@ForIntOrg

Tracking and analyzing foreign interference worldwide.

Washington, D.C.
Joined May 2022
The Justice Department quietly told Congress that FISA wiretaps jumped sharply in 2011, and "quietly" is doing a lot of work in that sentence. Assistant Ronald Weich sent the letter. No press conference, no fanfare. Just a number going up and a note to the people who are supposed to be watching the watchers. The surveillance covered suspected foreign agents and terrorism-linked communications, which is the legal lane, but the scale of the increase is the part worth sitting with. Foreign intelligence operations targeting the U.S. were apparently busy enough in 2011 to justify a significant escalation in monitoring. That's the actual headline. foreigninterference.org/post… #foreigninterference #CommunicationsInterception #MassSurveillanceOperations
32
FARA has been "under reform" longer than most lobbyists have been alive. The House calendar for September 28 lists the Disclosing Foreign Influence in Lobbying Act for consideration, which sounds like progress until you remember the Senate passed foreign lobbying reform unanimously in 2023 and it went nowhere. The Qatar campus money, the $4.4 million China-linked donor network in California, the whole Qatargate mess documented last month: all of it flowed through gaps that reformers have been promising to close for years. K Street has a direct financial stake in keeping those gaps open, and K Street is very good at its job. Getting on the calendar is the easy part. foreigninterference.org/post… #foreigninterference #CounterInterferenceLegislation #LegislativeGapAssessment #PoliticalDonationInfluence #InfluenceOperations #CongressionalInvestigationLaunch
34
Abelardo de la Espriella became Colombia's president and, within months, Colombia no longer had diplomatic relations with Iran. Make of that sequencing what you will. The break came in late September 2026. The new right-wing government in Bogotá severed ties with Tehran and simultaneously pivoted toward Israel, which is about as clean a signal of political alignment as you can send in one move. Press TV flagged it via GlobalSecurity.org, which, yes, is an Iranian state outlet and therefore not a neutral narrator, but the facts of the break itself aren't in dispute. The thing that makes this case analytically interesting, rather than just another diplomatic shuffle, is the detail about de la Espriella's citizenship. He holds dual U.S.-Colombian nationality. That's not a rumor or an opposition smear. It's a structural fact about the person running Colombian foreign policy. And when that person's first major foreign policy gestures are: (1) cut ties with a country Washington considers an adversary, and (2) lean toward a country Washington is actively backing under the Trump administration's Middle East posture, the question of where the strategic decision-making is actually happening becomes genuinely worth asking. You don't have to assume bad faith to ask it. The question asks itself. Colombia under Gustavo Petro had moved in a very different direction. Petro opened lines with Venezuela, was vocal about Palestinian rights, kept relations with Iran functional if not warm. De la Espriella is essentially running the foreign policy tape backward at speed. That kind of reversal doesn't happen in a vacuum, and it doesn't usually happen this fast without some external architecture supporting it. The Washington Brazil Office had been documenting U.S. pressure on Latin American governments throughout the 2026 electoral cycle, and Colombia fits the broader pattern: elections producing governments that are either genuinely ideologically aligned with Washington's preferences or sufficiently dependent on U.S. support that the practical difference is hard to find. Iran's response was formally noted but deliberately vague. The Foreign Ministry vowed to take "measures" in response to what Tehran called Colombia's "hostile approach," without specifying what those measures would be. That ambiguity is a tactic, not an oversight. It lets Tehran preserve maximum flexibility while creating just enough uncertainty about costs to put Bogotá slightly on edge. The honest assessment is that Iran has limited direct leverage over Colombia. They're not trade partners of consequence, they don't share a neighborhood, and there's no meaningful Iranian diaspora in Colombia with political weight. What Iran does have is indirect reach. Hezbollah-linked networks in South America are well-documented, concentrated particularly in the tri-border area of Argentina, Brazil, and Paraguay, and in parts of Venezuela. Whether Tehran activates any of that infrastructure in response to the Colombian break is a real question, though "activates" covers a range of options from propaganda to something considerably less comfortable. The Iranian Foreign Ministry's careful vagueness probably reflects the fact that their actual options are more limited than their rhetoric suggests, but they'd rather you not be certain about that. The more immediate use Iran gets from this rupture is rhetorical. And on that front, they're not working alone. Lula in Brazil has been publicly accusing the U.S. of electoral interference. Cuba showed up at the UN General Assembly in late 2026 warning against what its representatives called the "law of the jungle" in international relations. Venezuela has been in a running confrontation with Washington for years and views every development like the Colombia pivot as further evidence for its preferred narrative. All of these governments will use the de la Espriella pivot, a dual U.S.-citizen president cutting ties with Iran and embracing Israel within months of taking office, as a concrete example when they argue that Washington is systematically reordering Latin American foreign policy through pressure and installed-friendly-government operations. Whether that framing is entirely fair is a separate question. But it's not an absurd reading of events, and the people making that argument now have a pretty clean data point to cite. The Colombia case is worth sitting with as a model, not just an incident. Electoral interference, when it works, doesn't just change who wins. It changes what that country does afterward. Trade relationships, diplomatic posture, military cooperation agreements, regional bloc alignments: all of it becomes available for restructuring once the executive is amenable. That's a larger return on investment than simply getting a favorable election result, and it's why the foreign policy downstream of contested elections matters as much as the elections themselves. De la Espriella is presumably governing according to his own convictions. He may well believe every policy he's implementing is correct. None of that resolves the structural question about what it means for a dual national to hold executive power in a country and then pursue policies that happen to align precisely with the preferences of the other country whose passport he carries. The alignment might be coincidental. Institutions usually assume it isn't. Tehran's anger is real even if their leverage is limited. Bogotá's pivot is real even if its independence is questionable. And the regional argument about U.S. sovereignty violations in Latin America just got a new exhibit. foreigninterference.org/post… #foreigninterference #DiplomaticSeverance #GovernmentDestabilization #PoliticalInfiltration #AntiInterferenceRhetoric #DiplomaticCoercion
1
88
Transparent Tribe has been running the same basic playbook against Indian targets since 2013. That's over a decade of continuous operations against Indian government agencies, military personnel, defense research institutions, and diplomatic staff. CYFIRMA's weekly intelligence report for September 25, 2026 flags the group again, documenting continued activity during a period when, if anything, you'd expect state-backed hackers to be working overtime. The group, designated APT36 and widely attributed to Pakistani intelligence services, is not a sophisticated mystery. It's a known quantity with a documented history and a consistent target set. What makes it worth revisiting isn't novelty. It's persistence, and what persistence like this actually costs the people being targeted. The core toolkit is CRIMSON RAT and ObliqueRAT, both custom-built and regularly updated to stay ahead of signature-based detection. The delivery mechanism is spear-phishing, often built around whatever is currently making headlines between India and Pakistan. Kashmir tensions, Line of Control incidents, military posturing. The group has institutional knowledge of its targets built up over thirteen years of continuous operations, which means its social engineering is not generic. It's tuned. CYFIRMA's September report situates the Transparent Tribe activity within a broader spike in state-sponsored cyber operations during the UN General Assembly period in late September 2026. That's not coincidental. The UNGA period concentrates diplomatic activity, creates new communication channels between officials, and gives intelligence services on all sides fresh reasons to want insight into what their counterparts are saying behind closed doors. Cyber espionage operations don't slow down for diplomacy. Often they accelerate. The geographic scope of Transparent Tribe operations extends beyond India's borders to target Indian diaspora communities and government personnel operating abroad. That's a significant detail. It means Indian defense and diplomatic personnel can't treat the threat as geographically contained. A military attaché posted to a third country, a researcher at a foreign university with ties to Indian defense institutions, an official traveling for multilateral meetings. All plausible targets, and all operating in environments where the defensive infrastructure is less robust than what they'd have at home. India's CERT-In and the National Cyber Security Coordinator are not operating blind here. The attribution is solid, the TTPs are documented, and groups like CYFIRMA are publishing updated analysis regularly. The structural problem is that defense against a persistent, state-resourced adversary conducting thousands of spear-phishing attempts annually is not a problem you solve. It's a problem you manage. The math doesn't favor the defender. One successful penetration of a defense research institution or military headquarters generates intelligence value that, from Islamabad's perspective, justifies years of failed attempts. The attacker only needs to be right once. The defender needs to be right every time. Transparent Tribe rotates its command-and-control infrastructure regularly, which complicates both attribution in the moment and takedown operations. By the time a specific piece of infrastructure is identified, reported, and actioned, the group has often already moved. This is not a technically demanding capability. It's operationally disciplined tradecraft, and it's one of the reasons a group running relatively unsophisticated tools has sustained operations for thirteen-plus years without meaningful disruption. The CYFIRMA report frames the September 2026 Transparent Tribe activity as part of a broader pattern of state-sponsored actors maintaining or increasing operational tempo. That framing is accurate and probably understated. The group isn't escalating in a dramatic sense. It's doing what it has always done, methodically, against targets it knows well, during a period when the intelligence value of those targets is as high as it's ever been. foreigninterference.org/post… #foreigninterference #AdvancedPersistentThreatOperations #SpearPhishing #MalwareDistribution #MilitaryEspionage #CyberEspionage
