Tracking and analyzing foreign interference worldwide.

Washington, D.C.
Based in West Asia
Filter
Exclude
Time range
-
Minimum likes
RSA's March 2011 breach was the skeleton key. By May, PLA Unit 61398 had used it to walk through Lockheed Martin's front door, then Northrop Grumman's, then L-3 Communications, all inside a week. Lockheed locked out 126,000 employees from remote access while it figured out the damage. The supply chain attack wasn't novel in concept, but hitting RSA SecurID specifically meant one breach cascaded into the entire defense industrial base simultaneously. The 2014 DOJ indictment of five Unit 61398 officers was a milestone, though none of them ever saw a courtroom. foreigninterference.org/post… #foreigninterference #CyberEspionage #InfrastructureAttacks #TokenCompromise
30
Russia has spent the better part of 2025 running what amounts to a stress test on European infrastructure, and Germany keeps coming up as the interesting case. Hundreds of documented hybrid attacks across the continent: drone strikes, arson, railway sabotage, cyberattacks on energy systems, disinformation seeded into public discourse about government competence. The Leipzig drone factory. The weapons cache outside Berlin. BfV watching recruited agents plan sabotage operations on German soil in what is apparently becoming a fairly routine operational tempo for the GRU and its cutouts. But the Germany story isn't really about the attacks. It's about what the attacks are probing. Russia has figured out something genuinely useful: Germany's post-1945 constitutional architecture creates a set of legal seams that hybrid warfare fits into almost perfectly. The Basic Law and the legal framework built around it were designed, deliberately and with good reason, to prevent the reconstitution of a security state with unchecked domestic powers. That meant strict separation between intelligence and law enforcement, severe constraints on military deployment in domestic contexts, and a legal posture toward offensive cyber operations that leans heavily toward "we don't do that." These weren't accidents or oversights. They were the point. West Germany looked at what happened between 1933 and 1945 and built a constitutional order specifically designed to make a repeat structurally difficult. The problem is that the categories those legal distinctions depend on, civil versus military, domestic versus foreign, criminal versus state-sponsored, are precisely the categories that hybrid warfare is designed to dissolve. An arson attack on a logistics depot carried out by a recruited local criminal working for Russian intelligence: is that a crime or an act of war? A cyberattack that degrades an energy grid below the threshold of causing actual blackouts: where does law enforcement end and military response begin? Germany's legal system has specific, carefully constructed answers to these questions, and those answers keep generating the same outcome: slower response, more bureaucratic friction, and a systematic reluctance to use tools that other NATO members consider standard. That's not a bug Russia stumbled upon. That's a target they identified and are deliberately operating against. Here's the trajectory that matters. Russia has been running these operations at escalating volume through 2025 and into 2026, and the accumulated intelligence picture is that the campaign is calibrated, not chaotic. The below-Article-5 threshold isn't incidental. It's the entire operational concept. Keep the pressure high enough to impose real costs, low enough to prevent a unified NATO response, and use Germany specifically as a proof of concept that liberal constitutional constraints are a durable vulnerability. Every successful operation that goes unanswered, or that gets answered six months later after a lengthy inter-agency legal review, validates the model and encourages replication. The next phase of this, and European intelligence officials seem to believe it's already beginning, is likely to look less like isolated sabotage events and more like coordinated simultaneity. Multiple infrastructure targets across multiple countries in a compressed timeframe, designed to overwhelm response capacity and amplify the public confidence effect. The disinformation operations documented alongside the physical sabotage aren't a separate track. They're the force multiplier. The goal isn't just the blown transformer or the disrupted rail line. The goal is the public asking why the government can't seem to stop this, and the government having no clean answer because its legal toolkit doesn't match the threat. Germany is now having a public debate about whether the constitutional framework needs adaptation. That debate is painful and politically loaded for obvious reasons, and the people raising the loudest alarms about loosening those protections aren't wrong to be cautious. There's a genuine and unresolved tension between adapting to hybrid threats and creating the kind of expanded domestic security apparatus that the Basic Law was built to prevent. Wolfgang Schäuble was raising versions of this tension in German political discourse years before hybrid warfare became common vocabulary. The fact that it's now being discussed openly by intelligence officials and legal scholars, rather than quietly inside BfV, suggests the gap between threat and response has become too visible to manage quietly. But the adaptation debate is also exactly where Russia wants Germany to be spending its political energy right now. Every month that German domestic politics is consumed by arguments about constitutional reform versus institutional preservation is a month that the operational gap stays open. The Bundestag doesn't move fast on constitutional questions. The coalition arithmetic on security issues is complicated. And Russia, which has been running this campaign across a multi-year timeline with clear strategic patience, is in no particular hurry. What should observers actually watch? A few specific things. The recruitment pipeline is the leading indicator. The weapons cache near Berlin and the documented sabotage planning by recruited local agents points to Russia investing in a durable human network inside Germany, not just running one-off operations. When BfV or the Verfassungsschutz agencies report increased counter-espionage activity, that's not a sign the problem is being solved. It's a measure of how much activity there is to detect. Watch the prosecution numbers and the national security cases moving through German courts. If those numbers are climbing, the network is larger than what's publicly documented. The coordination with German domestic political actors is the second thing. Russian hybrid operations in Germany have historically included not just physical sabotage but also financial and informational support for political actors who favor weakened support for Ukraine or reduced NATO commitments. The AfD's documented Russian adjacency is not new news, but the question of whether that relationship is becoming more operationally active during an escalating hybrid campaign is one that BfV is certainly watching and largely not discussing in public. The European Parliament elections and the German electoral cycle create obvious windows. Third: the Baltic and Polish precedent. Estonia, Latvia, Lithuania, and Poland have all moved toward more aggressive counter-hybrid postures, including offensive cyber capabilities and expanded domestic security powers, with less political friction than Germany faces, partly because their historical memory of Russian occupation creates a different political baseline for these conversations. If those countries' frameworks prove effective at raising the operational cost for Russian hybrid operations, pressure on Germany to harmonize will increase significantly. NATO's hybrid warfare working groups are already pushing in this direction. The question is whether German domestic politics can absorb that pressure fast enough to matter. The complacency critique from European intelligence officials is pointed and specific. It's not saying Germany isn't spending enough on defense. Germany is moving toward the 2% GDP target. It's saying the legal architecture is generating a response gap that money doesn't fix. You can buy more Bundeswehr equipment and still have a constitutional framework that prevents using it in the contexts where hybrid warfare actually operates. That's the part that doesn't have an easy resolution. And Russia knows it. foreigninterference.org/post… #foreigninterference #InfrastructureAttacks #IndustrialSabotage #DisinformationCampaigns #PhysicalInfrastructureTampering #MultiDomainWarfareCoordination
102
TASK#STOMP is a document theft op with a collection list, not a smash-and-grab. That distinction matters. Late September 2026 is also when illegal AI model access solidified as a tradeable commodity in criminal markets. States build the tools, proxies buy in, and the attribution gets murkier every time. Meanwhile Russian disinfo, Chinese APT ops, Iranian diaspora targeting, and North Korean financial theft are all running concurrently. Not a coincidence. Governments have limited bandwidth right now and everyone knows it. foreigninterference.org/post… #foreigninterference #AdvancedPersistentThreatOperations #CyberEspionage #AIPlatformBreach #CriminalGroupWeaponization #ThreatIntelligenceBulletin
20
Alexander Kruglyansky is 31. Alexandra Kruglyansky is 42. Both hold Israeli and Russian citizenship. Both were arrested, according to YNet Global News, in a case that landed at the top of The Spy Collection's Week 39 intelligence digest, published September 26, 2026. The dual citizenship is not incidental. It's the mechanism. Russian intelligence services, across the SVR, GRU, and FSB, have used this playbook for long enough that it has a well-documented operational logic. A person holding citizenship in Russia and in a Western-aligned state carries legitimate residency in the target country, draws less attention at borders, has built-in professional and social networks, and can credibly minimize their Russian ties. That combination is worth quite a lot to a service trying to place assets without going through the increasingly scrutinized formal channels. Israel is a particularly productive environment for this. The large Russian-speaking Jewish community that emigrated after the Soviet collapse created a substantial population of people holding both Israeli and Russian citizenship. Some portion of that population has been recruited by Russian services. Some have been coerced. Shin Bet, which handles domestic counterintelligence, and Mossad, which handles external operations, have both acknowledged this as an ongoing problem. The Kruglyansky arrests are one documented instance of a pattern neither service claims to have resolved. What the Week 39 digest captures beyond that specific case is the width of the operational environment right now. Russian hybrid operations running against European infrastructure. Chinese collection activities in the Indo-Pacific. Iranian cyber operations aimed at diaspora communities. All of this in the same week. Intelligence analysts have framed this convergence as coordinated pressure by authoritarian states, timed to exploit the diplomatic attention being consumed by the Iran-U.S. conflict. Whether the timing