Guide

Attribution discipline

Spotting a pattern is the easy part. Saying who is behind it is the hardest question in influence-operations analysis, because almost everything an outsider can see — the words, the hashtags, the timing, the language mistakes — is also the cheapest thing for an operator to copy or fake, and is equally consistent with sincere people who happen to agree with one another. Professionals treat attribution as a matter of degree. They separate what was observed from who is responsible, they grade their confidence in stated terms, and they routinely publish findings that describe a network without naming a sponsor. This page explains the kinds of evidence involved, what each can and cannot carry, how confidence is expressed, how attribution has gone wrong, and how attribution claims are themselves used as a tactic. The aim is modest: that someone who has learned to recognize coordination does not become a confident amateur accusing strangers of being bots.

The ladder of evidence

1

Content cues

What the posts say and how: narratives, slogans, memes, language errors, spelling conventions, topics that serve some party's interests.

Can support: A description of which narratives are circulating and a hypothesis worth investigating.

Cannot support: Any identification of an actor. Narratives are shared by sincere believers, language quirks can be imitated or belong to a diaspora, and who-benefits is motive, not evidence.

2

Behavioral signals

How accounts act: batch creation dates, synchronized posting, identical text, personas that only amplify one another, reused profile photos.

Can support: A finding that activity is coordinated and possibly inauthentic, stated about the network as a whole.

Cannot support: Who is coordinating. Campaign volunteers, fan communities, marketing firms, and state units can produce similar signatures. It also cannot establish that any one named account is fake.

3

Technical infrastructure

Domains, hosting, registration records, analytics and advertising identifiers, malware code and tooling, reuse of servers across campaigns.

Can support: Links between assets, and between a new operation and a previously documented one.

Cannot support: Sponsorship on its own. Infrastructure can be rented, shared, stolen, or deliberately planted, as the Olympic Destroyer case showed.

4

Platform-side data

Information only the platform holds: login IP addresses, device fingerprints, phone numbers and emails used at registration, payment records, internal links between accounts.

Can support: Attribution to specific operators or organizations, which is why platform takedown reports can name a firm or an agency where outside researchers cannot.

Cannot support: Independent checking by the public. Outsiders must trust the platform's summary, and the data may identify a contractor without revealing the client.

5

Human and intelligence sources

Insiders, defectors, leaked internal documents, signals intelligence, and other government collection.

Can support: Intent, tasking, and chain of command — the question of who ordered it.

Cannot support: Public verification. Sources and methods are usually withheld, so the reader gets a conclusion and a confidence level and must weigh the track record of the body making it.

6

Legal process

Indictments, sanctions designations, court filings, and parliamentary or congressional inquiries with subpoena power.

Can support: Named individuals and units with specific, dated, testable allegations, often backed by records obtained under legal compulsion.

Cannot support: Certainty. An indictment is an allegation until tried, and many defendants in these cases will never appear in court. Charging decisions can also be shaped by diplomacy.

How professionals word their confidence

U.S. intelligence analysis is governed by Intelligence Community Directive 203, which requires products to express uncertainty and to keep two things apart: how likely a judgment is, and how confident the analysts are in the basis for it. The January 2017 assessment of Russian activity in the 2016 election is a public example: it states most judgments with high confidence and notes where one agency held only moderate confidence. Its annex explains that high confidence still does not mean fact or certainty.

High confidence:
The judgment rests on high-quality information from multiple sources. It can still be wrong.
Moderate confidence:
The information is credibly sourced and plausible but not corroborated enough, or not of sufficient quality, for a higher level.
Low confidence:
The information is scant, questionable, or fragmented, and solid inferences are difficult.
We assess / we judge:
Signals an analytic inference, not a statement of directly observed fact.
Almost certainly, likely, unlikely:
Likelihood terms. ICD 203 maps these to probability ranges and says they should not be blended with confidence levels in the same sentence.
ODNI, Intelligence Community Directive 203: Analytic Standards (2015), copy hosted by the Federation of American Scientists

The public example of those standards in use is the declassified Intelligence Community Assessment of January 2017. It is worth reading for its wording alone: judgments are graded, a difference between agencies is disclosed, and the document states that it did not assess the impact of Russian activity on the election outcome.