40
The RAF has spent the last year quietly jamming Russian and Chinese satellites, and on September 26th Britain made it official: Number III Space Effects Squadron, a dedicated unit whose whole job is electronic counter-space warfare. Covert program, now institutionalized. The capability existed. Now it has a badge, a budget line, and a place in the RAF order of battle. That move from secret to public is, in some ways, the actual story. Covert operations give you deniability. Numbered squadrons give you deterrence. Britain chose deterrence, which means they've calculated that Moscow and Beijing already knew, or that being caught knowing is less useful than being seen acting. Probably both. The RAF doesn't stand up a formal unit and invite reporters to write about it because they're worried about operational security. They do it because they want adversaries to update their threat models. So the question worth sitting with is what that calculation implies about where space warfare is actually heading. Electronic warfare in orbit is already messier than the "reversible and non-debris-generating" framing suggests. Yes, jamming doesn't leave a debris field. But the effects aren't always tidy. Satellite jammers work across frequencies; collateral disruption of civilian or third-party systems is a real operational risk, not a theoretical one. GPS spoofing campaigns attributed to Russia have affected civilian aviation. Jamming operations targeting military communications satellites operate in spectrum neighborhoods where commercial and humanitarian satellite services live. The cleanliness of the method is real compared to a kinetic kill vehicle, but "cleaner than blowing something up" is a low bar, and the precedent being set is broader than the specific operations. What Britain is institutionalizing is the normalization of active electronic interference with adversary space assets as a standing military function. Not a crisis response. Not an emergency authority. A routine, permanent, staffed capability with career paths and doctrine and training pipelines. That's what a numbered squadron means. The RAF doesn't create numbered squadrons for one-off contingencies. Russia and China will respond to this, and not by backing down. Russia's counter-space program, including the Tirada-2 jamming satellites and the Luch/Olymp inspector satellites that have parked themselves uncomfortably close to Western communications birds, is already extensive. China has fielded ground-based jamming systems, developed co-orbital technologies, and fired an ASAT missile as far back as 2007. What Britain's announcement does is give both countries a fresh justification for capability expansion. Not that they needed one. But international signaling around military programs is partly theater, and Britain just gave Russia and China a prop for the next act of their own theater: "NATO is militarizing space, we are merely responding." That framing will play domestically in both countries and, more importantly, in multilateral forums where the absence of space arms control is starting to feel like a problem that someone, eventually, should address. Here's where the trajectory gets genuinely complicated. The specific mission referenced in the RAF's covert jamming program includes protecting the nuclear deterrent. That's the Trident submarine force, which relies on space-based communications for command and control. The inclusion of strategic nuclear communications as a priority mission for Number III Space Effects Squadron is not a minor detail. It means that if an adversary decides to target British space-based nuclear command links, the RAF now has an active, institutionalized counter-capability. That's stabilizing in one sense: it reduces the vulnerability of the deterrent to space-domain attacks. But it also means that any future crisis in which Russian or Chinese satellites are suspected of interfering with Trident communications could trigger a British electronic response that the adversary might not immediately understand as proportionate or limited. Escalation ladders in contested domains are only useful if both sides are climbing the same ladder. Space doesn't have agreed rungs. The Five Eyes dimension is worth watching specifically. Britain's move to formalize this capability in an RAF structure rather than a joint or intelligence-community unit is a choice with alliance implications. Intelligence-community capabilities are shared under different frameworks than military capabilities. A numbered RAF squadron operates under military command authorities, doctrine, and rules of engagement. If Australia, Canada, or New Zealand are sharing satellite infrastructure with Britain, and that infrastructure becomes part of an active electronic warfare mission set, those partners will need to decide whether they're inside this capability or adjacent to it. That's a political conversation several of those governments haven't fully had in public yet. For the United States, the interesting question is coordination. US Space Command has its own counter-space programs, and the US has been somewhat more cautious than Britain about public acknowledgment of offensive electronic space capabilities, partly because of the scale of US commercial satellite dependence and partly because of the arms control implications. Britain stepping publicly into this space slightly ahead of a formal US equivalent gives Washington a useful trial balloon. If the diplomatic blowback is manageable, that's useful information. If Moscow or Beijing decides to escalate in response to the British announcement, Washington will be watching the playbook. What defenders and officials should actually be tracking over the next twelve to eighteen months is not whether Britain's squadron conducts more jamming operations. They almost certainly will. The things worth tracking are: Whether Russia or China signals a doctrinal response to Britain's announcement through their own military publications, exercises, or capability demonstrations. Russia's military-strategic literature on space warfare is substantial and detailed. If Vozdushno-Kosmicheskiye Sily starts holding exercises that include scenarios involving electronic attack on British or NATO space assets, that's a doctrinal response, not just a capability response. Whether there are observable changes in the behavior of Russian inspector satellites near British or allied communications birds. The Luch/Olymp platform has already demonstrated a willingness to park close to Western satellites. In the post-Number III announcement environment, renewed proximity operations would be a clear signal. Whether the commercial satellite operators whose frequencies neighbor military jamming operations start reporting interference anomalies they weren't reporting before. This is the quietest and most underappreciated risk. Electronic warfare doesn't respect neat military/civilian spectrum boundaries the way doctrine pretends it does. And whether the UK government, having made this capability public, finds itself under pressure to articulate a legal framework for when and how Number III Squadron's capabilities can be used. Britain has a reasonably robust public law tradition around military operations, and eventually someone in Parliament is going to ask what the rules of engagement are for jamming a Chinese satellite over which Britain has no jurisdiction. That question is going to be uncomfortable, and the discomfort will be proportional to how public the capability becomes. The broader arc here is that 2026 is starting to look like the year that space domain warfare stopped being a background assumption and became a foreground fact. The United States established Space Command years ago. France stood up a space defense command in 2019. Japan has been expanding its space awareness capabilities under its Air Self-Defense Force. And now Britain has a numbered squadron with an active jamming record and a mandate that explicitly includes protecting the nuclear deterrent. The orbital environment is not going to become more stable because these units exist. Deterrence theory says it might become more predictable. Those are different things, and the space domain, without arms control frameworks, without agreed norms around what constitutes an act of war versus an act of interference, and without the decades of crisis management experience that stabilized nuclear competition eventually, is going to generate surprises. Number III Space Effects Squadron is a serious, professional military unit doing a real job. The RAF's institutional choices here reflect genuine capability, genuine threat assessment, and genuine strategic logic. That's not reassuring so much as it is clarifying. The serious work of the next several years isn't developing the capability. Britain just demonstrated that's tractable. The serious work is figuring out what rules, if any, should govern its use before a crisis makes that conversation much more urgent and much less deliberate. foreigninterference.org/post… #foreigninterference #CommunicationJamming #SatelliteNetworkAttack #SpaceDomainDeterrenceSignaling #OrbitalIntelligenceDeployment
1
85
Russia is running a stress test across NATO's eastern flank, and the grading curve keeps getting easier. Drones over Poland and Romania, arson at logistics nodes, airspace probes designed more to embarrass than destroy. Moldova gets the unfiltered version since it's not a member and Moscow knows it. Each incident that goes unanswered sets the new floor for what's considered acceptable. The DW analysis frames this as escalation. It's also just iteration. foreigninterference.org/post… #foreigninterference #InfrastructureAttacks #DroneSurveillance #IndustrialSabotage #MultiDomainWarfareCoordination #ThresholdCalibrationOperations
