July 2024, when Storm-1679 released a deepfake video purporting to show members of Hamas threatening to carry out terrorist attacks during the Paris Games32. This artifact represented a complex multi-polar spoof, wherein a Russian-aligned network fabricated a threat from a Middle Eastern militant group against a Western nation.

MetricFinding
Artifact or event existenceVerified. Video surfaced globally across social networks32.
Content statusAI use was confirmed. Deepfake video manipulation and synthetic audio translation32.
CoordinationCentralized release with decentralized bot amplification32.
Actor identityStorm-167932.
Sponsorship or directionRussian state-aligned32.
IntentInstill terror, suppress Olympic attendance, and falsely implicate a third-party geopolitical actor32.
OutputDeepfake terrorist threat video32.
DistributionX, Telegram, and mainstream media aggregation32.
AvailabilityWidely accessible32.
ReachGlobal32.
ExposureMillions of impressions32.
AttentionSevere. Hamas officials themselves were forced to publicly debunk the video36.
RecallModerate. Quickly identified as a hoax by state intelligence32.
ComprehensionThe threat of violence was clearly understood32.
CredibilityBriefly high due to the ambient threat environment, but rapidly degraded upon Hamas' denial and OSINT analysis32.
Belief or attitudeTransitory spike in anxiety; no lasting shift in geopolitical belief architectures32.
IntentionInduce physical avoidance of Paris32.
BehaviorAbsent verified behavior change. The Paris Olympics proceeded without significant attendance drops37.
Operational outcomeFailed to achieve behavioral disruption, though it successfully hijacked media cycles32.
Strategic effectDemonstrated the vulnerability of attributing synthetic threats in multi-polar environments, muddying attribution waters32.

Shifting focus to domestic American geopolitics, Russian operatives tracked as Storm-1516 fabricated a video featuring an AI-generated persona named "Olesya," who claimed to be a Kyiv-based troll interfering in the U.S. election on behalf of Ukraine to support Joe Biden6. This operation sought to launder anti-Ukraine narratives through pseudo-independent platforms, mirroring organic whistleblowing to degrade Western support for Kyiv36.

MetricFinding
Artifact or event existenceVerified. Video surfaced and was amplified by identified Russian networks6.
Content statusAI use was confirmed. U.S. intelligence confirmed the persona and voice were synthetic6.
CoordinationNetworked distribution; laundered through pseudo-independent platforms to mimic organic whistleblowing6.
Actor identityStorm-1516 (Russian propagandist network)6.
Sponsorship or directionState-aligned Russian intelligence/propaganda apparatus36.
IntentDiscredit Ukraine, interfere in the U.S. election, and foster domestic American political polarization6.
OutputDeepfake video with synthetic audio and visual persona6.
DistributionX (formerly Twitter), Telegram, and fringe video-hosting sites36.
AvailabilityAccessible globally but targeted toward English-speaking American audiences36.
ReachHundreds of thousands within politically engaged digital spheres41.
ExposureHigh impression counts before being flagged by researchers6.
AttentionGarnered significant scrutiny from threat intelligence firms and U.S. agencies6.
RecallModerate among specific geopolitical analysts; low among the general public.
ComprehensionThe narrative of Ukrainian election interference was explicitly conveyed and understood6.
CredibilityHigh within algorithmic echo chambers predisposed to anti-Ukraine sentiment; low outside those silos36.
Belief or attitudeLikely entrenched pre-existing confirmation bias regarding foreign corruption6.
IntentionUnmeasured. Intended to degrade political support for the incumbent administration.
BehaviorAbsent verified behavior change. No documented shift in aggregate U.S. voting behavior directly linked to this artifact6.
Operational outcomeSuccessfully laundered the narrative into the U.S. information ecosystem41.
Strategic effectDemonstrated the evolution of "whistleblower" fabrication utilizing untraceable synthetic personas36.

Storm-1516 further exacerbated domestic US tensions by propagating a conspiracy theory asserting that the FBI had bugged Donald Trump’s Mar-a-Lago residence during the August 2022 search36. The campaign utilized synthetic elements, staged evidence, and coordinated bot deployment to mimic a groundswell of organic outrage.

