Disinformation & Influence Ops

Stories 10
Sources 17
Updated 2026.07.24
Europol flags 4,340 URLs tied to The Com extremist network in June-July 2026 crackdown
Europol says it flagged 4,340 URLs for removal during a June-July 2026 operation targeting online content linked to The Com, a decentralized extremist network that recruits and abuses young people online. The action was run by Europol's EU Internet Referral Unit and Spain's CITCO with investigators from nine countries, and focused on content tied to self-harm, child sexual abuse material, violent attacks, grooming, doxing, swatting, and attack manuals; Europol says The Com includes subgroups involved in cyber intrusions and ransomware. — This matters because The Com blends violent extremism with cyber-enabled abuse such as sextortion, doxing, swatting, and ransomware, often targeting minors through mainstream online platforms. Platforms, investigators, schools, and families should watch for coded recruitment content and coercion tactics, while defenders should note the group’s overlap with cybercrime activity.
Sources: Europol flags 4,340 URLs for removal in 'The Com' crackdown, Europol flags 4,340 'horrific' URLs linked to The Com
Ukraine says Russian hackers made media outlets a priority target after attacks on television broadcasters
Ukraine’s security agency says Russian hackers are increasingly targeting Ukrainian media organizations, including two previously undisclosed attacks on television broadcasters. The SBU said one incident this year was a large distributed denial-of-service, or DDoS, attack against a nationwide TV channel, while another last year combined phishing with attempts to access connected infrastructure to seize a major broadcaster’s platform and publish Russian propaganda as if it came from Ukrainian media. — This is a direct threat to news delivery and public trust during wartime, especially for broadcasters and media operations in Ukraine. Media organizations should urgently harden phishing defenses, review access to broadcast and publishing systems, and prepare for DDoS and account-takeover attempts.
Sources: Ukrainian media outlets now among 'priority targets' for Russian hackers
Google says pro-Russia influence operations are widening beyond Ukraine to target the U.S., Europe, NATO, and Africa
Google says covert pro-Russia influence campaigns are broadening their targets and narratives beyond Ukraine, with activity now aimed at the United States, European Union countries, NATO, Russia’s neighbors, the Middle East, Africa, and domestic Russian audiences. The report describes a shift from war-focused messaging to broader pre-war geopolitical objectives, indicating a wider information operation rather than a single isolated propaganda push. — This is relevant because it signals an expanded disinformation threat that can affect elections, public debate, and crisis response across multiple regions. Governments, platforms, researchers, and news consumers should expect more coordinated influence activity and scrutinize suspicious cross-platform narratives and inauthentic amplification.
Sources: In Other News: Canadian Hacker Jailed, Open Source Zero-Days, Two Sentenced for ATM Jackpotting
DOJ seizes CFAKE and SOCFAKE deepfake porn sites in first publicly announced TAKE IT DOWN Act action
The U.S. Justice Department seized CFAKE.com and SOCFAKE.com, two sites accused of hosting nonconsensual AI-generated nude images and videos of identifiable women. U.S. authorities said the domains violated the TAKE IT DOWN Act, which criminalizes publication of intimate digital forgeries without consent and requires platforms to remove reported content within 48 hours. The operation involved Homeland Security Investigations and law-enforcement partners in Italy and France, and French authorities arrested a suspect in Nice and seized related cryptocurrency. — This shows the TAKE IT DOWN Act is now being used in real enforcement, which matters to victims, platforms that host user content, and anyone tracking abuse enabled by generative AI. Platforms should review takedown processes and compliance timelines, while users should report nonconsensual deepfake imagery quickly.
Sources: DOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act
Fake breach notices were posted on Maine’s official disclosure portal using the names of VRChat and Discord
Fraudulent data-breach notices were submitted to Maine’s public breach portal and published as if they were real, falsely claiming incidents at VRChat and Discord. VRChat told BleepingComputer the filing was fake and used a nonexistent employee name, while Maine’s Attorney General office said notices can be posted without prior verification and that the VRChat entry would be removed. The incident appears to be abuse of a government disclosure system rather than a confirmed breach of the named companies. — This can mislead users, investors, journalists, and incident responders by making fake breaches look official. Organizations should monitor state breach portals for false filings in their name, and users should wait for confirmation from the affected company before reacting to reported breaches.