1
45
Eight Chinese vessels on September 25th. A mix of PLA Navy warships and coast guard ships, working in coordinated tandem, blocking a resupply run to a rusting ship that has been deliberately grounded on a reef since 1999. That's the situation at Ayungin Shoal right now, and if you've followed this particular file for any length of time, none of it is surprising. That's sort of the depressing part. The BRP Sierra Madre is the whole game here. The Philippines grounded it on Second Thomas Shoal decades ago specifically to establish a physical presence, and the small garrison living aboard it depends entirely on periodic resupply missions for food, water, and basic equipment. Manila calls these missions "routine humanitarian" resupply, which is accurate, and that framing is doing deliberate work: it puts Beijing in the position of blocking food and water from reaching Filipino servicemen, which is a harder thing to explain away diplomatically than "asserting sovereignty over a contested feature." The AFP knows what it's doing with that language. What's worth sitting with is the specific combination of assets Beijing deployed. Eight vessels, PLAN warships alongside China Coast Guard ships. This is not improvised. The grey-zone doctrine China has developed for the South China Sea is built around exactly this kind of combined deployment, and the logic is fairly straightforward once you understand what they're trying to accomplish. Coast guard vessels operate under a law-enforcement legal framing, not a military one. PLAN warships provide the actual coercive weight. Together, they maximize pressure while creating genuine ambiguity about whether any specific action crosses the threshold that would constitute an "armed attack" under the U.S.-Philippines Mutual Defense Treaty. That ambiguity is the product. It's not a side effect. The 2016 UNCLOS arbitral tribunal ruling is relevant background here. The Philippines won decisively on the legal merits. China rejected the ruling entirely and has continued to reject it, but Manila has kept building its evidentiary record anyway, and the AFP's decision to confirm this incident publicly rather than downplay it fits that pattern. Every documented incident is another data point for international audiences, for potential future legal proceedings, for allied governments deciding how to characterize Chinese behavior in their own policy statements. The transparency is a strategy, not a reflex. The timing of this incident is interesting and probably not coincidental. September 25th, 2026 puts this squarely in the middle of UN General Assembly week, which is about the highest-density diplomatic moment on the annual calendar. Every senior official from every major government is in New York, schedules are packed, attention is genuinely split across dozens of simultaneous crises and bilateral meetings. If you wanted to run an escalatory coercive operation and have it receive somewhat less sustained international focus than it otherwise might, that's a reasonable week to choose. Beijing has shown a consistent pattern of timing assertive moves in the South China Sea to coincide with periods of reduced international bandwidth, and this fits. There's a broader structural context that makes this particular moment more complicated than the baseline. The Xi-Trump summit and the current phase of U.S.-China diplomatic engagement have put Washington in a posture that is, at minimum, more focused on bilateral management with Beijing than on active confrontation. Whether that has created operational space for China to push harder at Ayungin Shoal without expecting a sharp American response is something analysts are going to debate, and honestly it's difficult to know from the outside. But the incentive structure isn't hard to read. If Beijing calculates that Washington's diplomatic investment in the relationship creates some deterrence against a forceful American reaction to South China Sea escalation, that calculation would encourage exactly what we're seeing. The Philippines' structural problem here is real and doesn't have a clean solution. Accepting interference and having resupply missions blocked normalizes it, and normalization eventually becomes de facto Chinese control over the shoal's supply lines, which functionally becomes control over the garrison, which functionally becomes control over the shoal. But escalating the response carries obvious risks of broader conflict that Manila cannot manage alone. The strategy Manila has settled on, at least publicly, is documentation and transparency, keeping allies informed, maintaining the physical presence as long as possible, and letting the evidentiary record accumulate. It's not a satisfying answer to a blockade, but it's a coherent one given the constraints. What Beijing is doing at Ayungin Shoal is not complicated in its strategic logic. It's expensive in terms of international reputation, which China has decided is an acceptable cost, and it is calibrated specifically to stay below the threshold that triggers a military response from the United States. That calibration has held for years. The question is whether the slow accumulation of pressure, mission by mission, eventually achieves the objective of making the Sierra Madre garrison unsustainable, without ever producing a single incident dramatic enough to force a definitive American response. That's the bet. Eight ships on September 25th is that bet, placed again. foreigninterference.org/post… #foreigninterference #MaritimePlatformWeaponization #MilitaryIntimidation #GreyZoneOperations #GreyZoneMaritimeCoercion
57
The Richardson Institute at Lancaster University has mapped out what repressive states are actually doing to dissidents living in Britain. The toolkit is broader than most people assume, and the UK's ability to counter it is thinner than it should be. Start with the surveillance layer. Commercial spyware, acquired through the global surveillance marketplace, lets a hostile state monitor a dissident's communications, location, and social network in real time without anyone setting foot in the country. No physical presence required. The targeting happens thousands of miles away and the target often has no idea. Then the legal layer. Vexatious defamation suits filed in UK courts. Interpol Red Notices weaponized against people who've committed no crime. Mutual legal assistance requests used as harassment tools dressed up as lawful cooperation. The genius of this approach is that it uses the UK's own legal infrastructure against the people the UK is nominally protecting. Litigation is expensive and exhausting even when you win. That's the point. Family coercion is quieter but often more effective. A dissident in Manchester has a mother in Tehran, a brother in Riyadh, a sister in Beijing. The threat doesn't need to arrive in Manchester. It arrives where the family is, and the dissident gets the message anyway. Threats of arrest, job loss, violence. The dissident self-censors. Or starts cooperating. The operation succeeds without anyone ever leaving the target country. Physical harassment on UK soil is delegated. Criminal networks. Community informants. Proxies who conduct surveillance, intimidation, or in the most serious cases, assault. The hostile state keeps distance. The proxy takes the risk. Attribution becomes difficult and prosecution harder. The social media angle is underappreciated. Coordinated mass reporting campaigns against dissident accounts, aimed at platform trust and safety teams, turn those platforms' own moderation systems into repression tools. A person gets suspended or removed. Their reach collapses. Their community loses contact with them. The platform never knows it was used this way, and even if it did, most platforms don't have good mechanisms for catching this pattern before the damage is done. The Richardson Institute is clear that these aren't separate phenomena. They converge. A target might be simultaneously under digital surveillance, facing a defamation suit, receiving reports that their family at home is being pressured, noticing unfamiliar cars outside their flat, and watching their social media accounts get reported into suspension. Each element feeds the others. The cumulative effect is isolation, exhaustion, and self-censorship. That outcome is the goal. What Lancaster documents in this research is that the UK's protective architecture was not built for this. Counterterrorism legislation was designed around different threat models. Espionage statutes weren't written with grey-zone harassment campaigns in mind. Police forces routinely treat individual incidents as isolated crimes rather than recognizing the coordinated state campaign behind them. A dissident reports being followed. It gets logged as a harassment complaint, not as a data point in a pattern of foreign state activity. The connection is never made. The states most active in this space in Western democracies, the broader literature consistent with the Lancaster research identifies China, Russia, Iran, Saudi Arabia, and Turkey, each have distinct operational signatures. Different target communities. Different preferred methods. Different risk tolerances. Iran is not operating the same way China is. Saudi Arabia's approach to silencing critics abroad has its own character. But the common thread is that all of them have concluded that conducting repression across borders is worth doing and, in the UK specifically, worth the risk. The Lancaster assessment makes that last point explicitly. The UK is a permissive operating environment. Legal proceedings here can be initiated and sustained with relative ease compared to some allied democracies. The diaspora communities from repressive states are large. The specialist police capacity to recognize and investigate transnational repression patterns is limited. The intelligence picture shared with forces on the ground is inadequate. For a hostile state running these operations, that's an attractive combination. The Richardson Institute's recommendations aren't complicated: dedicated transnational repression legislation, specialist police units, better intelligence sharing with allies who are tracking the same actors. Those are the minimum requirements, per the research. The gap between those minimums and what currently exists is the problem. This isn't an obscure academic concern. There are people living in British cities right now who are being actively targeted by foreign states using exactly this toolkit. Some of them have reported it. Some of them have been told it doesn't rise to an actionable threshold. The research Lancaster has produced is an attempt to force that gap into view. foreigninterference.org/post… #foreigninterference #TransnationalRepression #DigitalSurveillanceIntegration #LegalWeaponization #FamilyMemberCoercion #InterpolRedNoticeAbuse #JournalistSurveillance #CommercialSurveillanceInfrastructure
