Attribution discipline
Spotting a pattern is the easy part. Saying who is behind it is the hardest question in influence-operations analysis, because almost everything an outsider can see — the words, the hashtags, the timing, the language mistakes — is also the cheapest thing for an operator to copy or fake, and is equally consistent with sincere people who happen to agree with one another. Professionals treat attribution as a matter of degree. They separate what was observed from who is responsible, they grade their confidence in stated terms, and they routinely publish findings that describe a network without naming a sponsor. This page explains the kinds of evidence involved, what each can and cannot carry, how confidence is expressed, how attribution has gone wrong, and how attribution claims are themselves used as a tactic. The aim is modest: that someone who has learned to recognize coordination does not become a confident amateur accusing strangers of being bots.
The ladder of evidence
Content cues
What the posts say and how: narratives, slogans, memes, language errors, spelling conventions, topics that serve some party's interests.
Can support: A description of which narratives are circulating and a hypothesis worth investigating.
Cannot support: Any identification of an actor. Narratives are shared by sincere believers, language quirks can be imitated or belong to a diaspora, and who-benefits is motive, not evidence.
Behavioral signals
How accounts act: batch creation dates, synchronized posting, identical text, personas that only amplify one another, reused profile photos.
Can support: A finding that activity is coordinated and possibly inauthentic, stated about the network as a whole.
Cannot support: Who is coordinating. Campaign volunteers, fan communities, marketing firms, and state units can produce similar signatures. It also cannot establish that any one named account is fake.
Technical infrastructure
Domains, hosting, registration records, analytics and advertising identifiers, malware code and tooling, reuse of servers across campaigns.
Can support: Links between assets, and between a new operation and a previously documented one.
Cannot support: Sponsorship on its own. Infrastructure can be rented, shared, stolen, or deliberately planted, as the Olympic Destroyer case showed.
Platform-side data
Information only the platform holds: login IP addresses, device fingerprints, phone numbers and emails used at registration, payment records, internal links between accounts.
Can support: Attribution to specific operators or organizations, which is why platform takedown reports can name a firm or an agency where outside researchers cannot.
Cannot support: Independent checking by the public. Outsiders must trust the platform's summary, and the data may identify a contractor without revealing the client.
Human and intelligence sources
Insiders, defectors, leaked internal documents, signals intelligence, and other government collection.
Can support: Intent, tasking, and chain of command — the question of who ordered it.
Cannot support: Public verification. Sources and methods are usually withheld, so the reader gets a conclusion and a confidence level and must weigh the track record of the body making it.
Legal process
Indictments, sanctions designations, court filings, and parliamentary or congressional inquiries with subpoena power.
Can support: Named individuals and units with specific, dated, testable allegations, often backed by records obtained under legal compulsion.
Cannot support: Certainty. An indictment is an allegation until tried, and many defendants in these cases will never appear in court. Charging decisions can also be shaped by diplomacy.
How professionals word their confidence
U.S. intelligence analysis is governed by Intelligence Community Directive 203, which requires products to express uncertainty and to keep two things apart: how likely a judgment is, and how confident the analysts are in the basis for it. The January 2017 assessment of Russian activity in the 2016 election is a public example: it states most judgments with high confidence and notes where one agency held only moderate confidence. Its annex explains that high confidence still does not mean fact or certainty.
- High confidence:
- The judgment rests on high-quality information from multiple sources. It can still be wrong.
- Moderate confidence:
- The information is credibly sourced and plausible but not corroborated enough, or not of sufficient quality, for a higher level.
- Low confidence:
- The information is scant, questionable, or fragmented, and solid inferences are difficult.
- We assess / we judge:
- Signals an analytic inference, not a statement of directly observed fact.
- Almost certainly, likely, unlikely:
- Likelihood terms. ICD 203 maps these to probability ranges and says they should not be blended with confidence levels in the same sentence.
The public example of those standards in use is the declassified Intelligence Community Assessment of January 2017. It is worth reading for its wording alone: judgments are graded, a difference between agencies is disclosed, and the document states that it did not assess the impact of Russian activity on the election outcome.
- CIA and FBI have high confidence; NSA has moderate confidence:
- A disclosed disagreement about how strong the basis was for one judgment. Professional products show such differences instead of averaging them away.
- Did not make an assessment of the impact:
- An explicit limit on the claim. Attribution of activity is not a finding about effect.
