Case files

Operation anatomies

8 documented influence operations, taken apart the way analysts write them up: who was attributed and by whom, what they were trying to do, how it unfolded, which techniques carried it, what is honestly known about whether it worked, and how it was caught. The set spans Soviet, Russian, Chinese, Belarus-linked, United States military-linked, and corporate actors on purpose: the methods belong to no one side.

1953–1998

The tobacco industry's manufactured-doubt campaign

In December 1953, with laboratory and epidemiological studies linking cigarettes to lung cancer reaching the general press, the heads of the major American tobacco companies met at the Plaza Hotel in New York and retained the public relations firm Hill and Knowlton. The approach the firm proposed, as the historian Allan Brandt reconstructs it from the firm's files, was not to deny the science but to take hold of it: to call for more research, fund it conspicuously, publicise every sceptic, and so keep the question looking open. The result was a jointly funded research committee, a newspaper advertisement called A Frank Statement to Cigarette Smokers, and a position held in public for more than four decades, that a causal link between smoking and disease had not been proven. It is treated here as an influence operation because it had what such operations have: coordinated actors, concealed purposes, intermediaries presented as independent, and a defined effect sought in a mass audience. It differs from the other cases in this collection in one respect. The evidence comes not from outside inference but from millions of pages of the participants' own records and from the findings of a court.

Attributed to The major US cigarette manufacturers and two jointly funded trade bodies, the Tobacco Industry Research Committee (from 1964 the Council for Tobacco Research) and the Tobacco Institute, acting together as what a US federal court found to be a racketeering enterprise.
1983–1987 (residual activity to 1989)

Operation INFEKTION (Stasi codename "Denver"): the Soviet-bloc AIDS disinformation campaign

In the mid-1980s Soviet-bloc intelligence services promoted the false claim that the virus causing AIDS had been engineered by US military scientists at Fort Detrick, Maryland, and released through experiments on prisoners. The claim surfaced in an anonymous letter to a small pro-Soviet Indian newspaper in July 1983, went nowhere, and was revived in the Soviet press in October 1985. A retired East Berlin biophysicist, Jakob Segal, then gave it a scientific-looking form in a pamphlet that circulated at the 1986 Non-Aligned Movement summit in Harare. From there it was picked up by newspapers in Africa, Asia and Western Europe, by a best-selling West German novelist, and eventually by television documentaries. Soviet media largely dropped the story after US protests in late 1987, when Moscow wanted scientific cooperation on AIDS; the Stasi and Novosti kept feeding it until 1989. The name "INFEKTION" comes from Boghardt; Selvage, working from the Stasi files, found that the East German service called its part of the campaign "Denver" and regards "Infektion" as a misnomer. The belief itself long outlived the services that promoted it, but how much of that persistence they caused is disputed.

Attributed to The Soviet KGB (Service A of the First Chief Directorate), with the East German Ministry for State Security (Stasi) foreign-intelligence disinformation department HVA X as junior partner, and Soviet state media such as Literaturnaya Gazeta and the Novosti press agency as overt carriers.
2014–2020

Secondary Infektion

Secondary Infektion is the name researchers gave to a six-year series of campaigns that planted forged documents and fake stories across the internet. From January 2014 into early 2020 it posted at least 2,500 pieces of content in seven languages on more than 300 sites, from Facebook, Twitter, Reddit, Medium and YouTube to small regional discussion boards. Its typical product was a supposedly leaked letter, tweet or blog post attributed to a Western or Ukrainian official, designed to set one government against another. Graphika counted more than 250 suspected forgeries. The operation hid its tracks with unusual discipline, and it failed almost completely: nearly nothing it posted drew measurable engagement, and readers who did notice often mocked it. The one exception was the October 2019 release of apparently genuine US–UK trade documents, which entered the British general election campaign. The case matters for both halves of that record: influence operations are frequently ineffective, and authentic leaked material is far more potent than forgery.

Attributed to An unidentified "central entity" operating from Russia. No public report has named the organisation or individuals responsible.
2014–2017

The Internet Research Agency and the 2016 US election

Between 2014 and 2017 employees of a St. Petersburg company posed as Americans on Facebook, Instagram, Twitter, YouTube and smaller platforms. They built pages and personas for audiences across the political spectrum: conservative, Christian, Southern and gun-rights communities on one side; Black, Latino, Muslim and LGBT communities on the other. Most of what they posted was identity and culture content rather than election material, and most of it was unpaid. Around the 2016 election the Senate committee found the activity "overtly and almost invariably supportive" of Donald Trump and harmful to Hillary Clinton, including content urging Black voters to stay home or vote for a third party; in the primaries it had also denigrated Republican candidates such as Ted Cruz, Marco Rubio and Jeb Bush. Posing as local activists, the operators persuaded real Americans to hold rallies. The reach figures are very large. The best available measurements of persuasion, however, find no detectable effect on attitudes or votes, and this gap between reach and effect is the central lesson of the case.