CIA and FBI have high confidence; NSA has moderate confidence:
A disclosed disagreement about how strong the basis was for one judgment. Professional products show such differences instead of averaging them away.
Did not make an assessment of the impact:
An explicit limit on the claim. Attribution of activity is not a finding about effect.
ODNI, Assessing Russian Activities and Intentions in Recent US Elections, ICA 2017-01D (January 6, 2017)

Meta's takedown reports use a deliberately narrow vocabulary. The company attributes to the entity its own data can support and stops there. Its 2021 review of influence operations explains that it names the operator it can prove, which is sometimes a marketing firm, and does not speculate about clients or governments behind that operator.

We found links to individuals associated with...:
Platform data connects the network to specific people or an organization. It is a claim about operators, not necessarily about who directed or paid them.
Originated in [country]:
A statement about where the operators were located. It is not a statement that the country's government was responsible.
Attempted to conceal their identities and coordination:
Describes the violation (coordinated inauthentic behavior). It is about conduct, and the content may have been true.
We could not determine who was behind it:
A legitimate and common finding.
Meta, Threat Report: The State of Influence Operations 2017-2020 (May 2021)

Private threat-intelligence firms borrow the intelligence community's grading. Mandiant's reporting on the Ghostwriter campaign shows how an assessment moves as evidence accumulates: first described in 2020 only as aligned with Russian security interests, then in 2021 tied with high confidence to an intrusion group linked to Belarus, with moderate confidence that Belarus was at least partly responsible for the campaign, and an explicit note that Russian contributions could not be ruled out.

Assess with moderate confidence:
The firm believes the judgment is more likely right than wrong on credible evidence, and is telling you it may be revised.
Aligned with the interests of:
A statement about content and targeting only. It is not attribution.
UNC (uncategorized) group:
A cluster of activity tracked under a neutral label because the firm is not ready to merge it with a named actor.
Cannot rule out:
An alternative explanation that was considered and remains open.
Mandiant, UNC1151 Assessed with High Confidence to have Links to Belarus, Ghostwriter Campaign Aligned with Belarusian Government Interests (November 2021)

Getting it wrong

British Twitter users reported as Russian bots

2018

After the Salisbury poisoning and strikes on Syria, UK government sources briefed that Russian bot activity had surged, and two accounts critical of government policy were named in the press as examples. Both belonged to real people; one, a British man, went on live television to say so. Channel 4 FactCheck reported that government sources later accepted the accounts were not bots.

Lesson: High posting volume and an unwelcome viewpoint are not evidence of automation or foreign control. Naming individual accounts on behavioral evidence put real people in national headlines.

Channel 4 News FactCheck, How Twitter users were wrongly labelled as Russian bots after a government briefing

Hamilton 68 and the hashtags called Russian

2017–2023

The Alliance for Securing Democracy launched a dashboard showing what roughly 600 undisclosed Twitter accounts were discussing. Its methodology said the list mixed openly pro-Russian users, accounts that amplified attributed Russian media, and automated accounts, and that the method described the aggregate network, not individuals. News coverage nonetheless cited it to call hashtags popular with American conservatives Russian-driven. In 2023, internal Twitter emails published by Matt Taibbi showed the company's trust and safety head had concluded the listed accounts were mostly ordinary users. ASD responded that it had repeatedly cautioned against describing the accounts as Russian bots.

Lesson: A secret list cannot be checked, and caveats in a methodology paper do not travel with a live number. Both the builder's framing and the press's use of it carry responsibility. Read the inclusion rule before trusting any tracker.

German Marshall Fund, The Methodology of the Hamilton 68 Dashboard (ASD's own description of the tool)

Olympic Destroyer: three countries blamed in two weeks

2018

Malware disrupted the opening ceremony of the Pyeongchang Winter Olympics. Within days, different security firms pointed to North Korea, China, and Russia. Kaspersky then showed that a file header matching North Korea's Lazarus group had been forged to mislead analysts. In October 2020 the U.S. Justice Department indicted officers of Russia's GRU.

Lesson: Operators know which indicators analysts rely on and can plant them. A tidy match found quickly is a reason for more checking. The firm attribution took more than two years and legal process.