Meta's takedown reports use a deliberately narrow vocabulary. The company attributes to the entity its own data can support and stops there. Its 2021 review of influence operations explains that it names the operator it can prove, which is sometimes a marketing firm, and does not speculate about clients or governments behind that operator.
- We found links to individuals associated with...:
- Platform data connects the network to specific people or an organization. It is a claim about operators, not necessarily about who directed or paid them.
- Originated in [country]:
- A statement about where the operators were located. It is not a statement that the country's government was responsible.
- Attempted to conceal their identities and coordination:
- Describes the violation (coordinated inauthentic behavior). It is about conduct, and the content may have been true.
- We could not determine who was behind it:
- A legitimate and common finding.
Private threat-intelligence firms borrow the intelligence community's grading. Mandiant's reporting on the Ghostwriter campaign shows how an assessment moves as evidence accumulates: first described in 2020 only as aligned with Russian security interests, then in 2021 tied with high confidence to an intrusion group linked to Belarus, with moderate confidence that Belarus was at least partly responsible for the campaign, and an explicit note that Russian contributions could not be ruled out.
- Assess with moderate confidence:
- The firm believes the judgment is more likely right than wrong on credible evidence, and is telling you it may be revised.
- Aligned with the interests of:
- A statement about content and targeting only. It is not attribution.
- UNC (uncategorized) group:
- A cluster of activity tracked under a neutral label because the firm is not ready to merge it with a named actor.
- Cannot rule out:
- An alternative explanation that was considered and remains open.
Getting it wrong
British Twitter users reported as Russian bots
2018After the Salisbury poisoning and strikes on Syria, UK government sources briefed that Russian bot activity had surged, and two accounts critical of government policy were named in the press as examples. Both belonged to real people; one, a British man, went on live television to say so. Channel 4 FactCheck reported that government sources later accepted the accounts were not bots.
Lesson: High posting volume and an unwelcome viewpoint are not evidence of automation or foreign control. Naming individual accounts on behavioral evidence put real people in national headlines.
Channel 4 News FactCheck, How Twitter users were wrongly labelled as Russian bots after a government briefingHamilton 68 and the hashtags called Russian
2017–2023The Alliance for Securing Democracy launched a dashboard showing what roughly 600 undisclosed Twitter accounts were discussing. Its methodology said the list mixed openly pro-Russian users, accounts that amplified attributed Russian media, and automated accounts, and that the method described the aggregate network, not individuals. News coverage nonetheless cited it to call hashtags popular with American conservatives Russian-driven. In 2023, internal Twitter emails published by Matt Taibbi showed the company's trust and safety head had concluded the listed accounts were mostly ordinary users. ASD responded that it had repeatedly cautioned against describing the accounts as Russian bots.
Lesson: A secret list cannot be checked, and caveats in a methodology paper do not travel with a live number. Both the builder's framing and the press's use of it carry responsibility. Read the inclusion rule before trusting any tracker.
German Marshall Fund, The Methodology of the Hamilton 68 Dashboard (ASD's own description of the tool)Olympic Destroyer: three countries blamed in two weeks
2018Malware disrupted the opening ceremony of the Pyeongchang Winter Olympics. Within days, different security firms pointed to North Korea, China, and Russia. Kaspersky then showed that a file header matching North Korea's Lazarus group had been forged to mislead analysts. In October 2020 the U.S. Justice Department indicted officers of Russia's GRU.
Lesson: Operators know which indicators analysts rely on and can plant them. A tidy match found quickly is a reason for more checking. The firm attribution took more than two years and legal process.
Kaspersky Securelist, OlympicDestroyer is here to trick the industry (March 2018)Crowdsourced identification after the Boston Marathon bombing
2013Users on Reddit and Twitter compared photographs and named a missing university student as a suspect; the name was repeated by journalists. He had no connection to the attack; he had been missing for a month and was later found dead. Reddit's general manager publicly apologized to his family.
Lesson: This was not an influence-operations case, but it is the clearest demonstration of what happens when enthusiastic pattern-matching by non-professionals ends in a public accusation against a named person.
NPR, Social Media's Rush To Judgment In The Boston Bombings (April 23, 2013)Bot counts built on a classifier that mislabels humans
2020Many academic and news estimates of bot prevalence relied on the Botometer tool. Rauchfleisch and Kaiser tested it against accounts whose nature was known, including sitting members of parliament, and found that scores drifted over time and that even conservative thresholds labelled many real people as bots, especially outside English. The tool's developers say it was not intended for verdicts on individual accounts.