MetricFinding
Artifact or event existenceVerified. Coordinated posts and fabricated evidence circulated widely36.
Content statusAI use was alleged. Utilized manipulated imagery and highly coordinated synthetic bot networks for amplification36.
CoordinationHigh. Seeded by purported "citizen journalists" and amplified by unaffiliated proxy networks36.
Actor identityStorm-151636.
Sponsorship or directionRussian state-aligned36.
IntentErode domestic trust in U.S. law enforcement and stoke partisan outrage ahead of the 2024 election36.
OutputFabricated whistleblower testimonials and manipulated digital imagery36.
DistributionX, YouTube, and partisan American echo chambers36.
AvailabilityReadily accessible to the American electorate36.
ReachReached millions within domestic U.S. political networks36.
ExposureSignificant algorithmic amplification before mitigation36.
AttentionHigh intra-network attention; moderate mainstream media debunking36.
RecallHigh among constituencies predisposed to anti-institutional narratives36.
ComprehensionThe narrative of government overreach was explicitly clear36.
CredibilityHigh among targeted partisan demographics; zero among broader audiences36.
Belief or attitudeEntrenched existing institutional distrust36.
IntentionUnmeasured.
BehaviorAbsent verified behavior change. No physical action or proven electoral shift directly linked to this specific artifact36.
Operational outcomeSuccessfully penetrated domestic political discourse, forcing media fact-checking36.
Strategic effectFurther blurred the line between domestic hyper-partisanship and foreign interference36.

In another operation designed to drive a wedge between Western allies, Storm-1516 generated and disseminated a fake video depicting Ukrainian soldiers burning an effigy of Donald Trump36. This artifact sought to weaponize domestic American political loyalty against international military aid commitments.

MetricFinding
Artifact or event existenceVerified. Video surfaced and was documented by intelligence analysts36.
Content statusAI use was inferred/alleged. Synthetic generation and recontextualization suspected by forensic analysts36.
CoordinationDistributed rapidly through right-wing American channels36.
Actor identityStorm-151636.
Sponsorship or directionRussian state-aligned36.
IntentDiminish Western support for military aid in Ukraine following Russia's invasion36.
OutputFabricated video artifact36.
DistributionX, Telegram, and partisan video networks36.
AvailabilityHighly accessible to targeted political segments36.
ReachTargeted specific congressional constituencies and political influencers36.
ExposureAchieved viral metrics before platform suppression36.
AttentionAddressed by disinformation researchers and media outlets36.
RecallModerate among specific voter blocs.
ComprehensionNarrative of Ukrainian hostility toward a US political figure was clear36.
CredibilityHigh among audiences predisposed to skepticism regarding foreign aid36.
Belief or attitudeDesigned to solidify anti-Ukraine sentiment among specific demographics36.
IntentionUnmeasured.
BehaviorAbsent verified behavior change. Did not result in immediate legislative voting shifts36.
Operational outcomeSucceeded in manufacturing a polarizing cultural flashpoint36.
Strategic effectValidated the utility of manufacturing highly specific, visually provocative content to exploit legislative wedge issues36.

Category IV: Reputational Assassination and Tactical Shock

The precise targeting of individuals via synthetic media bypasses rational analysis, directly targeting the limbic system through outrage and shame42. In parallel, the integration of AI-generated battle damage into ongoing kinetic conflicts collapses the distinction between the physical and cognitive domains, achieving immediate tactical paralysis2. In November 2023, an audio deepfake circulated depicting London Mayor Sadiq Khan disparaging Remembrance weekend and prioritizing pro-Palestinian marches. Released during a period of high social tension in the UK, the artifact sought to incite physical clashes between far-right protestors and law enforcement45.

MetricFinding
Artifact or event existenceVerified. Audio clip spread virally across multiple platforms46.
Content statusAI use was confirmed. Analysis revealed unnatural cadences indicative of AI voice cloning47.
CoordinationAmplified organically by far-right networks; initial seeding remains murky46.
Actor identityUnidentified creator; amplified by domestic UK actors47.
Sponsorship or directionUnknown; likely domestic rogue actors seeking racial/political friction47.
IntentIncite hostility against the Mayor and spark civil disorder ahead of public demonstrations46.
OutputSynthetic audio clip embedded within video templates46.
DistributionTikTok, X, Facebook, and WhatsApp47.
AvailabilityHighly accessible; frequently forwarded through peer-to-peer networks47.
ReachMillions of UK citizens46.
ExposureHundreds of thousands of direct engagements and shares46.
AttentionSevere. Resulted in police reviews, mayoral statements, and national media coverage46.
RecallHigh, due to the emotional and controversial nature of the statements49.
ComprehensionNarrative of mayoral betrayal and partisan bias was easily understood47.
CredibilityHigh among far-right demographics; actively disputed by authorities47.
Belief or attitudeValidated pre-existing animosity; unlikely to have shifted neutral attitudes given prompt debunking49.
IntentionDesigned to incite mobilization against the Mayor and the police49.
BehaviorAbsent verified behavior change. While clashes with police occurred, directly attributing participation to the deepfake is confounding46.
Operational outcomeCreated an immediate crisis-management scenario for London authorities49.
Strategic effectHighlighted the legal void surrounding synthetic media; authorities determined no explicit crime was committed under existing laws45.

