The Lawfare Podcast
The Lawfare Podcast

Lawfare Archive: Making Sense of the Doppelganger Disinformation Operation, with Thomas Rid

4h ago55:539,366 words
0:000:00

From October 16, 2024: In early September, the U.S. Justice Department released a trove of information about the Russian influence campaign known as “Doppelganger”—a Kremlin-backed effort that created...

Transcript

EN

Do your current managed services really help run your operations or are they ...

Running isn't enough anymore. With PWC's managed services, your operations don't just run, they evolve continuously,

powered by AI embedded directly into your workflows. So instead of maintaining yesterday's model,

you're building tomorrow's advantage. PWC's managed services, we run your operations with tech and talent, so you can run faster, scale smarter, lead stronger. By Octopus Energy, Vexels, you're completely too far away. Now, on Octopus Energy, the E-vaccine and with the bonus code, Octopus 115, a 15-hour Vexel bonus session.

I'm Sarah Loverd. Internet Loverd with an episode from the Lover Archive for July 25th, 2026.

On July 16th, President Trump delivered a prime time speech in which he urged election security efforts and alleged that China had interfered in the 2020 presidential election. The White House also released stock events allegedly proving this interference, though critics have argued that little in the files support Trump's claims. For today's Archive, I chose an episode from Oct. 16, 2024, in which Quinto Dresset spoke with Thomas Rid about a different set of documents released by the Department of Justice,

that revealed information about Russian election interference. They discussed what the documents show, how the media covers potential election interference in glory. It's the Law Fair podcast. I'm Quinto Dresset, Senior Editor of Law Fair. With Thomas Rid, Professor of Strategic Studies and Founding Director of the All-Parvich Institute for Cybersecurity Studies at Johns Hopkins University's School of Advanced International Studies. A lot of entities are playing in the influence operation space, Chinese, Iranian others, multiple players in those countries, Russian contractors, multiple Russian contractors.

Because there's this collective fear of influence operations. So we have this weird constructivist feedback. We think there's a huge threat, therefore there actually is a significant threat. Today, we're talking about Thomas's new Foreign Affairs article, the lies Russia tells itself. An examination of what a trove of leaked documents can tell us about a long-running Kremlin-backed influence operation. I'd asked you on today to talk about a great article you recently published in Foreign Affairs titled, "The lies Russia tells itself about a really striking trauma documents that came available about a Kremlin-linked disinformation project known as doppelganger."

Which you described in the article as an infamous Russian disinformation project.

So what exactly is doppelganger and what led you to write about it now?

Yeah, so doppelganger has been widely exposed and tracked exposed as a Russian disinformation front of sorts. Almost immediately after it started operating back in the summer of 2022. So a couple years ago, but what's interesting about it is that it's been exposed again and again. And that apparently just kept them not just kept them going but made them even stronger.

And as a historian of disinformation, that for me was always a fascinating feature.

Exposure no longer is essentially kills an active measure, it helps an active measure. And so when the leak came out, and we can talk about how it came out, I'm sure, that I was extremely interested in seeing the internal documentation of that phenomenon. Yeah, so let's talk about the leak. So there are two components here. One is something that we've actually talked about before on the offer, which is this trench of documentation that the Justice Department released in the form of an affidavit related to operation to take down some of the websites that doppelganger put together and we can talk about that.

But there is another trench of information that came in the form of this leaked material.

So how did this come out, how did you come across it?

Yeah, that's a fascinating story. I think what happened is I was in fact, I was in Florida testifying in another disinformation related case.

When I got this text message from a German investigative journalist, who said...

Some common from you, can we talk?

And immediately I was extremely interested because leaks tend to be quite interesting.

So we kept in touch, and that was from a journalist who cooperates with Zutacce, Sanctum, the German Daily published in Munich. And so they received approximately 2.4 gigabytes of files, 3,000 files, if you break them around a little more, from that from the social design agency. But the intriguing thing is that they don't know from whom, it's an anonymous source.

And the source gave the files to 2 media outlets, to the Zutacce site, as well as to Delphi, which is a Baltic Estonian news site.

And they both ran a number of reports in collaboration with other media outlets that they sourced from these leaked files. And I should add, perhaps, they receive the files at some point in mid August. I can't precisely date the day. Must be before the 21st of August, because of some metadata issues. And that, of course, was also before the affidavit came out.

We have to assume the affidavit was in the works for a significant amount of time. I would guess something like 6 to 9 months.

So that also is interesting, because there's overlap between the exhibits in the affidavit, the affidavit, the affidavit, and the files in that leak to the German Estonian media.

And what do you make of that overlap, does it tell us anything about where this information would come from?

