Tracking and analyzing foreign interference worldwide.

Washington, D.C.
Based in West Asia
This Week in Foreign Interference: 81 incidents logged. That's a heavy week. The through-line, if there is one: scale. AI-enabled operations projecting 450-700% disinformation surges. An autonomous Windows implant making its own attack decisions. Eight Chinese vessels blockading a Philippine resupply mission. Western spy chiefs compressing the Russia-NATO attack timeline to "months not years." A lot is moving at once. Here's the week's notable activity. --- CLOSEDQUORUM (Sept 22): Cisco Talos documented the first publicly known Windows implant using embedded LLMs to autonomously select post-compromise actions without human command-and-control direction. This is not a theoretical capability. It's deployed malware that cuts the human out of the loop, eliminating the detection windows defenders have built their playbooks around. Talos released the CAIRN framework to help spot AI-driven behavior. Worth watching whether CAIRN spreads fast enough to matter. --- China at Ayungin Shoal (Sept 25): Eight PLAN and coast guard vessels blocked a Philippine humanitarian resupply to the BRP Sierra Madre garrison. The AFP confirmed the interference publicly. Beijing's playbook here is consistent: coercive enough to deny access, calibrated enough to stay below any treaty threshold. Manila is documenting. Washington is watching. The garrison stays cut off. --- RAF satellite jamming disclosure (Sept 25-26): Britain revealed it has been covertly jamming adversary satellites for approximately a year, then immediately formalized the capability with the debut of Number III Space Effects Squadron on Sept 26. The sequencing is deliberate. Disclosing an ongoing covert operation as you institutionalize it is a deterrence signal, not a transparency exercise. The targets, Russian and Chinese satellites, were not named officially. They didn't need to be. --- Polish Starlink sabotage (Sept 25): A fire at a Polish power station serving Starlink infrastructure was labeled sabotage. Denmark issued a concurrent Russian hybrid threat warning the same day. The target isn't coincidental. Starlink sustains Ukrainian military communications. Hitting the infrastructure in Poland lets Russia degrade that capability while keeping the strike on NATO soil ambiguous enough to dispute. Denmark's warning and the Baltic states' covert petition to the EU defence fund for drone shielding reflect how seriously the eastern flank is taking the pattern. --- CIA false-flag warning (Sept 25): CIA intelligence warned Russia is planning false-flag drone attacks against France, Spain, or Italy using weaponized civilian shipping as launch platforms. Russia's hybrid campaign has been concentrated on the eastern flank until now. Extending it to NATO's southern tier, under false attribution, is a meaningful escalation in both geography and method. --- Chinese operatives attacked Tibetan protesters in Washington D.C. (Sept 24): During Xi Jinping's state visit, pro-Beijing actors physically assaulted Tibetan demonstrators on U.S. soil. Transnational repression executed in front of cameras, during a summit. The Trump administration's response to the incident was not prominently documented. Congressional Democrats called on Trump to raise human rights with Xi. Whether he did is not publicly confirmed. --- F-35 component diverted to Hong Kong (Sept 23): A U.S.-bound F-35 component shipment from Australia was redirected to Hong Kong, triggering a defense supply chain investigation. Hong Kong functions as a Chinese SAR with intelligence service access to commercial cargo logistics. The incident fits a documented pattern. Hong Kong is not a neutral transit point, and treating it as one in defense supply chains has been a recurring problem that congressional attention hasn't yet fixed. --- New Zealand formally designates China as top cyber threat (Sept 24): New Zealand's cyber agency made it official, naming China the country's most persistent and capable state-backed cyber threat. The designation closes the last public attribution gap in Five Eyes' unified China cyber posture. All five eyes are now on record saying the same thing. That alignment matters for both policy coordination and diplomatic pressure, even if it doesn't immediately change Beijing's behavior. --- UK PM Burnham at UNGA (Sept 23): Burnham condemned Russian electoral interference and announced a National Centre for Information Defence. The announcement drew immediate domestic criticism framing it as a censorship architecture. That tension, between defending information environments and policing them, is going to follow every counter-disinformation institution announcement for the foreseeable future. Russia's SVR director, for his part, used UNGA week to accuse the West of election interference. Timing was not coincidental. --- Quebec interference warning (Sept 25): CAQ leader Fréchette publicly warned of U.S. interference risk in the 2026 Quebec provincial election and confirmed contact with CSIS. U.S. interference in a Canadian provincial election is a story that would have been treated as implausible ten years ago. It isn't implausible now. --- The rest of the week's volume: additional Russia hybrid warfare reporting on Poland, Romania, and Moldova (drone explosions, airspace violations, suspected arson), ENISA documenting escalating EU infrastructure cyberattacks with state actors exploiting shared providers for cascading multi-organization compromise, CYFIRMA's continued documentation of Pakistan-linked APT36 operations against Indian military and government targets, EU sanctions on Russian state media figure Xenia Fedorova for information manipulation, and the Canada-Nordic-Baltic Eight foreign ministers coordinating hybrid threat response at UNGA, the most institutionally significant counter-hybrid alignment outside NATO formats this week. Separately: AI disinformation projections are getting alarming in their specificity. A 450-700% surge projected for UK and European environments. A 350-550% surge projected for South America and the Caribbean. These aren't vague threat assessments. They're operational cost curves. AI reduces the personnel and financial overhead for sustained influence campaigns to the point where actors who couldn't previously sustain them can now. Historical context logged this week included documented Cold War baselines: the 1987 OSI dismantlement of a joint Soviet-Chinese espionage ring in Japan targeting U.S. Air Force weapon systems, Reagan-era KGB disinformation operations traced by R Street as direct precursors to current Russian information warfare doctrine, and a 54-year electoral intervention dataset confirming measurable, systematic impact on outcomes. The history is not academic. The methods have continuity. --- Next week: The House Foreign Affairs Committee's foreign influence inquiry is moving. The Disclosing Foreign Influence in Lobbying Act is calendared for Sept 28 House consideration, and K Street opposition to it is organized. Watch whether it survives markup intact or gets definitionally narrowed into something that doesn't close the gaps it's meant to close. foreigninterference.org #foreigninterference #DisinformationCampaigns #InfluenceOperations #TransnationalRepression #ElectionInterference
136
Citigroup found out on May 10, 2011, that someone had been walking through their customer database by changing numbers in a URL. That's it. That's the attack. Log in with your own account, look at the address bar, swap your account number for someone else's, press enter. Repeat 360,083 times. The technical term is an insecure direct object reference. The plain English translation is: the website handed you whatever account you asked for, no questions asked. The bank had presumably spent real money on security. Firewalls, intrusion detection, the works. And then they forgot to lock the thing that let authenticated users access each other's data freely by editing a URL. TIME called it a high-tech security system with the front door left open. That's charitable. The front door wasn't just unlocked. There was no door. The breach was undetected for weeks. Which makes sense, in a grim way. The attackers weren't triggering anything that looked anomalous to existing monitors because they were logged in legitimately. The access pattern looked, from a certain angle, like normal browsing. This is the frustrating physics of application-layer vulnerabilities. They don't set off the perimeter alarms because they happen inside the perimeter. California took the worst of it, 80,454 customers. Connecticut saw 5,066 affected. The total haul was names, account numbers, email addresses. Not passwords, apparently, but enough. By the time Citigroup finished replacing cards, 217,657 customers had gotten new account numbers in the mail. The fraudulent charges came to $2.7 million, which for a bank of Citigroup's size is a rounding error but isn't nothing to the people whose money moved without their permission. The notification delay is where it gets uglier. Discovery was May 10. Citigroup didn't start telling customers until June 3. Nearly three weeks. The argument banks usually make for delays like this is that they need to understand the scope before they communicate, that premature notification causes panic without giving people actionable information. There's a version of that reasoning that's defensible in narrow circumstances. Three weeks for a breach of this scope, involving a vulnerability this elementary, is not that version. Connecticut's attorney general investigated. What came out of that investigation was worse than the delay. Citi may have known about the vulnerability for up to three years before attackers exploited it. If accurate, that reframes the story considerably. The breach wasn't the result of attackers finding something Citi's own engineers hadn't noticed. It was the result of a known flaw sitting unpatched long enough for someone else to find it and use it. Knowing about an insecure direct object reference in your online banking platform and not fixing it for three years is a policy choice, even if no one called it that at the time. Senator Bob Menendez wrote to the Office of the Comptroller of the Currency asking for an investigation into both the breach and the notification lag. His office also put the Citigroup incident in a broader context: in the six years before 2011, there had been 288 publicly disclosed breaches at financial services firms, exposing at least 83 million customer records. That number deserves a moment. This wasn't an industry that had been catching criminals and learning from close calls. It was an industry bleeding customer data at a steady rate for years. The settlement Connecticut eventually extracted was $55,000. For Citigroup. Fifty-five thousand dollars. I'll just leave that there. What I find myself coming back to, having watched this sector for a while, is how thoroughly unsurprising the failure mode was. Insecure direct object reference vulnerabilities weren't obscure in 2011. The OWASP Top Ten, which is the closest thing the web security world has to a beginner's checklist, had been listing this class of vulnerability since 2007. It appeared on the list again in 2010, a year before the breach. Any developer or security team working on a financial platform had access to the information. The question was never whether anyone knew about this category of problem. The question was whether fixing it was someone's priority. At institutions the size of Citigroup, online banking platforms in 2011 were often running on layered legacy code with multiple teams responsible for different pieces. Access control logic, if it existed, might be applied inconsistently across different parts of the application. That's a realistic description of the environment, not an excuse. The realistic description and the accountability sit alongside each other. The foreign interference angle here isn't about a nation-state running this operation. The attack was unsophisticated by design, which is what made it effective and invisible. Organized criminal groups understood something important: banks spend heavily defending against the attacks they expect, meaning attacks that look like