Reputational assassination in conservative societies often relies on gendered synthetic media to bypass political debate entirely. In the lead-up to the 2024 general election in Bangladesh, female opposition politicians, including Rumin Farhana and Nipun Roy, were targeted with highly realistic deepfake videos placing them in bikinis or swimming pools24.

MetricFinding
Artifact or event existenceVerified. Media files were actively circulated and collected by researchers24.
Content statusAI use was confirmed. AI manipulation mapping faces to non-consensual or compromising imagery24.
CoordinationDecentralized, but likely orchestrated by partisan opposition networks14.
Actor identityUnattributed digital operatives14.
Sponsorship or directionInferred domestic pro-government or rival partisan forces23.
IntentSilence, shame, and discredit female leaders within a highly conservative cultural context22.
OutputSynthetic image and video files24.
DistributionWhatsApp, Facebook, and regional digital platforms23.
AvailabilityHighly accessible via peer-to-peer sharing23.
ReachNational reach across the Bangladeshi electorate14.
ExposureWidespread impressions, specifically targeting the constituencies of the victims24.
AttentionHigh. Triggered trauma, rapid public responses, and international human rights condemnation44.
RecallExtremely high due to the shocking cultural transgression of the imagery44.
ComprehensionTarget audience understood the intent to frame the women as morally corrupt44.
CredibilityHigh initial credibility. The seamlessness of the technology bypassed the digital literacy levels of many voters24.
Belief or attitudeInduced reputational damage and likely shifted cultural attitudes toward the candidates' viability24.
IntentionTo force withdrawal from public life and suppress support44.
BehaviorAbsent verified behavior change on voting. However, it contributed to an environment of severe political intimidation44.
Operational outcomeHighly successful in creating psychological distress and forcing defensive posturing44.
Strategic effectDemonstrated that in conservative societies, deepfakes do not require political substance to achieve political neutralization; character assassination suffices22.

In the same electoral cycle, a synthetic video of exiled Bangladeshi opposition leader Tarique Rahman was circulated, showing him urging the public not to criticize Israel’s bombardment of Gaza—a highly controversial stance in a Muslim-majority nation14. This artifact sought to sever the opposition from its core geopolitical alignment.

MetricFinding
Artifact or event existenceVerified. Video widely distributed during the campaign23.
Content statusAI use was confirmed. Deepfake video manipulation14.
CoordinationNetworked distribution across partisan channels23.
Actor identityUnattributed23.
Sponsorship or directionInferred state/pro-government actors attempting to alienate the opposition's base23.
IntentDrive a wedge between the opposition party and its Muslim-majority constituency over a highly emotive geopolitical issue23.
OutputDeepfake video23.
DistributionFacebook and domestic media networks23.
AvailabilityWidely accessible23.
ReachMillions of Bangladeshi voters23.
ExposureHigh impression rates across partisan divides23.
AttentionHigh. Required immediate organizational pushback from the opposition23.
RecallHigh, tying the candidate to a culturally resonant global conflict23.
ComprehensionNarrative was clearly understood23.
CredibilityModerate to high among low digital-literacy demographics23.
Belief or attitudeLikely diminished enthusiasm among opposition supporters who believed the artifact23.
IntentionUnmeasured.
BehaviorAbsent verified behavior change. The opposition ultimately boycotted the election, making specific behavioral attribution to the video impossible23.
Operational outcomeSucceeded in forcing the opposition to expend resources clarifying their geopolitical stance23.
Strategic effectShowcased the utility of synthesizing foreign policy positions to manipulate domestic electoral dynamics23.