Sources: Maine breach portal abused to publish fake data breach disclosures, Maine disables data breach notification portal after fake disclosures, Maine Disables Data Breach Portal Due to Fake Submissions (+1 more)
OpenAI says China-linked influence operators used ChatGPT to push anti-AI datacenter narratives on social media
OpenAI says it removed accounts likely tied to China that used ChatGPT to generate posts and images for a covert influence campaign aimed at Americans. The operation focused on social-media content claiming AI datacenters drive up electricity demand and household power costs, then posted the material through likely fake X accounts alongside links to real news stories; OpenAI said the campaign showed limited authentic engagement. — This is a concrete example of AI tools being used to support state-linked influence operations, even when the campaign gains little traction. It matters for platforms, policymakers, and the public because real debates can be manipulated with synthetic content, so readers should scrutinize coordinated posts and image-driven narratives around contentious policy issues.
Sources: Chinese agents caught rebuilding botnets and stirring the pot on AI datacenter debate
Russia-linked Matryoshka disinformation campaign targeted Armenia’s 2026 election with fake news, bot networks, and hoax bomb threats
Researchers and Armenian authorities say a large Russia-linked influence operation targeted Armenia’s parliamentary election with fake stories, manipulated videos, bot amplification, and false bomb threats at polling stations. Antibot4Navalny and the Institute for Strategic Dialogue linked the activity to the Matryoshka campaign, described as part of Russia’s broader Doppelganger operation, which impersonates trusted media and government sources to spread propaganda and election-related falsehoods over an eight-month period. — This is the kind of coordinated deception campaign that can mislead voters, intimidate the public, and erode trust in elections even without hacking voting machines. Platforms, journalists, election officials, and civil society groups should watch for cloned media sites, impersonation, bot-driven amplification, and hybrid tactics such as hoax threats around major votes.
Sources: Armenia’s pro-Europe party wins election despite Russia-linked disinformation
Researchers track 5,000+ election-themed domains and exposed political credentials ahead of the 2026 U.S. midterms
Security researchers say more than 5,000 election-themed internet domains were registered in recent weeks ahead of the 2026 U.S. midterms, raising the risk of fake voting sites, donation scams, and impersonation of election officials. Check Point said the registrations increased sharply between April and May and coincided with roughly 17,000 exposed credentials tied to ActBlue, WinRed, GOP, Democrats.org, and USA.gov accounts, creating infrastructure and account access that could support phishing, fraud, or influence operations. — This matters because voters, donors, campaigns, and election workers could be tricked by lookalike sites or targeted through reused or stolen passwords. People should verify election and donation websites carefully, avoid links in unsolicited messages, and reset passwords if they may have been exposed.
Sources: Election interlopers register 5K+ domains, hope to catch some voting phish
Dutch investigators seize 800 servers tied to Stark Industries hosting network allegedly used for cyberattacks and disinformation
Dutch authorities say they seized 800 servers and arrested two men linked to a hosting operation that allegedly helped cyberattacks, disruption campaigns, and online disinformation. Investigators said the action targeted infrastructure connected to Stark Industries, an EU-sanctioned hosting provider, and two Dutch companies allegedly used to keep its services running after sanctions; reporting links the network to pro-Russian DDoS, or distributed denial-of-service, activity by NoName057(16). — This matters because the seizure hits infrastructure allegedly used to support both cyberattacks and influence operations in Europe. Defenders, hosting providers, and abuse teams should watch for fallout such as service migration, replacement infrastructure, and renewed DDoS activity from the same actors.
Sources: Netherlands seizes 800 servers of hosting firm enabling cyberattacks, Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks, Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands (+1 more)
Kremlin appoints former Rostec cyber executive reportedly linked to GRU Unit 26165 to Russian Security Council post
Russia has appointed a former cybersecurity executive reportedly tied to a military intelligence hacking unit to a senior Security Council role. The Record reports that Andrei Kozlov, formerly of Rostec's RT-Information Security and a Russian cybersecurity industry association, was named an aide to Security Council Secretary Sergei Shoigu; leaked data cited by The Insider allegedly links him to GRU Military Unit 26165, widely tracked as Fancy Bear or APT28, a group long accused of espionage, credential theft and influence operations. — This matters because it may show direct overlap between Russia's state security leadership and a unit publicly tied to past hacking and disinformation campaigns. Defenders and policymakers should treat it as contextual evidence when tracking future APT28 operations, influence activity and Russian state cyber posture.
Sources: Kremlin appoints cyber executive with alleged GRU ties to Security Council role