You know, we can't come to any conclusions or even high confidence, really not even moderate confidence assessments on where it comes from. I will say, and I would like to preface that this is informed speculation, but still speculation. I will say it's interesting that the files overlap, and the source that contacted the Suddeutsch at sideswank in Germany, they didn't identify themselves, but they sounded kind of very serious. They wanted to help expose what Russia is doing. And I would also add that it appears that no information about American victims, for example, media organizations that were impersonated,

were contained in that leak. In fact, they seem to have been removed from the leak if you look at the broader context. Now, again, this is only speculation, but that kind of removal of American victim information, or target information, if you like, is probably what you would expect from an American foreign intelligence entity, you know, running an operation here. But again, we don't know, it was a very soft target, the SDA, the social design agency, quite unprofessional in their operational security as well. So it's very possible other entities had access as well.

So let's talk a little bit about this, this organization behind doppelganger, the social design agency, as you said, you know, we have known about this or people in the field have known about this since about 2022, I believe.

What is their MO, you kind of give us a little hint just now when you mentioned American victims and media organizations? What is it that they would do? How do they work? Yes, so their method of operation or their sort of their mean thing is to, together with another Russian contractor structure, they would essentially clone media sites in different countries, Germany, France and the US or at the top of the list, but also in the UK and Israel. Ukraine, of course, is high up on the list as well. They would clone these media sites and then plant, so they would look like exactly like the Spiegel built site owner or Washington Post or Fox.

And they would have URLs that if you only took a quick, quick glance at the URL, it contained Washington Post but it didn't have dot com but something like dot pick, for example. Lots of different ones and then it looked exactly like the Washington Post or built site owner in Germany. And only one story would be planted, the link to the other stories would be real to the actual real media outlet and the planted story would sort of spin a certain event in a way that further Russia's interests. That was one component of what they did, the other component is seed comments on social media that link to those cloned fake sites and in order to try to drive traffic to them.

So I will say so what I've seen in terms of the documents here is just the material that was in this, this affidavit and the Justice Department definitely took care, I think, to show a couple things.

One is that it does say explicitly according to the affidavit that the social...

And there's a lot of material there about the war and Ukraine.

I remember there are a lot of comments where they, their sort of workshopping comments, there's a lot of information about, you know, from the internal workings of this organization saying, you know, you could write something like, I'm an American and I live in New York and I don't understand why we're setting all this money to Ukraine. Particularly in this goes to the issue of professionalism, which I definitely want to make sure that we touch on.

There's sort of amusing things like, you know, my wife and I work in areas that involve commenting on issues sort of very, very, you know, clumsy, heavy handed attempts to impersonate.

In this case, Americans, are there any other themes from your look at these documents that jumped out of you sort of ideas that we're trying to be communicated here?

You know, it's an interesting question because what I'm seeing in these files and for example, the leak files include a lot of documentation of their comments. For example, Facebook or Instagram Twitter and then later X comments obviously that they would post.

And you can see some of their themes and emerge and scroll through the Excel sheets and look at even screenshots of the actual comment that they usually took immediately after posting it.

And the themes are effectively themes that we already know in terms of US political themes because we are following our politicized, you know, polarized partisan debates. Whatever it is, the landscape being corrupt or the landscape is advised by yachts, obviously was a theme that we have publicly seen links to Russian disinformation operations, although it doesn't appear to originate with Russian entities.

And that I think is the key piece. What we see is themes that emerge organically in the US debate, get amplified by them. And then it becomes really hard to disentangle afterwards.

What is actually an organic and real, so to speak, and what is an attempted influence operation and how successful is that. So that is I think the conundrum in this leak is really hard to assess how effective they are. I absolutely want to dig into that more. I did want to ask, I mean, I've been talking here about the sort of the US narratives, which, as you say, are very familiar and I should also say, I think one of the material and part of the material on the epidemic is explicitly saying, and we, we want to help elect.

I think it's listed as candidate A or candidate one or something like that, but it's clearly referring to Donald Trump and the Republican party. So there's a strong political balance in terms of the presidential election. And you're looking at this material that was passed to you from German news. It was their material in there that was touching on German internal political issues, Baltic internal political issues as well. Oh, yes, yeah, that's the, that's the demo. They have a monitoring team in place and the social design agency is contractor. The total staff is a little more than a 100 people and approximately 20, 25 of those different monitoring teams.

So they have a fairly okay understanding of what's happening in their target countries because they're monitoring the actual press. Also, they monitor telegram groups, they monitor social media debates. So they know the trigger issues, they know the polarizing issues in Germany and France and the UK. So for example, here last winter, they really try to drive a wedge into this issue in Germany. I say here because I'm currently in Europe. In which they wanted to highlight the costs of gas and just heating and blame the Ukrainian immigrants, ultimately for a number of social issues in Germany, including heating costs, but also, you know,

Immigrant violence and all sorts of things kind of things that you would expect. So they would do that as well. So we've touched briefly on the issue of the kind of professionalism or lack thereof of this operation. And a fair amount of your article is pointing out that, you know, this is, it's a workplace. It's a bureaucracy, right? They're putting together metrics. They're trying to sell their bosses on how effective they're being. What did you sort of come to understand about this operation in terms of its internal functioning, but also, you know, it's, it's professionalism. What kind of product are they putting forward? How would you rank it?