The most severe evolution of AI PSYOPS is its integration into kinetic military operations. During the "Twelve-Day War" engagements between Iran and Israel, synthetic videos depicting fabricated missile strikes on Tel Aviv and downed F-35 fighter jets circulated globally across five languages within hours of actual kinetic exchanges4. The capacity to generate synthetic battle damage assessments rapidly collapses the distinction between the physical and cognitive domains2.

MetricFinding
Artifact or event existenceVerified. Synthetic combat footage flooded digital platforms during the conflict4.
Content statusAI use was confirmed. AI-generated video and recontextualized synthetic assets2.
CoordinationMassive, decentralized swarm distribution2.
Actor identityUnattributed, likely Iranian state proxies and decentralized sympathetic networks2.
Sponsorship or directionState-aligned information warfare units2.
IntentProject military supremacy, demoralize the adversary, and control the global media narrative2.
OutputDeepfake combat footage4.
DistributionTelegram, X, TikTok, and regional news aggregators2.
AvailabilityUbiquitous during the crisis4.
ReachGlobal4.
ExposureHundreds of millions of impressions driven by crisis algorithms4.
AttentionExtreme. Mainstream media networks struggled to verify footage in real-time2.
RecallHigh, though specific artifacts blended into the broader fog of war4.
ComprehensionNarrative of devastating kinetic impact was instantly understood4.
CredibilityExtremely high in the critical first 24 hours due to the confirmation bias inherent in crisis situations2.
Belief or attitudeInduced temporary panic and altered perceptions of military parity2.
IntentionUnmeasured.
BehaviorAbsent verified behavior change. No data confirms military command altered kinetic strategy based solely on the deepfakes, though public anxiety spiked2.
Operational outcomeHighly successful disruption of the adversary's information dominance2.
Strategic effectNormalized synthetic battle damage as a standard operating procedure for modern kinetic engagements2.

Conversely, democratic states are actively adapting to this environment. Israel deployed Operation PRISONBREAK, releasing deepfake content targeted at adversaries within one hour of conducting physical strikes4. This operation signifies that Western-aligned militaries now treat AI-enabled PSYOPS as essential, legitimate components of modern warfighting4.

MetricFinding
Artifact or event existenceVerified through analytical reports on the conflict4.
Content statusAI use was confirmed. Synthetic media generation aligned with physical action4.
CoordinationHighly centralized and coordinated by military intelligence4.
Actor identityIsraeli state apparatus4.
Sponsorship or directionState military execution4.
IntentCompound the psychological shock of kinetic strikes and overwhelm adversary decision-making cycles2.
OutputDeepfake content integrated with authentic strike data4.
DistributionTargeted adversary communication channels and public networks4.
AvailabilityDirected specifically at adversarial populations and command structures4.
ReachRegional4.
ExposureHigh within the targeted operational theater4.
AttentionImmediate cognitive disruption for the adversary2.
RecallModerate; the kinetic strike generally supersedes the digital artifact in memory4.
ComprehensionHigh. Conveys absolute intelligence and operational dominance4.
CredibilityHigh, as the synthetic media was grounded by immediate, verifiable physical explosions4.
Belief or attitudeDiminished adversarial morale4.
IntentionInduce surrender, paralysis, or capitulation4.
BehaviorAbsent verified behavior change, but theoretically designed to slow adversarial response times.
Operational outcomeSuccessfully merged the physical and cognitive domains to achieve tactical shock2.
Strategic effectValidated that democratic states treat AI-enabled PSYOPS as essential, legitimate military capabilities4.