attacks. Systematic enumeration of account numbers by a logged-in user looked like an active customer. The monitoring infrastructure wasn't built to flag it. That's a lesson that has traveled. Actors interested in financial data, whether for fraud, for intelligence gathering on individuals, or for mapping financial relationships between persons of interest, have consistently looked for the gap between what a security system is designed to catch and what's actually happening. In 2011 the Citigroup platform had that gap, and it was wide. The broader picture Menendez's office sketched in 2011 is recognizable if you've been watching: 83 million records across 288 breaches is a systemic condition, not a series of isolated incidents. The financial sector was processing more transactions online, connecting more systems, expanding the attack surface, and not consistently increasing the baseline quality of the applications sitting on top of all that data. Citigroup's breach was the visible part of that. The less visible part was the accumulation of known vulnerabilities at other institutions that hadn't yet been exploited, or that had been exploited without anyone detecting it. The regulatory pressure that followed produced calls for legislation and enhanced oversight. Whether it produced better application-layer security practices across the sector in any systematic way is a different question. The class of vulnerability that exposed Citigroup's customers keeps appearing in assessments of financial platforms years later. Different institutions, different specifics, same underlying failure to validate that an authenticated user should actually have access to the object they're requesting. $2.7 million in fraudulent charges. $55,000 settlement. A vulnerability the bank may have known about for three years. Three weeks before customers were told. That's the accounting. foreigninterference.org/post… #foreigninterference #CyberEspionage #FinancialCyberTheft #UrlManipulation
1
96
Three weeks after Russia invaded Ukraine, the Senate Foreign Relations Committee sat down on March 15, 2022 to ask a question that probably should have been asked sooner: does the United States actually have the institutional machinery to fight back against authoritarian disinformation, or has it just been telling itself it does? The answer that emerged from the hearing was, roughly, "sort of, with some significant caveats that happen to be load-bearing." The central institution under the microscope was the Global Engagement Center, the State Department body tasked with identifying and countering foreign propaganda and disinformation. Witnesses confirmed that the GEC had done real work, establishing counter-disinformation partnerships with allies across Europe and the Indo-Pacific, helping partner countries protect elections from foreign interference operations. That part is genuine. The GEC has bilateral and multilateral frameworks in place, it works with foreign governments, it has relationships with platforms operating in those spaces. The problem is the wall. The GEC is statutorily prohibited from operating domestically. This is not an accident or an oversight; it reflects a real and legitimate concern about turning counter-disinformation machinery inward on American audiences and sliding into government-managed information control. The legal constraint is defensible in principle. The operational problem is that Russia and China figured out years ago that they don't need to directly inject disinformation into American domestic discourse. They just need to get it close enough to the border for American domestic actors to pick it up voluntarily. The mechanism senators pressed witnesses on is essentially a laundering operation. Russian or Chinese origin content, designed with full awareness of American domestic political faultlines, gets produced and seeded in spaces where American political figures, media personalities, and social media ecosystems will find it useful, entertaining, or validating. Those domestic actors then amplify it, strip the foreign fingerprints through simple repetition and recontextualization, and the content arrives in American information space wearing entirely domestic clothes. At that point, the GEC's legal mandate ends. The foreign-origin material has successfully cleared the perimeter, and the institution tasked with stopping it is statutorily required to look away. Senators asked the obvious question: does the domestic-foreign distinction remain coherent when adversaries have specifically engineered their operations to exploit that exact distinction? The witnesses, to their credit, did not try to pretend the perimeter model is fully adequate. They acknowledged the gap. The hearing record just doesn't contain a clean resolution of it, because there isn't one. Any expansion of the GEC's domestic authority runs into serious First Amendment and government overreach concerns that don't disappear because Russia is being inconvenient. The foreign interference risk assessment section of the hearing is worth sitting with for a moment, because the framework witnesses laid out is genuinely useful for understanding where adversaries focus their efforts. High-risk environments were characterized by four converging conditions: elections with narrow margins (where a small nudge in turnout or perception can change outcomes), significant diaspora communities with ties to adversary states (leverage points for identity-based manipulation), high-polarization information environments that adversaries can exploit through grievance campaigns, and weak platform enforcement capacity. The uncomfortable observation embedded in this framework is that the United States met all four conditions simultaneously in 2022, as did several European democracies facing upcoming elections, as did a range of emerging democracies in Africa and Asia where Chinese and Russian influence operations were actively expanding their footprint. The Russia-China coordination finding is the part of the hearing record that tends to get underplayed in retrospect. Witnesses addressed evidence that the two authoritarian powers were coordinating elements of their information operations, and the description is precise enough to be worth quoting accurately: not formal operational integration, but sharing of narratives, amplification of each other's content on third-party platforms, and parallel targeting of the same Western democratic institutions. This is not the same as a joint command structure. It is, however, considerably more alarming than two countries happening to dislike the same things. The practical effect is that democratic defenders face a combined authoritarian information capacity that is larger than either Russia or China would represent individually, without that combination requiring the kind of formal alliance architecture that might create visible signatures to track. The legislative discussion covered territory that has been circling the same drain for several years. Expanding the GEC's mandate and resources. Creating legal authorities for proactive declassification of foreign interference intelligence so adversary operations can be publicly exposed faster, before they complete their intended effect rather than after. Better information-sharing mechanisms between the intelligence community and platform companies to accelerate identification and removal of state-sponsored content. These are all reasonable ideas. They are also ideas that were reasonable in 2018, and 2019, and 2020, and 2021. The hearing's March 2022 urgency came partly from the invasion context but also from the recognition that the gap between identifying these structural problems and actually closing them had stretched across multiple Congressional sessions without resolution. The FARA section is its own study in institutional dysfunction. The Foreign Agents Registration Act requires individuals operating in the United States as agents of foreign principals to register as such. The enforcement gap the hearing addressed is the persistent, documented failure to prosecute unregistered foreign agents operating in influence capacities. FARA enforcement has been, for most of its history, remarkably tolerant of non-compliance. Witnesses and senators discussed the need to coordinate Treasury OFAC sanctions with criminal prosecutions and platform takedowns, the logic being that disinformation ecosystem participants face essentially no comprehensive cost for their activities when each enforcement mechanism operates in isolation. A sanctions designation without a corresponding prosecution and platform removal is a talking point, not a deterrent. The hearing acknowledged this coordination problem without resolving it either. The March 15 date matters more than it might seem. Three weeks after February 24, Russian disinformation about the invasion's causes, its conduct, and its humanitarian consequences was being actively produced and distributed at scale across global platforms. This was not a theoretical future threat being gamed out in committee. The committee was in real-time assessment mode, trying to determine whether the counter-interference apparatus was adequate to an active adversary information campaign targeting European and North American audiences simultaneously, while the war that campaign was supporting was still in its opening phase. What the hearing documented, taken as a whole, is a counter-disinformation architecture that was built for a slightly different version of the problem than the one it actually faces. The GEC's perimeter model made intuitive sense when foreign disinformation was something foreign. The FARA framework made sense when foreign agents were primarily engaging in trackable lobbying activities rather than narrative seeding through social media ecosystems. The intelligence-platform information sharing gap was tolerable when state-sponsored content operations were slower and more detectable. All of those assumptions have been systematically eroded by adversaries who had strong incentives to study the architecture and route around it. The senators who pressed witnesses on whether the domestic-foreign distinction remained operationally coherent were asking the right question. The honest answer, sitting in the transcript, is that it remains legally coherent because the law hasn't changed, and operationally problematic because the adversaries changed their operations to exploit exactly that legal line. Fixing the operational problem without creating new ones requires threading a needle that the hearing identified clearly but that Congress has not, as of that March, threaded. The Ukraine invasion context gave the 2022 hearing a sharp edge that earlier iterations of these same conversations lacked. Whether that urgency translated into the structural changes witnesses described is a different question, and a less satisfying one. foreigninterference.org/post… #foreigninterference #DisinformationCampaigns #CounterDisinformationFrameworkDevelopment #LegislativeGapAssessment #CrossBorderInfluenceOperations #SanctionsFrameworkEstablishment #IdentityGrievanceCampaigns #CongressionalInvestigationLaunch #ForeignInformationManipulation
50