Yeah, it's not super clear from the data because you have to interpret a bit and read different types of documents and compare figures.

But one thing that I've seen very clearly from some of their documents that were, and sometimes, you know, header information is missing, dates are missing as well.

You don't really know who is that document for.

And then we have to infer, okay, this document is like a translation of press coverage with snippets translated into Russian.

Sometimes with logos inserted, so it looks impressive. Sometimes even with logos translated into Russian, so it looks, you know, even more impressive to a Russian reader. So we have to assume that they put all this work into preparing some of these word documents these, you know, reports in order to impress their funders, because why else would they do it? They don't publish them. So if you look at those reports, one thing that is striking is, in some cases, they boast about their exposure even before they provide figures about what they actually did.

So it seems, in more than one document, very clearly that they like the exposure. One Excel file that I went through listed 163 press reports about their work. And if you look at the video that internal promotion video that they made for Putin for the presidential administration, which we can clearly see in a memo that they made it for them.

We know exactly when they did it and why they did it. That mentions, in the very first sentence, their exposure and the name that they received namely doppelganger in their exposure.

So they're really proud of being exposed and, you know, they're proud of being identified as a Putin threat, and that's the key marketing message that they use internally to their funders and the criminal.

And so, right, and just to drive that home, when you say, you know, they're putting this kind of thing together for their funders, that's, we're referring here to the Russian government or other more layers in between. They have direct meetings with the presidential administration, so basically the Kremlin, and various different people in the presidential administration, they list them by name. They're even their email addresses and they're in the leak, unredacted, obviously nothing is redacted. And it becomes sometimes they refer to them in acronyms and their, you know, initials.

That, that also is nicely laid out in the affidavit. So we clearly have evidence that they work for the presidential administration, although they don't list them on their website, because they're semi-covert, in that sense, working for the Kremlin.

And, and that's who they want to impress. So their most important important audience is not the American public with the German public.

Oh, the French public, the most important audience, as you would expect from a company, is their clients, the people who buy their product and that is a Kremlin, not Germans.

And so, how does this compare to past active measures, which is obviously something that you've, you've studied in, in great depth. And you write throughout your article that, you know, to some extent what we see here is the social design agency relying on to you familiar tools from Soviet active measures. And to some extent, it's incorporating new tools. We can talk about their use of AI here. To what extent is this a continuation of what we've seen in the past in terms of Soviet active measures in the 20th century to what extent is it degradation of that to what extent is it something new.

Yeah, that's a fascinating question indeed. And we see a few themes that are clearly continuity for example, the driving of wedges, but exploiting existing divisions and weakening countries and turning them inward by exploiting internal existing divisions. That is a theme that we clearly see going back a long time hundred years. We also see the theme here continued that it's hard to measure effect for them, but also for outsiders like us like me. And that is clearly the case also in the Cold War here.

And we also see in the Cold War that people overstated the ease of measuring effect, they overstated how clear it would be to show effect. And then afterwards admit it that they kind of did this in order to get more money and promotions. That we see it work here as well. I'll point out an interesting difference. The very mower that we just talked about the cloned media sites, you know, Washington Post built sites on the Zutoji, the Daily Mail, others, 20th of a minute in France.

Those cloned sites offer a sharp departure from Cold War tactics. And media outlets in the Cold War by the way, so that in itself is not brand new, but they appear no longer to try to trick journalists.

I mean, the most important audience for Cold War active measures were actually journalists because they amplified this information out to a vast audience, in some cases.

And that was the the jackpot, getting, you know, a leak or a fake document into, you know, the CBS coverage or some, or some, there's people or something in Germany.

They no longer even appear to try to do that, at least not the SDI, instead t...

They don't trick the real journalists, they copy the real journalists and then amplify themselves.

But of course, their own amplification in contrast to the actual, you know, outreach, reach that the real media organizations have is miniscule, it's tiny.

So that I think is an interesting lower level of ambition that we see today.

So is that a good story for the press in a sense?

Like does that speak to some level of practice or skill or journalistic, you know, standards or norm buildings such that press organizations are not being taken in?

I will say, I mean, reading your article, I was really struck by what's missing here in the social design agency story, which is, you know, a hack and lake operation, you know, what we saw in 2016. There, there were, of course, two pieces, there was the internet research agencies sort of social media influence operation, which will, we'll talk about effectiveness metrics in a minute, but it's very hard to measure if it was effective and to the extent that it can be measured, it probably wasn't. And the most effective influence operation, arguably, was the GRU hack and lake of internal democratic party and Clinton campaign information and that works because of, as you set out, it, you know, it, it played the press, it got into the, the headlines and that's really not what we're seeing here at all.

Yeah, for sure, absolutely correct, I completely agree.

