Entering the Cyber Battlespace
Digital Systems as Mission Terrain Evidence, Threat Intelligence, and Incident Response Authorization, Ethics, and Safe Practice What Cyberwarfare Is—and Is Not Cyberspace as an Operational Environment
The Road to Persistent Cyber Conflict
Estonia, Georgia, Stuxnet, and the First Shock Ukraine, 2015–2026: Campaigning Under Fire
Actors, Proxies, and Strategic Behavior
The State Cyber Ecosystem Strategic Cultures Without Stereotypes
Law, Authority, and Civilian Protection
Below Armed Conflict: Sovereignty, Intervention, Force, and Responsibility Armed Conflict: IHL and Cyber Effects
Intelligence, Indications, and Attribution
Intelligence Support to Cyber Operations Attribution Under Deception
Campaign Design and Command
From Policy Aim to Cyber Campaign Command, Authorities, and Deconfliction
Target Systems, Access, and Operational Security
Target-System Analysis and Cyber Key Terrain Access Stewardship, Capability Fit, and OPSEC
Effects Engineering and Campaign Assessment
Designing and Bounding Cyber Effects Measuring What the Campaign Changed
Critical Infrastructure and Cross-Domain Operations
Operational Technology, Safety, and Restoration Space, Telecommunications, and Multi-Domain Integration
Influence, Perception, and Public Truth
Cyber-Enabled Influence Operations Defending Truth, Trust, and Decision Space
Daily Defence in Competition and War
Mission Assurance and the Wartime Operations Floor Continuity, Recovery, and Collective Defence
Deterrence, Emerging Change, and the Final Campaign
Deterrence, Norms, and Collective Response The 2026 Horizon: AI, Supply Chains, Edge, and Identity Capstone: Build, Challenge, and Defend a Cyber Campaign
Influence, Perception, and Public Truth

Cyber-Enabled Influence Operations

Follow stolen or fabricated material from acquisition through framing, laundering, amplification, and audience response.

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.

In this lesson, you will learn to:

  • Map an influence campaign and distinguish reach, engagement, belief, behavior, and strategic effect.

Cyber-Enabled Influence Operations

This lesson joins technical intrusion analysis with audience and narrative analysis. It uses election, Olympic, and wartime examples to expose the full influence chain.

Treat intrusion and narrative as one campaign

The field guide to cyber-enabled influence operations and hack-and-leak response provides the full evidence model, persona and laundering analysis, authenticity workflow, communication plan, and measurement method used in this lesson.

A hack-and-leak campaign selects targets for the information and story they can produce. The chain includes access, collection, selection, alteration or fabrication, persona preparation, timed release, laundering through intermediaries, amplification, and audience adaptation. Technical teams that stop at exfiltration miss the objective.

The GRU-related cases described by US indictments include theft and release of anti-doping records under the Fancy Bears persona and targeting around the 2017 French election. Material may be authentic, selectively edited, mixed with falsehood, or framed misleadingly. Authenticity of one document does not validate the narrative built around the collection.

DDoS and defacement can serve cognitive effect by creating visible proof for a claim of power or collapse. Measure availability separately from attention, reach, belief, behavior, and policy consequence. Large engagement may reflect opposition or curiosity rather than persuasion.

Add AI without magical thinking

In cyberwarfare influence campaigns, generative AI reduces the cost of translation, persona content, targeting research, variation, and scale. Google’s 2025 reporting found government-backed actors using Gemini mainly to assist familiar tasks rather than create unprecedented capability; its 2026 reporting describes maturation toward industrial-scale workflow augmentation and AI-assisted vulnerability work. The practical change is tempo and volume, not the disappearance of human objectives and constraints.

Track model use as part of the production system: inputs, operator review, distribution, platform controls, and feedback. Synthetic content can saturate verification and create “liar’s dividend,” but high volume can also create recognizable patterns. Defenders need provenance where available, behavior-based detection, rapid verification, and trusted human channels.

Resources