is that deliberately choreographed or whether it reflects parallel opportunism is genuinely hard to assess from open sources, but the effect is the same: Western services are working multiple high-priority cases simultaneously. The counterintelligence numbers give some context for the pace. FBI Director Kash Patel reported that 80 foreign intelligence agents were removed from the United States in FY2026. That is a 125% increase over the prior year. The U.S. caseload alone is running at roughly double what it was. The Kruglyansky case shows that allied services are managing comparable surges, not as a spillover from American activity but as independent loads generated by the same global intelligence tempo. Dual-national exploitation as a methodology will not go away. The population of individuals holding citizenship in both Russia and a Western country is large and largely legitimate. The intelligence services recruiting from within it count on that. Every counterintelligence service working this problem is, by definition, looking for a small number of recruited assets inside a large group of people with completely ordinary lives. The Kruglyanskys' ages, 31 and 42, suggest possible recruitment at different life stages, which is worth noting for what it implies about the range of access each may have provided, though the public record on specifics remains thin. The digest format The Spy Collection uses is useful precisely because it resists the tendency to treat each case as isolated. The Kruglyansky arrests, the European infrastructure operations, the Indo-Pacific collection, the diaspora targeting, all of it sits in the same week for a reason that has less to do with coincidence and more to do with the operational reality that adversary services are not pausing for Western convenience. foreigninterference.org/post… #foreigninterference #DeepCoverOperations #IdentityConcealment #MilitaryEspionage #CounterintelligenceOperations #LongTermAssetDevelopment
39
The East StratCom Task Force, which is the EU's primary body for tracking and calling out pro-Kremlin disinformation, was running on a small staff and a limited analytical budget. That's the baseline the European Court of Auditors was working from when they published Special Report No. 9/2021, and it shapes everything else in that document. The report is the most rigorous external audit the EU's counter-disinformation architecture had received up to that point. And what it found wasn't a scandal exactly. It was something arguably harder to fix: a structural mismatch between the scale of the problem and the institutional capacity assigned to address it. The core diagnosis is fragmentation. Counter-disinformation responsibilities were spread across the European External Action Service (home of StratCom), multiple directorates inside the European Commission, and then again across member state-level authorities, with no unified command and no coordination mechanism that actually worked at the speed the problem demanded. State adversaries, the auditors noted, could exploit the gaps between those institutional mandates. Which is not a theoretical concern. If one body's remit ends where another's begins, and there's no real handoff protocol, that seam is operationally useful to anyone trying to stay inside it. The project-level findings make this concrete. The auditors looked at Project 14 and Project 16, two EU-funded counter-disinformation and media literacy initiatives. Both illustrated the same problem: limited scale relative to the systemic challenge they were meant to address. Project structures had capped time spans and no continuity funding. Websites built for specific campaigns were subsequently taken down. You don't build durable counter-disinformation capacity by funding discrete projects with expiration dates, then pulling the infrastructure when the grant cycle ends. The adversary doesn't operate on grant cycles. The effectiveness measurement gap is the part that should bother people most. Project 16 used established media literacy techniques, which is fine. But the auditors found insufficient evidence that any of it actually reduced susceptibility to disinformation at population scale. The EU had no systematic evaluation framework connecting what its programs spent and did to measurable changes in how target audiences processed and responded to influence operations. You can't improve what you're not measuring. And if you're not measuring it, you also can't make a credible case to finance ministers that the investment is working. The timing of this report matters. By 2021, Russian information operations targeting EU audiences had been documented extensively, both by independent researchers and by StratCom itself. The Kremlin wasn't hiding the general shape of what it was doing. Chinese state media expansion in European markets was also generating real concern inside member state security agencies, a quieter conversation than the Russia one but picking up speed. The Court of Auditors dropped this audit into that environment, which gave institutional weight to arguments that had previously come mostly from researchers and civil society groups. When an EU audit body says your counter-disinformation architecture is under-resourced and poorly coordinated, that's a different kind of paper than a think tank saying the same thing. The recommendations were straightforward: a comprehensive EU-level counter-disinformation strategy, real coordination mechanisms, sustainable funding (not project-cycle funding), and actual effectiveness measurement. None of that is exotic. It's basic program management applied to an information security problem. The fact that it needed to be recommended by an audit body in 2021 tells you where the baseline was. The deeper issue the report surfaces is that democratic institutions tend to build counter-disinformation capacity reactively and incrementally, adding units and action plans in response to specific incidents, without stepping back to ask whether the architecture as a whole is coherent. The EU had established frameworks and produced action plans. The auditors weren't saying nothing existed. They were saying that the sum of the parts wasn't adding up to a functioning system, and that the adversaries the system was designed to counter were outpacing it on resources by a significant margin. StratCom's EUvsDisinfo database, which has been cataloguing pro-Kremlin messaging since 2015, is genuinely useful and its analysts do serious work. But that operation was never sized to match the information volume being pushed at EU audiences across multiple languages, platforms, and member states simultaneously. The audit put a formal institutional stamp on that gap. For anyone tracking how Western institutions have responded to state-sponsored disinformation campaigns, this report is a useful baseline document. It captures where the EU stood in 2021, before the Digital Services Act came into force, before the Russian full-scale invasion of Ukraine in 2022 triggered another round of institutional urgency. Whether the coordination and funding gaps it documented were subsequently addressed in any durable way is a separate question, and the honest answer is: partially, unevenly, and still without the kind of systematic effectiveness measurement the auditors called for. foreigninterference.org/post… #foreigninterference #DisinformationCampaigns #CounterDisinformationFrameworkDevelopment #StateMediaCoordination #InfluenceOperations #ComputationalPropaganda
36
Hegseth has directed Cyber Command to defend the 2026 midterms from foreign interference. That's the headline. Here's what it actually signals. Russia's 2026 operation is not a replay of 2016. The current campaign uses LLM-generated content at scale, bot amplification, and what the reporting calls "narrative segmentation," meaning the disinformation isn't broadcast uniformly. It's targeted. Different messages, different demographics, different congressional districts. The operational pipeline has matured. What took a troll farm in 2016 takes considerably less effort and fewer people today. Cyber Command's elevation into this role is worth understanding precisely. The command's core competencies are offensive and defensive cyber operations against adversary infrastructure. Disrupting servers. Burning down bot networks. That's real and it matters. What it cannot do is the work that CISA's election security team and the Global Engagement Center did: coordinate with state election officials, run information-sharing with platforms, support media literacy campaigns, push public communications. Those functions are gone or gutted. The Hegseth directive doesn't rebuild them. It deploys a different instrument for a different part of the problem and leaves the rest of the gap open. That gap is not invisible to Moscow. Russian information warfare doctrine, particularly since 2022, has emphasized identifying and exploiting seams in adversary defensive structures. The seam here is obvious and documented. A military cyber posture covers one dimension of the threat. The influence operation dimension, the narrative layer, the domestic amplification networks, the social media coordination, those remain largely unaddressed by any federal architecture that still exists in functional form. GEC is disbanded. CISA is cut. The interagency mechanisms that connected federal agencies to state officials and platform trust and safety teams have been degraded. Representative Himes put it plainly on Face the Nation: the loss of federal intelligence-sharing with state election officials is a structural vulnerability. He's right, and military cyber operations do not compensate for it. So where does this go. The trajectory of Russian tradecraft over the next twelve months almost certainly involves accelerating the LLM integration. Content generation costs are approaching zero. The limiting factor is no longer production, it's distribution and believability. Expect the next phase to focus on building out synthetic personas with longer operational histories, more coherent identities, engagement patterns that pass casual scrutiny. The 2024 cycle showed early versions of this. 2026 is the iteration after that. Geographically, the targeting will sharpen. Narrative segmentation means individual House districts, not swing states as a concept. Competitive races in specific places, candidate vulnerabilities, local wedge issues. The operation doesn't need to move national polling. It needs to move a few thousand voters in a handful of districts. The operational requirement is much smaller than the framing of "election interference" usually implies, which is part of why the broader civilian infrastructure mattered. You need local knowledge and local communication to counter local targeting. Cyber Command operates at a different altitude. For state election officials, the practical reality is this: federal intelligence sharing is reduced. The early warning function that previously flowed from CISA to state officials is degraded. If a coordinated influence operation is targeting a specific district or candidate in the run-up to a primary, the officials responsible for that election may not hear about it through federal channels the way they would have in 2020. They need to be building their own monitoring capacity and their own relationships with platform security teams, because the intermediary infrastructure has been removed. For voters and campaigns, the specific risk is the synthetic local voice. Not RT. Not obviously foreign content. Local-seeming accounts and websites with local concerns, operated at scale by people who aren't local. The tell, historically, has been newness, thin history, coordinated posting patterns. Those tells are getting harder to read as persona construction improves. The Hegseth directive is a real institutional step. It reflects someone in the building taking the threat seriously enough to formally activate military resources. Credit where it's due. But the civilian architecture wasn't dismantled by accident and it isn't coming back before November 2026. The adversary knows what's there and what isn't. The military cyber instrument is now being asked to cover ground it wasn't designed to cover, in an environment where the other instruments no longer exist. That's the condition. Watch how Russia's operation evolves against it. foreigninterference.org/post… #foreigninterference #ElectionInterference #DisinformationCampaigns #CounterDisinformationFrameworkDevelopment #CoordinatedCyberWarfare #ComputationalPropaganda