By 2019, the Oxford Internet Institute had documented computational propaganda running across 70 countries. Not 7. Not 17. Seventy. And that was before anyone had fully worked out why it kept working regardless of who was running it or what the specific message was. That gap, the distance between mounting case studies and actual theoretical understanding, is what a 2022 City University London open-access study tried to close. It's worth spending some time with what the framework actually says, because it cuts against a few comfortable assumptions. The Chinese operations section draws on Lu's 2022 analysis and uses the term "participatory digital warfare," which is precise in a way that matters. The Soviet active measures model was largely a professional intelligence function. Handlers, front organizations, planted stories, carefully managed assets. You could, in principle, follow the chain. The Chinese model the framework describes is structurally different: mass mobilization of patriotic users, commercial PR firms embedded in state media ecosystems, volume generated at a scale that platform moderation simply cannot process in real time. Individual participants may have zero formal intelligence affiliation. A lot of them probably believe what they're posting. That's the attribution problem in a nutshell. The coordinating architecture, which topics get seeded, when amplification happens, which platforms get targeted, reflects professional operational planning. The participants executing it often don't. Classic intelligence attribution frameworks look for the handler. Here there may not be a single handler to find, just a system that produces the desired output. The psychological architecture section is where the framework earns most of its analytical weight. Three campaign types, and they're not what most people assume disinformation is for. The first is confidence degradation. The goal is not to convince anyone of a specific false thing. The goal is to destroy confidence that reliable information exists at all. Epistemic paralysis. If a target population can be brought to a state where they assume everything is probably manipulated and truth is essentially unknowable, they become effectively ungovernable by information. Democratic decision-making requires a shared epistemic baseline. Remove that baseline and you haven't just confused people, you've degraded the functional infrastructure of collective judgment. The second is identity polarization. This one is older than social media, older than the internet, older than broadcasting. Exploit existing fault lines, deepen in-group and out-group divisions, erode social trust. The innovation isn't the concept, it's the targeting precision and the speed. Algorithmic platforms that already optimize for engagement are doing half the work for you, because conflict and outrage drive engagement, and engagement drives reach. The third is elite discrediting. Targeted operations against specific politicians, journalists, scientists, institutional actors. The goal is not just to damage a particular individual but to disable the credibility mechanisms that democratic societies use to evaluate competing truth claims. If the sources a population would normally use to adjudicate factual disputes have been rendered suspect, the population loses its epistemic immune system. Whatever comes next, accurate or not, has no reliable filter to pass through. What the framework does with these three categories is argue they operate across perpetrators regardless of the specific state running the operation or the specific grievance being exploited. Russia uses these mechanisms. China uses them. Iran uses them. Smaller states running more limited operations use variants adapted to their resource constraints. The 2022 study builds on the Oxford baseline to show methodological convergence: automated amplification, fake persona networks, media impersonation, strategic content injection. The same toolkit, differently calibrated. This convergence has a defensive implication that the framework states directly and that doesn't get enough attention: platform-level interventions that disrupt one state actor's infrastructure will simultaneously constrain others using the same methods. The infrastructure overlaps. The techniques overlap. You are not, when you act against one operation, doing something narrowly targeted that leaves the rest untouched. There may be disproportionate defensive returns available from coordinated platform action precisely because the adversaries have converged on similar approaches. Whether platforms act on that is a different question, and not a comfortable one. The Stimson Center's 2022 companion analysis on social media misinformation and political instability puts it plainly: major technology companies remained hesitant to employ policies that might be seen as limiting free expression. This created a structural asymmetry. Disinformation operators can exploit full platform reach with essentially no normative friction. Defenders face normative constraints on response. The operators have already decided the information environment is a battlefield. The platforms are still treating it primarily as a speech venue. That asymmetry becomes especially acute in mass atrocity contexts. The Stimson analysis specifically flags situations where disinformation campaigns precede or accompany political violence, creating intervention dilemmas that existing platform policies cannot adequately address. At the point where content is actively contributing to conditions for atrocity, the normal content moderation calculus, designed for more ambient conditions, is not fit for purpose. The OFAC piece fits into this as the legal mechanism that operates outside the platform layer entirely. The March 2022 Federal Register publication documented sanctions designations against specific individuals and entities whose primary function was disinformation production and distribution, targeting them as participants in malicious cyber-enabled activities and Russian government election interference operations. Sanctions are blunt. They don't require proving criminal intent in a domestic court. They establish financial consequences for participation in information operations infrastructure, which matters because that infrastructure has costs and participants who respond to financial incentives. It's not sufficient on its own, but as a complement to platform takedowns and the occasional criminal prosecution, it closes some of the gaps each individual mechanism leaves open. The City University framework is not exciting reading. It's an academic synthesis, which means it is careful and qualified and footnoted and unlikely to go viral. But the thing it documents, the convergence of methods across state actors, the three-campaign psychological architecture, the structural advantages that disinformation operators hold relative to defenders, those are not theoretical problems. They are operational realities that have been running for years across dozens of countries. The literature caught up to them in 2022. The operational responses are still catching up. foreigninterference.org/post… #foreigninterference #DisinformationCampaigns #ComputationalPropaganda #CognitiveExploitation #DemocraticInstitutionTargeting #HistoricalNarrativeManipulation #SanctionsFrameworkEstablishment #CounterDisinformationFrameworkDevelopment #IdentityGrievanceCampaigns
64
The 2022 ODNI Annual Threat Assessment put four adversary cyber programs on the record in one document. China rated as the broadest and most persistent threat. Russia demonstrated hybrid integration of cyber and kinetic operations in Ukraine. Iran made contact with U.S. election infrastructure. North Korea tied cryptocurrency theft directly to missile financing. The public baseline is now set. What the assessment actually signals is less about the individual actors than about where all four programs are converging in their architecture. Start with China. The March 2022 penetration of at least six state government networks wasn't the leading edge of something new. The ODNI language was "endemic rather than episodic." That framing matters because it forecloses the incident-response model as a sufficient defense. You cannot patch your way out of an endemic condition. The state-level targeting is also a tell about where Chinese collection is heading: federal hardening is pushing operations toward softer targets. State election infrastructure, county-level emergency management systems, port authorities. Places that have CISA guidance but not CISA budgets. That gap is the operational seam China has been probing, and the 2022 document essentially confirmed it in public. The Russia picture is structurally different and in some ways more instructive. What the Ukraine theater demonstrated is that Russia has operationalized something the U.S. military only codified in Joint Publication 3-04 in 2022: the integration of information operations, cyber tools, and kinetic action into a single campaign. Russia field-tested this doctrine before we finished writing ours. The RT-linked AI content operations disrupted by DOJ were not a separate track. The assessment described them as integral to the cyber-information hybrid architecture. That means future attribution calls on Russian influence operations will need to account for the possibility that what looks like a propaganda campaign is functioning as cover or noise for a concurrent cyber intrusion, and vice versa. Analysts who silo those two disciplines will miss the compound event. Iran's trajectory is the one that should occupy election security officials most immediately. The joint DHS/DOJ finding of contact with U.S. election infrastructure during the 2022 cycle is the data point, but the direction is what matters. Iranian APT groups have been running transnational repression campaigns against Persian-language diaspora for years, which means they have developed persistent access to community networks, messaging platforms, and the kind of soft infrastructure that exists well outside federal cybersecurity coverage. The overlap between diaspora targeting and domestic political communities is not zero. Iranian actors looking to amplify division in U.S. politics have a ready-made access route through diaspora networks they already own. North Korea is the cleanest case in terms of operational logic. Lazarus Group and affiliated actors stole an estimated 400 million dollars in cryptocurrency in 2021, and Pyongyang's 2022 missile testing program ran at a pace that required exactly that kind of supplemental financing. The linkage is direct. The implication for defenders is that North Korean cyber operations against financial infrastructure are not going to de-escalate as long as the sanctions regime holds and the weapons program requires hard currency. There is no diplomatic resolution on the horizon that changes that calculus. Crypto exchanges, DeFi protocols, and the custodial infrastructure around them remain high-probability targets for the foreseeable future, and the 2022 assessment gave no indication that the operational tempo was slowing. The structural problem the assessment exposed, and which the Senate Foreign Relations hearing made explicit, is the gap between the threat's integration and the defense's fragmentation. The Global Engagement Center was doing counter-disinformation work with partner countries on elections. CISA was doing cyber hardening. DOJ was running disruption operations. None of these are bad programs. But the adversaries assessed in this document are running unified campaigns, and the U.S. counter-architecture is organized by bureaucratic lane. That mismatch doesn't resolve itself. A few specific things to watch over the next election cycle. First, watch for Chinese targeting of secretaries of state offices and the vendors who supply voter registration database software. The 2022 state network penetrations established that Chinese actors have appetite for subnational government access. Voter infrastructure is subnational. Second, watch for compound Russian operations where a visible influence campaign coincides with a quieter intrusion against the same target set. The doctrine is now explicit. Third, watch Iranian operations against diaspora community organizations in swing-state cities with large Persian-speaking populations. Atlanta, Northern Virginia, Los Angeles. The access already exists in some of those networks. Fourth, watch North Korean actors pivot toward newer DeFi and cross-chain bridge protocols as traditional exchange security improves. They adapt faster than compliance frameworks. The 2022 ATA was a baseline document. The actors it described have not stood still since it was published. foreigninterference.org/post… #foreigninterference #CyberEspionage #AdvancedPersistentThreatOperations #ElectionInfrastructureTargeting #DisinformationCampaigns #CryptocurrencyTheft #CognitiveWarfare #CriticalInfrastructureMapping #MultiDomainWarfareCoordination #ThreatAssessmentFramework
72