And indeed, I think what we see today is this weird contradiction layout that the United States in particular, but the same really applies in European countries is a harder target than it was in 2016 or 2020.

Hard to target, because more journalists are aware, they cover this information, they watch out for it, they're quite cautious, not all of them, obviously, but a lot of them are. And then, also, the campaigns are harder targets, because, you know, you'd have to assume that more people use, maybe I'm overly optimistic, still, making that assumption that they use to factor authentication are a little more cautious. Certainly, the US intelligence community, including FBI Department of Justice, certainly, they are a lot more aggressive in terms of countering this information, the platforms are a lot more aggressive Facebook, others with the exception perhaps of X now.

So, all this makes the US a harder target, but of course, we're also a lot more polarized, which makes the US a softer target, you can more easily inject narratives or at least amplify these narratives by feeding to the people who are outraged farmers, essentially, who want to deliver off of the off of the outrage and we saw them, you know, literally presented in their video there in their promotional internal video.

They're tweets and whatnot, including, you know, people like Marjorie, Taylor Greene and others that they internally cite as well.

But of course, they are not, and I want to stress this, I don't want to be misunderstood, I'm not calling Marjorie Taylor Greene a Russian influence agent at all, she's doing her thing. And they sometimes claim that she may have amplified something that they said, actually not sometimes not even providing good evidence to make that case, which, and just as I think an important point to highlight, we see, you know, their internal documentation and social design agency. They're not scholars, they don't footnote very well, they don't do this with a high, you know, fidelity and attention to detail.

So they just claim things on a very abstract way, and as a scholar, I'm like, okay, cannot take their claiming credit for something as proof that they did it. And I came to the conclusion that I can't even do that because internally it's so shallow and so unprofessional, what they do, that they would just, they're just not serious in so many ways. So let's talk about the use of AI here, because that is something that the Justice Department at least really played up in the release of this, this affidavit, there are quotes in the Justice Department's press release about the, and I quote,

the Russia's Reliance on cutting edge AI to so disinformation, the covert promotion of AI generated false narratives on social media. What exactly is going on here in terms of the use of AI and is that, you know, a nefarious example of how generative AI is, you know, destroying the truth or is it maybe an example of kind of the shotiness of the work product. You know, I mean, of course, we would expect almost anybody in the influence operations game, in fact, also the same as true for cyber operators, you know, reaching hacking operations.

To use AI in some form in order to speed up their development cycle or do thi...

So we should see some effects or some documentation of AI in the leaked files, and indeed there's only one.

In fact, there's only one example, which is interesting, I'm going to read it to you in translation because it's so short.

They have a memo from June 2023, so a little more than a year ago, in which they say run memes through the GPT chat in the style of Monet and the style of Goga, etc. So this is a very sort of staccato style instruction, which is perhaps not that interesting, but one thing that, that is, in my view, remarkable is that they are not using, at least in that one memo, not using an I or attempting to use it for deepfakes, for something to make something look real, but instead they want to make it look more artistic, even naming, you know, a number of impressionists, post and post,

and post impressionists.

I like that the name Kandinsky specifically, it's a nice touch.

Very much so, but yeah, so that's interesting.

I don't know why AI was played up in the press release so much that the DJ did appear that AI is a hot new thing, so it wasn't actually wrong to say that some AI was used, but it wasn't used in the ways that a lot of people feared it would be. And so it wasn't used to generate the text in the articles you're saying. Well that, of course, is a really difficult thing to prove or disprove, because how is the department of justice going to prove and show that certain texts were generated with, you know, generative AI models.

It's open AI is able to do that if they test against their logs, but not even they are able to do that for a text that was generated with, you know, clawed from anthropic or other models, which, of course, relates to a bigger issue, how do we actually show content is artificial.

If it's text for images, we have sort of a telltale science, but for text, it's a little harder, at least if it's text of that sort of short nature like a social media comment.

So, but I would assume that they used some, but by looking at their logs, you know, you can see these are humans doing the actual work, because they make mistakes, because of the time lag between posting and then screenshotting and then posting the screenshot. You can compare the timestamps and it's just, it's the kind of human variance that you would expect. It's not automated.

Do your current managed services really help run your operations or are they just running in circles?

Running isn't enough anymore. With PWC's managed services, your operations don't just run, they evolve continuously, powered by AI embedded directly into your workflows. So, instead of maintaining yesterday's model, you're building tomorrow's advantage. PWC's managed services, we run your operations with tech and talent, so you can run faster, scale smarter, lead stronger. So, let's take into this issue of effectiveness that we've kind of been circling around. As you say, you know, it's very difficult to get to the effectiveness of an operation like this, obviously we've been arguing about the effectiveness of the IRA,

a social media influence operation for many, many years now, and one of the things that I found really fascinating about this article is that you describe how this question of effectiveness is an issue, even for the people who are producing this work in the first place. And you've touched on that here and there so far in this conversation, but I'm wondering if we can just dig a little bit more into that, how do you see the social design agency sort of struggling to voice, whether or not what they're doing is working and why is it that it is so hard to determine that both from the perspective of, you know, researchers and people within the organization.