25
Counting deleted accounts is not the same as understanding whether an influence operation worked. That distinction seems obvious once you say it out loud. In 2021, the Journal of Information Warfare put it in print anyway, because the field needed to hear it. Volume 19, Issue 4 made a methodological argument that cut against how most governments and platforms were measuring success: aggregate numbers, accounts removed, posts deleted, estimated impressions, tell you almost nothing about whether a campaign achieved its actual objective. The research called this the quantitative trap, and it's a fair name for it. You can take down ten thousand accounts and still lose the information war if the message already landed. The piece analyzed Russian, Chinese, and Iranian operations and found a common design logic underneath the surface differences. These weren't blunt broadcast efforts just pushing pro-state content at volume. They were built around specific psychological vulnerabilities in target populations: existing political grievances, identity anxieties, the mental shortcuts people rely on during crises. The targeting architecture included message framing calibrated for emotional resonance, timing relative to news cycles, and platform-specific amplification strategies. None of that shows up in a removal count. The argument cuts both ways and the research didn't shy away from that. A smaller, precisely targeted campaign that seeds doubt in a specific community before an election may do more damage than a mass-broadcast operation that gets detected and pulled by platform moderators in week two. The latter generates a better-looking success metric. The former accomplishes the mission. Counter-disinformation programs optimizing for the former are, functionally, optimizing for the appearance of effectiveness rather than the reality of it. This matters because by 2021, multiple governments had built out counter-disinformation architectures with platform takedown metrics at the center. The transparency reports that companies like Meta, Twitter, and YouTube had been publishing since roughly 2018 became the primary public record of what was being done about state-sponsored influence operations. The research questioned whether those reports, useful as they are for documenting the existence and scale of networks, provide any meaningful insight into whether the campaigns they describe actually moved audiences. They largely don't. Removing a network tells you a network existed. It tells you almost nothing about what the network accomplished before it was removed. The policy implication is uncomfortable because it requires harder work. Qualitative assessment of influence operation effectiveness means behavioral and attitudinal research, surveying whether target populations absorbed specific narratives, tracking downstream belief shifts, measuring changes in political trust or willingness to vote. That's slower, more expensive, and methodologically messier than counting deleted accounts. It also doesn't produce the clean before-and-after numbers that make for good press releases when a takedown happens. There's a deterrence problem buried in here too. If public attribution of removed networks is supposed to discourage future operations, that logic depends on attribution carrying real cost for the operating state. The research gestured at whether that assumption holds, and the honest answer is that the evidence is thin. Russia ran documented operations in 2016, faced public attribution and platform removals, and ran documented operations again in 2018 and 2020. China expanded its influence infrastructure across the same period. The deterrence model, built on transparency reports and removal announcements, hasn't obviously deterred much. None of this means takedowns are worthless. Removing inauthentic networks reduces their operational reach and forces adversaries to rebuild infrastructure, which costs resources and creates opportunities for further detection. That has value. The problem is treating it as the primary measure of success, because an adversary willing to accept attrition can keep running operations while the platforms keep announcing victories. What the 2021 research pushed for was integrating technical platform analysis with genuine behavioral research. Understand what got through before you declare the operation neutralized. Assess whether narratives seeded by a removed network are still circulating in organic communities, because often they are. The accounts get deleted. The content keeps living in screenshots, in forwarded messages, in the heads of people who saw it when it was live. The journal was contributing to a scholarly conversation that had been building since 2018, with researchers at institutions like the Oxford Internet Institute, Stanford Internet Observatory, and the Atlantic Council's Digital Forensic Research Lab all producing work on the limits of platform transparency as an analytical framework. The 2021 volume sat in that context and made the methodological critique explicitly enough that it's useful as a reference point for why the field's dominant metrics are insufficient. The basic problem hasn't been solved. Governments still report counter-disinformation success primarily in terms of networks identified and content removed. Platforms still publish transparency reports built around the same numbers. The research that would actually answer whether any of it is working, longitudinal attitudinal studies in targeted populations, comparative analysis of belief change in exposed versus unexposed communities, is expensive, slow, and nobody is funding it at the scale the question deserves. That's where the field is. Measuring what's easy to count, not what actually matters. foreigninterference.org/post… #foreigninterference #ComputationalPropaganda #CognitiveExploitation #DisinformationCampaigns #InfluenceOperations #CounterDisinformationFrameworkDevelopment
37
Khieo Lapchanh is gone. No arrest, no statement, just gone. Thailand has become operational space for Lao and Chinese security services. Freedom House and HRW have both documented the infrastructure: surveillance tech, facial recognition, data-sharing that lets Vientiane find people it couldn't track alone. Lapchanh is at minimum the latest in a years-long series of Lao exile disappearances on Thai soil. Bangkok won't move. UNHCR can't. Western governments have called for targeted sanctions on the officials responsible and implemented exactly none. foreigninterference.org/post… #foreigninterference #TransnationalRepression #CrossBorderRendition #ForcedAbduction #DiasporaSurveillance #DigitalSurveillanceIntegration
26
An Alberta RCMP officer is currently on trial in Red Deer for accessing a national police database and feeding that information to the Rwandan government. The Crown has finished presenting its evidence. What it laid out is a fairly textbook foreign recruitment operation, run through the Rwandan High Commission in Canada. The officer, according to prosecutors, wasn't an ideological sympathizer. That's actually the more instructive part of this. The Crown's case is that he was cultivated over time through a relationship with a High Commission contact who gradually steered him toward pulling database records. The intelligence purpose was concealed. That's how these operations tend to work when they're working well. You don't recruit a cop by handing him a manifesto. You build a relationship, normalize small requests, and escalate slowly enough that no single step feels like a crossing. What Rwanda would get from Canadian law enforcement databases is specific. Whereabouts. Legal status. Associations. Travel patterns. For a government that has made a sustained practice of tracking, harassing, and in some cases killing its exiles abroad, that's not background reading. That's a targeting file. Freedom House has documented Rwanda as one of the more aggressive practitioners of transnational repression among African states. The Kagame government uses its diplomatic infrastructure the same way Beijing and Tehran do: as a platform for intelligence collection against diaspora communities that it considers threats. Rwandan nationals in Canada include refugee claimants, political exiles, and people whose family members are still inside Rwanda and therefore reachable. Knowing where someone lives, what their immigration status is, and who they associate with gives a foreign security service meaningful leverage. It can pressure the person directly. It can pressure people back home. Both. The trial also puts a spotlight on something that counterintelligence people have flagged for years and that nobody has really fixed. Sub-federal law enforcement in Canada, and in most Western allied states, does not have the personnel security architecture that federal intelligence agencies have. The vetting is lighter. The counterintelligence training is thinner. The monitoring is less systematic. Adversarial states know this. Recruiting a provincial or municipal officer, or in this case an RCMP officer in a provincial posting, is a lower-friction path to sensitive databases than trying to penetrate CSIS or the Communications Security Establishment directly. The access is real. The security around it is comparatively weak. That asymmetry is a structural problem, not a one-off. It's been exploited by Chinese intelligence services against law enforcement in multiple Western jurisdictions. It's not surprising that Rwanda, operating with the same basic doctrine, found a similar seam. The trial is ongoing. But the Crown's evidentiary record, as presented, documents something Canada should take seriously beyond this individual case: a foreign diplomatic mission running an active recruitment operation against a law enforcement officer, successfully enough to produce actual database access. Whatever the verdict, that happened. foreigninterference.org/post… #foreigninterference #TransnationalRepression #AssetRecruitment #DatabaseAccessOperations #DiasporaSurveillance #CommunityBasedIntelligenceOperations
51
