top of page

OPERATION OVERLOAD Part III: The Operation Grows Smarter

11 minutes ago
3 min read

Debunk.org has been a confirmed target of Operation Overload since 2023. Our first report documented 120 emails received through that point, identified five thematic clusters, named Telegram as the dominant link destination, identified Gmail as the primary sending infrastructure, and noted a consistent correlation between email volume spikes and major EU-Ukraine geopolitical events.  Our second report extended the dataset to nearly 350 emails and analysed more than 100 images through the MAAM (Media Asset Annotation and Management), a platform developed by CERTH's MeVer Group as part of AI-CODE, a Horizon Europe project: over 80% of visual materials were classified as disinformative, and a third were fully or partially AI-generated. The analysis documented systematic impersonation of Reuters, Bellingcat, and MSNBC, and established AI generation as a core operational tool of the campaign.


This report presents a third and longitudinal analysis — more than 1,000 emails from October 2023 to April 2026 — extending the documented scope in three directions: a month-by-month platform migration analysis tracking how the operation's link distribution shifted across Telegram, X/Twitter, TikTok, Bluesky and TruthSocial; platform enforcement analysis measuring account-level takedown rates; and forensic image analysis of a 120-image sample drawn from the 2025–2026 active campaign period.

Operation Overload is best understood not simply as a campaign that circulates false content, but as an operation that pressures the verification ecosystem itself. Across 32 months of submissions to Debunk.org, the campaign shows sustained operational discipline: disposable sender infrastructure, repeated payload reuse, recurring amplification channels, weekday dispatch patterns, and gradual migration across platforms as the information environment changed.

The evidence points to a campaign that has become more adaptive over time. Early activity relied heavily on Telegram and repeated email submissions. Later phases diversified across X/Twitter, TikTok, Bluesky and other platforms, while increasing the amount of content bundled into each submission. By April 2026, the operation’s intensity was no longer defined only by the number of emails received, but by the density of links and claims imposed on analysts through each targeting event.


This evolution increases the cost of verification. A single submission can now contain multiple links, platform accounts, fabricated media artefacts, AI-generated visuals and impersonated news brands. Each element requires a different form of review: account-level checks, source verification, image forensics, media-brand authentication and narrative analysis. The operation’s efficiency lies in compressing all of these tasks into routine-looking fact-check requests.


Platform evidence also shows the campaign isn't tied to a single distribution model. On Telegram, it relied on durable amplification channels. On X/Twitter, it used aged or low-credibility accounts with signs of artificial reach. On Bluesky, it used a more sophisticated tactic: appropriating real credibility through compromised or misused accounts belonging to journalists, academics, and public-facing users. These differences indicate tactical flexibility rather than a fixed platform model.

The visual evidence reinforces the same conclusion. Operation Overload does not rely on a single manipulation pattern. It uses AI-generated imagery where synthetic scenes are useful, compositing where altered but plausible images are needed, and falsified media templates where the goal is to borrow institutional credibility. A Not AI-Generated result is therefore not equivalent to authenticity; it may simply mean the deception sits in the overlay, the claim, the source attribution or the impersonated format rather than in the base image.


Taken together, the findings show a campaign built around overload, laundering and adaptation. It overloads analysts with repeated submissions and dense link packages. It launders false claims through the visual identity of trusted media and, in some cases, through real, aged or repurposed social accounts. And it adapts its infrastructure as platforms moderate, audiences move and detection methods improve.


Read the full report here:


For more information about the AI-CODE Project, click here. The AI-CODE project is funded by the HORIZON Europe Programme of the European Union. 
For more information about the AI-CODE Project, click here. The AI-CODE project is funded by the HORIZON Europe Programme of the European Union. 

Comments


bottom of page