So, let's make a quick thought experiment to get that point across. Let's make the thought experiment for 2016, we have those, let's keep it simple, those two main venues, vectors of influence operations in 2016. The internet research agency, the famous troll farm is the one and the other one is GRU and again I'm simplifying the podesta leaks of October 2016. And let's, and of course it was more complex, but let's just keep it simple, let's assume that neither of the two had ever been exposed for a moment.

That's assume, IRA, nobody, no journalist had ever had a no department of jus...

And also let's assume the same that GRU had never been exposed. And then put yourself into the shoes of those people, how do you prove success? Well, for GRU it's fairly easy, you can just point to all the press coverage about the, about the podesta leaks that were was actually happening and going on and there was a lot of it.

Obviously, you can point at reactions on the part of the Clinton campaign, etc. So it's fairly easy to prove success there by simply quoting press coverage that otherwise would not have happened.

But for the IRA, it's really hard because the actual metrics, the engagement metrics are not very impressive if you look at the numbers.

And we see that in the case of the social design agency as well. Fact social design agency numbers are a little better than IRA numbers, I would argue. But if we, if we don't include the exposure, then it's very clear that social design agency would be, you know, quite ineffective presumably. And so it's not very understandable that they would highlight their own coverage in their own internal reporting because that's, let's be brutal for a moment. They are effective. And I'm not saying they're not effective. They are effective to a very significant extent because we are making them more effective by being so afraid of them.

We're talking them up and helping them get money, but also really making them effective in the first place.

And I don't want to dismiss this. This is this is real effect for a 100 person shop. They got a loss of press coverage out of this. So quite effective in terms of, you know, money spent. But only because we're talking about them so much.

And so when you say there's an effectiveness and, you know, making people afraid of them, how do you see that fear manifest? Is it just an, you know, sort of anxiety around, you know, Russian bots, Russian disinformation?

Where do you sort of see that manifest in the, in the public conversation? And also, I guess I'm curious whether you see differences in how it appears in the American context versus in the European context or whether it's a sort of a similar set of anxieties. Yeah. That's a super difficult, obviously, very political question. You're raising there. It'll take it in reverse. In Europe, I think we see that the whole disinformation conversation does not have the magnitude in the public, you know, suddenly in the press coverage, but also the public imagination that it has in the United States.

And of course, in the US disinformation itself has become highly politicized. The term disinformation, as such, is extremely politicized. I tend to avoid for that reason, actually. And, and that, of course, they also exploit. So the fact that talking about Russian influence almost marked you out politically as being on one specific side of the political divide, that in itself is a weakness that we have created ourselves. And it's also an effective effectiveness for the adversary that we have created for them in the United States by polarizing this information as such.

In Europe, you don't have that to the same extent, but it's beginning to be, to be a quite similar problem, but not as not as high profile as it is in the US. It seems like, you know, in some ways, what you're describing is a kind of a positive feedback loop or almost a perpetual motion machine, where, you know, the SGA puts out this stuff. It's reported on people, you know, report on it, read it, become anxious, SGA is able to say to the Kremlin, "Look how we know what great work we're doing, please keep funding us and, you know, around and around we go."

And you suggest that this points to what you describe as a flaw in democracy's coverage of disinformation campaigns, that the exposure of these campaigns itself paradoxically feeds the campaign. How do you see that working? If I may, sometimes I get criticized by people who say, "Well, and rightly so," they say, "Well, but should we not write about, because that clearly trying to exploit democracies, and should we not expose these operations?"

And the answer is, yeah, we should expose these operations. There's no question about it. I mean, I literally wrote a book about that kind of thing.

Occasionally, double it in exposing myself, and it's important to do, but at the same time, the dilemma is that if we under-expose the adversary, we help the adversary.

And if we over-expose, we also help the adversary. The only venue, the only right thing that we can do is to be rigorous and as sober as we can possibly be. And that, of course, gets really hard if you have yourself a vested interest in reporting about disinformation operators, about influence operations.

Sometimes say jokingly, and this is going to sound offensive, or at least pro...

Question is, where can you make most money? And it appears that actually DC might be on the top of that list. And that, of course, is an issue as well.

Yeah, I mean, in the most provocative framing what this reminds me of is a article by Joseph Bernstein and Harper's that came out a few years ago that I don't know if it actually coined the term disinformation and industrial complex, but it certainly led to a lot of discussion of it, which is, you know, there is an ecosystem that grew up in the wake of 26 years. I think of 2016 where, you know, these stories get, you know, if you're a journalist having a story about Russian disinformation, it's flashy, you get a lot of clicks. If you're a nonprofit, perhaps you can get funders excited about you're, you know, doing your work to expose that kind of thing that there is a, there is a kind of a self perpetuation there.