Thirty-plus nations stood up in July 2021 and named China's MSS as the architect of the ProxyLogon campaign. Hundreds of thousands of Exchange servers. Maritime, aviation, defense, biomedical research, law firms. The indictments named four MSS officers. Then mostly nothing happened, which is the part worth sitting with. Let's be clear about what the contractor model actually means, because it tends to get summarized in ways that make it sound neater than it is. The MSS isn't just outsourcing inconvenient tasks. It is running a parallel workforce of criminal hackers who operate under state protection and direction while remaining formally deniable. When attribution lands, Beijing gestures at the gap between the contractor and the ministry. When the contractor wants to run a ransomware side operation for personal profit, the MSS apparently tolerates that too, because the access those groups generate is useful regardless of whether the immediate motive was espionage or money. The ProxyLogon campaign saw both happening simultaneously, sometimes through the same initial compromise. That's not a bug. It's how you keep plausible deniability intact while still running a global intelligence collection program at scale. The DOJ indictment documented targeting across twelve countries spanning sectors that don't have an obvious common thread until you map them against what China's Five-Year Plans actually prioritize: biopharmaceuticals, aviation technology, maritime logistics, defense systems. Cambodia and Indonesia showing up on that list alongside Germany and Norway is a reminder that this isn't primarily about stealing American secrets. It's about building a comprehensive picture of global economic and strategic positioning. The United States is a target, but it's one node in a much wider collection architecture. So where does this go from here. The contractor model has been successful enough that there's no incentive to abandon it. If anything, the 2021 attribution likely prompted refinements rather than a strategic rethink. The things that got MSS-affiliated actors caught, which included operational overlap between the espionage infrastructure and the criminal ransomware operations, the breadth of the campaign which made anomaly detection easier, and the sheer number of compromised organizations which meant defenders were comparing notes, are all correctable. Expect smaller, more targeted exploitation windows. Expect better operational separation between the intelligence-gathering function and whatever the contractors are doing on the side. Expect more use of pre-positioned access that sits dormant long enough that the initial intrusion gets forgotten, then activates well after the attribution window has closed. The sectors targeted in the ProxyLogon campaign should be treated as a priority list, not a historical footnote. Defense contractors already knew they were targets. The addition of infectious disease researchers in 2020 and 2021 reflected real-time collection against COVID-19 response data, which was an improvisation on an existing template. The template being: identify what decision-makers need to know right now, and collect against whoever holds that information. Climate technology, semiconductor supply chain mapping, rare earth processing alternatives. Those are the current equivalents. Organizations working in those spaces that are still running security postures designed for 2019 threat models are not ready for what's already in their networks. The multilateral attribution itself deserves more scrutiny than it usually gets. Thirty-plus nations is an impressive number and the coordination was genuinely difficult to achieve. It was also, operationally, nearly consequence-free for Beijing. The four indicted MSS officers are not going to appear in a U.S. courtroom. Sanctions were not applied. NATO's collective defense framework was not invoked. What the coalition demonstrated was that it could coordinate public statements. That's useful for norm-setting over long time horizons. It does not change the calculus for an MSS planner deciding whether to run the next campaign. The Europeans who joined the attribution in 2021 did so at some diplomatic cost. China pushed back hard on several EU member states individually, and some of the coordination that happened in 2021 has been harder to sustain since. The bilateral pressure Beijing applies after these events is a feature of Chinese counter-attribution strategy, not a side effect. The goal is to make the coalition expensive to maintain so that the next time a threshold decision is being made about whether to attribute publicly, some partners calculate that quiet diplomacy is less painful. Watch which countries join the next major joint attribution and which ones decline. That delta will tell you something about how effective the post-attribution pressure campaign has been. For defenders, the operational lesson from ProxyLogon that still isn't fully absorbed is the authentication bypass piece. Remote code execution without credentials on a widely deployed enterprise mail server is not a niche threat scenario. It's the scenario you actually have to plan for. The assumption that perimeter authentication is a meaningful barrier has been wrong for long enough now that its continued presence in security architectures is mostly a policy failure rather than a technical one. Every organization running enterprise mail infrastructure, collaboration tools, or remote access platforms should be asking whether their detection capability is built around the assumption that authenticated access is probably legitimate. It isn't, and it hasn't been for years. The ransomware-plus-espionage hybrid that showed up in the ProxyLogon campaign is worth watching because it scrambles incident response in useful ways, from Beijing's perspective. When a defender sees ransomware, the immediate priority is recovery and containment. The investigation into how the actor got in, what they accessed, and whether they left persistent implants tends to get compressed by operational pressure to restore services. The espionage payload may already be weeks or months old by the time the ransomware fires. By the time anyone is asking the right questions about what was exfiltrated, the trail is cold and the attribution is murky because the group that deployed the ransomware is nominally criminal rather than state-affiliated. This is a feature. Voters and elected officials who read about these attribution events and conclude that the problem is being managed should look at what happened after the 2021 announcement. The sectors named in the indictment continued to be targeted. The contractor model continued to operate. The four named MSS officers are presumably still employed. Public attribution without consequences is a press release. That's not an argument against doing it, because norm documentation and coalition maintenance matter over time, but it is an argument for not mistaking the announcement for a resolution. The trajectory here is not toward escalation in the dramatic sense. It's toward normalization. Persistent, broad-spectrum collection against government and private targets, operating through a deniable contractor layer, calibrated carefully enough to stay below the threshold that would compel a meaningful response. The 2021 campaign was probably larger and noisier than MSS planners intended, partly because zero-days at that scale are hard to use quietly. The next iteration will be quieter. The access will be harder to find. The connection to the state will be more carefully obscured. The 30-nation coalition was the right move. It just didn't move the needle on what comes next. foreigninterference.org/post… #foreigninterference #ZeroDayExploitation #AdvancedPersistentThreatOperations #CyberEspionage #CriminalGroupWeaponization #ContractorOperations #PersistentNetworkInfiltration #JointIntelligenceWarning
81
The ODNI's 2021 threat assessment is essentially a scoreboard nobody wanted to see. China gets the top billing as the one adversary with both the intent and the capacity to reshape the international order. Russia kept running election interference narratives straight through the 2020 post-election period, Putin-authorized, amplified through state media. Iran was quietly stockpiling enriched uranium and spearphishing senior officials at the same time. North Korea was stealing cryptocurrency by the hundreds of millions to fund the missile program sanctions were supposed to starve. Four countries, every domain, all at once. The convergence is the point. foreigninterference.org/post… #foreigninterference #SpearPhishing #ElectionInterference #DisinformationCampaigns #CyberEspionage #CryptocurrencyTheft #NuclearDefiance #InfluenceOperations
20
This Week in Foreign Interference: 81 incidents logged. That's a heavy week. The through-line, if there is one: scale. AI-enabled operations projecting 450-700% disinformation surges. An autonomous Windows implant making its own attack decisions. Eight Chinese vessels blockading a Philippine resupply mission. Western spy chiefs compressing the Russia-NATO attack timeline to "months not years." A lot is moving at once. Here's the week's notable activity. --- CLOSEDQUORUM (Sept 22): Cisco Talos documented the first publicly known Windows implant using embedded LLMs to autonomously select post-compromise actions without human command-and-control direction. This is not a theoretical capability. It's deployed malware that cuts the human out of the loop, eliminating the detection windows defenders have built their playbooks around. Talos released the CAIRN framework to help spot AI-driven behavior. Worth watching whether CAIRN spreads fast enough to matter. --- China at Ayungin Shoal (Sept 25): Eight PLAN and coast guard vessels blocked a Philippine humanitarian resupply to the BRP Sierra Madre garrison. The AFP confirmed the interference publicly. Beijing's playbook here is consistent: coercive enough to deny access, calibrated enough to stay below any treaty threshold. Manila is documenting. Washington is watching. The garrison stays cut off. --- RAF satellite jamming disclosure (Sept 25-26): Britain revealed it has been covertly jamming adversary satellites for approximately a year, then immediately formalized the capability with the debut of Number III Space Effects Squadron on Sept 26. The sequencing is deliberate. Disclosing an ongoing covert operation as you institutionalize it is a deterrence signal, not a transparency exercise. The targets, Russian and Chinese satellites, were not named officially. They didn't need to be. --- Polish Starlink sabotage (Sept 25): A fire at a Polish power station serving Starlink infrastructure was labeled sabotage. Denmark issued a concurrent Russian hybrid threat warning the same day. The target isn't coincidental. Starlink sustains Ukrainian military communications. Hitting the infrastructure in Poland lets Russia degrade that capability while keeping the strike on NATO soil ambiguous enough to dispute. Denmark's warning and the Baltic states' covert petition to the EU defence fund for drone shielding reflect how seriously the eastern flank is taking the pattern. --- CIA false-flag warning (Sept 25): CIA intelligence warned Russia is planning false-flag drone attacks against France, Spain, or Italy using weaponized civilian shipping as launch platforms. Russia's hybrid campaign has been concentrated on the eastern flank until now. Extending it to NATO's southern tier, under false attribution, is a meaningful escalation in both geography and method. --- Chinese operatives attacked Tibetan protesters in Washington D.C. (Sept 24): During Xi Jinping's state visit, pro-Beijing actors physically assaulted Tibetan demonstrators on U.S. soil. Transnational repression executed in front of cameras, during a summit. The Trump administration's response to the incident was not prominently documented. Congressional Democrats called on Trump to raise human rights with Xi. Whether he did is not publicly confirmed. --- F-35 component diverted to Hong Kong (Sept 23): A U.S.