The Justice Department quietly told Congress that FISA wiretaps jumped sharply in 2011, and "quietly" is doing a lot of work in that sentence. Assistant Ronald Weich sent the letter. No press conference, no fanfare. Just a number going up and a note to the people who are supposed to be watching the watchers. The surveillance covered suspected foreign agents and terrorism-linked communications, which is the legal lane, but the scale of the increase is the part worth sitting with. Foreign intelligence operations targeting the U.S. were apparently busy enough in 2011 to justify a significant escalation in monitoring. That's the actual headline. foreigninterference.org/post… #foreigninterference #CommunicationsInterception #MassSurveillanceOperations
49
FARA has been "under reform" longer than most lobbyists have been alive. The House calendar for September 28 lists the Disclosing Foreign Influence in Lobbying Act for consideration, which sounds like progress until you remember the Senate passed foreign lobbying reform unanimously in 2023 and it went nowhere. The Qatar campus money, the $4.4 million China-linked donor network in California, the whole Qatargate mess documented last month: all of it flowed through gaps that reformers have been promising to close for years. K Street has a direct financial stake in keeping those gaps open, and K Street is very good at its job. Getting on the calendar is the easy part. foreigninterference.org/post… #foreigninterference #CounterInterferenceLegislation #LegislativeGapAssessment #PoliticalDonationInfluence #InfluenceOperations #CongressionalInvestigationLaunch
47
Abelardo de la Espriella became Colombia's president and, within months, Colombia no longer had diplomatic relations with Iran. Make of that sequencing what you will. The break came in late September 2026. The new right-wing government in Bogotá severed ties with Tehran and simultaneously pivoted toward Israel, which is about as clean a signal of political alignment as you can send in one move. Press TV flagged it via GlobalSecurity.org, which, yes, is an Iranian state outlet and therefore not a neutral narrator, but the facts of the break itself aren't in dispute. The thing that makes this case analytically interesting, rather than just another diplomatic shuffle, is the detail about de la Espriella's citizenship. He holds dual U.S.-Colombian nationality. That's not a rumor or an opposition smear. It's a structural fact about the person running Colombian foreign policy. And when that person's first major foreign policy gestures are: (1) cut ties with a country Washington considers an adversary, and (2) lean toward a country Washington is actively backing under the Trump administration's Middle East posture, the question of where the strategic decision-making is actually happening becomes genuinely worth asking. You don't have to assume bad faith to ask it. The question asks itself. Colombia under Gustavo Petro had moved in a very different direction. Petro opened lines with Venezuela, was vocal about Palestinian rights, kept relations with Iran functional if not warm. De la Espriella is essentially running the foreign policy tape backward at speed. That kind of reversal doesn't happen in a vacuum, and it doesn't usually happen this fast without some external architecture supporting it. The Washington Brazil Office had been documenting U.S. pressure on Latin American governments throughout the 2026 electoral cycle, and Colombia fits the broader pattern: elections producing governments that are either genuinely ideologically aligned with Washington's preferences or sufficiently dependent on U.S. support that the practical difference is hard to find. Iran's response was formally noted but deliberately vague. The Foreign Ministry vowed to take "measures" in response to what Tehran called Colombia's "hostile approach," without specifying what those measures would be. That ambiguity is a tactic, not an oversight. It lets Tehran preserve maximum flexibility while creating just enough uncertainty about costs to put Bogotá slightly on edge. The honest assessment is that Iran has limited direct leverage over Colombia. They're not trade partners of consequence, they don't share a neighborhood, and there's no meaningful Iranian diaspora in Colombia with political weight. What Iran does have is indirect reach. Hezbollah-linked networks in South America are well-documented, concentrated particularly in the tri-border area of Argentina, Brazil, and Paraguay, and in parts of Venezuela. Whether Tehran activates any of that infrastructure in response to the Colombian break is a real question, though "activates" covers a range of options from propaganda to something considerably less comfortable. The Iranian Foreign Ministry's careful vagueness probably reflects the fact that their actual options are more limited than their rhetoric suggests, but they'd rather you not be certain about that. The more immediate use Iran gets from this rupture is rhetorical. And on that front, they're not working alone. Lula in Brazil has been publicly accusing the U.S. of electoral interference. Cuba showed up at the UN General Assembly in late 2026 warning against what its representatives called the "law of the jungle" in international relations. Venezuela has been in a running confrontation with Washington for years and views every development like the Colombia pivot as further evidence for its preferred narrative. All of these governments will use the de la Espriella pivot, a dual U.S.-citizen president cutting ties with Iran and embracing Israel within months of taking office, as a concrete example when they argue that Washington is systematically reordering Latin American foreign policy through pressure and installed-friendly-government operations. Whether that framing is entirely fair is a separate question. But it's not an absurd reading of events, and the people making that argument now have a pretty clean data point to cite. The Colombia case is worth sitting with as a model, not just an incident. Electoral interference, when it works, doesn't just change who wins. It changes what that country does afterward. Trade relationships, diplomatic posture, military cooperation agreements, regional bloc alignments: all of it becomes available for restructuring once the executive is amenable. That's a larger return on investment than simply getting a favorable election result, and it's why the foreign policy downstream of contested elections matters as much as the elections themselves. De la Espriella is presumably governing according to his own convictions. He may well believe every policy he's implementing is correct. None of that resolves the structural question about what it means for a dual national to hold executive power in a country and then pursue policies that happen to align precisely with the preferences of the other country whose passport he carries. The alignment might be coincidental. Institutions usually assume it isn't. Tehran's anger is real even if their leverage is limited. Bogotá's pivot is real even if its independence is questionable. And the regional argument about U.S. sovereignty violations in Latin America just got a new exhibit. foreigninterference.org/post… #foreigninterference #DiplomaticSeverance #GovernmentDestabilization #PoliticalInfiltration #AntiInterferenceRhetoric #DiplomaticCoercion
1
115
Transparent Tribe has been running the same basic playbook against Indian targets since 2013. That's over a decade of continuous operations against Indian government agencies, military personnel, defense research institutions, and diplomatic staff. CYFIRMA's weekly intelligence report for September 25, 2026 flags the group again, documenting continued activity during a period when, if anything, you'd expect state-backed hackers to be working overtime. The group, designated APT36 and widely attributed to Pakistani intelligence services, is not a sophisticated mystery. It's a known quantity with a documented history and a consistent target set. What makes it worth revisiting isn't novelty. It's persistence, and what persistence like this actually costs the people being targeted. The core toolkit is CRIMSON RAT and ObliqueRAT, both custom-built and regularly updated to stay ahead of signature-based detection. The delivery mechanism is spear-phishing, often built around whatever is currently making headlines between India and Pakistan. Kashmir tensions, Line of Control incidents, military posturing. The group has institutional knowledge of its targets built up over thirteen years of continuous operations, which means its social engineering is not generic. It's tuned. CYFIRMA's September report situates the Transparent Tribe activity within a broader spike in state-sponsored cyber operations during the UN General Assembly period in late September 2026. That's not coincidental. The UNGA period concentrates diplomatic activity, creates new communication channels between officials, and gives intelligence services on all sides fresh reasons to want insight into what their counterparts are saying behind closed doors. Cyber espionage operations don't slow down for diplomacy. Often they accelerate. The geographic scope of Transparent Tribe operations extends beyond India's borders to target Indian diaspora communities and government personnel operating abroad. That's a significant detail. It means Indian defense and diplomatic personnel can't treat the threat as geographically contained. A military attaché posted to a third country, a researcher at a foreign university with ties to Indian defense institutions, an official traveling for multilateral meetings. All plausible targets, and all operating in environments where the defensive infrastructure is less robust than what they'd have at home. India's CERT-In and the National Cyber Security Coordinator are not operating blind here. The attribution is solid, the TTPs are documented, and groups like CYFIRMA are publishing updated analysis regularly. The structural problem is that defense against a persistent, state-resourced adversary conducting thousands of spear-phishing attempts annually is not a problem you solve. It's a problem you manage. The math doesn't favor the defender. One successful penetration of a defense research institution or military headquarters generates intelligence value that, from Islamabad's perspective, justifies years of failed attempts. The attacker only needs to be right once. The defender needs to be right every time. Transparent Tribe rotates its command-and-control infrastructure regularly, which complicates both attribution in the moment and takedown operations. By the time a specific piece of infrastructure is identified, reported, and actioned, the group has often already moved. This is not a technically demanding capability. It's operationally disciplined tradecraft, and it's one of the reasons a group running relatively unsophisticated tools has sustained operations for thirteen-plus years without meaningful disruption. The CYFIRMA report frames the September 2026 Transparent Tribe activity as part of a broader pattern of state-sponsored actors maintaining or increasing operational tempo. That framing is accurate and probably understated. The group isn't escalating in a dramatic sense. It's doing what it has always done, methodically, against targets it knows well, during a period when the intelligence value of those targets is as high as it's ever been. foreigninterference.org/post… #foreigninterference #AdvancedPersistentThreatOperations #SpearPhishing #MalwareDistribution #MilitaryEspionage #CyberEspionage
58