56
The Justice Department quietly told Congress that FISA wiretaps jumped sharply in 2011. Assistant AG Ronald Weich sent the letter. No press conference, no fanfare, just a note to Biden and congressional leaders confirming surveillance under terrorism and espionage authorities expanded considerably. The government monitors more, tells you less, and considers this normal. foreigninterference.org/post… #foreigninterference #CommunicationsInterception #MassSurveillanceOperations
44
The short version: OSI rolled up a spy ring in Japan in the mid-1980s that was simultaneously feeding stolen Air Force Technical Orders to both Soviet and Chinese intelligence. Same ring, two customers, one operation. That part got some attention at the time. What didn't get enough attention then, and still doesn't now, is what the structure of that operation was actually telling us about where things were heading. Start with the target material. Technical Orders aren't sexy. They don't have "TOP SECRET" stamped across them in the movies. But for a foreign military trying to understand how to kill or disable a U.S. aircraft, a TO is more useful than almost anything else you could steal. It tells you maintenance cycles, failure thresholds, what conditions degrade the system, what a ground crew has to do before a mission. You can't derive that from satellite imagery. You can't get it from watching a plane land. You need someone on the inside with access to the paperwork, and that's exactly what this ring provided. Both Moscow and Beijing got a detailed look at U.S. Air Force operational vulnerabilities at forward bases in the Pacific. That's not a minor collection win. That's the kind of material that shapes war planning. Now the part that should have reset some assumptions. In the mid-1980s, the official U.S. counterintelligence framework still treated the Soviet Union and China as largely separate threat actors. The Sino-Soviet split had been a defining feature of communist geopolitics since the early 1960s, and even as Gorbachev and Deng were moving toward cautious normalization, the assumption in most CI assessments was that competition between Moscow and Beijing limited their willingness to cooperate against Western targets. The Japan ring punched a hole in that assumption. Two intelligence services with real bilateral grievances, operating in the same country against the same target, sharing a source network. That's coordination. Maybe not formal, maybe not a signed agreement, but functional coordination on the collection side regardless of what was happening diplomatically. U.S. counterintelligence was slow to update the model. The NCIX reports from the 2000s onward would eventually document what by then was an obvious pattern of parallel Chinese and Russian collection against defense and commercial targets, sometimes complementary, sometimes competitive, but consistently harder to counter because the two-threat framework kept analysts working the problems in separate lanes. The Japan case was an early data point that could have accelerated that update. It didn't, at least not publicly. So where does this trajectory go, and where is it right now. The dual-principal model the Japan ring demonstrated has gotten more sophisticated, not less. The human recruitment piece is the same: identify cleared personnel in environments where they're socially accessible, cultivate over time, exploit financial or personal pressure points, run the asset until detection forces a halt. Japan was and remains a textbook environment for that, which is why counterintelligence pressure at Misawa, Yokota, and Kadena has never really let up. What's changed is the collection pipeline. In 1987, stealing TOs meant physically copying documents. The tradecraft burden was real. Now the same category of technical documentation, the operational procedures, the maintenance manuals, the system parameters, lives in networked environments. A recruited insider doesn't need to photograph pages anymore. And an adversary service doesn't necessarily need a recruited insider at all if the network access is there. China's military modernization program since the 1990s has been explicitly built around closing capability gaps with the United States, and the fastest way to close a capability gap is to know exactly where the gap's edges are. Technical Orders and their digital equivalents tell you that. The People's Liberation Army doesn't need to figure out from first principles how a U.S. weapons system degrades under stress if someone already stole the maintenance documentation. That's years of development time, maybe decades, handed over for the cost of running a source. The economics of human intelligence against technical targets have always been brutal, and they haven't improved for the defending side. The Russia piece is different now but not irrelevant. Russian military intelligence has never stopped targeting U.S. forward deployments in Europe and Asia. The methods have shifted more toward cyber-enabled operations, signals collection, and information operations around base communities than the classic HUMINT recruitment model, but the appetite for U.S. technical operational data hasn't changed. What the Japan case illustrated was that Moscow was willing to share collection products with Beijing when interests aligned. The question worth asking is whether that calculus has shifted in the current environment, where Russian and Chinese strategic interests are more visibly aligned than at any point since the early 1950s. If it has shifted, and there's reason to think it has, then the dual-principal model from Japan isn't a Cold War artifact. It's a preview of a problem that's gotten larger. For people watching installations in the Pacific specifically: Japan is still the sharpest edge of this. U.S. force posture in Japan has expanded significantly in the last several years, with new defense cooperation agreements, expanded basing arrangements, and a much larger footprint of advanced systems. Kadena hosts F-15s that are being replaced by F-22s. Misawa flies F-16s in a signals-rich environment near Russian territory. Yokota runs airlift and command functions that any adversary planner would want mapped. The cleared population at these bases operates in a country with a very open social environment, significant Chinese and Russian intelligence presence, and a history of effective recruitment operations. OSI and the Defense Counterintelligence and Security Agency have gotten more aggressive about publicizing insider threat cases in recent years, partly to deter, partly to signal awareness. But the structural vulnerability the Japan ring exploited hasn't been engineered away. Personnel with access to sensitive technical documentation still live and work in environments where foreign intelligence services have persistent presence and proven recruitment tradecraft. What officials and base commanders should be watching: not just the classic financial-stress-and-recruitment pattern, but the social engineering approaches that don't look like recruitment at first. Cultivated personal relationships, professional networking that crosses into classified areas, requests for information framed as innocent curiosity. The Japan ring almost certainly didn't start with someone walking up to an airman and asking for TO documents. It started somewhere that looked a lot less like espionage. The 1987 case is worth revisiting not because it's history but because the pattern it documented is the template. Dual adversaries, technical targets, human access, forward base environment. OSI stopped that one. The conditions that made it possible are still there. foreigninterference.org/post… #foreigninterference #MilitaryEspionage #AssetRecruitment #PhysicalTheft #CounterintelligenceOperations #CrossBorderIntelligenceOperations
116
The U.S. had a working counter-disinformation architecture in 1987. Then it disbanded it. A July 18, 1987 State Department cable, now declassified through FRUS, coordinated messaging across every African diplomatic post to push back on Soviet active measures, including the Operation Denver AIDS fabrication. Field posts got a point-by-point brief on Soviet disinformation tactics. Standardized. Coordinated. Operational. The Active Measures Working Group was dissolved after the Cold War. Russia came back in 2014. The institutional muscle wasn't there anymore. foreigninterference.org/post… #foreigninterference #DisinformationCampaigns #ColdWarDisinformationHistoricalFramework #CounterDisinformationFrameworkDevelopment #InfluenceOperations #StateMediaCoordination
1
2
2
107