-bound F-35 component shipment from Australia was redirected to Hong Kong, triggering a defense supply chain investigation. Hong Kong functions as a Chinese SAR with intelligence service access to commercial cargo logistics. The incident fits a documented pattern. Hong Kong is not a neutral transit point, and treating it as one in defense supply chains has been a recurring problem that congressional attention hasn't yet fixed. --- New Zealand formally designates China as top cyber threat (Sept 24): New Zealand's cyber agency made it official, naming China the country's most persistent and capable state-backed cyber threat. The designation closes the last public attribution gap in Five Eyes' unified China cyber posture. All five eyes are now on record saying the same thing. That alignment matters for both policy coordination and diplomatic pressure, even if it doesn't immediately change Beijing's behavior. --- UK PM Burnham at UNGA (Sept 23): Burnham condemned Russian electoral interference and announced a National Centre for Information Defence. The announcement drew immediate domestic criticism framing it as a censorship architecture. That tension, between defending information environments and policing them, is going to follow every counter-disinformation institution announcement for the foreseeable future. Russia's SVR director, for his part, used UNGA week to accuse the West of election interference. Timing was not coincidental. --- Quebec interference warning (Sept 25): CAQ leader Fréchette publicly warned of U.S. interference risk in the 2026 Quebec provincial election and confirmed contact with CSIS. U.S. interference in a Canadian provincial election is a story that would have been treated as implausible ten years ago. It isn't implausible now. --- The rest of the week's volume: additional Russia hybrid warfare reporting on Poland, Romania, and Moldova (drone explosions, airspace violations, suspected arson), ENISA documenting escalating EU infrastructure cyberattacks with state actors exploiting shared providers for cascading multi-organization compromise, CYFIRMA's continued documentation of Pakistan-linked APT36 operations against Indian military and government targets, EU sanctions on Russian state media figure Xenia Fedorova for information manipulation, and the Canada-Nordic-Baltic Eight foreign ministers coordinating hybrid threat response at UNGA, the most institutionally significant counter-hybrid alignment outside NATO formats this week. Separately: AI disinformation projections are getting alarming in their specificity. A 450-700% surge projected for UK and European environments. A 350-550% surge projected for South America and the Caribbean. These aren't vague threat assessments. They're operational cost curves. AI reduces the personnel and financial overhead for sustained influence campaigns to the point where actors who couldn't previously sustain them can now. Historical context logged this week included documented Cold War baselines: the 1987 OSI dismantlement of a joint Soviet-Chinese espionage ring in Japan targeting U.S. Air Force weapon systems, Reagan-era KGB disinformation operations traced by R Street as direct precursors to current Russian information warfare doctrine, and a 54-year electoral intervention dataset confirming measurable, systematic impact on outcomes. The history is not academic. The methods have continuity. --- Next week: The House Foreign Affairs Committee's foreign influence inquiry is moving. The Disclosing Foreign Influence in Lobbying Act is calendared for Sept 28 House consideration, and K Street opposition to it is organized. Watch whether it survives markup intact or gets definitionally narrowed into something that doesn't close the gaps it's meant to close. foreigninterference.org #foreigninterference #DisinformationCampaigns #InfluenceOperations #TransnationalRepression #ElectionInterference
177
Citigroup found out on May 10, 2011, that someone had been walking through their customer database by changing numbers in a URL. That's it. That's the attack. Log in with your own account, look at the address bar, swap your account number for someone else's, press enter. Repeat 360,083 times. The technical term is an insecure direct object reference. The plain English translation is: the website handed you whatever account you asked for, no questions asked. The bank had presumably spent real money on security. Firewalls, intrusion detection, the works. And then they forgot to lock the thing that let authenticated users access each other's data freely by editing a URL. TIME called it a high-tech security system with the front door left open. That's charitable. The front door wasn't just unlocked. There was no door. The breach was undetected for weeks. Which makes sense, in a grim way. The attackers weren't triggering anything that looked anomalous to existing monitors because they were logged in legitimately. The access pattern looked, from a certain angle, like normal browsing. This is the frustrating physics of application-layer vulnerabilities. They don't set off the perimeter alarms because they happen inside the perimeter. California took the worst of it, 80,454 customers. Connecticut saw 5,066 affected. The total haul was names, account numbers, email addresses. Not passwords, apparently, but enough. By the time Citigroup finished replacing cards, 217,657 customers had gotten new account numbers in the mail. The fraudulent charges came to $2.7 million, which for a bank of Citigroup's size is a rounding error but isn't nothing to the people whose money moved without their permission. The notification delay is where it gets uglier. Discovery was May 10. Citigroup didn't start telling customers until June 3. Nearly three weeks. The argument banks usually make for delays like this is that they need to understand the scope before they communicate, that premature notification causes panic without giving people actionable information. There's a version of that reasoning that's defensible in narrow circumstances. Three weeks for a breach of this scope, involving a vulnerability this elementary, is not that version. Connecticut's attorney general investigated. What came out of that investigation was worse than the delay. Citi may have known about the vulnerability for up to three years before attackers exploited it. If accurate, that reframes the story considerably. The breach wasn't the result of attackers finding something Citi's own engineers hadn't noticed. It was the result of a known flaw sitting unpatched long enough for someone else to find it and use it. Knowing about an insecure direct object reference in your online banking platform and not fixing it for three years is a policy choice, even if no one called it that at the time. Senator Bob Menendez wrote to the Office of the Comptroller of the Currency asking for an investigation into both the breach and the notification lag. His office also put the Citigroup incident in a broader context: in the six years before 2011, there had been 288 publicly disclosed breaches at financial services firms, exposing at least 83 million customer records. That number deserves a moment. This wasn't an industry that had been catching criminals and learning from close calls. It was an industry bleeding customer data at a steady rate for years. The settlement Connecticut eventually extracted was $55,000. For Citigroup. Fifty-five thousand dollars. I'll just leave that there. What I find myself coming back to, having watched this sector for a while, is how thoroughly unsurprising the failure mode was. Insecure direct object reference vulnerabilities weren't obscure in 2011. The OWASP Top Ten, which is the closest thing the web security world has to a beginner's checklist, had been listing this class of vulnerability since 2007. It appeared on the list again in 2010, a year before the breach. Any developer or security team working on a financial platform had access to the information. The question was never whether anyone knew about this category of problem. The question was whether fixing it was someone's priority. At institutions the size of Citigroup, online banking platforms in 2011 were often running on layered legacy code with multiple teams responsible for different pieces. Access control logic, if it existed, might be applied inconsistently across different parts of the application. That's a realistic description of the environment, not an excuse. The realistic description and the accountability sit alongside each other. The foreign interference angle here isn't about a nation-state running this operation. The attack was unsophisticated by design, which is what made it effective and invisible. Organized criminal groups understood something important: banks spend heavily defending against the attacks they expect, meaning attacks that look like attacks. Systematic enumeration of account numbers by a logged-in user looked like an active customer. The monitoring infrastructure wasn't built to flag it. That's a lesson that has traveled. Actors interested in financial data, whether for fraud, for intelligence gathering on individuals, or for mapping financial relationships between persons of interest, have consistently looked for the gap between what a security system is designed to catch and what's actually happening. In 2011 the Citigroup platform had that gap, and it was wide. The broader picture Menendez's office sketched in 2011 is recognizable if you've been watching: 83 million records across 288 breaches is a systemic condition, not a series of isolated incidents. The financial sector was processing more transactions online, connecting more systems, expanding the attack surface, and not consistently increasing the baseline quality of the applications sitting on top of all that data. Citigroup's breach was the visible part of that. The less visible part was the accumulation of known vulnerabilities at other institutions that hadn't yet been exploited, or that had been exploited without anyone detecting it. The regulatory pressure that followed produced calls for legislation and enhanced oversight. Whether it produced better application-layer security practices across the sector in any systematic way is a different question. The class of vulnerability that exposed Citigroup's customers keeps appearing in assessments of financial platforms years later. Different institutions, different specifics, same underlying failure to validate that an authenticated user should actually have access to the object they're requesting. $2.7 million in fraudulent charges. $55,000 settlement. A vulnerability the bank may have known about for three years. Three weeks before customers were told. That's the accounting. foreigninterference.org/post… #foreigninterference #CyberEspionage #FinancialCyberTheft #UrlManipulation
