Alberto Fittarelli
@fittarelli.com
2.7K followers 520 following 210 posts
Sr. Researcher @citizenlab.ca, Disinformation & Harassment. Fmr. Meta. Trainer: find & expose covert influence. I like doers.
Posts Media Videos Starter Packs
fittarelli.com
Imagine if Napster back then said something like “I just don’t know how you go around, asking everyone first. I just don’t see how that would work.”
fittarelli.com
15/ At the moment of publishing this, several PRISONBREAK profiles continue to be active. We notified X prior to publication - but got no reply.
fittarelli.com
14/ So - who’s behind PRISONBREAK? We analytically weighed multiple hypotheses. The one most consistent with the available evidence is that the Israeli gov, directly or through a contractor, conducted the operation. Alternatively, but less likely, the US gov could be responsible for it.
fittarelli.com
13/ Finally, we noticed PRISONBREAK consistently promoting and interacting with an account named “تل‌آویو تهران” (Tel Aviv Tehran), which used an AI-generated persona to spread content very similar to the IO’s one. Including another AI-made “Evin Prison” video.
fittarelli.com
12/ Another tactic used by PRISONBREAK was the creation of fake content (and fake links) attributed to inexistent news reports, claiming that the outlets had removed them quickly after posting them. This echoed something we @citizenlab.ca had already seen as used… by Iran. Remember Endless Mayfly?
Burned After Reading: Endless Mayfly’s Ephemeral Disinformation Campaign - The Citizen Lab
Using Endless Mayfly as an illustration, this highlights the challenges of investigating & addressing disinformation from research & policy perspectives.
citizenlab.ca
fittarelli.com
11/ We have many more examples in the report. But one that’s worth highlighting here is the creation of a whole videoclip for “Baraye”, an Iranian protest anthem. The catch? The lyrics were changed to a direct call for uprising; and the video is a (poorly made) deepfake of 3 known Iranian singers.
fittarelli.com
10/ The use of AI in the campaign is *pervasive*. An attentive reader could have spotted the botched artifacts that often come with AI-generated videos, like the one claiming to show a crowd withdrawing their money from a bank in apparent panic. Just check the distorted human figure in yellow.
fittarelli.com
9/ In fact, the network had only just started increasing pressure on the Iranian government by spreading claims of state bankruptcy, generalized lack of basic resources (water, for example), and broader societal unrest.
fittarelli.com
8/ We now know that that didn’t happen. Iranian security forces retook control of the prison later that same day, temporarily transferring prisoners to different facilities before returning them to Evin in August 2025. But PRISONBREAK was not done yet.
fittarelli.com
7/ What was possibly even more fascinating was the quick pivot by the network, immediately after the bombings stopped, to encourage Iranians in reaching the Evin Prison and free the prisoners. “The area is now safe”, some of the accounts posted.
fittarelli.com
6/ The video initially tricked the international press into republishing it as real. Not only that: it was even reposted by the Israeli MoFA, Gideon Sa’ar. It was later spotted as AI-generated footage by several outlets.
fittarelli.com
5/ Among the targeted locations, on June 23, was the infamous Evin Prison in Tehran, where political detainees routinely suffer torture and deprivation. And guess what? PRISONBREAK posted an AI-generated video of Evin’s bombing *while the bombing was still happening*.
fittarelli.com
4/ As we know, in June 2025, tensions between Israel and Iran came to a head with the so-called “12-day War”, which saw targeted assassinations of key figures in the Iranian Islamic Republic, while the IDF bombed multiple Iranian locations.
fittarelli.com
3/ We started analyzing the network’s behavior. Created in 2023, it only began posting regularly in January 2025. What could have been the purpose for this IO?
fittarelli.com
2/ A few months ago, Darren Linvill @ the Media Forensics Hub at Clemson University made us aware of a set of X accounts that they were tracking. The profiles appeared to be inorganic: artificially set up to spread disparaging narratives on the Iranian regime. Also, they were clearly coordinated.
fittarelli.com
This.
timothysnyder.bsky.social
This is, without any exaggeration, exactly how Putin and Orbán proceeded — using antisemitism to discredit the idea of civil society and political opposition, and as an excuse to undo the rule of law.
www.nytimes.com/2025/09/25/u...
Justice Dept. Official Pushes Prosecutors to Investigate George Soros’s Foundation
www.nytimes.com
fittarelli.com
Also to highlight once again the use of “local influencers on Facebook or TikTok to target audiences that don’t follow politics closely [as] another growing trend.”

This is a particularly difficult one for detection and especially mitigation.
fittarelli.com
Some novel TTPs described here.

“Another effective tool is sending “fake government orders”. There was (a fake government order) for public institutions to display rainbow flags and another one for schools to display LGBT informational posters at the beginning of the school year,” he pointed out.”
Russia’s disinfo in Moldova: Bot networks, church spin and vote buying
Russia intensified its “hybrid war” against Moldova as the country is heading to the parliamentary elections on Sunday, Moldovan authorities say. What tools is Moscow using in Moldova this time, and a...
www.euronews.com
fittarelli.com
“Google said in a statement […] “On YouTube, as part of our proactive coverage for the 2025 Moldova elections, we have terminated more than 1,000 channels since June 2024 for being part of coordinated influence operations targeting Moldova.””
Moldova's election faces AI-driven disinformation from Russia
Moldovans are facing a wave of AI-driven disinformation ahead of a crucial parliamentary election on Sunday
abcnews.go.com
fittarelli.com
Oh, and #abandonEurope too, of course.
fittarelli.com
I’m sure it’s not news to anyone actually paying attention, but we should probably care more that a lot of “name-surname-5digits” accounts are spreading the hashtag #abandonNATO on X at the moment.
fittarelli.com
Correction: *all* secondary schools in *two* towns.