Strategic Synthesis and Insights

The compilation and analysis of these twenty cases yield critical second- and third-order insights regarding the trajectory of AI-enabled psychological operations. The evolution observed across these incidents dictates a fundamental reassessment of cognitive defense strategies and the mechanisms by which state and non-state actors influence the global information environment. The primary defense against analog disinformation historically relied on factual verification and media literacy. However, the data reveals that the integration of AI models has shifted adversarial strategy toward structural epistemic contamination4. The Pravda Network (Case 6\) and the deployment of Doppelgänger cloned media sites demonstrate that influence operations are increasingly targeting the architectural layer of information retrieval6. By grooming Large Language Models and poisoning training data, adversaries ensure that users querying an AI assistant regarding geopolitical events are served state-sponsored propaganda framed as objective machine output4. Fact-checking frameworks are rendered obsolete when the baseline architecture of knowledge retrieval is compromised. The target experiences the induced doubt not as a partisan attack, but as an organic discovery of facts3. Furthermore, the data consistently highlights a profound disconnect between distribution metrics and psychological efficacy, reinforcing the critical distinction between exposure and persuasion7. Operations such as the New Hampshire Biden Robocall and the Paris Olympics Hamas Threat achieved massive digital reach and generated severe media spectacles, yet they failed entirely to manifest the intended physical behavior17. Voter turnout remained robust, and Olympic attendance did not crash21. This divergence indicates that while AI can effortlessly scale exposure and hijack attention networks, genuine behavioral manipulation still encounters intense cognitive friction9. Exposure to a deepfake does not invariably translate into a structural ideological shift10. The intersection of these technologies with societal structures reveals deep contextual vulnerabilities. The targeted attacks on female politicians in Bangladesh demonstrate that AI PSYOPS are devastatingly effective when they exploit localized cultural paradigms24. In conservative societies bound by stringent modesty norms, an adversary does not need to articulate a complex political argument to neutralize an opponent; generating a synthetic image that transgresses cultural taboos achieves immediate reputational destruction22. The technological capability is universal, but the psychological payload is strictly culturally contingent. Simultaneously, the convergence of the cognitive and kinetic domains during military conflict represents an alarming escalation2. The deployment of deepfakes during the "Twelve-Day War" and the proactive use of synthetic media in Israel's Operation PRISONBREAK signify the militarization of AI generative platforms4. Artificial intelligence allows for the fabrication of battle damage within hours of a kinetic event, operating well inside an adversary's decision cycle2. The strategic effect is not long-term persuasion, but immediate tactical paralysis. If a military command cannot rapidly verify whether a missile strike has occurred, decision-making is frozen, fundamentally altering the tempo of physical warfare2. Finally, the persistence of operations like Storm-1516 and Doppelgänger, despite repeated exposure and infrastructure takedowns by Western intelligence and technology platforms, indicates a doctrinal shift among adversaries27. These threat networks do not view detection as an operational failure. Instead, they operate on a "burn-and-learn" methodology, utilizing the detection mechanisms of targeted nations to actively A/B test the efficacy and resilience of their generative models4. The continuous friction provided by defensive countermeasures actively trains adversarial algorithms, ensuring that subsequent cognitive campaigns are increasingly sophisticated, culturally attuned, and structurally integrated into the modern information environment4.

Works cited

1. O'Reilly Media \- Apple Podcasts, https://podcasts.apple.com/us/podcast/oreilly-bots-podcast-oreilly-media-podcast/id1145426486

2. When Perception Becomes the Battlefield \- Small Wars Journal, https://smallwarsjournal.com/2026/07/15/when-perception-becomes-the-battlefield/

3. Invisible by design: NATO's 2026 cognitive warfare paper and the crisis of discovery, https://complexdiscovery.com/invisible-by-design-natos-2026-cognitive-warfare-paper-and-the-crisis-of-discovery/

4. AI-Driven Information Warfare: Disinformation and Psychological Manipulation, https://bisi.org.uk/reports/ai-driven-information-warfare-disinformation-and-psychological-manipulation

5. Soft Power 'Sky Net' – The Importance of Artificial Intelligence for Information Operations, https://researchcentre.army.gov.au/library/australian-army-journal-aaj/volume-19-number-1/soft-power-sky-net-importance-artificial-intelligence-information-operations

6. Entity: Storm-1516 \- AI Incident Database, https://incidentdatabase.ai/entities/storm-1516/

7. MAKING THEORY USING HEURISTICS AND BIASES TO ANALYZE PILOTS' DECISION NOT TO VACCINATE \- ProQuest, https://search.proquest.com/openview/3ca91044d0977631bbdf80014b6646a4/1.pdf?pq-origsite=gscholar\&cbl=18750\&diss=y

8. Foundations of Effective Influence Operations: A Framework for Enhancing Army Capabilities \- RAND, https://www.rand.org/content/dam/rand/pubs/monographs/2009/RAND\_MG654.pdf

9. The Attention-Information Trade-Off \- Gwern.net, https://gwern.net/doc/economics/advertising/2026-serragarcia.pdf

10. The Immensely Inflated News Audience: Assessing Bias in Self-Reported News Exposure, https://www.researchgate.net/publication/253746032\_The\_Immensely\_Inflated\_News\_Audience\_Assessing\_Bias\_in\_Self-Reported\_News\_Exposure