The RAF has spent the last year quietly jamming Russian and Chinese satellites, and on September 26th Britain made it official: Number III Space Effects Squadron, a dedicated unit whose whole job is electronic counter-space warfare. Covert program, now institutionalized. The capability existed. Now it has a badge, a budget line, and a place in the RAF order of battle. That move from secret to public is, in some ways, the actual story. Covert operations give you deniability. Numbered squadrons give you deterrence. Britain chose deterrence, which means they've calculated that Moscow and Beijing already knew, or that being caught knowing is less useful than being seen acting. Probably both. The RAF doesn't stand up a formal unit and invite reporters to write about it because they're worried about operational security. They do it because they want adversaries to update their threat models. So the question worth sitting with is what that calculation implies about where space warfare is actually heading. Electronic warfare in orbit is already messier than the "reversible and non-debris-generating" framing suggests. Yes, jamming doesn't leave a debris field. But the effects aren't always tidy. Satellite jammers work across frequencies; collateral disruption of civilian or third-party systems is a real operational risk, not a theoretical one. GPS spoofing campaigns attributed to Russia have affected civilian aviation. Jamming operations targeting military communications satellites operate in spectrum neighborhoods where commercial and humanitarian satellite services live. The cleanliness of the method is real compared to a kinetic kill vehicle, but "cleaner than blowing something up" is a low bar, and the precedent being set is broader than the specific operations. What Britain is institutionalizing is the normalization of active electronic interference with adversary space assets as a standing military function. Not a crisis response. Not an emergency authority. A routine, permanent, staffed capability with career paths and doctrine and training pipelines. That's what a numbered squadron means. The RAF doesn't create numbered squadrons for one-off contingencies. Russia and China will respond to this, and not by backing down. Russia's counter-space program, including the Tirada-2 jamming satellites and the Luch/Olymp inspector satellites that have parked themselves uncomfortably close to Western communications birds, is already extensive. China has fielded ground-based jamming systems, developed co-orbital technologies, and fired an ASAT missile as far back as 2007. What Britain's announcement does is give both countries a fresh justification for capability expansion. Not that they needed one. But international signaling around military programs is partly theater, and Britain just gave Russia and China a prop for the next act of their own theater: "NATO is militarizing space, we are merely responding." That framing will play domestically in both countries and, more importantly, in multilateral forums where the absence of space arms control is starting to feel like a problem that someone, eventually, should address. Here's where the trajectory gets genuinely complicated. The specific mission referenced in the RAF's covert jamming program includes protecting the nuclear deterrent. That's the Trident submarine force, which relies on space-based communications for command and control. The inclusion of strategic nuclear communications as a priority mission for Number III Space Effects Squadron is not a minor detail. It means that if an adversary decides to target British space-based nuclear command links, the RAF now has an active, institutionalized counter-capability. That's stabilizing in one sense: it reduces the vulnerability of the deterrent to space-domain attacks. But it also means that any future crisis in which Russian or Chinese satellites are suspected of interfering with Trident communications could trigger a British electronic response that the adversary might not immediately understand as proportionate or limited. Escalation ladders in contested domains are only useful if both sides are climbing the same ladder. Space doesn't have agreed rungs. The Five Eyes dimension is worth watching specifically. Britain's move to formalize this capability in an RAF structure rather than a joint or intelligence-community unit is a choice with alliance implications. Intelligence-community capabilities are shared under different frameworks than military capabilities. A numbered RAF squadron operates under military command authorities, doctrine, and rules of engagement. If Australia, Canada, or New Zealand are sharing satellite infrastructure with Britain, and that infrastructure becomes part of an active electronic warfare mission set, those partners will need to decide whether they're inside this capability or adjacent to it. That's a political conversation several of those governments haven't fully had in public yet. For the United States, the interesting question is coordination. US Space Command has its own counter-space programs, and the US has been somewhat more cautious than Britain about public acknowledgment of offensive electronic space capabilities, partly because of the scale of US commercial satellite dependence and partly because of the arms control implications. Britain stepping publicly into this space slightly ahead of a formal US equivalent gives Washington a useful trial balloon. If the diplomatic blowback is manageable, that's useful information. If Moscow or Beijing decides to escalate in response to the British announcement, Washington will be watching the playbook. What defenders and officials should actually be tracking over the next twelve to eighteen months is not whether Britain's squadron conducts more jamming operations. They almost certainly will. The things worth tracking are: Whether Russia or China signals a doctrinal response to Britain's announcement through their own military publications, exercises, or capability demonstrations. Russia's military-strategic literature on space warfare is substantial and detailed. If Vozdushno-Kosmicheskiye Sily starts holding exercises that include scenarios involving electronic attack on British or NATO space assets, that's a doctrinal response, not just a capability response. Whether there are observable changes in the behavior of Russian inspector satellites near British or allied communications birds. The Luch/Olymp platform has already demonstrated a willingness to park close to Western satellites. In the post-Number III announcement environment, renewed proximity operations would be a clear signal. Whether the commercial satellite operators whose frequencies neighbor military jamming operations start reporting interference anomalies they weren't reporting before. This is the quietest and most underappreciated risk. Electronic warfare doesn't respect neat military/civilian spectrum boundaries the way doctrine pretends it does. And whether the UK government, having made this capability public, finds itself under pressure to articulate a legal framework for when and how Number III Squadron's capabilities can be used. Britain has a reasonably robust public law tradition around military operations, and eventually someone in Parliament is going to ask what the rules of engagement are for jamming a Chinese satellite over which Britain has no jurisdiction. That question is going to be uncomfortable, and the discomfort will be proportional to how public the capability becomes. The broader arc here is that 2026 is starting to look like the year that space domain warfare stopped being a background assumption and became a foreground fact. The United States established Space Command years ago. France stood up a space defense command in 2019. Japan has been expanding its space awareness capabilities under its Air Self-Defense Force. And now Britain has a numbered squadron with an active jamming record and a mandate that explicitly includes protecting the nuclear deterrent. The orbital environment is not going to become more stable because these units exist. Deterrence theory says it might become more predictable. Those are different things, and the space domain, without arms control frameworks, without agreed norms around what constitutes an act of war versus an act of interference, and without the decades of crisis management experience that stabilized nuclear competition eventually, is going to generate surprises. Number III Space Effects Squadron is a serious, professional military unit doing a real job. The RAF's institutional choices here reflect genuine capability, genuine threat assessment, and genuine strategic logic. That's not reassuring so much as it is clarifying. The serious work of the next several years isn't developing the capability. Britain just demonstrated that's tractable. The serious work is figuring out what rules, if any, should govern its use before a crisis makes that conversation much more urgent and much less deliberate. foreigninterference.org/post… #foreigninterference #CommunicationJamming #SatelliteNetworkAttack #SpaceDomainDeterrenceSignaling #OrbitalIntelligenceDeployment
1
103
Russia is running a stress test across NATO's eastern flank, and the grading curve keeps getting easier. Drones over Poland and Romania, arson at logistics nodes, airspace probes designed more to embarrass than destroy. Moldova gets the unfiltered version since it's not a member and Moscow knows it. Each incident that goes unanswered sets the new floor for what's considered acceptable. The DW analysis frames this as escalation. It's also just iteration. foreigninterference.org/post… #foreigninterference #InfrastructureAttacks #DroneSurveillance #IndustrialSabotage #MultiDomainWarfareCoordination #ThresholdCalibrationOperations
1
54
Eight Chinese vessels on September 25th. A mix of PLA Navy warships and coast guard ships, working in coordinated tandem, blocking a resupply run to a rusting ship that has been deliberately grounded on a reef since 1999. That's the situation at Ayungin Shoal right now, and if you've followed this particular file for any length of time, none of it is surprising. That's sort of the depressing part. The BRP Sierra Madre is the whole game here. The Philippines grounded it on Second Thomas Shoal decades ago specifically to establish a physical presence, and the small garrison living aboard it depends entirely on periodic resupply missions for food, water, and basic equipment. Manila calls these missions "routine humanitarian" resupply, which is accurate, and that framing is doing deliberate work: it puts Beijing in the position of blocking food and water from reaching Filipino servicemen, which is a harder thing to explain away diplomatically than "asserting sovereignty over a contested feature." The AFP knows what it's doing with that language. What's worth sitting with is the specific combination of assets Beijing deployed. Eight vessels, PLAN warships alongside China Coast Guard ships. This is not improvised. The grey-zone doctrine China has developed for the South China Sea is built around exactly this kind of combined deployment, and the logic is fairly straightforward once you understand what they're trying to accomplish. Coast guard vessels operate under a law-enforcement legal framing, not a military one. PLAN warships provide the actual coercive weight. Together, they maximize pressure while creating genuine ambiguity about whether any specific action crosses the threshold that would constitute an "armed attack" under the U.S.-Philippines Mutual Defense Treaty. That ambiguity is the product. It's not a side effect. The 2016 UNCLOS arbitral tribunal ruling is relevant background here. The Philippines won decisively on the legal merits. China rejected the ruling entirely and has continued to reject it, but Manila has kept building its evidentiary record anyway, and the AFP's decision to confirm this incident publicly rather than downplay it fits that pattern. Every documented incident is another data point for international audiences, for potential future legal proceedings, for allied governments deciding how to characterize Chinese behavior in their own policy statements. The transparency is a strategy, not a reflex. The timing of this incident is interesting and probably not coincidental. September 25th, 2026 puts this squarely in the middle of UN General Assembly week, which is about the highest-density diplomatic moment on the annual calendar. Every senior official from every major government is in New York, schedules are packed, attention is genuinely split across dozens of simultaneous crises and bilateral meetings. If you wanted to run an escalatory coercive operation and have it receive somewhat less sustained international focus than it otherwise might, that's a reasonable week to choose. Beijing has shown a consistent pattern of timing assertive moves in the South China Sea to coincide with periods of reduced international bandwidth, and this fits. There's a broader structural context that makes this particular moment more complicated than the baseline. The Xi-Trump summit and the current phase of U.S.