I don't want to fall into the most, you know, exaggerated version of this critique, which is, and therefore there's nothing really there, and this is all a bunch of people getting spun up about nothing, because there clearly is something there, but in the same, in a sense, you know, what you're describing here. Struck me as kind of a mirror image of that, of that vision where there's a mutual benefit in some ways of the sort of, of the SDA in this instance and, you know, nonprofits, journalist organizations and so on kind of playing off each other to the point where I actually wondered whether, you know,

there's something about the, these kinds of operations that is compelling to the US intelligence community to, you know, nonprofits, bureaucratic organizations on the other side, precisely because it's so recognizable in a way.

I mean, I was reading these, these documents, and of course, you know, I have never put together anything for the Kremlin saying, you know, please fund my disinformation operation, but there is something that's a little bit familiar about, you know, you're trying to show to your funders that your work is impactful. How do you show the metric, right? There's an extent to which we're sort of, there's a operating in the same kind of like intellectual universe, even though an opposite sides. And again, I don't want to fall into the trap of saying that means that there's nothing there, but it was very thought provoking.

I think where I would take this is, if you ask yourself, what kind of exposure is helpful, what kind of exposure makes life for the adversary harder and what kind of exposure makes life for the adversary easier and in fact helps them get money.

That's an interesting question to discuss. And, and it seems to me the simple answer is the kind of exposure that doesn't just scream, oh no, they're there, they're so, you know, powerful and so big and so effective. That kind of exposure is not that helpful alone. Sometimes it's still being necessary, but it's not that helpful by itself. What's more helpful is take action, take a weather, take away their toys, take away their infrastructure, their freedom to operate by, you know, exposing that infrastructure, shutting it down like the Department of Justice was doing, by being quick on the draw in terms of being a platform and like not even letting them come back up on the platform to spread their comments and their amplification attempts.

So taking away infrastructure works. And then, if I may, I would just also quickly offer a sort of very unusual angle on the whole thing.

We, there's an alternative history of the past 20 years of western, you know, US and UK and five eyes and other intelligence operations writ large in this space. And that is as the story of, you know, the rise of exposure operations as well. I don't say influence operations for a reason I say exposure operations. And that, of course, has its origin in the cybersecurity context where you expose the infrastructure that adversaries are using, sometimes only privately, in order to take it down without any public footprint.

And we see something similar happening in the dis, this info space. Of course, with the Department of Justice, the FBI, we're doing here was a type of exposure operation in the form of an affidela, whoever leaked to the Dutch citizen who also allowed them to share with me explicit not with me named but with researchers. They also did an exposure operation that probably really embarrassed the SDA in the eyes of their funders because they're not that they have their pants down now. So, you know, these types of exposure operations is something that the West is actually pretty good at today, which just don't like to see ourselves in that light.

Yeah, I mean, we're also playing in the dirty trick, they're not that dirty in these tricks because we're not foraging documents, in fact, quite the opposite.

Exposure and these kinds of operations that put stuff into the public domain ...

So, you said I think that the West doesn't like to think of itself as being good at these kinds of things. What do you mean by that?

It seems to me that in the United States and Britain and European countries, we don't usually use the term exposure operations.

We call it cyber defense or call it indictments, and we call it by investigative journalism, if you like. But behind the scenes, you often see certain individuals and sometimes organizations having an interest in exposing some adversarial behavior. And when I say adversarial behavior in this context, I very clearly mean authoritarian governments running covert operation or influence operations of some sorts behind the scenes.

And it's a healthy thing to expose that and to expose it in a way that is actually accurate, and that makes it harder for them to repeat what they do.

I found your description of this kind of dynamic, which is the term that you use for this is upstream exposure. Very interesting for two reasons. One is that you seem to really identify something that at least I feel that the Justice Department and other agencies, all their chiefly DOJ, have really been digging into recently in terms of trying to counter foreign election interference. We also we've been talking about Russia here. There was also released alongside the double getting her after David, a big indictment of RT employees for funding US based influencers.

But of course there's there's also been an indictment of Iranian hackers for an alleged attempt to hack the Trump campaign and put together a sort of clumsy and so far basically I think failed hack and lake.

That's a conversation for another time, but DOJ to me has seemed to be very consciously leaning toward a posture of aggressively exposing these operations.

I'm putting as much information now as possible, which is really a contrast to 2016, where I think a lot of people may have forgotten the intelligence community basically stayed mum.

There was one statement that was released in October, and then it was sort of quiet until after the election. So how do you see the federal government using this strategy? Is that a fair description do you think? Yes, of course they are under significant political pressure now in this election cycle to counter this information influence operations threats from a number of countries. We see the ODI and I, the Director of National Intelligence, but I think I believe it's weekly updates on what's happening and have they have exposed the Iranian operation that you just mentioned, but also Chinese attempts at interfering with congressional races in interesting ways in order to further the Taiwan policy.