1
110
Three weeks after Russia invaded Ukraine, the Senate Foreign Relations Committee sat down on March 15, 2022 to ask a question that probably should have been asked sooner: does the United States actually have the institutional machinery to fight back against authoritarian disinformation, or has it just been telling itself it does? The answer that emerged from the hearing was, roughly, "sort of, with some significant caveats that happen to be load-bearing." The central institution under the microscope was the Global Engagement Center, the State Department body tasked with identifying and countering foreign propaganda and disinformation. Witnesses confirmed that the GEC had done real work, establishing counter-disinformation partnerships with allies across Europe and the Indo-Pacific, helping partner countries protect elections from foreign interference operations. That part is genuine. The GEC has bilateral and multilateral frameworks in place, it works with foreign governments, it has relationships with platforms operating in those spaces. The problem is the wall. The GEC is statutorily prohibited from operating domestically. This is not an accident or an oversight; it reflects a real and legitimate concern about turning counter-disinformation machinery inward on American audiences and sliding into government-managed information control. The legal constraint is defensible in principle. The operational problem is that Russia and China figured out years ago that they don't need to directly inject disinformation into American domestic discourse. They just need to get it close enough to the border for American domestic actors to pick it up voluntarily. The mechanism senators pressed witnesses on is essentially a laundering operation. Russian or Chinese origin content, designed with full awareness of American domestic political faultlines, gets produced and seeded in spaces where American political figures, media personalities, and social media ecosystems will find it useful, entertaining, or validating. Those domestic actors then amplify it, strip the foreign fingerprints through simple repetition and recontextualization, and the content arrives in American information space wearing entirely domestic clothes. At that point, the GEC's legal mandate ends. The foreign-origin material has successfully cleared the perimeter, and the institution tasked with stopping it is statutorily required to look away. Senators asked the obvious question: does the domestic-foreign distinction remain coherent when adversaries have specifically engineered their operations to exploit that exact distinction? The witnesses, to their credit, did not try to pretend the perimeter model is fully adequate. They acknowledged the gap. The hearing record just doesn't contain a clean resolution of it, because there isn't one. Any expansion of the GEC's domestic authority runs into serious First Amendment and government overreach concerns that don't disappear because Russia is being inconvenient. The foreign interference risk assessment section of the hearing is worth sitting with for a moment, because the framework witnesses laid out is genuinely useful for understanding where adversaries focus their efforts. High-risk environments were characterized by four converging conditions: elections with narrow margins (where a small nudge in turnout or perception can change outcomes), significant diaspora communities with ties to adversary states (leverage points for identity-based manipulation), high-polarization information environments that adversaries can exploit through grievance campaigns, and weak platform enforcement capacity. The uncomfortable observation embedded in this framework is that the United States met all four conditions simultaneously in 2022, as did several European democracies facing upcoming elections, as did a range of emerging democracies in Africa and Asia where Chinese and Russian influence operations were actively expanding their footprint. The Russia-China coordination finding is the part of the hearing record that tends to get underplayed in retrospect. Witnesses addressed evidence that the two authoritarian powers were coordinating elements of their information operations, and the description is precise enough to be worth quoting accurately: not formal operational integration, but sharing of narratives, amplification of each other's content on third-party platforms, and parallel targeting of the same Western democratic institutions. This is not the same as a joint command structure. It is, however, considerably more alarming than two countries happening to dislike the same things. The practical effect is that democratic defenders face a combined authoritarian information capacity that is larger than either Russia or China would represent individually, without that combination requiring the kind of formal alliance architecture that might create visible signatures to track. The legislative discussion covered territory that has been circling the same drain for several years. Expanding the GEC's mandate and resources. Creating legal authorities for proactive declassification of foreign interference intelligence so adversary operations can be publicly exposed faster, before they complete their intended effect rather than after. Better information-sharing mechanisms between the intelligence community and platform companies to accelerate identification and removal of state-sponsored content. These are all reasonable ideas. They are also ideas that were reasonable in 2018, and 2019, and 2020, and 2021. The hearing's March 2022 urgency came partly from the invasion context but also from the recognition that the gap between identifying these structural problems and actually closing them had stretched across multiple Congressional sessions without resolution. The FARA section is its own study in institutional dysfunction. The Foreign Agents Registration Act requires individuals operating in the United States as agents of foreign principals to register as such. The enforcement gap the hearing addressed is the persistent, documented failure to prosecute unregistered foreign agents operating in influence capacities. FARA enforcement has been, for most of its history, remarkably tolerant of non-compliance. Witnesses and senators discussed the need to coordinate Treasury OFAC sanctions with criminal prosecutions and platform takedowns, the logic being that disinformation ecosystem participants face essentially no comprehensive cost for their activities when each enforcement mechanism operates in isolation. A sanctions designation without a corresponding prosecution and platform removal is a talking point, not a deterrent. The hearing acknowledged this coordination problem without resolving it either. The March 15 date matters more than it might seem. Three weeks after February 24, Russian disinformation about the invasion's causes, its conduct, and its humanitarian consequences was being actively produced and distributed at scale across global platforms. This was not a theoretical future threat being gamed out in committee. The committee was in real-time assessment mode, trying to determine whether the counter-interference apparatus was adequate to an active adversary information campaign targeting European and North American audiences simultaneously, while the war that campaign was supporting was still in its opening phase. What the hearing documented, taken as a whole, is a counter-disinformation architecture that was built for a slightly different version of the problem than the one it actually faces. The GEC's perimeter model made intuitive sense when foreign disinformation was something foreign. The FARA framework made sense when foreign agents were primarily engaging in trackable lobbying activities rather than narrative seeding through social media ecosystems. The intelligence-platform information sharing gap was tolerable when state-sponsored content operations were slower and more detectable. All of those assumptions have been systematically eroded by adversaries who had strong incentives to study the architecture and route around it. The senators who pressed witnesses on whether the domestic-foreign distinction remained operationally coherent were asking the right question. The honest answer, sitting in the transcript, is that it remains legally coherent because the law hasn't changed, and operationally problematic because the adversaries changed their operations to exploit exactly that legal line. Fixing the operational problem without creating new ones requires threading a needle that the hearing identified clearly but that Congress has not, as of that March, threaded. The Ukraine invasion context gave the 2022 hearing a sharp edge that earlier iterations of these same conversations lacked. Whether that urgency translated into the structural changes witnesses described is a different question, and a less satisfying one. foreigninterference.org/post… #foreigninterference #DisinformationCampaigns #CounterDisinformationFrameworkDevelopment #LegislativeGapAssessment #CrossBorderInfluenceOperations #SanctionsFrameworkEstablishment #IdentityGrievanceCampaigns #CongressionalInvestigationLaunch #ForeignInformationManipulation
54
By 2019, the Oxford Internet Institute had documented computational propaganda running across 70 countries. Not 7. Not 17. Seventy. And that was before anyone had fully worked out why it kept working regardless of who was running it or what the specific message was. That gap, the distance between mounting case studies and actual theoretical understanding, is what a 2022 City University London open-access study tried to close. It's worth spending some time with what the framework actually says, because it cuts against a few comfortable assumptions. The Chinese operations section draws on Lu's 2022 analysis and uses the term "participatory digital warfare," which is precise in a way that matters. The Soviet active measures model was largely a professional intelligence function. Handlers, front organizations, planted stories, carefully managed assets. You could, in principle, follow the chain. The Chinese model the framework describes is structurally different: mass mobilization of patriotic users, commercial PR firms embedded in state media ecosystems, volume generated at a scale that platform moderation simply cannot process in real time. Individual participants may have zero formal intelligence affiliation. A lot of them probably believe what they're posting. That's the attribution problem in a nutshell. The coordinating architecture, which topics get seeded, when amplification happens, which platforms get targeted, reflects professional operational planning. The participants executing it often don't. Classic intelligence attribution frameworks look for the handler. Here there may not be a single handler to find, just a system that produces the desired output. The psychological architecture section is where the framework earns most of its analytical weight. Three campaign types, and they're not what most people assume disinformation is for. The first is confidence degradation. The goal is not to convince anyone of a specific false thing. The