-China diplomatic engagement have put Washington in a posture that is, at minimum, more focused on bilateral management with Beijing than on active confrontation. Whether that has created operational space for China to push harder at Ayungin Shoal without expecting a sharp American response is something analysts are going to debate, and honestly it's difficult to know from the outside. But the incentive structure isn't hard to read. If Beijing calculates that Washington's diplomatic investment in the relationship creates some deterrence against a forceful American reaction to South China Sea escalation, that calculation would encourage exactly what we're seeing. The Philippines' structural problem here is real and doesn't have a clean solution. Accepting interference and having resupply missions blocked normalizes it, and normalization eventually becomes de facto Chinese control over the shoal's supply lines, which functionally becomes control over the garrison, which functionally becomes control over the shoal. But escalating the response carries obvious risks of broader conflict that Manila cannot manage alone. The strategy Manila has settled on, at least publicly, is documentation and transparency, keeping allies informed, maintaining the physical presence as long as possible, and letting the evidentiary record accumulate. It's not a satisfying answer to a blockade, but it's a coherent one given the constraints. What Beijing is doing at Ayungin Shoal is not complicated in its strategic logic. It's expensive in terms of international reputation, which China has decided is an acceptable cost, and it is calibrated specifically to stay below the threshold that triggers a military response from the United States. That calibration has held for years. The question is whether the slow accumulation of pressure, mission by mission, eventually achieves the objective of making the Sierra Madre garrison unsustainable, without ever producing a single incident dramatic enough to force a definitive American response. That's the bet. Eight ships on September 25th is that bet, placed again. foreigninterference.org/post… #foreigninterference #MaritimePlatformWeaponization #MilitaryIntimidation #GreyZoneOperations #GreyZoneMaritimeCoercion
78
The Richardson Institute at Lancaster University has mapped out what repressive states are actually doing to dissidents living in Britain. The toolkit is broader than most people assume, and the UK's ability to counter it is thinner than it should be. Start with the surveillance layer. Commercial spyware, acquired through the global surveillance marketplace, lets a hostile state monitor a dissident's communications, location, and social network in real time without anyone setting foot in the country. No physical presence required. The targeting happens thousands of miles away and the target often has no idea. Then the legal layer. Vexatious defamation suits filed in UK courts. Interpol Red Notices weaponized against people who've committed no crime. Mutual legal assistance requests used as harassment tools dressed up as lawful cooperation. The genius of this approach is that it uses the UK's own legal infrastructure against the people the UK is nominally protecting. Litigation is expensive and exhausting even when you win. That's the point. Family coercion is quieter but often more effective. A dissident in Manchester has a mother in Tehran, a brother in Riyadh, a sister in Beijing. The threat doesn't need to arrive in Manchester. It arrives where the family is, and the dissident gets the message anyway. Threats of arrest, job loss, violence. The dissident self-censors. Or starts cooperating. The operation succeeds without anyone ever leaving the target country. Physical harassment on UK soil is delegated. Criminal networks. Community informants. Proxies who conduct surveillance, intimidation, or in the most serious cases, assault. The hostile state keeps distance. The proxy takes the risk. Attribution becomes difficult and prosecution harder. The social media angle is underappreciated. Coordinated mass reporting campaigns against dissident accounts, aimed at platform trust and safety teams, turn those platforms' own moderation systems into repression tools. A person gets suspended or removed. Their reach collapses. Their community loses contact with them. The platform never knows it was used this way, and even if it did, most platforms don't have good mechanisms for catching this pattern before the damage is done. The Richardson Institute is clear that these aren't separate phenomena. They converge. A target might be simultaneously under digital surveillance, facing a defamation suit, receiving reports that their family at home is being pressured, noticing unfamiliar cars outside their flat, and watching their social media accounts get reported into suspension. Each element feeds the others. The cumulative effect is isolation, exhaustion, and self-censorship. That outcome is the goal. What Lancaster documents in this research is that the UK's protective architecture was not built for this. Counterterrorism legislation was designed around different threat models. Espionage statutes weren't written with grey-zone harassment campaigns in mind. Police forces routinely treat individual incidents as isolated crimes rather than recognizing the coordinated state campaign behind them. A dissident reports being followed. It gets logged as a harassment complaint, not as a data point in a pattern of foreign state activity. The connection is never made. The states most active in this space in Western democracies, the broader literature consistent with the Lancaster research identifies China, Russia, Iran, Saudi Arabia, and Turkey, each have distinct operational signatures. Different target communities. Different preferred methods. Different risk tolerances. Iran is not operating the same way China is. Saudi Arabia's approach to silencing critics abroad has its own character. But the common thread is that all of them have concluded that conducting repression across borders is worth doing and, in the UK specifically, worth the risk. The Lancaster assessment makes that last point explicitly. The UK is a permissive operating environment. Legal proceedings here can be initiated and sustained with relative ease compared to some allied democracies. The diaspora communities from repressive states are large. The specialist police capacity to recognize and investigate transnational repression patterns is limited. The intelligence picture shared with forces on the ground is inadequate. For a hostile state running these operations, that's an attractive combination. The Richardson Institute's recommendations aren't complicated: dedicated transnational repression legislation, specialist police units, better intelligence sharing with allies who are tracking the same actors. Those are the minimum requirements, per the research. The gap between those minimums and what currently exists is the problem. This isn't an obscure academic concern. There are people living in British cities right now who are being actively targeted by foreign states using exactly this toolkit. Some of them have reported it. Some of them have been told it doesn't rise to an actionable threshold. The research Lancaster has produced is an attempt to force that gap into view. foreigninterference.org/post… #foreigninterference #TransnationalRepression #DigitalSurveillanceIntegration #LegalWeaponization #FamilyMemberCoercion #InterpolRedNoticeAbuse #JournalistSurveillance #CommercialSurveillanceInfrastructure
86
The Justice Department quietly told Congress that FISA wiretaps jumped sharply in 2011. Assistant AG Ronald Weich sent the letter. No press conference, no fanfare, just a note to Biden and congressional leaders confirming surveillance under terrorism and espionage authorities expanded considerably. The government monitors more, tells you less, and considers this normal. foreigninterference.org/post… #foreigninterference #CommunicationsInterception #MassSurveillanceOperations
47
The short version: OSI rolled up a spy ring in Japan in the mid-1980s that was simultaneously feeding stolen Air Force Technical Orders to both Soviet and Chinese intelligence. Same ring, two customers, one operation. That part got some attention at the time. What didn't get enough attention then, and still doesn't now, is what the structure of that operation was actually telling us about where things were heading. Start with the target material. Technical Orders aren't sexy. They don't have "TOP SECRET" stamped across them in the movies. But for a foreign military trying to understand how to kill or disable a U.S. aircraft, a TO is more useful than almost anything else you could steal. It tells you maintenance cycles, failure thresholds, what conditions degrade the system, what a ground crew has to do before a mission. You can't derive that from satellite imagery. You can't get it from watching a plane land. You need someone on the inside with access to the paperwork, and that's exactly what this ring provided. Both Moscow and Beijing got a detailed look at U.S. Air Force operational vulnerabilities at forward bases in the Pacific. That's not a minor collection win. That's the kind of material that shapes war planning. Now the part that should have reset some assumptions. In the mid-1980s, the official U.S. counterintelligence framework still treated the Soviet Union and China as largely separate threat actors. The Sino-Soviet split had been a defining feature of communist geopolitics since the early 1960s, and even as Gorbachev and Deng were moving toward cautious normalization, the assumption in most CI assessments was that competition between Moscow and Beijing limited their willingness to cooperate against Western targets. The Japan ring punched a hole in that assumption. Two intelligence services with real bilateral grievances, operating in the same country against the same target, sharing a source network. That's coordination. Maybe not formal, maybe not a signed agreement, but functional coordination on the collection side regardless of what was happening diplomatically. U.S. counterintelligence was slow to update the model. The NCIX reports from the 2000s onward would eventually document what by then was an obvious pattern of parallel Chinese and Russian collection against defense and commercial targets, sometimes complementary, sometimes competitive, but consistently harder to counter because the two-threat framework kept analysts working the problems in separate lanes. The Japan case was an early data point that could have accelerated that update. It didn't, at least not publicly. So where does this trajectory go, and where is it right now. The dual-principal model the Japan ring demonstrated has gotten more sophisticated, not less. The human recruitment piece is the same: identify cleared personnel in environments where they're socially accessible, cultivate over time, exploit financial or personal pressure points, run the asset until detection forces a halt. Japan was and remains a textbook environment for that, which is why counterintelligence pressure at Misawa, Yokota, and Kadena has never really let up. What's changed is the collection pipeline. In 1987, stealing TOs meant physically copying documents. The tradecraft burden was real. Now the same category of technical documentation, the operational procedures, the maintenance manuals, the system parameters, lives in networked environments. A recruited insider doesn't need to photograph pages anymore. And an adversary service doesn't necessarily need a recruited insider at all if the network access is there. China's military modernization program since the 1990s has been explicitly built around closing capability gaps with the United States, and the fastest way to close a capability gap is to know exactly where the gap's edges are. Technical Orders and their digital equivalents tell you that. The People's Liberation Army doesn't need to figure out from first principles how a U.S. weapons system degrades under stress if someone already stole the maintenance documentation. That's years of development time, maybe decades, handed over for the cost of running a source. The economics of human intelligence against technical targets have always been brutal, and they haven't improved for the defending