People often imagine disinformation as a lie wearing a cheap moustache. In practice, the most effective versions are far better dressed.
The photograph may be genuine. The statistic may be accurate. The document may be authentic. Yet the photograph is from another war, the statistic has lost its denominator, and the document has been released at precisely the moment when it can cause maximum damage.
Disinformation works by counterfeiting one or more of three things:
- The messenger: Who supposedly created or shared the information?
- The meaning: How should genuine facts, images or statistics be interpreted?
- Reality itself: Did the reported event, statement or evidence ever exist?
Researchers Claire Wardle and Hossein Derakhshan identify seven major forms of problematic information: satire or parody, false connection, misleading content, false context, impostor content, manipulated content and fabricated content. These categories often overlap, and the same campaign may use several at once.
Read the Information Disorder report
Before Entering the Factory: Three Important Definitions
- Misinformation is false information shared without an intention to cause harm.
- Disinformation is false information deliberately created or distributed to deceive or harm.
- Malinformation is genuine information used strategically to cause harm, such as private information released selectively or at a damaging moment.
The difference is often not the post itself, but the intention and circumstances surrounding it.
Part I: Faking the Messenger
1. Impostor Content: Borrowing Somebody Else’s Credibility
Instead of inventing a new source, a disinformation operator can impersonate one that people already trust. A copied logo, familiar page layout and almost-correct web address can turn an anonymous claim into something that appears to come from a newspaper, government department, university or international organization.
A striking example is the Doppelganger operation documented by EU DisinfoLab. Investigators found websites imitating at least 17 established media organizations, including Bild, 20 Minutes, The Guardian and ANSA. Operators bought domains resembling those of legitimate outlets, copied their visual designs and published fake articles, videos and polls.
Read EU DisinfoLab’s investigation
In 2024, the United States Department of Justice announced the seizure of 32 domains allegedly used in a related Russian government-directed campaign. According to the department, the operation used copied news sites, advertisements, artificial intelligence tools and social media profiles posing as ordinary citizens to direct readers toward counterfeit pages.
Read the US Department of Justice announcement
Why this strategy is effective: Impostor content does not need to build trust from scratch. It steals the accumulated reputation of a familiar institution. Readers may recognize the logo and stop checking.
Why it is difficult to counter: Fact-checking the article’s claims is not enough. Investigators must also inspect domain names, publication histories, account creation dates and technical infrastructure. Counterfeit sites can disappear and reappear under new addresses, making them slippery digital eels.
2. False Personas and Astroturfing: Manufacturing a Crowd
Sometimes the message is less important than the apparent identity of the people spreading it. Operators create fake local activists, concerned parents, veterans, journalists or community organizations. A centrally managed campaign then appears to be an organic public movement.
The 2018 United States indictment of individuals associated with the Internet Research Agency alleged that Russian operators created hundreds of social media accounts posing as Americans. They purchased advertisements, contacted real activists and organized political rallies. The indictment described the use of opposing personas and campaigns, allowing the same operation to inflame multiple sides of a dispute.
The Department of Justice explicitly noted that the charges did not establish that the conduct changed the election result.
Read the Department of Justice indictment summary
Why this strategy is effective: Astroturfing creates the illusion of consensus. People are influenced not only by evidence but also by what appears to be the opinion of their community. A hundred coordinated accounts can make a marginal claim look like a public uprising.
Why it is difficult to counter: An individual post may contain no obviously false statement. The deception becomes visible only when analysts examine synchronized posting, repeated wording, shared infrastructure, unusual account networks and concealed organizational control. Moderators must also distinguish manipulation from genuine collective action.
3. Synthetic Impersonation: Making Someone Appear to Speak
Deepfakes and cloned voices extend impostor content into audiovisual territory. The attacker does not merely imitate a news organization. The attacker manufactures the apparent presence of a real person.
In March 2022, a fabricated video appeared to show Ukrainian President Volodymyr Zelenskyy telling Ukrainians to put down their weapons. The video was technically poor and quickly exposed, but it demonstrated how synthetic media could be inserted into a military crisis, when audiences have little time to verify what they see.
Read Reuters’ report on the Zelenskyy deepfake
Why this strategy is effective: Video and audio create a feeling of direct witnessing. A written claim says, “This person surrendered.” A deepfake appears to say, “Watch the surrender happening.”
Why it is difficult to counter: Detection is a moving target. Compression, reposting and screen recording can erase forensic clues. Even an unsuccessful deepfake can create general uncertainty, allowing people to dismiss authentic recordings as artificial. Verification increasingly requires trusted publication channels, provenance records and independent corroboration.
Part II: Faking the Meaning
4. False Connection: When the Headline, Image and Story Do Not Agree
False connection occurs when a headline, photograph, caption or thumbnail creates an impression that the underlying material does not support.