Kaspersky Securelist, OlympicDestroyer is here to trick the industry (March 2018)

Crowdsourced identification after the Boston Marathon bombing

2013

Users on Reddit and Twitter compared photographs and named a missing university student as a suspect; the name was repeated by journalists. He had no connection to the attack; he had been missing for a month and was later found dead. Reddit's general manager publicly apologized to his family.

Lesson: This was not an influence-operations case, but it is the clearest demonstration of what happens when enthusiastic pattern-matching by non-professionals ends in a public accusation against a named person.

NPR, Social Media's Rush To Judgment In The Boston Bombings (April 23, 2013)

Bot counts built on a classifier that mislabels humans

2020

Many academic and news estimates of bot prevalence relied on the Botometer tool. Rauchfleisch and Kaiser tested it against accounts whose nature was known, including sitting members of parliament, and found that scores drifted over time and that even conservative thresholds labelled many real people as bots, especially outside English. The tool's developers say it was not intended for verdicts on individual accounts.

Lesson: A score is a probability about a population. Percent-of-accounts-are-bots headlines, from any political direction, should be read with the false positive rate in mind, and a score should never be used to accuse a person.

Rauchfleisch & Kaiser, The False positive problem of automatic bot detection in social science research, PLOS ONE (2020)

A counter-example: Secondary Infektion, published without a named sponsor

2020

Graphika documented more than 2,500 pieces of forged and planted content posted over six years in seven languages on over 300 platforms. The investigators described the operation as run from Russia and said plainly that they could not identify the entity responsible.

Lesson: Stopping where the evidence stops is a complete and respectable result. A detailed description of behavior is more useful to the public than a confident guess at a name.

Graphika, Exposing Secondary Infektion (June 2020)

Attribution as a tactic

A write-up template

The structure analysts use so that a reader can see what was observed, what was inferred, and how sure the author is. Fill every section, including the last one.

  1. 1. Scope and collection method
    What did you look at, over what dates, gathered how? What did you not look at? State any tool used and its known error rate. A reader should be able to repeat your collection.
  2. 2. What was observed
    Describe the activity in neutral terms with counts and examples: how many accounts, what they posted, when. No adjectives about intent and no actor names in this section.
  3. 3. Actors, behavior, content (ABC)
    Following Camille François's framework, say separately what you know about the content (narratives), the behavior (coordination signals), and the actors (usually: nothing verifiable from public data). Leave a heading blank instead of filling it with inference.
  4. 4. Alternative explanations considered
    List at least three: genuine grassroots enthusiasm, an organized but disclosed campaign, a commercial firm, a different state, a false flag, an artifact of your own collection method. For each, say what you would expect to see and whether you saw it.
  5. 5. Confidence and why
    Give a level (low, moderate, high) for each judgment separately — that coordination exists, that it is inauthentic, that a given party is responsible — and name the evidence rung each rests on. Public data alone rarely justifies more than low confidence on the last.
  6. 6. What would change the assessment
    Name the specific evidence that would raise or lower your confidence, such as a platform disclosure, registration records, or accounts turning out to belong to identifiable real people.
  7. 7. What is NOT claimed
    Write this out explicitly: that no individual account is asserted to be fake, that no sponsor is identified unless stated above, that no effect on opinion or outcomes has been measured, and that alignment with a party's interests is not evidence of its involvement.

Rules for the rest of us

  • Never name an individual account publicly as a bot, troll, or agent on behavioral evidence alone. If you are wrong, a real person pays for it; if you are right, you have taught the operator what to fix.
  • Describe patterns, not perpetrators. It is fine to say that forty accounts created in the same week are posting identical text. It is not fine to say whose accounts they are.
  • Report to the platform or to an established research group instead of posting an accusation. They hold the data that can settle the question, and you do not.
  • Answer the argument regardless of who made it. If a claim is false, show that it is false; the identity of the poster is not a rebuttal.
  • Treat disagreement, high volume, poor English, numeric handles, and missing profile photos as what they usually are: ordinary people.
  • Carry the hedges with you. When you repeat someone else's attribution, repeat their confidence level and their caveats, and link to the original instead of a summary of it.
  • Apply the same standard to claims that flatter your side. If you would not accept this evidence for an accusation against your own allies, do not accept it against opponents.
  • Be willing to say you do not know. Professionals publish that conclusion regularly, and it is almost always the accurate one from the outside.
Last reviewed See also the Coordination Analyzer and the operation anatomies.