So just speaking about partisan way because they fund people, appear to help or counter people according to their Taiwan position, not whether they're Republican or Democrats. So that's interesting. We see clearly a higher volume of adversarial activity, and of course the federal government precisely because they really entered the game quite late in 2016, now rightly is a lot more aggressive, a lot more forward leaning and I think that's a good thing. Clearly, so absolutely that trend is happening, but again, that we see that feedback loop at play here as well.

A lot of entities are playing in the influence operation space, Chinese, Iranian others, multiple players in those countries, Russian contractors, multiple Russian contractors, because there's this collective fear of influence operations. So we have this weird constructivist feedback loop. We think there's a huge threat, therefore there actually is a significant threat. Keeping in mind that some kind of exposure, as you've said, can actually be very productive here, is there a way that you think that the government, the press,

the nonprofits we've been talking about, should be thinking about framing these kinds of exposures in a way that sort of gets the benefits of showing the internal workings in ways that, you know, makes these organizations look as kind of as silly and minimally confident as they are well not feeding into that same feedback loop.

I think the question really is particularly pressing for a lot of journalists in this space. After we published a piece in Foreign Affairs earlier this year, together with Olga Bellagolova, Lee Foster and Gavin Wilde,

don't hype the disinformation threat, I think it was the title. After that came out, a number of people contacted us, probably as well, journalists, of course I won't name anyone.

They said, hey, thanks so much for doing this, because now I have something t...

So there's a certain sort of expectation because you now have people doing disinformation, the disinformation, beat that they actually have to do something for their money, so to speak, and write about disinformation.

So then I think they have to make that this difficult decision. Will the information operation here that I'm writing about the influence operation, will it receive more eyeballs and more impact?

Because I write about them, then they would have ever received without us. That I think is the key question.

So that could mean sadly that sometimes when some researcher pitches you the journalist with a story and you look at the figures and you have to make that difficult judgment call, isn't it really?

Am I really helping here by writing about this or am I making the problem or sometimes the answers? Probably it doesn't deserve to be covered because it would do more harm than good.

And sometimes the answer is the opposite, obviously.

Yeah, and so where is the kind of the hinge point there? Is it a certain point of visibility in terms of the amount of people who may have engaged with this material? Because in a way I guess I, you know, it is also interesting to read these news stories saying like, hey, someone was running this kind of hinged disinformation operation. It doesn't seem like many people clicked on it and was kind of a waste of money. That, you know, on the one hand, that can seem like what a waste of a story, but on the other hand, I have kind of wondered whether those stories are themselves helpful in increasing people's understanding.

If that's at the top line because then the takeaway is more, you know, these things are can kind of be bunk. It doesn't have to be scary.

You know, it's, that's a fascinating question. And I think it helps probably to think about coverage or making information available, not as a yes or no, but as a question of how much volume and how much reach should a certain story get.

And some operations if they get exposed by some, you know, nerds like ourselves who loved to sink their teeth into what a certain, you know, synthetic network is doing. Then that is probably the right audience for some networks. People who just study that for a living basically or intelligence analysts and people in the private sector who can't trade up, you know, meta and elsewhere and Google. But, but not the Washington Post or the New York Times or NBC News or something like that. So some, some operations should be exposed only to the nerds and the professionals.

And others should be exposed, you know, perhaps to a slightly larger audience and then some should get the big ticket treatment.

But then the question is what, what should push you up into the times, you know, so to speak. And, and there I think it's a difficult, it has to be serious. It has to be a risk for somebody not just a curiosity to, to a very few people.

It's interesting because I'm thinking about thinking this out as I'm saying it. So we'll see how coherent my question is. But it, it feels like what you're saying there in terms of, you know, these are going to have to be judgment calls on one level, you know, of course, right. I feel like I've seen that same conversation happening in terms of how the press should report about hacked information, for example. On the other hand, it is also the case that the same political environment that leads people to be so anxious about this information.

Part of it is the feedback loop. Part of it is the underlying political and societal tensions, just speaking for the United States, which is what I know that leads the US to be vulnerable to these kinds of anxieties in the first place. Have themselves degrade a trust in same institutions that are going to need to be making these judgment calls, like it's very easy for me to imagine. You know, we saw this with the Iran hack and like, for example, they're all this, this sort of outcry on the left actually of saying, you know, why is in the New York Times publishing these documents.

There's a level of kind of societal trust. I guess is what I'm trying to say that that is needs to be there in order for people to kind of trust that the folks, you know, the nerds, as you say, are using their best judgment in deciding what to put forward, what to report and that kind of thing, which is itself what has, what is so fractured and what has kind of got us in the situation to begin with, is that is that to pessimistic. I mean, I'll share your underlying sense of the problem that there is the erosion in democratic institutions, but also, you know, the criminal justice system, intelligence, community, science, scholars and experts, that trust has been eroding for a while now.

I feel that by talking too much about this information about influence operat...

So, yeah, I think it's time to, it's time to rebuild some of that trust.