goal is to destroy confidence that reliable information exists at all. Epistemic paralysis. If a target population can be brought to a state where they assume everything is probably manipulated and truth is essentially unknowable, they become effectively ungovernable by information. Democratic decision-making requires a shared epistemic baseline. Remove that baseline and you haven't just confused people, you've degraded the functional infrastructure of collective judgment. The second is identity polarization. This one is older than social media, older than the internet, older than broadcasting. Exploit existing fault lines, deepen in-group and out-group divisions, erode social trust. The innovation isn't the concept, it's the targeting precision and the speed. Algorithmic platforms that already optimize for engagement are doing half the work for you, because conflict and outrage drive engagement, and engagement drives reach. The third is elite discrediting. Targeted operations against specific politicians, journalists, scientists, institutional actors. The goal is not just to damage a particular individual but to disable the credibility mechanisms that democratic societies use to evaluate competing truth claims. If the sources a population would normally use to adjudicate factual disputes have been rendered suspect, the population loses its epistemic immune system. Whatever comes next, accurate or not, has no reliable filter to pass through. What the framework does with these three categories is argue they operate across perpetrators regardless of the specific state running the operation or the specific grievance being exploited. Russia uses these mechanisms. China uses them. Iran uses them. Smaller states running more limited operations use variants adapted to their resource constraints. The 2022 study builds on the Oxford baseline to show methodological convergence: automated amplification, fake persona networks, media impersonation, strategic content injection. The same toolkit, differently calibrated. This convergence has a defensive implication that the framework states directly and that doesn't get enough attention: platform-level interventions that disrupt one state actor's infrastructure will simultaneously constrain others using the same methods. The infrastructure overlaps. The techniques overlap. You are not, when you act against one operation, doing something narrowly targeted that leaves the rest untouched. There may be disproportionate defensive returns available from coordinated platform action precisely because the adversaries have converged on similar approaches. Whether platforms act on that is a different question, and not a comfortable one. The Stimson Center's 2022 companion analysis on social media misinformation and political instability puts it plainly: major technology companies remained hesitant to employ policies that might be seen as limiting free expression. This created a structural asymmetry. Disinformation operators can exploit full platform reach with essentially no normative friction. Defenders face normative constraints on response. The operators have already decided the information environment is a battlefield. The platforms are still treating it primarily as a speech venue. That asymmetry becomes especially acute in mass atrocity contexts. The Stimson analysis specifically flags situations where disinformation campaigns precede or accompany political violence, creating intervention dilemmas that existing platform policies cannot adequately address. At the point where content is actively contributing to conditions for atrocity, the normal content moderation calculus, designed for more ambient conditions, is not fit for purpose. The OFAC piece fits into this as the legal mechanism that operates outside the platform layer entirely. The March 2022 Federal Register publication documented sanctions designations against specific individuals and entities whose primary function was disinformation production and distribution, targeting them as participants in malicious cyber-enabled activities and Russian government election interference operations. Sanctions are blunt. They don't require proving criminal intent in a domestic court. They establish financial consequences for participation in information operations infrastructure, which matters because that infrastructure has costs and participants who respond to financial incentives. It's not sufficient on its own, but as a complement to platform takedowns and the occasional criminal prosecution, it closes some of the gaps each individual mechanism leaves open. The City University framework is not exciting reading. It's an academic synthesis, which means it is careful and qualified and footnoted and unlikely to go viral. But the thing it documents, the convergence of methods across state actors, the three-campaign psychological architecture, the structural advantages that disinformation operators hold relative to defenders, those are not theoretical problems. They are operational realities that have been running for years across dozens of countries. The literature caught up to them in 2022. The operational responses are still catching up. foreigninterference.org/post… #foreigninterference #DisinformationCampaigns #ComputationalPropaganda #CognitiveExploitation #DemocraticInstitutionTargeting #HistoricalNarrativeManipulation #SanctionsFrameworkEstablishment #CounterDisinformationFrameworkDevelopment #IdentityGrievanceCampaigns
69
The 2022 ODNI Annual Threat Assessment put four adversary cyber programs on the record in one document. China rated as the broadest and most persistent threat. Russia demonstrated hybrid integration of cyber and kinetic operations in Ukraine. Iran made contact with U.S. election infrastructure. North Korea tied cryptocurrency theft directly to missile financing. The public baseline is now set. What the assessment actually signals is less about the individual actors than about where all four programs are converging in their architecture. Start with China. The March 2022 penetration of at least six state government networks wasn't the leading edge of something new. The ODNI language was "endemic rather than episodic." That framing matters because it forecloses the incident-response model as a sufficient defense. You cannot patch your way out of an endemic condition. The state-level targeting is also a tell about where Chinese collection is heading: federal hardening is pushing operations toward softer targets. State election infrastructure, county-level emergency management systems, port authorities. Places that have CISA guidance but not CISA budgets. That gap is the operational seam China has been probing, and the 2022 document essentially confirmed it in public. The Russia picture is structurally different and in some ways more instructive. What the Ukraine theater demonstrated is that Russia has operationalized something the U.S. military only codified in Joint Publication 3-04 in 2022: the integration of information operations, cyber tools, and kinetic action into a single campaign. Russia field-tested this doctrine before we finished writing ours. The RT-linked AI content operations disrupted by DOJ were not a separate track. The assessment described them as integral to the cyber-information hybrid architecture. That means future attribution calls on Russian influence operations will need to account for the possibility that what looks like a propaganda campaign is functioning as cover or noise for a concurrent cyber intrusion, and vice versa. Analysts who silo those two disciplines will miss the compound event. Iran's trajectory is the one that should occupy election security officials most immediately. The joint DHS/DOJ finding of contact with U.S. election infrastructure during the 2022 cycle is the data point, but the direction is what matters. Iranian APT groups have been running transnational repression campaigns against Persian-language diaspora for years, which means they have developed persistent access to community networks, messaging platforms, and the kind of soft infrastructure that exists well outside federal cybersecurity coverage. The overlap between diaspora targeting and domestic political communities is not zero. Iranian actors looking to amplify division in U.S. politics have a ready-made access route through diaspora networks they already own. North Korea is the cleanest case in terms of operational logic. Lazarus Group and affiliated actors stole an estimated 400 million dollars in cryptocurrency in 2021, and Pyongyang's 2022 missile testing program ran at a pace that required exactly that kind of supplemental financing. The linkage is direct. The implication for defenders is that North Korean cyber operations against financial infrastructure are not going to de-escalate as long as the sanctions regime holds and the weapons program requires hard currency. There is no diplomatic resolution on the horizon that changes that calculus. Crypto exchanges, DeFi protocols, and the custodial infrastructure around them remain high-probability targets for the foreseeable future, and the 2022 assessment gave no indication that the operational tempo was slowing. The structural problem the assessment exposed, and which the Senate Foreign Relations hearing made explicit, is the gap between the threat's integration and the defense's fragmentation. The Global Engagement Center was doing counter-disinformation work with partner countries on elections. CISA was doing cyber hardening. DOJ was running disruption operations. None of these are bad programs. But the adversaries assessed in this document are running unified campaigns, and the U.S. counter-architecture is organized by bureaucratic lane. That mismatch doesn't resolve itself. A few specific things to watch over the next election cycle. First, watch for Chinese targeting of secretaries of state offices and the vendors who supply voter registration database software. The 2022 state network penetrations established that Chinese actors have appetite for subnational government access. Voter infrastructure is subnational. Second, watch for compound Russian operations where a visible influence campaign coincides with a quieter intrusion against the same target set. The doctrine is now explicit. Third, watch Iranian operations against diaspora community organizations in swing-state cities with large Persian-speaking populations. Atlanta, Northern Virginia, Los Angeles. The access already exists in some of those networks. Fourth, watch North Korean actors pivot toward newer DeFi and cross-chain bridge protocols as traditional exchange security improves. They adapt faster than compliance frameworks. The 2022 ATA was a baseline document. The actors it described have not stood still since it was published. foreigninterference.org/post… #foreigninterference #CyberEspionage #AdvancedPersistentThreatOperations #ElectionInfrastructureTargeting #DisinformationCampaigns #CryptocurrencyTheft #CognitiveWarfare #CriticalInfrastructureMapping #MultiDomainWarfareCoordination #ThreatAssessmentFramework
83