11. teaching public diplomacy and the information instruments of power in a complex media environment \- State Department, https://www.state.gov/wp-content/uploads/2020/08/Teaching-Public-Diplomacy-and-the-Information-Instruments-of-Power-in-a-Complex-Media-Environment-2020.pdf

12. Slovakia as the Precursor to Deepfake-Enabled Election Interference: Lessons Learned and Pathways Forward \- Proceedings of the ICWSM Workshops, https://workshop-proceedings.icwsm.org/pdf/2024\_67.pdf

13. Incident 573: Deepfake Recordings Allegedly Influence Slovakian Election, https://incidentdatabase.ai/cite/573/

14. The 2026 Electoral Information Crisis: A Quantitative Analysis of AI-Generated Misinformation and Media Impersonation in Bangladesh \- ResearchGate, https://www.researchgate.net/publication/404659494\_The\_2026\_Electoral\_Information\_Crisis\_A\_Quantitative\_Analysis\_of\_AI-Generated\_Misinformation\_and\_Media\_Impersonation\_in\_Bangladesh

15. Trolls in Slovakian election tap AI deepfakes to spread disinformation | The Straits Times, https://www.straitstimes.com/world/europe/trolls-in-slovakian-election-tap-ai-deepfakes-to-spread-disinformation

16. Get informed on the top stories of the day in one quick scan | CBC News, https://www.cbc.ca/news/canada/morning-brief-january-18-2024-1.7086086

17. New Hampshire jury acquits consultant behind AI robocalls mimicking Biden on all charges, https://www.courthousenews.com/new-hampshire-jury-acquits-consultant-behind-ai-robocalls-mimicking-biden-on-all-charges/

18. Political consultant behind fake Biden robocalls faces $6 million fine and criminal charges, https://apnews.com/article/biden-robocalls-ai-new-hampshire-charges-fines-9e9cc63a71eb9c78b9bb0d1ec2aa6e9c

19. Federal Communications Commission FCC 24-59 1, https://docs.fcc.gov/public/attachments/FCC-24-59A1.pdf

20. Company that sent fake Biden robocalls in New Hampshire agrees to $1m fine | Technology, https://www.theguardian.com/technology/article/2024/aug/22/fake-biden-robocalls-fine-lingo-telecom

21. Political consultant behind fake Biden robocalls faces $6 million fine and criminal charges \- Newsday, https://www.newsday.com/business/Biden-robocalls-AI-new-hampshire-charges-fines-v02798

22. AI, Disinformation and the Battle for Truth: How Ghana's 2024 elections exposed the new age of political deception \- WITNESS Blog, https://blog.witness.org/2025/03/disinformation-ghana-2024-election/

23. Deepfakes, Disinformation & Rationality: A Case Study of the 2024 Bangladesh Elections \- KSPP Website CMS \- Kautilya School of Public Policy, https://cms.kspp.edu.in/public/issuebrief/issuebriefdocument\_670f6b833e231.pdf

24. Deepfakes deceive voters from India to Indonesia before elections \- The Hindu, https://www.thehindu.com/sci-tech/technology/deepfakes-deceive-voters-from-india-to-indonesia-before-elections/article67700785.ece

25. Election Trends for 2024: Possible Implications for the U.S. Presidential Election, https://thesoufancenter.org/intelbrief-2024-november-6/

26. Russian Disinformation Campaign “DoppelGänger” Unmasked: A Web of Deception, https://www.cybercom.mil/Media/News/Article/3895345/russian-disinformation-campaign-doppelgnger-unmasked-a-web-of-deception/

27. Doppelganger (disinformation campaign) \- Wikipedia, https://en.wikipedia.org/wiki/Doppelganger\_(disinformation\_campaign)

28. Justice Department Disrupts Covert Russian Government-Sponsored Foreign Malign Influence Operation Targeting Audiences in the United States and Elsewhere, https://www.justice.gov/archives/opa/pr/justice-department-disrupts-covert-russian-government-sponsored-foreign-malign-influence

29. Russia's AI Interference in 2024 US Elections, https://bisi.org.uk/reports/russias-ai-interference-in-2024-us-elections

30. Imposing Sanctions on Actors Supporting Kremlin-Directed Disinformation Efforts, https://2021-2025.state.gov/imposing-sanctions-on-actors-supporting-kremlin-directed-disinformation-efforts/