And I think just that the risk that some of our listeners may be thinking now that, well, yeah, clearly the rights has the bulk of responsibility here, and I'm not saying that don't have responsibility at all, in fact.

But it's important to also see this, what happened in 2017, late 2017, 2018 and 2019, where the whole narrative about, you know, the IRA and Russian, and Russian-election interference was so overwhelming, so big, and it's very public as well, that a lot of people assumed that President Trump had not won the election fair in square, but, in fact, was somehow installed by Russians, that narrative itself was extremely damaging, because it was simply wrong, Trump won in 2016 fair in square, and he lost in 2020 fair in square, and we'll see what happens in a couple weeks.

But that, we have to trust the system, and I think, if we undermine that baseline democratic trust in the system, and I understand the system is under a lot of pressure, I'm not naive, but still, if we lose that trust, then all bets are off, we become, we enter a conspiratorial mindset, that is exactly what Russia has done a long time ago, and we're unable to leave that mindset.

So we must avoid that mistake at all costs that we collectively get drawn into what is a conspiratorial world view.

So as you mentioned, we're only a few weeks out from the presidential election, of course, are there things that you're keeping an eye on in this space in the weeks to come?

Yeah, the big one is some form of leak operation that could, again, drive the news coverage, but it's late in the game, it's mid-uptober. I don't, frankly, I would be surprised if it happens now, I would have happened already probably, it's getting a little late, and probably, I would assume that when we look back at this election cycle, whoever wins, I don't think that this information or influence operations from foreign countries, neither Iran nor China nor Russia, have a major role to play in our sort of collective memory of the 2024 election cycle, that is a good thing.

Just in the sense that if it had happened, we would have already started to see the seeds of it. Yeah, absolutely yes, because the leak operation ultimately is the one that I think a lot of professionals like me who watched this space closely, but I would assume also in the intelligence community are probably most concerned about, because it's really hard to counter. We know that from history, if you release really newsworthy information into the bloodstream of the public press coverage, even if you know it comes from a foreign intelligence agency, if it's newsworthy, if it's authentic, if you can prove that it's authentic, it's still newsworthy, you have to still cover it.

That I think is the difficult one to deal with for an open democracy, because you have to cover it.

Is there anything else that we haven't touched on that you'd like to make sure we discuss?

Yeah, I mean, the one thing that I don't think has received the amount of attention that it deserves is a very curious paragraph in the open AI threat report. The second one that came out, when was it just a couple, it feels like a couple of days ago or about a week ago, where opening AI observed that threat actors in the cybersecurity or cyber operation space, but also in the disinformation influence operation space. Are using models, generative AI, large language models predominantly here, in what they refer to as a midsection in an intermediary phase of their operation to accelerate certain development cycles internally.

And why is that so interesting, because it means that the labs, open AI, at the top of the list, but also others in traffic, Google, etc, will have fascinating visibility into what adversaries are doing on their networks. And I think it's a super exciting moment to be working in the threat intelligence teams or build those threat intelligence teams really in the labs, because the telemetry that they have, the internal visibility that they have into these operations will be able to probably, I would assume, they will be able to link behavior together and identify new behavior adversaries in a way that was simply not possible before the use of LLMs.

That I think is an exciting insight that was sort of hidden in a report that ...

So the nerds should be keeping a close eye out for these kinds of threat reports from open AI and other generative AI companies.

Yes, and I think the AI company is in a much more popular law fair is among the AI crowd in San Francisco and Silicon Valley, but I think it's really important that they get the message, I believe they're getting the message that they are abused by adversaries.

And they have an opportunity here to build internal teams that see things that nobody else can see. And, but in order to do that, they have to stuff their own teams accordingly with people who have that talent and that background.

And then, of course, they have to equip them with the necessary internal sort of resources to get it to get the job done. So that's an exciting development to watch for me.

All right, let's leave it there.

Thomas Red, thank you so much for coming on. Thank you for having me.

The law fair podcast is produced in cooperation with the Brookings Institution.

You can get ad free versions of this and other law fair podcasts by becoming a law fair material supporter. Through our website, lawfirmedia.org/support. You'll also get access to special events and other content available only to our supporters. Please rate and review us wherever you get your podcasts. Look out for our other podcasts, including rational security, chatter, allies, and the aftermath.

Our latest law fair presents podcast series and the government's response to January 6th. And check out our written work at lawfirmedia.org. The podcast is edited by Jen Pachia. And your audio engineer this episode was Kara Shilling of Goat Rodeo. Our theme song is from Alabama, music.

As always, thanks for listening.

Do your current managed services really help run your operations or are they just running in circles?

Running isn't enough anymore. With PWC's managed services, your operations don't just run, they evolve continuously, powered by AI embedded directly into your workflows. So instead of maintaining yesterday's model, you're building tomorrow's advantage. PWC's managed services, we've run your operations with tech and talent, so you can run faster, scale smarter, lead stronger.

Compare and Explore