By Md. Tauhid Hossain Rubel
Doctoral Researcher | Artificial Intelligence, Data Analytics, Cybersecurity & Financial Intelligence
United States
This is the LinkedIn summary of my full Medium article. Read the full version here: https://mdtauhidhossainrubel.medium.com/disinformation-is-a-cyberattack-635a98343c1c?sharedUserId=mdtauhidhossainrubel
Foreign influence campaigns look like a communication problem. Underneath, they use hacker methods. Attackers take over accounts, build fake profiles, rent hidden servers, and post in a planned way. The FBI Internet Crime Complaint Center logged 1,008,597 complaints and $20.877 billion in losses in 2025, up 26% from 2024 (FBI IC3, 2026). This summary shows the pattern, two federal cases, and one step that any business or agency can take now.
Keywords: Disinformation; Cybersecurity; National Security; U.S. Economy; Critical Infrastructure; Public Trust
Why This Matters to Business Leaders
Leaders already know that a data breach can hurt revenue and reputation. Fewer leaders know that a false story can do the same. A fake post about a product failure, a fake claim about a power outage, or a leaked and edited email can spread in hours.
The national picture shows the scale. IC3 received more than one million complaints in 2025, close to 3,000 a day (Morris, 2026). Losses were $10.3 billion in 2023, $16.6 billion in 2024, and $20.877 billion in 2025 (Fox Baltimore, 2026). The 2025 report also included an AI section for the first time, with 22,364 complaints and about $893 million in losses (FBI IC3, 2026).
Most of this money is lost to criminals and not to governments. Still, the tools are shared. Phishing, fake profiles, and social engineering are the base of both. When you block them, you cut both risks.
The Gap in Many Organizations
Most firms have two teams that rarely meet. The security team watches networks. The communications team watches the public. A state sponsored campaign is built to sit between them. An attacker breaks into an account, and then uses it to carry a message. The security team sees a login problem. The communications team sees a rumor. Nobody sees one incident.
CISA has said that foreign actors can mix influence operations with cyber activity, and that this needs a response by the whole organization (CISA, 2022). This is the key idea. The answer is not a bigger post removal team. The answer is one incident process.
Five Steps of the Attack
A disinformation campaign follows a chain that security teams already know.
Recon. The attacker studies a topic or a target.
Access. The attacker uses phishing or stolen passwords to take over real accounts.
Build. The attacker creates fake profiles and the servers needed to register them.
Amplify. The accounts post and share each other in a planned way.
Impact. People lose trust, send money, or share data. Stolen material may be leaked at a chosen time.
The five steps shared by disinformation campaigns and cyberattacks.
Two Real Cases
The Russian bot farm, 2024. The Justice Department seized two domain names and searched 968 accounts on X (UPI, 2024). The accounts were made with AI software called Meliorator, and many claimed to be American (The Hacker News, 2024). The project was tied to an employee of RT, a Russian state owned outlet. FBI Director Christopher Wray called it “a first in disrupting a Russian-sponsored Generative AI-enhanced social media bot farm” (Associated Press, 2024).
The Iranian hack and leak, 2024. The FBI, ODNI, and CISA said Iran was behind a hack of the Trump campaign, and that Iranian linked actors also targeted people tied to the Harris campaign (Nextgov, 2024). Later, the Justice Department charged three Iranian hackers linked to the Islamic Revolutionary Guard Corps. The charges said they took over personal accounts and tried to pass stolen material to media outlets and to people tied to the other campaign (Secureblink, 2024).
What Is Changing in 2026
Federal support is shifting. The Center for Democracy and Technology reports that CISA has cut more than a third of its workforce since February 2025 and halted most election programs (Center for Democracy and Technology, 2026). In 2026, Senator Mark Warner asked DHS what CISA is doing to warn local officials about malign influence, and he cited testimony that foreign adversaries are expected to target the 2026 elections (Nextgov, 2026).
DHS released a 13 page plan in late September 2026 for the November 3 midterms, covering cyber and physical threats and Russian disinformation (CiberCuba, 2026). Leaders should follow how it is carried out.
For companies and local agencies, the message is practical. Do not wait for outside help. Build the basic plan yourself.
One Step to Take Now
Write an MDM incident response plan, as CISA advises (CISA, 2022). Keep it to one or two pages.
• Name one leader for the plan.
• Name who speaks to the public.
• Name who watches logs for fake or hijacked accounts.
• Link the plan to your normal incident process, using the respond and communicate functions of NIST CSF 2.0 (NIST, 2024).
• Turn on multi factor authentication for staff and brand accounts, as the FBI advises (TechRadar, 2024).
• Run one drill a year with security and communications together.
Protect free speech while you do this. Focus on fake identities, stolen accounts, and hidden foreign control, and leave lawful opinion alone.
What Leaders Often Get Wrong
They treat it as a one time event. A false story may come back many times, and each wave may use new accounts. A standing plan works better than a one time fix.
They wait for a platform to act. Platforms help, but the first harm often lands on your own customers and staff. Own your response.
They focus only on the post. The post is the visible part. The hidden part is the account, the server, and the login. If you watch only the post, you miss the source.
They forget the human side. Phishing is still the easiest way in. A short staff lesson on fake emails and fake login pages is one of the best low cost steps you can take. WaterISAC told its members to prioritize defenses against phishing, credential compromise, and financial fraud (WaterISAC, 2026).
A Quick Test for Your Team
Ask your team three questions this week.
- If a fake post about our company went viral tonight, who would lead the response?
- If a staff member lost control of a brand account, how fast could we lock it?
- Do our security and communications teams share one contact list and one plan? If the answer to any of these is not clear, you have found your first task.