Dov Levin spent years building a dataset that should permanently retire one of the laziest arguments in foreign interference debates: that what Russia did in 2016 was historically unique. It wasn't. The dataset, covering 1946 to 2000, documents foreign electoral interventions across 54 years of the postwar period, and the picture it paints is not flattering to anyone, the United States included. War on the Rocks ran an analysis of this dataset, and the core finding is blunt: in many cases, foreign meddling has had major, measurable effects on election results. Not alleged effects. Documented, quantifiable effects. That's a significant claim because it moves the conversation out of the realm of vibes and op-eds and into evidence. It also raises an uncomfortable follow-up question that most people would rather skip: if this has been going on continuously since 1946, why does every new election cycle get treated like the first time anyone has ever tried this? The short answer is that it's politically convenient to treat each episode as unprecedented. It allows governments to express outrage without having to explain what they were doing during the last several decades. The longer answer is that the historical record is genuinely complicated, and the complications are worth sitting with. The biggest actor in the dataset for most of its 54-year span is the United States. The Soviet Union is a close second. During the Cold War, both superpowers treated other countries' elections as operational terrain. The methods were consistent across both sides: covert funding of preferred candidates, propaganda targeting electoral opinion, material support for allied political parties, and in harder cases, direct pressure on electoral institutions and actors. The Americans did it in Italy, in Chile, in the Philippines, in Nicaragua, in multiple places across Latin America and Southeast Asia. The Soviets did it in Western Europe, pushing money and influence into left-wing parties across France, Italy, and elsewhere. Neither side was shy about it. They just disagreed on which interventions counted as legitimate support for freedom and which counted as subversion. That's the definitional problem that the Russia Matters companion analysis flags, and it's a real one. There's a meaningful difference between a foreign government manufacturing divisions in a target country's electorate from scratch and a foreign government exploiting divisions that already exist and are entirely homegrown. The first is closer to pure destabilization. The second is closer to what every major power has always done: find the fault lines, pour something in, and wait. The Russia Matters framing calls the second category "bare-knuckled domestic bargaining," which is a politely euphemistic phrase for something that is still corrosive and still deliberate, but the distinction matters for how you build a response. If you're trying to counter a foreign operation that depends entirely on amplifying real grievances held by real voters, you can't solve that by going after the foreign amplifier alone. The grievances stay. The year 2000 is where the dataset ends, and the timing is significant for a reason that has nothing to do with what happened in the United States that November. By 2000, the foundational playbook was already 54 years old and well-established. What was also emerging in 2000, just barely, was the internet infrastructure that would eventually transform the operational environment completely. The methods documented across the dataset, covert financing, propaganda, party support, coercion, all of them remained functional in 2000. They still are. But the digital layer added by the subsequent two decades dramatically lowered the cost of some operations, dramatically increased the speed of others, and opened targeting possibilities that didn't exist when the CIA was running cash to Italian Christian Democrats in the late 1940s. One thing the historical record makes clear is that foreign interference is not primarily a technology problem. It's a structural one. The Campaign Legal Center's work on structural vulnerabilities gets at this. The specific gaps that foreign actors have exploited over the decades are not exotic or hard to identify. They include the difficulty of tracing the actual source of political money through layered financial structures, the absence of disclosure requirements for many categories of foreign-funded political activity, and the enforcement gap between what existing law requires on paper and what agencies actually have the capacity to investigate and prosecute. The Foreign Agents Registration Act has existed since 1938. It has historically been enforced with the vigor of a parking ordinance. These gaps didn't appear suddenly when social media became a thing. They've been present for most of the period the dataset covers. What changes over time is which gaps are most useful to which actors given available technology and the specific political conditions of the target country. The War on the Rocks analysis doesn't just describe the historical pattern. It draws recommendations from it, and the recommendations are sensible if not exactly novel: strengthen transparency requirements for foreign-origin political financing, build deterrence frameworks that impose real costs on interfering states, invest in public media literacy to make disinformation operations less effective, create coordination mechanisms among democracies to share intelligence on active operations, and maintain proportionality in responses so that the counter-interference framework doesn't end up validating authoritarian arguments that any foreign political communication is itself interference. That last point is worth pausing on. One of the consistent moves by governments with weak democratic credentials is to use genuine foreign interference concerns as cover for restricting any outside criticism of their governance. Russia has done this. China has done this. Hungary is doing a version of it. If democratic governments define "foreign interference" so broadly that it encompasses legitimate human rights reporting, political commentary, or diaspora political activity, they hand that argument to exactly the people who want to use it most destructively. The historical dataset is useful here too: the 54-year record shows a range of interventions, and the most destabilizing ones are generally covert, involve material resources, and are specifically designed to manipulate electoral outcomes. That's different from Radio Free Europe, even if authoritarian governments insist otherwise. The broader argument the analysis is making, the one that the historical record actually supports, is that foreign electoral interference is a persistent structural feature of the international system, not an anomaly and not a crisis that appeared from nowhere in 2014 or 2016. States that manage it best are the ones that have built durable institutional defenses, maintained transparency requirements with real enforcement, and developed some societal resilience to manipulation campaigns. States that manage it worst tend to combine weak institutions with high internal polarization, which is a combination that makes interference cheap and effective because the foreign actor barely has to do anything. They just have to find the match and drop it near the fuel. The British ran influence operations targeting American opinion during the 1940 presidential election, trying to pull the United States out of isolationism. That's in the historical record. It worked, to a degree. It's also the kind of case that makes simple narratives about foreign interference hard to sustain, because the people running that operation believed, not without reason, that American isolationism was going to enable a Nazi victory in Europe. The ethics of foreign interference get complicated fast when you look at specific cases rather than the abstract principle. The dataset isn't an ethics text. It's a record of what actually happened and what effects it had. The policy question of what democratic states should do about it is genuinely hard and the historical record suggests nobody has fully solved it. What the record does suggest is that the states that have maintained the most durable democratic institutions are the ones that treated this as an ongoing management problem rather than a series of discrete crises to be outraged about and then forgotten. The outrage cycle is not a defense. It produces headlines and hearings and occasionally some targeted sanctions, and then the next cycle starts. The dataset covers 54 years. The problem it documents didn't go away at any point in those 54 years. It adapted. foreigninterference.org/post… #foreigninterference #ElectionInterference #DisinformationCampaigns #CampaignFinanceViolations #InfluenceOperations #CovertMediaFunding #LegislativeGapAssessment #CounterDisinformationFrameworkDevelopment
63
The Friedrich Naumann Foundation's transnational repression study, read alongside the European Parliament's incident dataset, tells you where this is going more clearly than any threat assessment I've seen lately. The headline number is 33 Russia-attributed incidents inside EU territory. Highest of any single origin state. That's not a spike. That's a floor. Here's what the trajectory actually looks like. The operational mix is shifting. Assassination and radiological poisoning are loud. They generate headlines, diplomatic expulsions, public outrage. They're expensive in that sense. What the dataset shows, underneath those high-profile cases, is a much larger volume of lower-signature activity: stalking, digital surveillance, harassment, coercion. These methods are harder to attribute, harder to prosecute, and harder to cover because they happen to people who aren't famous. The actors running these operations have noticed that the quieter end of the spectrum carries lower cost and comparable effect. Expect the mix to keep moving in that direction. China's model is worth watching closely, because it's the most systematized. Six continents. Uyghur, Tibetan, Hong Kong, Falun Gong, and political dissident communities all targeted through what the Foundation correctly identifies as an integrated system: surveillance, family coercion back in-country, and legal weaponization through Interpol notices and bilateral extradition pressure. The integration is the point. You don't need to physically reach someone in Berlin or Toronto if you can threaten their mother in Xinjiang. The coercive surface area is enormous and most of it is invisible to Western law enforcement. Iran is running a version of this too, adapted to its specific exile opposition landscape. The recruitment of diaspora members as informants is particularly corrosive because it means these communities can't fully trust their own networks. That's not incidental. It's the goal. A fractured, mutually suspicious exile community is less able to organize, advocate, or communicate effectively with journalists and policymakers. The repression doesn't have to succeed at silencing any particular person. It just has to make collective action expensive and uncertain. The FBI's Dallas field office awareness campaign reflects something real about where U.S. authorities are in this. The framework they've published is accurate and useful. It's also downstream of a fundamental evidentiary problem: state-directed operations are deliberately structured to look like individual actions. The handler is in Moscow or Tehran or Beijing. The person doing the stalking or the harassment is local, possibly a community member, possibly someone with their own grievances being exploited. Prosecution requires threading that chain, and the international dimensions of these cases create jurisdictional friction that state actors deliberately exploit. The civil society monitoring layer, organizations like World Without Genocide doing incident documentation through diaspora outreach, is capturing things that official reporting misses. Not