Attributed to The Internet Research Agency (IRA), a St. Petersburg company funded by Yevgeniy Prigozhin through Concord Management and Consulting and related firms.
2016–2022 (documented activity; named in 2020)

Ghostwriter

Ghostwriter is a campaign that joins hacking to fabrication. Instead of building fake audiences, its operators broke into real news websites and the real social media accounts of politicians, or sent emails dressed up as coming from officials, and used that borrowed credibility to publish invented stories: that NATO was pulling out of Lithuania because of Covid-19, that German soldiers had desecrated a Jewish cemetery in Kaunas, that a NATO vehicle had run over a Lithuanian child. A small cast of invented commentators then wrote the fabrications up as opinion pieces on sites that accept outside contributions. Mandiant, which named the campaign in July 2020, traced it back several years and first found it aimed at Lithuania, Latvia and Poland with anti-NATO themes. After the disputed Belarusian election of August 2020 it turned toward discrediting the Polish and Lithuanian governments and the Belarusian opposition, and in 2021 toward German parliamentarians and a large hack-and-leak affair in Poland. Several fabrications were publicly called out as false by the governments concerned. No public study measures whether any of it changed opinion.

Attributed to A cyber espionage group tracked by Mandiant as UNC1151, which Mandiant links to the government of Belarus. Germany, Poland and the European Union have instead publicly associated the activity with the Russian state. The attributions differ and have not been publicly reconciled.
2019–present (earliest activity reported from 2019)

Spamouflage (also tracked as Spamouflage Dragon and DRAGONBRIDGE)

Spamouflage is the name Graphika gave in September 2019 to a network of fake and hijacked accounts on YouTube, Twitter and Facebook that mixed Chinese-language political posts with unrelated filler such as scenery, basketball and short videos, apparently to camouflage the politics, which is where the name comes from. The first targets were the Hong Kong protest movement and an exiled Chinese businessman and critic of the government. Over the next four years the network added English and other languages, spread to dozens of platforms, and turned to praising China and criticising the United States, Western foreign policy and individual critics of Beijing. Google and Mandiant track the same activity as DRAGONBRIDGE. In August 2023 Meta called it the largest known cross-platform covert influence operation in the world. It is also, by every published measure, among the least successful at reaching real people. That combination of vast scale, long life and minimal uptake is the reason to study it.

Attributed to Individuals associated with Chinese law enforcement, according to Meta. A US Department of Justice complaint separately alleges that officers of the Ministry of Public Security, working in a unit called the 912 Special Project Working Group, ran a fake-account operation of closely similar description.
2017–2022 (some Twitter accounts dated to 2012)

The pro-Western covert network removed by Meta and Twitter (Unheard Voice)

In July and August 2022 Twitter and Meta removed two overlapping sets of fake accounts that had promoted the interests of the United States and its allies to audiences in the Middle East and Central Asia. Both companies passed data to Graphika and the Stanford Internet Observatory, whose joint report, Unheard Voice, appeared on 24 August 2022. The researchers described it as the most extensive case of covert pro-Western influence activity on social media analysed by open-source researchers to that point. They found not one campaign but a series of them over almost five years, using invented personas, some with computer-generated faces, and outlets posing as independent local media. They also found that almost nobody was listening. The case is included here because it shows a democratic state's military-linked operators using the same deceptive toolkit that Western governments criticise in others, being caught by the same platform enforcement, and getting the same poor return. A separate US military operation, reported by Reuters in June 2024 and concerning Chinese COVID-19 vaccines in the Philippines, is often confused with this network. It is described below only to keep the two apart.

Attributed to Individuals associated with the US military, according to Meta. No official US body has publicly claimed or confirmed the network. The Washington Post, citing unnamed officials, reported that US Central Command was among the commands whose online activities came under review.
2022–present

Doppelganger (also tracked as RRN)

Doppelganger is a long-running operation that publishes fabricated articles on websites built to look like established news outlets, and later like government ministries, using web addresses that differ from the real ones by a few characters. EU DisinfoLab and the Swedish forensics non-profit Qurium named it in September 2022 after German journalists at T-Online and Sueddeutsche Zeitung reported on forged versions of German news sites. The first report counted at least 17 cloned media brands, including Bild, 20 Minutes, ANSA, The Guardian and RBC Ukraine. Meta, reporting the same day, counted more than 60 impersonating sites. The French agency VIGINUM, which calls the campaign RRN after its hub site Reliable Recent News, later recorded 355 impersonating domain names registered between June 2022 and May 2023. The forged pages were promoted through paid advertisements and large numbers of short-lived fake social media accounts. The operation is notable less for what it achieved than for how often it was exposed and kept going anyway.

Attributed to The Russian companies Social Design Agency and Structura National Technologies, together with ANO Dialog, which the US Department of Justice says operated under the direction and control of the Russian Presidential Administration.

Descriptive and sourced; never a how-to. Attribution is reported in the attributing bodies' own words. To look for the same behaviors in a set of posts, use the Coordination Analyzer.