Skip to content
World clockEU--:--UK--:--USA--:--CN--:--PLDEFRIT中文EN

portal about AI and technologyevents · analysis · interviews · technical background

Search
LIVE
›

Tracking Disinformation Networks: New Guide Maps Four-Step Method as Riot Cases Pile Up

A new practitioner guide sets out a four-step method for mapping coordinated disinformation networks. Investigators, it argues, should stop chasing individual false posts and start looking at the infrastructure behind them.

Media & internetNewsRachel NwosuPublished: 27 September 20266 min readSources 5
Tracking Disinformation Networks: New Guide Maps Four-Step Method as Riot Cases Pile Up

The guide comes from the Exposing the Invisible project. It describes disinformation as increasingly organised into "network infrastructures" built to manipulate and deceive in a coordinated way, and walks readers through a four-step method for finding, mapping and tracking those networks across languages and contexts.

Its core argument is a distinction between fact-checking and network investigation. Fact-checking verifies a single item: a photo, a video, a news story. Network tracking looks at what surrounds that item, meaning the sites, the accounts and the amplification path. The guide calls this a shift from text to context. It takes more time, it says, but it does a better job of identifying the actors beyond whoever wrote a single post.

The four steps, and why they repeat

The guide lays out its four steps in consecutive order for ease of reading, then warns that real investigations are recursive. "Many steps will be recursive and it will therefore be necessary to move from one step to the next in a non-sequential manner," it states. Each step contains three sub-sections, marked in the guide with different colour bars.

It also flags a terminology problem that trips up casual readers. Not everyone caught up in a disinformation campaign knows they are part of one. Where participants are unaware, the guide says experts use the term misinformation rather than disinformation. Get that distinction wrong in public and you mislabel ordinary users as operatives.

The guide draws on a definition from the Media Manipulation Casebook at the Shorenstein Center on Media, Politics and Public Policy. That definition describes media manipulation as a process in which actors use "specific conditions or features within an information ecosystem" to generate attention and influence public discourse through deceptive, creative or unfair means. The guide also notes that the European Union has introduced the acronym FIMI, for foreign information manipulations and interference, and describes it as strategic, coordinated and intentional.

Macedonian teenagers, Italian sites, AI-generated news

Not every network has a political sponsor. The guide points to economic motives, including monetisation through advertising, and cites the network of sites run during the 2016 US elections by a group of teenagers from a small town in Macedonia. It also references a case the author worked on in Italy, which led to the discovery of a network of sites in a very small town in southern Italy.

Other examples it lists include Buzzfeed News reporting on how one of Italy's biggest alternative media networks spread anti-immigrant misinformation on Facebook, and Poynter Institute work on a website that impersonated a fact-checking outlet to publish fake news in Brazil. On generative AI, the guide cites a network of 125 unreliable AI-generated news sites brought to light by NewsGuard. It also mentions Russian "troll factory" operations and what it calls well-known pro-China or pro-India disinformation networks.

The guide quotes Whitney Phillips and Ryan M. Milner from "You Are Here: A Field Guide for Navigating Polarized Speech, Conspiracy Theories, and Our Polluted Media Landscape." The two write that "polluted information never just appears" and that researchers should triangulate what they find. The quoted passage sets out three possible roots for such pollution: economic, interpersonal and ideological.

"The first task is to triangulate our respective 'you are here' stickers on the network map (…) Looking down at the roots beneath our feet helps us trace where polluted information came from and how it got there."

Why the network view matters

The practical case for network-level analysis shows up in the aftermath of specific incidents. Three young girls were killed in the British town of Southport in July 2024. False claims about the attacker's name, religion and migration status spread within hours, according to CNBC. Hannah Rose, a hate and extremism analyst at the Institute for Strategic Dialogue, told CNBC that a post on X falsely named the perpetrator as "Ali al-Shakati" and that by 3 p.m. the following day the false name had over 30,000 mentions on X alone.

Police debunked the claims the day after they emerged, saying the suspect was born in Britain. CNBC reported that the narrative had already gained traction. Far-right groups organised anti-migrant and anti-Islam protests, which escalated into days of riots with attacks on mosques, immigration centres and hotels housing asylum seekers. Rose said that when users searched "Southport" on TikTok, the platform itself promoted the false name of the attacker in the "Others Searched For" section, including eight hours after police confirmed it was incorrect.

Joe Ondrak, research and tech lead for the UK at Logically, told CNBC that such false claims serve to rationalise pre-existing prejudice and bias before established facts emerge. Telegram denied to CNBC that it was helping spread misinformation, saying its moderators were monitoring the situation and removing channels and posts calling for violence.

Other documented operations are larger and more persistent. A CNN review of court documents and public disclosures by social media companies found that the Chinese government has built what it described as the world's largest known online disinformation operation, and is using it to harass US residents, politicians and businesses. CNN reported that Meta said it took down a cluster of nearly 8,000 accounts attributed to the group in the second quarter of 2023 alone. Google told CNN it had shut down more than 100,000 associated accounts in recent years, and X had blocked hundreds of thousands of China state-backed or state-linked accounts.

The US State Department told CNN that the tactics form part of a broader multi-billion-dollar effort to shape the world's information environment and silence critics of Beijing. The network is known as "Spamouflage" or "Dragonbridge".

Regional surges follow the same pattern. Balkan Insight reported that in October 2023, during the Israel-Hamas conflict, false claims spread across the Balkans. One was a baseless assertion that Israel had deliberately bombed the Orthodox Church of St Porphyrius in Gaza, later debunked by fact-checkers including AP and AFP. In Kosovo, a manipulated image circulated on 20 October suggesting Atletico Madrid fans had displayed a Palestinian flag. Closer examination showed it had been digitally fabricated using AI technology, according to Balkan Insight.

The guide's closing case is simpler. A study by UC Riverside and USC education scholars, published in the journal New Media & Society, found that Black and Latino teens reported significantly more digital literacy skills than their white peers, particularly on content related to race and ethnicity. Those skills include detecting online disinformation. Avriel Epps, an assistant professor at UC Riverside's School of Education and lead author, said the teens developed them in many cases from lived experience navigating online racism rather than from school instruction.

That finding cuts against a 2021 study by the Stanford History Education Group, now the Digital Inquiry Group, in which Black students scored significantly lower than other racial-ethnic groups on analysing real-life digital media. The UCR study notes that the earlier research did not examine reactions related to race or racism.

Comments 0

Sources

5
  1. 01How to Track Online Disinformation Networks - Exposing the InvisibleEN
  2. 02Online disinformation sparked a wave of far-right violence in the UKEN
  3. 03China is using the world's largest online disinformation operation to harass AmericansEN
  4. 04Online Disinformation Surges in Balkans Amid Israel-Hamas ConflictEN
  5. 05Black and Latino teens show strong digital literacyEN

All figures and quotations in this text come from the sources listed below.

Content prepared by the editorial team with AI assistance.

Rachel Nwosu

Rachel Nwosu

AI, models and technology

Rachel Nwosu covers AI, models and technology for FLASH24, working from public model documentation, benchmark releases and repository histories rather than press summaries, and she skips announcements that arrive without reproducible numbers. She checks training-data claims against dataset cards and reruns reported metrics where code is available. She spends much of her week interviewing researchers and engineers, tracking model launch calendars, and comparing vendor benchmarks with independent evaluations. Outside the desk she runs 3D printers, restores old computers, and tests how models learn from internet junk. She does not publish benchmark figures she cannot trace to a source.

Newsroom →

Comments

0
  1. No comments yet — be the first.

Write a comment

Comments are public. We do not publish abuse, spam or advertising.