side. The Russia piece is different now but not irrelevant. Russian military intelligence has never stopped targeting U.S. forward deployments in Europe and Asia. The methods have shifted more toward cyber-enabled operations, signals collection, and information operations around base communities than the classic HUMINT recruitment model, but the appetite for U.S. technical operational data hasn't changed. What the Japan case illustrated was that Moscow was willing to share collection products with Beijing when interests aligned. The question worth asking is whether that calculus has shifted in the current environment, where Russian and Chinese strategic interests are more visibly aligned than at any point since the early 1950s. If it has shifted, and there's reason to think it has, then the dual-principal model from Japan isn't a Cold War artifact. It's a preview of a problem that's gotten larger. For people watching installations in the Pacific specifically: Japan is still the sharpest edge of this. U.S. force posture in Japan has expanded significantly in the last several years, with new defense cooperation agreements, expanded basing arrangements, and a much larger footprint of advanced systems. Kadena hosts F-15s that are being replaced by F-22s. Misawa flies F-16s in a signals-rich environment near Russian territory. Yokota runs airlift and command functions that any adversary planner would want mapped. The cleared population at these bases operates in a country with a very open social environment, significant Chinese and Russian intelligence presence, and a history of effective recruitment operations. OSI and the Defense Counterintelligence and Security Agency have gotten more aggressive about publicizing insider threat cases in recent years, partly to deter, partly to signal awareness. But the structural vulnerability the Japan ring exploited hasn't been engineered away. Personnel with access to sensitive technical documentation still live and work in environments where foreign intelligence services have persistent presence and proven recruitment tradecraft. What officials and base commanders should be watching: not just the classic financial-stress-and-recruitment pattern, but the social engineering approaches that don't look like recruitment at first. Cultivated personal relationships, professional networking that crosses into classified areas, requests for information framed as innocent curiosity. The Japan ring almost certainly didn't start with someone walking up to an airman and asking for TO documents. It started somewhere that looked a lot less like espionage. The 1987 case is worth revisiting not because it's history but because the pattern it documented is the template. Dual adversaries, technical targets, human access, forward base environment. OSI stopped that one. The conditions that made it possible are still there. foreigninterference.org/post… #foreigninterference #MilitaryEspionage #AssetRecruitment #PhysicalTheft #CounterintelligenceOperations #CrossBorderIntelligenceOperations
127
The U.S. had a working counter-disinformation architecture in 1987. Then it disbanded it. A July 18, 1987 State Department cable, now declassified through FRUS, coordinated messaging across every African diplomatic post to push back on Soviet active measures, including the Operation Denver AIDS fabrication. Field posts got a point-by-point brief on Soviet disinformation tactics. Standardized. Coordinated. Operational. The Active Measures Working Group was dissolved after the Cold War. Russia came back in 2014. The institutional muscle wasn't there anymore. foreigninterference.org/post… #foreigninterference #DisinformationCampaigns #ColdWarDisinformationHistoricalFramework #CounterDisinformationFrameworkDevelopment #InfluenceOperations #StateMediaCoordination
1
2
2
109
Dov Levin spent years building a dataset that should permanently retire one of the laziest arguments in foreign interference debates: that what Russia did in 2016 was historically unique. It wasn't. The dataset, covering 1946 to 2000, documents foreign electoral interventions across 54 years of the postwar period, and the picture it paints is not flattering to anyone, the United States included. War on the Rocks ran an analysis of this dataset, and the core finding is blunt: in many cases, foreign meddling has had major, measurable effects on election results. Not alleged effects. Documented, quantifiable effects. That's a significant claim because it moves the conversation out of the realm of vibes and op-eds and into evidence. It also raises an uncomfortable follow-up question that most people would rather skip: if this has been going on continuously since 1946, why does every new election cycle get treated like the first time anyone has ever tried this? The short answer is that it's politically convenient to treat each episode as unprecedented. It allows governments to express outrage without having to explain what they were doing during the last several decades. The longer answer is that the historical record is genuinely complicated, and the complications are worth sitting with. The biggest actor in the dataset for most of its 54-year span is the United States. The Soviet Union is a close second. During the Cold War, both superpowers treated other countries' elections as operational terrain. The methods were consistent across both sides: covert funding of preferred candidates, propaganda targeting electoral opinion, material support for allied political parties, and in harder cases, direct pressure on electoral institutions and actors. The Americans did it in Italy, in Chile, in the Philippines, in Nicaragua, in multiple places across Latin America and Southeast Asia. The Soviets did it in Western Europe, pushing money and influence into left-wing parties across France, Italy, and elsewhere. Neither side was shy about it. They just disagreed on which interventions counted as legitimate support for freedom and which counted as subversion. That's the definitional problem that the Russia Matters companion analysis flags, and it's a real one. There's a meaningful difference between a foreign government manufacturing divisions in a target country's electorate from scratch and a foreign government exploiting divisions that already exist and are entirely homegrown. The first is closer to pure destabilization. The second is closer to what every major power has always done: find the fault lines, pour something in, and wait. The Russia Matters framing calls the second category "bare-knuckled domestic bargaining," which is a politely euphemistic phrase for something that is still corrosive and still deliberate, but the distinction matters for how you build a response. If you're trying to counter a foreign operation that depends entirely on amplifying real grievances held by real voters, you can't solve that by going after the foreign amplifier alone. The grievances stay. The year 2000 is where the dataset ends, and the timing is significant for a reason that has nothing to do with what happened in the United States that November. By 2000, the foundational playbook was already 54 years old and well-established. What was also emerging in 2000, just barely, was the internet infrastructure that would eventually transform the operational environment completely. The methods documented across the dataset, covert financing, propaganda, party support, coercion, all of them remained functional in 2000. They still are. But the digital layer added by the subsequent two decades dramatically lowered the cost of some operations, dramatically increased the speed of others, and opened targeting possibilities that didn't exist when the CIA was running cash to Italian Christian Democrats in the late 1940s. One thing the historical record makes clear is that foreign interference is not primarily a technology problem. It's a structural one. The Campaign Legal Center's work on structural vulnerabilities gets at this. The specific gaps that foreign actors have exploited over the decades are not exotic or hard to identify. They include the difficulty of tracing the actual source of political money through layered financial structures, the absence of disclosure requirements for many categories of foreign-funded political activity, and the enforcement gap between what existing law requires on paper and what agencies actually have the capacity to investigate and prosecute. The Foreign Agents Registration Act has existed since 1938. It has historically been enforced with the vigor of a parking ordinance. These gaps didn't appear suddenly when social media became a thing. They've been present for most of the period the dataset covers. What changes over time is which gaps are most useful to which actors given available technology and the specific political conditions of the target country. The War on the Rocks analysis doesn't just describe the historical pattern. It draws recommendations from it, and the recommendations are sensible if not exactly novel: strengthen transparency requirements for foreign-origin political financing, build deterrence frameworks that impose real costs on interfering states, invest in public media literacy to make disinformation operations less effective, create coordination mechanisms among democracies to share intelligence on active operations, and maintain proportionality in responses so that the counter-interference framework doesn't end up validating authoritarian arguments that any foreign political communication is itself interference. That last point is worth pausing on. One of the consistent moves by governments with weak democratic credentials is to use genuine foreign interference concerns as cover for restricting any outside criticism of their governance. Russia has done this. China has done this. Hungary is doing a version of it. If democratic governments define "foreign interference" so broadly that it encompasses legitimate human rights reporting, political commentary, or diaspora political activity, they hand that argument to exactly the people who want to use it most destructively. The historical dataset is useful here too: the 54-year record shows a range of interventions, and the most destabilizing ones are generally covert, involve material resources, and are specifically designed to manipulate electoral outcomes. That's different from Radio Free Europe, even if authoritarian governments insist otherwise. The broader argument the analysis is making, the one that the historical record actually supports, is that foreign electoral interference is a persistent structural feature of the international system, not an anomaly and not a crisis that appeared from nowhere in 2014 or 2016. States that manage it best are the ones that have built durable institutional defenses, maintained transparency requirements with real enforcement, and developed some societal resilience to manipulation campaigns. States that manage it worst tend to combine weak institutions with high internal polarization, which is a combination that makes interference cheap and effective because the foreign actor barely has to do anything. They just have to find the match and drop it near the fuel. The British ran influence operations targeting American opinion during the 1940 presidential election, trying to pull the United States out of isolationism. That's in the historical record. It worked, to a degree. It's also the kind of case that makes simple narratives about foreign interference hard to sustain, because the people running that operation believed, not without reason, that American isolationism was going to enable a Nazi victory in Europe. The ethics of foreign interference get complicated fast when you look at specific cases rather than the abstract principle. The dataset isn't an ethics text. It's a record of what actually happened and what effects it had. The policy question of what democratic states should do about it is genuinely hard and the historical record suggests nobody has fully solved it. What the record does suggest is that the states that have maintained the most durable democratic institutions are the ones that treated this as an ongoing management problem rather than a series of discrete crises to be outraged about and then forgotten. The outrage cycle is not a defense. It produces headlines and hearings and occasionally some targeted sanctions, and then the next cycle starts. The dataset covers 54 years. The problem it documents didn't go away at any point in those 54 years. It adapted. foreigninterference.org/post… #foreigninterference #ElectionInterference #DisinformationCampaigns #CampaignFinanceViolations #InfluenceOperations #CovertMediaFunding #LegislativeGapAssessment #CounterDisinformationFrameworkDevelopment