A revealing experiment came from the satirical website Science Post, which published the headline, “Study: 70% of Facebook users only read the headline of science stories before commenting.” Beneath the opening paragraph was largely meaningless placeholder text. The headline nevertheless circulated widely, illustrating how a claim can travel independently of the content supposedly supporting it.
Read The Washington Post’s discussion of headline-only sharing
In deliberate disinformation, the same structure can be used without the joke. A dramatic photograph may accompany an unrelated article, a cautious scientific paper may receive a sensational headline, or a video thumbnail may depict an event absent from the footage.
Why this strategy is effective: The headline reaches people who never open the article. It can plant an association between a person and an accusation even when the article quietly concedes that the evidence is weak.
Why it is difficult to counter: Platforms often distribute headlines, thumbnails and fragments rather than complete articles. A correction buried in paragraph twelve cannot repair an impression formed in half a second while scrolling.
5. Misleading Framing: Using Facts to Manufacture a False Conclusion
Misleading content frequently contains real numbers, genuine quotations or accurate observations. The deception lies in what is omitted, compared or implied.
During the COVID-19 pandemic, posts argued that vaccines were ineffective because a large number, or sometimes a majority, of recorded COVID-19 deaths occurred among vaccinated people. The raw count could be accurate in highly vaccinated populations, but it ignored the much larger size and older age profile of the vaccinated group. When mortality rates were compared properly, the risk of severe illness and death was lower among vaccinated adults.
Read Reuters’ explanation of the statistical issue
The numbers were not necessarily invented. Their meaning was bent.
Common framing techniques include:
- Reporting totals while hiding rates or denominators
- Selecting a convenient starting date
- Comparing unlike populations
- Quoting a person accurately but removing the surrounding explanation
- Presenting correlation as proof of causation
- Highlighting one study while ignoring the larger body of evidence
Why this strategy is effective: Misleading framing offers plausible deniability. The operator can say, “Every number I used was real.” It is also highly adaptable, because the same dataset can be sliced into many emotionally useful shapes.
Why it is difficult to counter: A simple “true” or “false” label is inadequate. Correcting the claim may require explaining statistics, sampling, confounding variables and uncertainty. The misleading version fits on a meme; the correction arrives carrying luggage.
6. False Context: Genuine Evidence from the Wrong Place or Time
False context attaches an inaccurate date, location, identity or event to authentic material. It is among the cheapest and most effective forms of visual deception because no sophisticated editing is required.
At the beginning of Russia’s 2022 invasion of Ukraine, a dramatic video was shared as footage of a Russian aircraft being shot down. The clip was genuine, but it actually showed a warplane being downed in Libya in 2011. Other old images and videos were similarly recirculated as evidence of current events.
Read the Associated Press fact check
In another case, a 2016 photograph of Ukrainian children saluting troops was shared as though it had been taken during the 2022 invasion.
Read the Associated Press report on the reused photograph
Why this strategy is effective: Genuine media looks convincing because its pixels contain no obvious fabrication. The emotional impact is real even when the caption is false. Old disasters also provide an enormous warehouse of reusable smoke, explosions and frightened crowds.
Why it is difficult to counter: Image-forensic tools may correctly conclude that the photograph is authentic while missing that it has been miscaptioned. Verification requires reverse-image searching, geolocation, weather analysis, landmark comparison and investigation of the earliest known upload.
Part III: Faking Reality
7. Manipulated Content: Editing Genuine Material to Change Its Message
Manipulated content begins with something real and alters it. The change may be crude, such as cropping out relevant details, or subtle, such as changing playback speed, removing a sentence or rearranging several clips.
In 2019, a video of United States House Speaker Nancy Pelosi was slowed to make her speech appear slurred. The underlying footage was genuine, but the altered speed created a false impression about her condition.
Read the Associated Press report on the altered Pelosi video
Manipulation can include:
- Cropping a photograph to remove explanatory context
- Splicing sentences from different moments
- Changing audio speed or pitch
- Adding or deleting people and objects
- Altering screenshots
- Translating speech inaccurately
- Editing charts by truncating axes or changing labels
Why this strategy is effective: Manipulated material retains a visible connection to reality. Viewers can recognize the person, location or event, which makes the alteration harder to reject than a completely invented story.
Why it is difficult to counter: The question is no longer simply, “Is this file genuine?” Investigators must determine which parts are genuine, what was changed and whether the alteration affects the meaning. Small edits can require frame-by-frame comparison with the original recording.
8. Fabricated Content: Inventing the Event Itself
Fabricated content is the classic all-out falsehood: a nonexistent quotation, invented document, fictional crime, fake scientific discovery or event that never occurred.
One of the most widely discussed examples from the 2016 United States election was a completely false article claiming that Pope Francis had endorsed Donald Trump. The story imitated the structure of political reporting but had no factual basis. It became a standard example in later information-disorder research.