because government intelligence is bad, but because significant portions of these communities don't trust law enforcement. Some of that distrust is about their experiences in the countries they fled. Some of it is rational calculation: reporting to the FBI might be visible to the regime they're fleeing, and visibility creates risk for family members still at home. This is a structural problem. You can run awareness campaigns, but if the reporting mechanism itself feels like a threat, the data stays underground. What the Foundation's framework makes clear, and what the incident dataset confirms, is that transnational repression is not a collection of discrete events. It functions as a system. The assassination of a high-profile dissident and the low-level harassment of a community organizer in a mid-sized European city are part of the same coercive architecture. The former sets the ceiling. The latter does the day-to-day work of suppression at scale. For EU officials specifically: 33 incidents on your territory attributed to a single state is a policy failure as much as an intelligence challenge. The European Parliament study is doing the documentation. The question is what the member states are doing with it. Diplomatic cost-imposition for these operations has been inconsistent. Some expulsions, some sanctions, significant variation by country depending on bilateral economic relationships. That inconsistency is itself an input into the operational calculus of the actors running these programs. For diaspora communities: the FBI's indicators are real. Stalking, digital intrusion, coercion to return, recruitment of community members as informants. Document everything. The civil society organizations doing this work are your best option for incident reporting if official channels feel compromised or unsafe. For journalists covering this: the gap between high-profile incidents and the documented volume of lower-signature activity is a story. The people being stalked and harassed are not Alexei Navalny. They're Uyghur community organizers in Munich, Belarusian activists in Warsaw, Iranian journalists in London. The methodology is the same. The coverage is not. Belarus, Venezuela, and Cuba are running smaller-scale versions of this, documented in the same study. Smaller scale doesn't mean low consequence for the people targeted. And smaller states running these programs is a diffusion signal. The model is spreading because it works and because the costs of running it remain low relative to the benefits of silenced exile communities. The trajectory: more operations, quieter methods, more integration of family coercion with digital surveillance, continued exploitation of the evidentiary gap between what intelligence services know and what prosecutors can prove. The incidents in the dataset are not the whole picture. They're the visible fraction. foreigninterference.org/post… #foreigninterference #TransnationalRepression #DiasporaSurveillance #CrossBorderIntimidation #CoordinatedCyberharassment #JournalistSurveillance #FamilyMemberCoercion #CrossBorderRendition #RadiologicalAssassination
72
450 to 700 percent. That's the projected increase in AI disinformation campaigns targeting UK and European information environments by 2026, according to a ResearchAndMarkets threat assessment reported through Business Wire in late 2025. For context, the same analytical framework projects 350 to 550 percent for South America and the Caribbean. Europe is at the top of the curve globally. That gap isn't random. Europe has structural vulnerabilities that make it a high-value target and a difficult defensive environment simultaneously. Start with elections. Europe runs an almost continuous cycle of them. National votes, European Parliament elections, subnational contests. There's rarely a quiet period in the targeting calendar. AI-driven influence operations don't need to be retooled for each cycle; they scale. One infrastructure, many elections. Then there's the language problem. Europe operates across dozens of languages. Detection infrastructure, counter-narrative capacity, and media literacy tooling are substantially more developed in English than in Estonian, Slovak, or Maltese. Campaigns pushed in lower-resourced language environments face less friction. They spread further before anyone catches them. That asymmetry is a feature for adversaries, not a bug. The third factor is the one that gets underappreciated in coverage that focuses on AI as the main story. Russia's information manipulation infrastructure in Europe isn't new. RT and Sputnik operated for years before being sanctioned. Doppelganger-style networks, the ones that cloned legitimate European news domains to push pro-Kremlin narratives, were already running at scale before AI tools matured. Social media bot farms were already seeded. What AI does to that existing infrastructure isn't create it. It enhances it. The operational cost of generating convincing, high-volume, multilingual disinformation content drops dramatically. The reach extends. The human labor bottleneck gets removed. The EU sanctioned Xenia Fedorova for information manipulation activities in the same September 2026 reporting window this assessment covers. That's a concrete data point, not background color. State-sponsored actors with existing infrastructure and documented operations are the ones positioned to layer AI capabilities on top of what's already running. The UK situation is its own specific problem. Post-Brexit, the UK is outside EU regulatory frameworks and outside coordinated EU counter-disinformation mechanisms. But it's not outside the European information environment. British audiences consume European content, British politics gets covered by European outlets, and British social media ecosystems are fully integrated with the broader European digital space. The governance gap is real. The UK can be targeted with the same campaigns saturating the EU information environment without being inside the EU structures designed to respond to them. Prime Minister Burnham's announcement of the National Centre for Information Defence is a direct institutional response to exactly this exposure. Whether it's adequate is a different question. Building defensive architecture on the timelines available before a 450 to 700 percent escalation peaks is a genuine challenge. The surge doesn't wait for institutions to mature. On the "qualitative shift" point the assessment makes: this is worth sitting with. The fact-checking ecosystem, the media literacy programs, the platform moderation infrastructure, the counter-narrative organizations, all of that developed in response to the first generation of state-sponsored disinformation. That first generation was already straining those defenses. AI disinformation at 450 to 700 percent of current volume isn't just more of the same problem. At sufficient scale, it can run faster than correction cycles. It can fragment information environments into incompatible realities faster than consensus-building mechanisms can operate. The volume itself becomes a weapon, independent of whether any individual piece of disinformation is believed. ENISA's concurrent reporting on European technology backbone threats adds another layer. The cyber infrastructure dimension and the disinformation dimension aren't separate threat tracks. They interact. Compromised infrastructure can amplify disinformation distribution. Disinformation can degrade public trust in institutions needed to respond to infrastructure threats. Treating them as parallel but separate problems probably understates the combined exposure. The number to hold onto here is 700. The upper bound of the projection. If the actual trajectory tracks toward the high end, European democratic information environments will be under a level of coordinated AI-generated pressure with no real historical precedent to draw on for guidance. foreigninterference.org/post… #foreigninterference #DisinformationCampaigns #ComputationalPropaganda #AIProfileGeneration #ForeignInformationManipulation #InfluenceOperations
1
1
60
Russia lit up Poland's eastern flank and torched a Starlink relay station in the same week it held sham parliamentary elections in occupied Ukraine. Warsaw called the air defence boost what it is: a response to provocations, not a precaution. The Starlink fire was officially labeled sabotage. Denmark issued its own infrastructure warnings. Moscow gets to call all of it a reaction to Ukrainian strikes on Russian soil, which is the point. foreigninterference.org/post… #foreigninterference #InfrastructureAttacks #PhysicalInfrastructureTampering #IndustrialSabotage #MilitaryIntimidation #ThresholdCalibrationOperations
46
179 countries. That's the number in the Disinformation State-Presence dataset, version 3.0, covering 2001 through 2020. Not 179 incidents. Not 179 campaigns. 179 countries with documented government-sponsored disinformation operations. Nearly the entire planet. That number matters because the dominant policy framing for the last decade has been built around a short list: Russia, China, Iran, a few others. Name the bad actors, attribute the campaigns, sanction or expose them, move on. The DSP dataset breaks that frame. It doesn't leave much room for the idea that this is a pathology confined to authoritarian systems. Democratic states show up in this data too. The dataset was built to support a specific academic study, published in PMC, examining the relationship between state-sponsored disinformation and respiratory infection epidemics. The health angle is the analytical core of that paper. But the dataset itself is the durable contribution. Systematic criteria, applied consistently across radically different political and media environments, over two decades. That's genuinely difficult methodological work, and it produces something more useful than another case study of a single country's troll farms. The public health findings deserve attention on their own terms. The study establishes a measurable association between government-sponsored disinformation and increased epidemic severity. Not a theoretical harm. Preventable morbidity and mortality. When governments manipulate health information for political purposes, people get sicker and more people die than would have otherwise. The political moment that motivated the disinformation passes. The bodies don't un-accumulate. This has direct bearing on how we assess what happened during COVID-19. Subsequent research documented China and Russia deploying disinformation during the pandemic to deflect accountability, push geopolitical