How online disinformation networks work, from Southport riots to black PR firms
False claims about the Southport attacker reached 155 million impressions on X in under two weeks, according to a July 2025 parliamentary report. The riots that followed showed how disinformation networks turn a lie into street violence.

On 29 July 2024, three children were killed at a dance class in Southport, northwest England. Within hours, false claims about the attacker's name, religion and migration status were circulating on social media. By 3 p.m. the following day, one false name had more than 30,000 mentions on X alone, according to Hannah Rose of the Institute for Strategic Dialogue, quoted by CNBC.
That is the anatomy of a modern disinformation network: a real event, a fast and false narrative, algorithmic amplification, and offline consequences. Police debunked the claims the day after they emerged, saying the suspect was born in Britain. By then the narrative had already gained traction.
What a disinformation network actually is
The term covers a lot of ground. At one end are loosely connected accounts that pile onto a breaking news story. At the other are commercial operations that sell manipulation as a service, often called black PR.
A BuzzFeed News review of platform takedowns and security-firm investigations found that since 2011 at least 27 online information operations had been partially or wholly attributed to PR or marketing firms. Nineteen of those occurred in 2019 alone. The review was reported in partnership with the Reporter, an investigative news site in Taiwan.
Nathaniel Gleicher, Facebook's head of cybersecurity policy, told BuzzFeed News that "the professionalization of deception" is a growing threat. "The broader notion of deception and influence operations has been around for some time, but over the past several years, we have seen [...] companies grow up that basically build their business model around deception," he said.
One example: the Archimedes Group, an Israeli firm that built networks of hundreds of Facebook pages, accounts and groups. Its website promised to "use every tool and take every advantage available in order to change reality according to our client's wishes." In Mali it ran a fake fact-checking page that claimed to be run by local students. In Tunisia it ran a page titled "Stop a la Desinformation et aux Mensonges." In Nigeria it ran pages both for and against the same politician, former vice president Atiku Abubakar.
The pipeline: scrape, rewrite, publish, amplify
Peng Kuan Chin, a 32-year-old based in Taichung, Taiwan, showed the Reporter how his system worked. Servers crawled the web for Chinese articles and posts, reorganised the words and sentences into new text, then published the output across a set of websites he controlled. Thousands of fake social media accounts pushed it into feeds, messaging apps and search results.
"I developed this for manipulating public opinion," Peng told the Reporter. Automation and artificial intelligence "can quickly generate traffic and publicity much faster than people."
His clients were companies, brands, political parties and candidates in Asia. "Customers have money, and I don't care what they buy," he said.
Not every operation relies on custom software. In Ukraine, the PR firm Pragmatico employed dozens of young, digitally savvy people to post positive comments on fake Facebook accounts about clients. In Poland, Cat@Net ran networks of fake Twitter accounts operated by staffers with disabilities working from home. The agency hired them because it could pay them below-market rates while they received government subsidies. Reporting by Investigate Europe also found Cat@Net performed work for Art-Media, one of Poland's most prominent PR agencies. Art-Media denied working with Cat@Net.
Cindy Otis, a former CIA officer and author of True or False: A CIA Analyst's Guide to Spotting Fake News, told BuzzFeed News that information operations by nation-states like Russia and Iran provided "a playbook for individuals and groups that are financially motivated" to enter the space.
How the Southport narrative spread
The Southport case did not need a paid contractor. It needed a platform, an audience and a story that fit what parts of that audience already believed.
Joe Ondrak, research and tech lead for the UK at Logically, told CNBC that the false claims were "catnip" to anti-migration groups. "It's really the exact right thing to say to provoke a much angrier reaction than there likely would have been were the disinformation not circulated," he said.
Ondrak added that the reports acted as "a way to rationalize and reinforce pre-existing prejudice and bias and speculation before any sort of established truth could get out there."
Amplification did much of the work. Rose said accounts with hundreds of thousands of followers and paid-for blue ticks shared the false information, which platform algorithms then pushed to other users. "For example when you searched 'Southport' on TikTok, in the 'Others Searched For' section, which recommends similar content, the false name of the attacker was promoted by the platform itself, including 8 hours after the police confirmed that this information was incorrect," she said.