Read the Information Disorder report
Another modern variant is the fully fabricated “news video.” In 2023, a clip imitating BBC News branding falsely claimed that Ukraine had supplied weapons to Hamas. The BBC and Bellingcat confirmed that the video was not their work and that the supposed report did not exist.
Read the Associated Press fact check
Why this strategy is effective: Fabrication gives the operator complete narrative freedom. There is no inconvenient evidence to accommodate, because the quotation, witness and event can all be designed for maximum emotional impact.
Why it is difficult to counter: Individual fabrications can sometimes be disproved quickly, but unlimited new ones can be produced at low cost. The defender must investigate every claim; the fabricator merely presses “publish” again. Corrections also tend to travel less dramatically than the original accusation.
Part IV: The Borderlands
9. Satire Stripped of Its Warning Label
Satire is not inherently disinformation. Its purpose is usually criticism, comedy or exaggeration, and it does not depend on audiences believing it literally.
Trouble begins when satirical material loses its source label or is deliberately presented as genuine.
In 2012, China’s People’s Daily treated an Onion article naming Kim Jong-un its “Sexiest Man Alive” as a real accolade and produced an extensive online photo presentation. The original item was an obvious joke to its intended audience, but that context did not survive its journey.
Read Reuters’ report on the incident
More recently, Reuters documented a fabricated screenshot styled as a Donald Trump social-media post. It originated as satire but was subsequently shared without that context by users who appeared to regard it as authentic.
Why this strategy is effective when weaponized: Satire is emotional, memorable and highly shareable. A malicious distributor can also retreat behind “It was only a joke” after the false impression has spread.
Why it is difficult to counter: Satire is legitimate expression. Platforms cannot simply remove every absurd or fictional statement. The task is to identify when parody has been deceptively relabeled, not to appoint an algorithm as the Minister of Humor.
10. Malinformation: Using Truth as a Weapon
Not every harmful information operation depends on false content. Genuine documents, private correspondence or personal information can be selectively released, stripped of context or timed for maximum disruption.
During the 2017 French presidential election, emails from Emmanuel Macron’s campaign were released shortly before the legally mandated media blackout preceding the final vote. The Information Disorder report classifies this as malinformation: substantially genuine private material deployed at a moment designed to maximize harm and minimize the opportunity for examination or response.
Read the Information Disorder report
Why this strategy is effective: Authentic documents are difficult to dismiss. A large leak also creates an information avalanche in which journalists and citizens cannot examine every file before rumors and selective interpretations begin circulating.
Why it is difficult to counter: Suppressing genuine information can conflict with press freedom and the public interest. Journalists must distinguish legitimate revelations from strategically curated dumps, protect private individuals and avoid amplifying unsupported interpretations.
Why Disinformation Campaigns Combine These Strategies
The most sophisticated disinformation does not choose only one drawer from the toolbox.
A campaign might:
- Create a fabricated claim.
- Publish it on a cloned newspaper website.
- Attach an authentic but unrelated photograph.
- Promote it through fake local personas.
- Use genuine statistics framed misleadingly.
- Encourage real users and journalists to debate it.
- Claim censorship when platforms intervene.
The objective is often not to make everyone believe one specific story. It may be enough to produce confusion, exhaust investigators, inflame existing divisions or make citizens conclude that no source can be trusted.
This is why disinformation cannot be addressed through fact-checking alone. Source-checking is equally important, because the origin of a message may reveal more than its surface content. Visual misinformation is particularly difficult to trace, and careless debunking can provide additional publicity to a previously obscure claim.
A Practical Checklist for Evaluating Suspicious Information
Who Is Speaking?
- Is this the authentic account, website or institution?
- Is the domain name spelled correctly?
- Can the statement be found on the organization’s official channels?
- Does the account have a credible posting history?
What Has Been Done to the Meaning?
- Does the headline accurately reflect the article?
- Is the statistic a rate or merely a total?
- What information is missing from the quotation?
- Is the image really from the stated date and location?
What Has Been Done to Reality?
- Has the audio been slowed, clipped or synthetically generated?
- Does an earlier version of the image or video exist?
- Do independent sources confirm that the event occurred?
- Can the original document, recording or dataset be located?
Conclusion: There Is No Single Antidote
The central lesson is simple: disinformation is not merely false content. It is the engineering of false belief.
Sometimes it counterfeits the speaker. Sometimes it bends a fact until it points in the opposite direction. Sometimes it manufactures an event from empty air. Sometimes it uses the truth itself as a blade.
Recognizing which component has been falsified is the first step toward choosing the right response. A false statistic needs analysis. A stolen photograph needs provenance. A cloned newspaper needs source verification. A coordinated influence network needs behavioral investigation.
There is no single antidote because there is no single poison. The information factory has many assembly lines, and each leaves a different kind of fingerprint.
No comments:
Post a Comment