The Justice Department quietly told Congress that FISA wiretaps jumped sharply in 2011, and "quietly" is doing a lot of work in that sentence. Assistant Ronald Weich sent the letter. No press conference, no fanfare. Just a number going up and a note to the people who are supposed to be watching the watchers. The surveillance covered suspected foreign agents and terrorism-linked communications, which is the legal lane, but the scale of the increase is the part worth sitting with. Foreign intelligence operations targeting the U.S. were apparently busy enough in 2011 to justify a significant escalation in monitoring. That's the actual headline. foreigninterference.org/post… #foreigninterference #CommunicationsInterception #MassSurveillanceOperations
50
FARA has been "under reform" longer than most lobbyists have been alive. The House calendar for September 28 lists the Disclosing Foreign Influence in Lobbying Act for consideration, which sounds like progress until you remember the Senate passed foreign lobbying reform unanimously in 2023 and it went nowhere. The Qatar campus money, the $4.4 million China-linked donor network in California, the whole Qatargate mess documented last month: all of it flowed through gaps that reformers have been promising to close for years. K Street has a direct financial stake in keeping those gaps open, and K Street is very good at its job. Getting on the calendar is the easy part. foreigninterference.org/post… #foreigninterference #CounterInterferenceLegislation #LegislativeGapAssessment #PoliticalDonationInfluence #InfluenceOperations #CongressionalInvestigationLaunch
48
Abelardo de la Espriella became Colombia's president and, within months, Colombia no longer had diplomatic relations with Iran. Make of that sequencing what you will. The break came in late September 2026. The new right-wing government in Bogotá severed ties with Tehran and simultaneously pivoted toward Israel, which is about as clean a signal of political alignment as you can send in one move. Press TV flagged it via GlobalSecurity.org, which, yes, is an Iranian state outlet and therefore not a neutral narrator, but the facts of the break itself aren't in dispute. The thing that makes this case analytically interesting, rather than just another diplomatic shuffle, is the detail about de la Espriella's citizenship. He holds dual U.S.-Colombian nationality. That's not a rumor or an opposition smear. It's a structural fact about the person running Colombian foreign policy. And when that person's first major foreign policy gestures are: (1) cut ties with a country Washington considers an adversary, and (2) lean toward a country Washington is actively backing under the Trump administration's Middle East posture, the question of where the strategic decision-making is actually happening becomes genuinely worth asking. You don't have to assume bad faith to ask it. The question asks itself. Colombia under Gustavo Petro had moved in a very different direction. Petro opened lines with Venezuela, was vocal about Palestinian rights, kept relations with Iran functional if not warm. De la Espriella is essentially running the foreign policy tape backward at speed. That kind of reversal doesn't happen in a vacuum, and it doesn't usually happen this fast without some external architecture supporting it. The Washington Brazil Office had been documenting U.S. pressure on Latin American governments throughout the 2026 electoral cycle, and Colombia fits the broader pattern: elections producing governments that are either genuinely ideologically aligned with Washington's preferences or sufficiently dependent on U.S. support that the practical difference is hard to find. Iran's response was formally noted but deliberately vague. The Foreign Ministry vowed to take "measures" in response to what Tehran called Colombia's "hostile approach," without specifying what those measures would be. That ambiguity is a tactic, not an oversight. It lets Tehran preserve maximum flexibility while creating just enough uncertainty about costs to put Bogotá slightly on edge. The honest assessment is that Iran has limited direct leverage over Colombia. They're not trade partners of consequence, they don't share a neighborhood, and there's no meaningful Iranian diaspora in Colombia with political weight. What Iran does have is indirect reach. Hezbollah-linked networks in South America are well-documented, concentrated particularly in the tri-border area of Argentina, Brazil, and Paraguay, and in parts of Venezuela. Whether Tehran activates any of that infrastructure in response to the Colombian break is a real question, though "activates" covers a range of options from propaganda to something considerably less comfortable. The Iranian Foreign Ministry's careful vagueness probably reflects the fact that their actual options are more limited than their rhetoric suggests, but they'd rather you not be certain about that. The more immediate use Iran gets from this rupture is rhetorical. And on that front, they're not working alone. Lula in Brazil has been publicly accusing the U.S. of electoral interference. Cuba showed up at the UN General Assembly in late 2026 warning against what its representatives called the "law of the jungle" in international relations. Venezuela has been in a running confrontation with Washington for years and views every development like the Colombia pivot as further evidence for its preferred narrative. All of these governments will use the de la Espriella pivot, a dual U.S.-citizen president cutting ties with Iran and embracing Israel within months of taking office, as a concrete example when they argue that Washington is systematically reordering Latin American foreign policy through pressure and installed-friendly-government operations. Whether that framing is entirely fair is a separate question. But it's not an absurd reading of events, and the people making that argument now have a pretty clean data point to cite. The Colombia case is worth sitting with as a model, not just an incident. Electoral interference, when it works, doesn't just change who wins. It changes what that country does afterward. Trade relationships, diplomatic posture, military cooperation agreements, regional bloc alignments: all of it becomes available for restructuring once the executive is amenable. That's a larger return on investment than simply getting a favorable election result, and it's why the foreign policy downstream of contested elections matters as much as the elections themselves. De la Espriella is presumably governing according to his own convictions. He may well believe every policy he's implementing is correct. None of that resolves the structural question about what it means for a dual national to hold executive power in a country and then pursue policies that happen to align precisely with the preferences of the other country whose passport he carries. The alignment might be coincidental. Institutions usually assume it isn't. Tehran's anger is real even if their leverage is limited. Bogotá's pivot is real even if its independence is questionable. And the regional argument about U.S. sovereignty violations in Latin America just got a new exhibit. foreigninterference.org/post… #foreigninterference #DiplomaticSeverance #GovernmentDestabilization #PoliticalInfiltration #AntiInterferenceRhetoric #DiplomaticCoercion
1
122
Transparent Tribe has been running the same basic playbook against Indian targets since 2013. That's over a decade of continuous operations against Indian government agencies, military personnel, defense research institutions, and diplomatic staff. CYFIRMA's weekly intelligence report for September 25, 2026 flags the group again, documenting continued activity during a period when, if anything, you'd expect state-backed hackers to be working overtime. The group, designated APT36 and widely attributed to Pakistani intelligence services, is not a sophisticated mystery. It's a known quantity with a documented history and a consistent target set. What makes it worth revisiting isn't novelty. It's persistence, and what persistence like this actually costs the people being targeted. The core toolkit is CRIMSON RAT and ObliqueRAT, both custom-built and regularly updated to stay ahead of signature-based detection. The delivery mechanism is spear-phishing, often built around whatever is currently making headlines between India and Pakistan. Kashmir tensions, Line of Control incidents, military posturing. The group has institutional knowledge of its targets built up over thirteen years of continuous operations, which means its social engineering is not generic. It's tuned. CYFIRMA's September report situates the Transparent Tribe activity within a broader spike in state-sponsored cyber operations during the UN General Assembly period in late September 2026. That's not coincidental. The UNGA period concentrates diplomatic activity, creates new communication channels between officials, and gives intelligence services on all sides fresh reasons to want insight into what their counterparts are saying behind closed doors. Cyber espionage operations don't slow down for diplomacy. Often they accelerate. The geographic scope of Transparent Tribe operations extends beyond India's borders to target Indian diaspora communities and government personnel operating abroad. That's a significant detail. It means Indian defense and diplomatic personnel can't treat the threat as geographically contained. A military attaché posted to a third country, a researcher at a foreign university with ties to Indian defense institutions, an official traveling for multilateral meetings. All plausible targets, and all operating in environments where the defensive infrastructure is less robust than what they'd have at home. India's CERT-In and the National Cyber Security Coordinator are not operating blind here. The attribution is solid, the TTPs are documented, and groups like CYFIRMA are publishing updated analysis regularly. The structural problem is that defense against a persistent, state-resourced adversary conducting thousands of spear-phishing attempts annually is not a problem you solve. It's a problem you manage. The math doesn't favor the defender. One successful penetration of a defense research institution or military headquarters generates intelligence value that, from Islamabad's perspective, justifies years of failed attempts. The attacker only needs to be right once. The defender needs to be right every time. Transparent Tribe rotates its command-and-control infrastructure regularly, which complicates both attribution in the moment and takedown operations. By the time a specific piece of infrastructure is identified, reported, and actioned, the group has often already moved. This is not a technically demanding capability. It's operationally disciplined tradecraft, and it's one of the reasons a group running relatively unsophisticated tools has sustained operations for thirteen-plus years without meaningful disruption. The CYFIRMA report frames the September 2026 Transparent Tribe activity as part of a broader pattern of state-sponsored actors maintaining or increasing operational tempo. That framing is accurate and probably understated. The group isn't escalating in a dramatic sense. It's doing what it has always done, methodically, against targets it knows well, during a period when the intelligence value of those targets is as high as it's ever been. foreigninterference.org/post… #foreigninterference #AdvancedPersistentThreatOperations #SpearPhishing #MalwareDistribution #MilitaryEspionage #CyberEspionage
62