Lesson: A score is a probability about a population. Percent-of-accounts-are-bots headlines, from any political direction, should be read with the false positive rate in mind, and a score should never be used to accuse a person.
Rauchfleisch & Kaiser, The False positive problem of automatic bot detection in social science research, PLOS ONE (2020)A counter-example: Secondary Infektion, published without a named sponsor
2020Graphika documented more than 2,500 pieces of forged and planted content posted over six years in seven languages on over 300 platforms. The investigators described the operation as run from Russia and said plainly that they could not identify the entity responsible.
Lesson: Stopping where the evidence stops is a complete and respectable result. A detailed description of behavior is more useful to the public than a confident guess at a name.
Graphika, Exposing Secondary Infektion (June 2020)Attribution as a tactic
- »Dismissing real critics as fake so their arguments need no answer: False Bot Accusation. It is used by governments, campaigns, and ordinary users on every side.
- »Answering a leak or exposé only by naming a hostile source, leaving authenticity unaddressed: Attribution as Deflection.
- »Letting a hedged or unsupported claim harden as outlets cite one another: Attribution Laundering. Count independent bodies of evidence, not mentions.
- »Overstating what a foreign operation achieved in order to discredit an opponent, a result, or a protest: Foreign Interference Inflation.
- »Running an operation so that someone else is blamed: Online False-Flag Operation. Documented but uncommon, and not to be confused with the evidence-free False-Flag Accusation.
- »Operating in order to be noticed, so the public concludes that everything is compromised: Perception Hacking. Breathless coverage completes the operation.
- »Making attribution hard by design with real documents and invented messengers: Hack-and-Leak and Cutout Personas.
- »Hiding the sponsor behind a contract: Influence Operations for Hire. The contractor's country is not the client's country.
- »The analyst's own errors, which hand ammunition to everyone above: Premature Attribution, The Bot-or-Not Fallacy, and Dashboard Overreach.
A write-up template
The structure analysts use so that a reader can see what was observed, what was inferred, and how sure the author is. Fill every section, including the last one.
- 1. Scope and collection methodWhat did you look at, over what dates, gathered how? What did you not look at? State any tool used and its known error rate. A reader should be able to repeat your collection.
- 2. What was observedDescribe the activity in neutral terms with counts and examples: how many accounts, what they posted, when. No adjectives about intent and no actor names in this section.
- 3. Actors, behavior, content (ABC)Following Camille François's framework, say separately what you know about the content (narratives), the behavior (coordination signals), and the actors (usually: nothing verifiable from public data). Leave a heading blank instead of filling it with inference.
- 4. Alternative explanations consideredList at least three: genuine grassroots enthusiasm, an organized but disclosed campaign, a commercial firm, a different state, a false flag, an artifact of your own collection method. For each, say what you would expect to see and whether you saw it.
- 5. Confidence and whyGive a level (low, moderate, high) for each judgment separately — that coordination exists, that it is inauthentic, that a given party is responsible — and name the evidence rung each rests on. Public data alone rarely justifies more than low confidence on the last.
- 6. What would change the assessmentName the specific evidence that would raise or lower your confidence, such as a platform disclosure, registration records, or accounts turning out to belong to identifiable real people.
- 7. What is NOT claimedWrite this out explicitly: that no individual account is asserted to be fake, that no sponsor is identified unless stated above, that no effect on opinion or outcomes has been measured, and that alignment with a party's interests is not evidence of its involvement.
Rules for the rest of us
- Never name an individual account publicly as a bot, troll, or agent on behavioral evidence alone. If you are wrong, a real person pays for it; if you are right, you have taught the operator what to fix.
- Describe patterns, not perpetrators. It is fine to say that forty accounts created in the same week are posting identical text. It is not fine to say whose accounts they are.
- Report to the platform or to an established research group instead of posting an accusation. They hold the data that can settle the question, and you do not.
- Answer the argument regardless of who made it. If a claim is false, show that it is false; the identity of the poster is not a rebuttal.
- Treat disagreement, high volume, poor English, numeric handles, and missing profile photos as what they usually are: ordinary people.
- Carry the hedges with you. When you repeat someone else's attribution, repeat their confidence level and their caveats, and link to the original instead of a summary of it.
- Apply the same standard to claims that flatter your side. If you would not accept this evidence for an accusation against your own allies, do not accept it against opponents.
- Be willing to say you do not know. Professionals publish that conclusion regularly, and it is almost always the accurate one from the outside.