66
The Friedrich Naumann Foundation's transnational repression study, read alongside the European Parliament's incident dataset, tells you where this is going more clearly than any threat assessment I've seen lately. The headline number is 33 Russia-attributed incidents inside EU territory. Highest of any single origin state. That's not a spike. That's a floor. Here's what the trajectory actually looks like. The operational mix is shifting. Assassination and radiological poisoning are loud. They generate headlines, diplomatic expulsions, public outrage. They're expensive in that sense. What the dataset shows, underneath those high-profile cases, is a much larger volume of lower-signature activity: stalking, digital surveillance, harassment, coercion. These methods are harder to attribute, harder to prosecute, and harder to cover because they happen to people who aren't famous. The actors running these operations have noticed that the quieter end of the spectrum carries lower cost and comparable effect. Expect the mix to keep moving in that direction. China's model is worth watching closely, because it's the most systematized. Six continents. Uyghur, Tibetan, Hong Kong, Falun Gong, and political dissident communities all targeted through what the Foundation correctly identifies as an integrated system: surveillance, family coercion back in-country, and legal weaponization through Interpol notices and bilateral extradition pressure. The integration is the point. You don't need to physically reach someone in Berlin or Toronto if you can threaten their mother in Xinjiang. The coercive surface area is enormous and most of it is invisible to Western law enforcement. Iran is running a version of this too, adapted to its specific exile opposition landscape. The recruitment of diaspora members as informants is particularly corrosive because it means these communities can't fully trust their own networks. That's not incidental. It's the goal. A fractured, mutually suspicious exile community is less able to organize, advocate, or communicate effectively with journalists and policymakers. The repression doesn't have to succeed at silencing any particular person. It just has to make collective action expensive and uncertain. The FBI's Dallas field office awareness campaign reflects something real about where U.S. authorities are in this. The framework they've published is accurate and useful. It's also downstream of a fundamental evidentiary problem: state-directed operations are deliberately structured to look like individual actions. The handler is in Moscow or Tehran or Beijing. The person doing the stalking or the harassment is local, possibly a community member, possibly someone with their own grievances being exploited. Prosecution requires threading that chain, and the international dimensions of these cases create jurisdictional friction that state actors deliberately exploit. The civil society monitoring layer, organizations like World Without Genocide doing incident documentation through diaspora outreach, is capturing things that official reporting misses. Not because government intelligence is bad, but because significant portions of these communities don't trust law enforcement. Some of that distrust is about their experiences in the countries they fled. Some of it is rational calculation: reporting to the FBI might be visible to the regime they're fleeing, and visibility creates risk for family members still at home. This is a structural problem. You can run awareness campaigns, but if the reporting mechanism itself feels like a threat, the data stays underground. What the Foundation's framework makes clear, and what the incident dataset confirms, is that transnational repression is not a collection of discrete events. It functions as a system. The assassination of a high-profile dissident and the low-level harassment of a community organizer in a mid-sized European city are part of the same coercive architecture. The former sets the ceiling. The latter does the day-to-day work of suppression at scale. For EU officials specifically: 33 incidents on your territory attributed to a single state is a policy failure as much as an intelligence challenge. The European Parliament study is doing the documentation. The question is what the member states are doing with it. Diplomatic cost-imposition for these operations has been inconsistent. Some expulsions, some sanctions, significant variation by country depending on bilateral economic relationships. That inconsistency is itself an input into the operational calculus of the actors running these programs. For diaspora communities: the FBI's indicators are real. Stalking, digital intrusion, coercion to return, recruitment of community members as informants. Document everything. The civil society organizations doing this work are your best option for incident reporting if official channels feel compromised or unsafe. For journalists covering this: the gap between high-profile incidents and the documented volume of lower-signature activity is a story. The people being stalked and harassed are not Alexei Navalny. They're Uyghur community organizers in Munich, Belarusian activists in Warsaw, Iranian journalists in London. The methodology is the same. The coverage is not. Belarus, Venezuela, and Cuba are running smaller-scale versions of this, documented in the same study. Smaller scale doesn't mean low consequence for the people targeted. And smaller states running these programs is a diffusion signal. The model is spreading because it works and because the costs of running it remain low relative to the benefits of silenced exile communities. The trajectory: more operations, quieter methods, more integration of family coercion with digital surveillance, continued exploitation of the evidentiary gap between what intelligence services know and what prosecutors can prove. The incidents in the dataset are not the whole picture. They're the visible fraction. foreigninterference.org/post… #foreigninterference #TransnationalRepression #DiasporaSurveillance #CrossBorderIntimidation #CoordinatedCyberharassment #JournalistSurveillance #FamilyMemberCoercion #CrossBorderRendition #RadiologicalAssassination
75
450 to 700 percent. That's the projected increase in AI disinformation campaigns targeting UK and European information environments by 2026, according to a ResearchAndMarkets threat assessment reported through Business Wire in late 2025. For context, the same analytical framework projects 350 to 550 percent for South America and the Caribbean. Europe is at the top of the curve globally. That gap isn't random. Europe has structural vulnerabilities that make it a high-value target and a difficult defensive environment simultaneously. Start with elections. Europe runs an almost continuous cycle of them. National votes, European Parliament elections, subnational contests. There's rarely a quiet period in the targeting calendar. AI-driven influence operations don't need to be retooled for each cycle; they scale. One infrastructure, many elections. Then there's the language problem. Europe operates across dozens of languages. Detection infrastructure, counter-narrative capacity, and media literacy tooling are substantially more developed in English than in Estonian, Slovak, or Maltese. Campaigns pushed in lower-resourced language environments face less friction. They spread further before anyone catches them. That asymmetry is a feature for adversaries, not a bug. The third factor is the one that gets underappreciated in coverage that focuses on AI as the main story. Russia's information manipulation infrastructure in Europe isn't new. RT and Sputnik operated for years before being sanctioned. Doppelganger-style networks, the ones that cloned legitimate European news domains to push pro-Kremlin narratives, were already running at scale before AI tools matured. Social media bot farms were already seeded. What AI does to that existing infrastructure isn't create it. It enhances it. The operational cost of generating convincing, high-volume, multilingual disinformation content drops dramatically. The reach extends. The human labor bottleneck gets removed. The EU sanctioned Xenia Fedorova for information manipulation activities in the same September 2026 reporting window this assessment covers. That's a concrete data point, not background color. State-sponsored actors with existing infrastructure and documented operations are the ones positioned to layer AI capabilities on top of what's already running. The UK situation is its own specific problem. Post-Brexit, the UK is outside EU regulatory frameworks and outside coordinated EU counter-disinformation mechanisms. But it's not outside the European information environment. British audiences consume European content, British politics gets covered by European outlets, and British social media ecosystems are fully integrated with the broader European digital space. The governance gap is real. The UK can be targeted with the same campaigns saturating the EU information environment without being inside the EU structures designed to respond to them. Prime Minister Burnham's announcement of the National Centre for Information Defence is a direct institutional response to exactly this exposure. Whether it's adequate is a different question. Building defensive architecture on the timelines available before a 450 to 700 percent escalation peaks is a genuine challenge. The surge doesn't wait for institutions to mature. On the "qualitative shift" point the assessment makes: this is worth sitting with. The fact-checking ecosystem, the media literacy programs, the platform moderation infrastructure, the counter-narrative organizations, all of that developed in response to the first generation of state-sponsored disinformation. That first generation was already straining those defenses. AI disinformation at 450 to 700 percent of current volume isn't just more of the same problem. At sufficient scale, it can run faster than correction cycles. It can fragment information environments into incompatible realities faster than consensus-building mechanisms can operate. The volume itself becomes a weapon, independent of whether any individual piece of disinformation is believed. ENISA's concurrent reporting on European technology backbone threats adds another layer. The cyber infrastructure dimension and the disinformation dimension aren't separate threat tracks. They interact. Compromised infrastructure can amplify disinformation distribution. Disinformation can degrade public trust in institutions needed to respond to infrastructure threats. Treating them as parallel but separate problems probably understates the combined exposure. The number to hold onto here is 700. The upper bound of the projection. If the actual trajectory tracks toward the high end, European democratic information environments will be under a level of coordinated AI-generated pressure with no real historical precedent to draw on for guidance. foreigninterference.org/post… #foreigninterference #DisinformationCampaigns #ComputationalPropaganda #AIProfileGeneration #ForeignInformationManipulation #InfluenceOperations
1
1
63
Russia lit up Poland's eastern flank and torched a Starlink relay station in the same week it held sham parliamentary elections in occupied Ukraine. Warsaw called the air defence boost what it is: a response to provocations, not a precaution. The Starlink fire was officially labeled sabotage. Denmark issued its own infrastructure warnings. Moscow gets to call all of it a reaction to Ukrainian strikes on Russian soil, which is the point. foreigninterference.org/post… #foreigninterference #InfrastructureAttacks #PhysicalInfrastructureTampering #IndustrialSabotage #MilitaryIntimidation #ThresholdCalibrationOperations
47