ISD's analysis found algorithms worked similarly on X, where the incorrect name featured as a trending topic. False claims also reached Telegram, which Ondrak said consolidates narratives and exposes more people to "more hardline beliefs." Telegram told CNBC it was not helping spread misinformation, saying moderators were monitoring the situation and removing channels and posts calling for violence.
The numbers got large. A July 2025 report from the House of Commons Science, Innovation and Technology Committee said that between 29 July and 9 August 2024, false or unfounded claims about the Southport attacker achieved 155 million impressions on X. Across social media, the false name was seen 420,000 times, with a potential reach of 1.7 billion people, the report said. It was directly promoted by algorithmic tools, appearing on X's "Trending in the UK" and TikTok's "Others searched for" features.
When the network leaves the screen
Far-right groups organised anti-migrant and anti-Islam protests, including a demonstration at the planned vigil for the girls who were killed. The unrest escalated into days of riots. Mosques, immigration centres and hotels housing asylum seekers were attacked.
At least some of the accounts calling for participation in the protests could be traced back to the extreme right, according to analysis by Logically, including some linked to National Action, a banned right-wing extremist group named a terrorist organisation in 2016 under the UK's Terrorism Act. Ondrak also noted that many groups that had previously circulated false information about the attack had started walking it back, saying it was a hoax.
X owner Elon Musk weighed in during the riots, making controversial comments about the violent demonstrations. The UK's courts minister called on him to "behave responsibly." TikTok and X did not immediately respond to CNBC's request for comment.
On the Wednesday after the worst of the violence, thousands of anti-racism protesters rallied in cities and towns across the UK, far outnumbering the recent anti-immigrant protests.
The rulebook problem
Britain has an Online Safety Act, but its ability to cover this kind of content is disputed. The law received royal assent in October 2023. Elements requiring social media companies to protect users from illegal content came into force on 17 March 2025.
At an April 29 hearing of the Science, Innovation and Technology Committee, Baroness Jones of Whitchurch, a minister at DSIT and the Department for Business and Trade, said misinformation and disinformation were covered by the Act. Mark Bunting, online safety strategy delivery director at Ofcom, said the previous government had removed legal material that might be harmful to adults from the Act's scope, including forms of misinformation. He added there was "one small caveat": the Act introduced an offence of false communications with intent to cause harm, where companies have reasonable grounds to infer intent.
Committee chair Chi Onwurah pointed out that intent is very difficult to prove. She said there were no duties on Ofcom to act on misinformation, even if codes discuss it. "That seems to be a key issue," she said.
Talitha Rowland, director for security and online harm at DSIT, told the committee that "mis- and disinformation isn't one thing." It can be illegal, foreign interference, content that incites hate or violence, or content below the illegal threshold that is still harmful to children.
By July, the committee's report was blunter. It said the Act fails to address the algorithmic amplification of "legal but harmful content," leaving the public vulnerable to a repeat of the previous summer. "It's clear that the Online Safety Act just isn't up to scratch," Onwurah said. The committee urged the government to adopt five principles for future regulation, from protecting free expression to holding platforms accountable for content they put online.
One more wrinkle: the tools used to spread this material are changing. Grokipedia, launched by Musk in October 2025, uses AI to scrape and transform content with little human oversight, wrote Andrew Orlowski in UnHerd. Early reports on version 0.1 noted AI-generated falsehoods and derogatory passages added "in the name of accuracy." Orlowski argues large language models "are statistical word completion engines that hallucinate, and these hallucinations are endemic."
Sources
5- 01Online disinformation sparked a wave of far-right violence in the UKEN
- 02Disinformation For Hire: How A New Breed Of PR Firms Is Selling Lies OnlineEN
- 03Does the Online Safety Act cover misinformation? Well, that dependsEN
- 04UK Online Safety Act 'not up to scratch' on misinformation, warn MPsEN
- 05Grokipedia is another form of online disinformationEN
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.