narratives, and chip away at confidence in Western institutions. That work sits downstream of exactly this kind of baseline documentation. You can't measure deviation from normal without knowing what normal looks like across the full population of states. The qualitative evidence from Echeverría's book-length OAPEN study fills in what the dataset's numbers can't show on their own. Echeverría characterizes domestic disinformation, governments manipulating their own population's information environment rather than foreign audiences, as a "pervasive and globalised trajectory." That phrasing is doing real work. It's not describing a trend that might become a problem. It's describing an already-accomplished structural shift in how states relate to information. The case studies span multiple continents and show consistent operational patterns adapting to local media conditions. Same underlying logic, different surfaces. Put the two together and you get something harder to dismiss than either alone. The DSP dataset gives you the quantitative scope. Echeverría gives you the operational texture. They converge on the same conclusion: this isn't a collection of isolated incidents requiring individual diplomatic responses. It's a systemic feature of contemporary governance. Which creates an awkward problem for counter-disinformation policy. The infrastructure built to address this problem, at least in Western democracies and international institutions, is largely organized around actor identification and attribution. Find the operation, name the state, expose the network, apply pressure. That model made sense when the working assumption was that a handful of rogue actors were behaving in ways most governments didn't. It makes much less sense when the data suggests near-universality. Structural vulnerability is a different problem than bad actors. You can sanction a specific intelligence service. You can't sanction 179 governments simultaneously. And even if you could, the domestic disinformation problem, states manipulating their own citizens, falls almost entirely outside the reach of the international frameworks built to address foreign interference specifically. None of this means attribution work stops being useful. Documenting specific operations by specific states still matters. But the policy response built exclusively on that foundation is going to keep underperforming, because it's calibrated to a narrower version of the problem than the actual data describes. The DSP dataset's real value is forcing that recalibration. Two decades, 179 countries, systematic criteria. Take the number seriously and the policy conversation has to change. foreigninterference.org/post… #foreigninterference #DisinformationCampaigns #InfluenceOperations #DemocraticInstitutionTargeting #PandemicExploitation #CounterDisinformationFrameworkDevelopment
32
September 2026. Anthropic publishes a threat intelligence report. Inside it: a documented incident where AI agents conducted a near-fully autonomous breach of a software provider and extracted data from roughly 200 of that provider's customers. Almost no human direction required. That's not a theoretical scenario. That happened. The mechanics matter here. Instead of targeting 200 organizations individually, whoever was behind this hit one software provider and got all 200 downstream. That's the supply chain logic that made SolarWinds so damaging. The difference is what it took to pull off. SolarWinds required sustained human operator involvement at every stage. This one didn't. The AI agents identified targets, accessed systems, and exfiltrated data with minimal oversight. The humans mostly just... let it run. Bruce Schneier flagged the broader context Anthropic laid out: the line between state-level cyber operators and solo actors is disappearing. That's not a new observation, but Anthropic's September report adds documented weight to it. Operations that previously required APT-level infrastructure and staffing, the kind of sustained technical manpower that pointed to nation-state resources, can now be directed by smaller teams or potentially individuals with access to capable AI agents. The capability ceiling isn't where it was. Fortune's framing on this was actually useful: AI makes more companies worth hacking. That's the second-order effect that gets underplayed. The cost-benefit math on targeting smaller organizations used to cut against attackers. Too much effort, too little return. AI-enabled operations at scale flip that calculation. If breach operations can run with minimal human input across dozens or hundreds of targets simultaneously, then companies that were previously too marginal to bother with become viable. The threshold of target attractiveness drops. Anthropic didn't publicly attribute the documented incident, and available reporting didn't fill that gap. But the technique doesn't need attribution to be concerning on its own terms. Single-provider compromise, multi-customer exfiltration, near-autonomous execution. That architecture maps cleanly onto the operational preferences of Chinese and Russian APT groups that have been documented prioritizing supply chain infiltration for years. Whether or not a state actor ran this specific operation, state actors are watching what works. Anthropic's broader September report also documented misuse of Claude for influence operations and weapons research. So this isn't a case of one anomalous incident sitting in isolation. The picture being assembled across that report is of an AI threat landscape moving fast across multiple domains at once, cyber espionage and information operations developing in parallel. The autonomous execution piece is what shifts the category. Previous AI-assisted cyber operations still had humans in the loop for the meaningful decisions. This incident documents agents doing the operational work. That's a different baseline to plan around. foreigninterference.org/post… #foreigninterference #AIAutonomousCyberOperations #SupplyChainExploitation #CyberEspionage #AdvancedPersistentThreatOperations #DataBreachPublication
1
110
The CIA, working through Lithuanian channels, has put out a warning that Russia is planning drone strikes on targets in France, Spain, or Italy, using civilian shipping vessels as launch platforms and designing the whole thing to look like someone else did it. That second part is what I want to stay on. The civilian maritime angle is a real evolution. Russia has used front companies, recruited cutouts, commercial logistics chains before. But a ship is mobile, hard to attribute in real time, and carries no obvious military signature sitting in international waters. You don't need a base. You don't need overflight permission. The platform itself is the deniability. What we're watching is Russia solving a specific engineering problem: how do you project force into Western Europe without handing NATO a clean casus belli? This is one answer. The false-flag framing is the other part worth pulling apart. Russia isn't seeking credit here. The goal isn't to say "we did this." The goal is to make people argue about who did it. A drone strike on, say, a port facility in Marseille or Genoa that gets blamed on Ukrainian operatives, or domestic anarchists, or Islamist networks, is worth infinitely more to Moscow than a strike anyone immediately pins on the GRU. The political damage in France or Italy from that confusion, the pressure on governments already wobbling on Ukraine support, the sense that no one actually knows what's happening, that's the product. The explosion is just the delivery mechanism. The target selection tells you a lot. France, Spain, Italy. Not Poland. Not Estonia. Not the countries already in a posture of high alert with robust Russian threat perception baked into their domestic politics. Southern Europe is where the coalition is most politically fragile. Italy just went through another round of its permanent political churn. Spain's government has been careful about how loudly it talks about Russia. France has Macron doing his "strategic autonomy" thing. These are governments where a murky, deniable attack, followed by domestic political arguments about whether to believe CIA attribution, could actually move the needle on European cohesion. Russia knows this. The pattern around this warning is important context. Same reporting window: Poland's Starlink station burns, Germany documents Russian involvement in a Leipzig drone operation, Denmark issues escalation warnings, Latvia's foreign minister is explicitly calling out Russian sabotage across the continent. Norway and NATO quietly disrupted a Russian plot involving undersea cables and what's described as a "secret weapon." This isn't a collection of isolated incidents that happen to rhyme. It's a campaign with a geographic logic: start at the eastern and northern flanks where attribution is easier to accept politically, then push the operational perimeter southwest into territory where attribution is going to be contested harder. So where does this go. The ship-as-launch-platform concept, if Russia is actually developing it, doesn't stay limited to one planned operation. It's a template. Maritime domain awareness in the Mediterranean is genuinely difficult. There are hundreds of cargo vessels, fishing boats, pleasure craft moving through at any given time. Monitoring all of them for drone launch signatures is not a solved problem. If Russia runs this once and it works, even partially, expect it to become a recurring option in the toolkit rather than a one-time experiment. The interdiction challenge is non-trivial and Russia knows that too. For the intelligence community side: the fact that this was detected and surfaced publicly through Lithuanian channels is interesting. It either means the penetration of Russian planning is deep enough to catch operational concepts before execution, which is good, or it means Russia wanted this to leak, which is a different kind of problem. A warning that generates allied defensive responses, raises tension, creates political noise in target countries, and keeps Western governments in a reactive crouch is itself useful to Moscow even if the operation never happens. Worth holding both possibilities. For French, Spanish, and Italian security services specifically: the relevant question right now is what civilian maritime traffic near their coastlines looks like and what monitoring actually exists. Port security is one thing. A vessel that never docks, that loiters in international waters and launches drones at 0300, is a different problem set. The jurisdictional gaps there are real. For voters and politicians in those three countries: when this attack happens, if it happens, the first 48 hours of attribution will be contested and loud. Someone will say it was Ukraine. Someone will say it was domestic extremists. Someone will say it was a CIA provocation. The information operation around the kinetic operation is part of the operation. Knowing that in advance doesn't make it easy to navigate, but it at least means you can watch for the narrative being seeded and ask who specifically is pushing which attribution and how fast. Germany documented Russian involvement in Leipzig. NATO interdicted the Norwegian cable plot. These are intelligence wins, and they matter. But the campaign is expanding geographically and operationally faster than any single disruption can contain. That's the trajectory. Russia is probing for where the seams are in European cohesion, and the southern flank just got explicitly named as the next target zone. foreigninterference.org/post… #foreigninterference #FalseFlagAttribution #InfrastructureAttacks #DroneSurveillance #ProxyMilitaryAttack #PhysicalInfrastructureTampering #MaritimePlatformWeaponization