What Good Looks Like in 90 Days
In the first month, finish the basics. List your official accounts, lock them with multi factor authentication, and name the three roles in your plan.
In the second month, test the plan. Hold a short drill that starts with a fake post and a fake phishing email at the same time. See how fast the two teams find each other. Write down what went wrong.
In the third month, improve. Fix the gaps, add alerts for your brand name, and share the plan with your board or leadership group. Plan the next drill.
This is not a large project. It is a habit. Organizations that build the habit will be calmer and faster when a real campaign arrives.
Why It Is a National Interest
This approach protects economic growth by cutting fraud and false stories. It supports national security by protecting critical infrastructure. It builds resilience through clear plans. It supports U.S. leadership, since the bot farm case involved Canadian and Dutch partners (Security Boulevard, 2024). It also builds a workforce that can read both network logs and social patterns.
Conclusion
Disinformation is not only a message problem. It is an attack that uses stolen access, hidden servers, and fake people. If leaders write the plan, name the owners, protect the accounts, and practice, they will protect their organizations and the trust that supports the U.S. economy.
Read the full article with more data, cases, and references on Medium: https://mdtauhidhossainrubel.medium.com/disinformation-is-a-cyberattack-635a98343c1c?sharedUserId=mdtauhidhossainrubel
Expert Voices
• Jen Easterly, former CISA Director, on preparing for foreign influence. Source: Wash100
• Christopher Wray, former FBI Director, on the AI bot farm. Source: Associated Press via ClickOrlando
• Matthew Olsen, Assistant Attorney General, on Iranian hack and leak. Source: Secureblink
• Adrian Fontes, Arizona Secretary of State, on federal election support. Source: Brennan Center
Declaration of Original Work
I, Md. Tauhid Hossain Rubel, declare that this article is not copied from any other source. I collected facts and figures from public data sources such as the FBI IC3, CISA, the Department of Justice, and news reports, and I list each one in the references. I wrote the analysis with the help of AI. Short quotes are marked and linked to their sources.
References
Associated Press. (2024, July 9). US disrupts Russian government-backed disinformation campaign that relied on AI technology. ClickOrlando. https://www.clickorlando.com/news/world/2024/07/09/us-disrupts-russian-government-backed-disinformation-campaign-that-relied-on-ai-technology/
Center for Democracy and Technology. (2026). Countdown to the midterms: Mapping the rapid evolution of election security. https://cdt.org/insights/countdown-to-the-midterms-mapping-the-rapid-evolution-of-election-security/
CiberCuba. (2026, September 25). The U.S. presents a plan to protect the 2026 elections against cyberattacks and physical threats. https://en.cibercuba.com/noticias/2026-09-25-u1-e208574-s27061-nid341173-eeuu-presenta-plan-proteger-elecciones-2026-ataques
Cybersecurity and Infrastructure Security Agency. (2022). Preparing for and mitigating foreign influence operations targeting critical infrastructure (CISA Insights). https://www.cisa.gov/mdm-resource-library
Federal Bureau of Investigation, Internet Crime Complaint Center. (2026). 2025 Internet crime report. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
Fox Baltimore. (2026). Americans lost over $20 billion in 2025 to online scams, FBI report finds. https://foxbaltimore.com/news/nation-world/americans-lost-over-20-billion-in-2025-to-online-scams-fbi-report-finds-cryptocurrency-online
Morris, L. (2026). FBI cybercrime report reveals $20.8 billion lost in 2025. National CIO Review. https://nationalcioreview.com/articles-insights/extra-bytes/fbi-cybercrime-report-reveals-20-8-billion-lost-in-2025/
National Institute of Standards and Technology. (2024). The NIST cybersecurity framework (CSF) 2.0 (NIST CSWP 29). https://www.nist.gov/cyberframework
Nextgov. (2024, August 20). US agencies conclude Iran was behind hack targeting Trump campaign. https://www.nextgov.com/cybersecurity/2024/08/us-agencies-conclude-iran-was-behind-hack-targeting-trump-campaign/398935/
Nextgov. (2026, May). Senator warns CISA election security pullback could leave midterms vulnerable. https://www.nextgov.com/cybersecurity/2026/05/senator-warns-cisa-election-security-pullback-could-leave-midterms-vulnerable/413378/
Secureblink. (2024). Iranian hackers indicted for 2024 U.S. election hack and leak plot. https://www.secureblink.com/threat-feeds/iranian-hackers-indicted-for-2024-u-s-election-hack-and-leak-plot
Security Boulevard. (2024). DOJ shutters massive Russian bot farm spreading disinformation. https://securityboulevard.com/2024/07/doj-shutters-massive-russian-bot-farm-spreading-disinformation
TechRadar. (2024). FBI says it is sure Iran was to blame for Trump campaign hack. https://www.techradar.com/pro/iran-behind-trump-hack-fbi-confirms
The Hacker News. (2024). U.S. seizes domains used by AI-powered Russian bot farm for disinformation. https://thehackernews.com/2024/07/us-seizes-domains-used-by-ai-powered.html
UPI. (2024, July 10). U.S. foils Russian AI-enhanced bot farm of nearly 1,000 X accounts. https://www.upi.com/amp/Top_News/US/2024/07/10/DOJ-foils-Russian-bot-farm/5311720595912/
WaterISAC. (2026, April 9). FBI’s IC3 releases 2025 Internet Crime Report. https://www.waterisac.org/?p=65669
Author Note
Md. Tauhid Hossain Rubel is a doctoral researcher in Artificial Intelligence, Data Analytics, Cybersecurity, and Financial Intelligence. His work focuses on protecting U.S. economic resilience, critical infrastructure, and public trust through data driven security.
Top comments (0)