31. UK action against Russian foreign information warfare \- GOV.UK, https://www.gov.uk/government/publications/uk-action-against-russian-foreign-information-warfare/new-uk-action-against-foreign-information-warfare

32. Storm-1516: A wake-up call for Europe's cognitive defence \- EPC, European Policy Centre, https://www.epc.eu/publication/Storm-1516-A-wake-up-call-for-Europes-cognitive-defence-650d24/

33. Doppelganger hub \- EU DisinfoLab, https://www.disinfo.eu/doppelganger-hub/

34. Entity: Structura National Technologies \- AI Incident Database, https://incidentdatabase.ai/entities/structura-national-technologies/

35. Escalation of State-Sponsored Cyber Threat Activity | Latest Alerts and Advisories | NJCCIC, https://www.cyber.nj.gov/Home/Components/News/News/1376/214

36. Storm-1516 \- Wikipedia, https://en.wikipedia.org/wiki/Storm-1516

37. How Russia Disrupted the 2024 Paris Olympics | Security Insider \- Microsoft, https://www.microsoft.com/en-us/security/security-insider/threat-landscape/how-russia-is-trying-to-disrupt-the-2024-paris-olympic-games

38. Russian Deepfakes Fool Media: Storm-1679 Campaign Exposed \- Reality Defender, https://www.realitydefender.com/insights/russian-propaganda-network-impersonates-major-us-news-outlets-platforms-and-gover

39. Entity: Storm-1679 \- AI Incident Database, https://incidentdatabase.ai/entities/storm-1679/

40. 20250507\_TLP-CLEAR\_NP\_SGDSN\_VIGINUM\_Technical report\_Storm-1516.pdf, https://www.sgdsn.gouv.fr/files/files/Publications/20250507\_TLP-CLEAR\_NP\_SGDSN\_VIGINUM\_Technical%20report\_Storm-1516.pdf

41. Russian US election interference targets support for Ukraine after slow start \- Microsoft On the Issues, https://blogs.microsoft.com/on-the-issues/2024/04/17/russia-us-election-interference-deepfakes-ai/

42. White Paper on Influence in an Age of Rising Connectedness \- Public Intelligence, https://info.publicintelligence.net/SMA-InfluenceConnectedness.pdf

43. Emotionally based strategic communications as a new tool in defensive cognitive warfare \- PMC, https://pmc.ncbi.nlm.nih.gov/articles/PMC12920201/

44. When AI Becomes Abuse \- LSE International Development, https://blogs.lse.ac.uk/internationaldevelopment/2025/07/21/when-ai-becomes-abuse/

45. Let's stop deepfakes damaging our democracy | Good Law Project, https://goodlawproject.org/petition/lets-stop-deepfakes-damaging-our-democracy/

46. AI-Generated Deepfake of London Mayor Sadiq Khan Incites Social Disorder \- OECD.AI, https://oecd.ai/en/incidents/2024-02-13-a372

47. No evidence Sadiq Khan 'Remembrance weekend' audio clip is real \- Full Fact, https://fullfact.org/online/remembrance-day-audio-sadiq-khan-fake/

48. Sadiq Khan AI deepfake: Explained \#shorts \#news \- YouTube, https://www.youtube.com/shorts/dLIwmaHTiCQ

49. Deepfake audio of Sadiq Khan could have caused serious disorder \- CARE, https://care.org.uk/news/2024/02/deepfake-audio-of-sadiq-khan-could-have-caused-serious-disorder

50. London Mayor Sadiq Khan says fake AI audio of him nearly led to serious disorder | BBC News \- YouTube, https://www.youtube.com/watch?v=PujHvnbRJKg

51. London Mayor Sadiq Khan confronts deepfake controversy amid AI misuse, https://dig.watch/updates/london-mayor-sadiq-khan-confronts-deepfake-controversy-amid-ai-misuse

52. Pakistan's Electoral Laboratory Shows the Drawbacks and Incentives of AI Technology for Politics \- VOA, https://www.voanews.com/a/7481049.html

53. The Burn and Learn Theory of Agency Clusterfucks | by Michael Filimowicz | Spy Novel Research | Medium, https://medium.com/spy-novel-research/the-burn-and-learn-theory-of-agency-clusterfucks-b1b51aca5bb7