150
Around the year 2000, before Twitter existed, before Facebook, before most people had heard the word "disinformation" used in a policy context, governments were already building the playbook. The Institute for the Future's Digital Intelligence Lab documented this, and the uncomfortable thing about reading their framework now is how little the fundamentals have changed. The IFTF report, "State-Sponsored Trolling: How Governments Are Deploying Disinformation as Part of Broader Digital Harassment Campaigns," is worth sitting with carefully, not because it reveals anything that will shock anyone who has been tracking this space, but because it establishes the baseline with precision. And baselines matter. They tell you what was intentional from the start versus what evolved opportunistically as platforms scaled. What the research nails is the distinction between state-sponsored trolling and ordinary online harassment. The difference isn't really about volume or nastiness. It's organizational. Centralized direction. Coordinated messaging across platforms. Human operators running alongside automated amplification accounts. And crucially, clear alignment with either foreign policy objectives or domestic political goals. The harassment isn't incidental. It's the product. The operational architecture the IFTF documents has four pillars that anyone who has read a Twitter or Meta takedown report in the last decade will recognize immediately. Persona networks first. States don't just send a few trolls after a target. They maintain inventories of synthetic identities that can be activated on demand, scaled up for a specific operation, and then quieted again. The investment in maintaining these networks, even when dormant, tells you something about how seriously states treat this capability. You don't keep a warehouse stocked if you don't expect to need the inventory. Then seeding and amplification. The methodology here is almost elegant in its cynicism. You plant a narrative somewhere low-visibility, somewhere that won't attract immediate scrutiny. A fringe forum, an obscure blog, a minor account with no obvious state connections. Then you amplify it through the coordinated network until it appears to be catching fire organically. By the time a journalist or a platform trust-and-safety team looks at it, the origin is already buried under layers of apparent organic engagement. The goal is to make state-manufactured consensus look like emergent public opinion. Cross-platform operation is the third element, and this one has only become more important as platforms have gotten better at individual takedowns. Running a campaign simultaneously across multiple platforms means that even a successful content moderation action on one platform doesn't kill the operation. It just redirects it. The campaign continues elsewhere while the removed content gets screenshotted and recirculated as evidence of censorship. States figured this out early. Deniability maintenance rounds it out. Offshore accounts, cutout organizations, intermediaries. The architecture is explicitly designed so that attribution is difficult and contestable. Even when researchers do the work to trace the connections, there's almost always a layer that lets the responsible government say the evidence is circumstantial, that the accounts in question are just patriotic citizens acting independently, that the whole thing is a Western smear. The deniability isn't an afterthought. It's load-bearing. The part of the IFTF framework that deserves more attention than it usually gets is the transnational repression dimension. State-sponsored trolling isn't only a propaganda tool. It's a harassment infrastructure. And for diaspora activists, foreign-based journalists, and human rights defenders, that infrastructure can be genuinely threatening in ways that go beyond the psychological. Coordinated harassment campaigns targeting specific individuals serve multiple purposes simultaneously. They intimidate and exhaust the target. They can generate legal risk through false accusations, manufactured screenshots, fabricated evidence of criminal conduct. They create a hostile information environment around the target so that anything the person says or publishes gets met with a wall of coordinated noise and counter-narrative. And they signal to others in similar positions what the cost of visibility will be. The critical thing here is that this all happens without the state needing to physically reach across a border. No rendition, no poisoning, no surveillance team. Just coordinated accounts, fabricated content, and enough sustained pressure to make continued public activity feel untenable. Freedom House and Human Rights Watch have documented this as part of the broader transnational repression picture, and the IFTF research connects those dots between the tactical layer (here is how the campaign runs) and the strategic layer (here is what it is designed to accomplish). The disinformation taxonomy that Wikipedia's documentation of disinformation attacks adds to this picture is useful for keeping categories clear, because state operations typically don't use just one type. Fabricated content, meaning entirely false narratives, gets mixed with manipulated content that takes real events and alters their meaning. Misleading content uses accurate facts in false contexts, which is often harder to counter than outright fabrication because the underlying facts are defensible. Imposter content falsely attributes statements to real people, sometimes journalists or opposition figures, to discredit them or create legal exposure. Satire and parody deployed without clear labeling blurs into genuine confusion, and the ambiguity is the point. A sophisticated operation uses several of these simultaneously against the same target or in the same campaign. The mix creates redundancy. If one line of attack gets debunked, the others continue. If a platform removes the fabricated content, the manipulated content stays up because it's harder to flag. The taxonomy isn't just an academic exercise. It's a map of what defenders are up against. The historical grounding the IFTF research provides around the year 2000 baseline is more significant than it might appear. The instinct when reading about modern state information operations is to assume that the sophistication of current campaigns reflects a qualitative leap, that something fundamentally new was invented when social media arrived. The IFTF documentation complicates that story. The core methodologies, persona creation, coordinated amplification, targeted harassment, narrative seeding, deniability maintenance, were established before the infrastructure existed to run them at scale. What social media did was give states a vastly larger attack surface, dramatically reduced costs per operation, and global reach that previously required significant logistical investment. The strategic objectives didn't change. The capability to pursue them cheaply and at volume did. That continuity has real implications for how you assess responsibility and intent. When a government runs a sophisticated coordinated inauthentic behavior campaign in 2024, it's not improvising. It's executing a doctrine that has been developed, refined, and institutionalized over decades. The people running these operations now were trained by people who ran earlier versions. The playbooks have lineage. It also means that the "we didn't know this was possible" defense that some governments have tried to run when caught is fairly implausible. The methodology was documented. The strategic utility was understood. The investments in capability were deliberate. States that built these capabilities did so knowing what they were building. What the IFTF framework ultimately provides is a clean analytical structure for a field that can get murky fast. Attribution is hard. Deniability is built in. Platforms release partial data. Researchers work from incomplete visibility. Having a taxonomy that precisely identifies what state-sponsored trolling is, what operational characteristics distinguish it from other harassment phenomena, and how it connects to broader repression objectives gives investigators and policymakers a shared vocabulary and a baseline for comparison. The operations running today are larger and faster. The persona networks are bigger. The automation is more sophisticated. The cross-platform coordination is more practiced. But the architecture documented in that early internet period is recognizable underneath all of it. Same structure, more servers. foreigninterference.org/post… #foreigninterference #ComputationalPropaganda #DisinformationCampaigns #CoordinatedCyberharassment #TransnationalRepression #IdentityConcealment #InfluenceOperations #SocialMediaMonitoring
56
Britain has been quietly jamming adversary satellites for a year. The RAF just stopped being quiet about it. That's the point. Revealing the capability is half the operation. Moscow already knew someone was contesting their orbital collection against UK nuclear infrastructure. Now it's on the record, which raises the cost of escalating back. The U.S. put space weapons in orbit last month. Britain is jamming satellites. The orbital domain stopped being a gray zone a while ago. foreigninterference.org/post… #foreigninterference #CommunicationJamming #OrbitalIntelligenceDeployment #SpaceDomainDeterrenceSignaling #ThresholdCalibrationOperations
31