Our weekly Briefing is free, but you should upgrade to access all of our reporting, resources, and a monthly workshop.
This week on Indicator
Craig shared the video, slides, and transcript of his recent workshop about “Finding hidden connections with digital ad data.” He demonstrated how to map shared infrastructure between websites and apps to assist with investigations and attribution. Guest speaker Zach Edwards, co-founder of DecryptAds, also highlighted some useful techniques.
Alexios published a guide to investigating Wikipedia, which has information-rich sockpuppet investigations and plenty of tools to help sniff out manipulation and deceptive coordination on the online encyclopedia.
Disinformation conference stirs up transatlantic drama

A roll up banner for the Disinfo2026 conference covers the logos of government institutions from Canada, the EU, and Lithuania
Hello from Vilnius, where the Disinfo2026 conference hosted by EU DisinfoLab just wrapped up. A redacted poster welcomed participants as several government bodies pulled back from the event at the last minute.
Late last week, Twitter Files co-author Michael Shellenberger had emailed several conference speakers, including me. Shellenberger – who likes to use terms like “Censorship-Industrial Complex” when referring to platform content moderation – asked about two conference sessions in particular: a workshop on running “counter-disinformation campaigns” and a panel discussion about the United States as a foreign information manipulation and interference (FIMI) threat.

You can see his questions and answers from Ben Shultz, a researcher and Indicator contributor, here.
I chose not to respond. I am generally skeptical of government efforts to combat disinformation; I’d much rather they focus on enforcing platform transparency and other preconditions for a healthy information ecosystem. Plus, political elites are themselves a top source of false content. But I am uninterested in engaging with people who, as Techdirt’s Mike Masnick puts it, have been “bumbling around cosplaying as ‘free speech’ experts, [while doing] tremendous damage to free speech.”
Somehow, word of the event reached the US State Department. (Republicans in Congress have called on Shellenberger at least eight times as an expert witness on content moderation.)
Politico and The Guardian reported that the State Department asked US embassies in Europe to pressure several countries to withdraw their support for the conference. Canada, Lithuania, and the European External Action Service (EEAS) ultimately agreed. In a statement to The Guardian, Global Affairs Canada said that “following changes to the framing of several panel discussions, GAC decided to revise its participation in those sessions at the EU DisinfoLab 2026 conference.” EEAS said it pulled back because “the organisers chose to frame some of the discussions in a way which does not align with the official positions held by the EU.” In a follow-up email sent to me after his initial questions, Shellenberger wrote that Lithuania’s Ministry of Foreign Affairs decided to withdraw from the conference “upon becoming aware of the above-mentioned discussion topics.”
The panel on the US as an interference threat has been on the DisinfoLab’s public website for at least a month. And a European Commission spokesperson struggled to justify the EEAS decision in a press briefing, refusing to answer journalists’ questions about American pressure.
France was the only sponsoring government not to change its position, telling The Guardian that “there’s absolutely no reason for us to change our commitments” and that “we stick to supporting civil society. It’s not just principled, it’s operational.”
Maldita’s Carlos Hernández-Echevarría, who moderated the panel that provoked all this transatlantic discord, told me that “all I have to say is that I'm amazed that anyone would get nervous at the thought of 4 researchers having a discussion in a conference in Lithuania.”
To recap: The US government didn't like a panel that discussed its potential interference in foreign information environments. So it interfered in a foreign information environment. — Alexios
Deception in the News
📍 BBC News reported that “prosecutors in Egypt have charged six journalists working for the independent fact-checking platform Matsda2sh with belonging to the outlawed Muslim Brotherhood.” According to the Egyptian Initiative for Personal Rights, the journalists “reported beatings, forced stripping, electric shocks and threats to harm them or their families.”
📍 Wikimedia shared that its projects were targeted by OpenAI’s “rogue” agents. In a blogpost, the foundation said most of the edits were sandbox tests, but a few changed a citation tool’s configuration in what it believes was an attempt to use the tool as a proxy to fetch outside data.
📍 This week in provenance news: OpenAI announced it will roll out its textGrain watermark to “eligible ChatGPT and Codex users across all plans in the EU” and enable it as an opt-in for API users. The company said the tool performs less well on shorter texts and its detection rate fell from about 92% to 66% when 10% of words were swapped for synonyms. Meanwhile, Google expanded access to its public detector for the SynthID watermark. Both moves follow new transparency requirements in the EU and California.
📍 The 8th U.S. Circuit Court of Appeals granted an injunction sought by xAI to pause enforcement of a Minnesota law making AI nudifiers liable for the content they generate. “The court issued a brief, one-sentence order and did not explain its reasoning,” according to CBS.
📍 Google paused new submissions to its product vulnerability open-source bug bounty program “due to a significant rise in automated submissions, the vast majority of which are not valid.”
📍 The New York Times reported that “a North Carolina man was sentenced to 18 months in prison for using artificial intelligence to defraud music streaming platforms and musicians of millions of dollars in royalty payments.” He must also forfeit more than $8 million in royalties.
📍 OpenAI disrupted the first “Category 5” influence operation it detected using its products (the highest level on its impact scale is 6). The banned users were based in Russia and primarily used ChatGPT to write internal reports about their efforts to spread disinformation in Latin America.
📍 Forbes reported that TikTok “gutted” its advertising policies, leading to a surge in scams:
Executives slashed the number of violations for which a TikTok advertiser could be immediately banned by more than half, from 37 down to 13, according to policy documents detailing this change. Running so-called “non delivery” scams … is no longer considered severe enough to merit a suspension. Neither is selling weapons, sketchy financial investments, weight-loss miracle products, fake GLP-1 drugs and pro-eating disorder material. The documents showed a vast relaxing of policy that for years had protected consumers from fraud and harm.
Tools & Tips

I recently published a deep dive guide to OSINT on Reddit. Since then, there have been two developments of note:
Good news: developer José Alberto RG just released a free tool, RedditOSINT. Give it a username and it queries Arctic Shift and PullPush to deliver “everything the public Reddit archives have indexed for that account: posts, comments, what was deleted and what is still live, activity patterns, leaked identifiers, and an exposure score.” Arctic Shift and PullPush are two useful, free Reddit data sources.
I updated the guide to include both items. — Craig
📍 DrishX is an open-source tool that uses a quirk in how the Sentinel-2 satellite captures imagery to display a “traffic activity time-series.” From its GitHub page:
The sensor records red, green, and blue light 1.01 seconds apart. Anything stationary looks normal. But a vehicle moving at highway speed shifts position between those captures, leaving a distinctive blue-green-red spectral smear across a few pixels. DrishX finds those smears, counts them, estimates their speed and direction, and tracks how volume changes across weeks and months.
The output is a traffic activity time-series for any major road corridor on the planet. Built on completely free Copernicus data, runs locally in a browser, and requires zero ground infrastructure.
Developer Sairaj Balaji shared more on LinkedIn, including some of the tool’s limitations:
It has real limits, and I'd rather say them upfront. At 10 m resolution it only sees large vehicles, not cars. It can't tell you what kind of truck it is. And clouds block it completely. It isn't built to follow anyone; it's built to show trends. One image tells you very little. Six months of images tell you a story.
📍 TRACEON.re is a free Telegram search tool that allows you to search a database of over 90 million messages from channels and groups. (via Ben Heubl)
📍 Stephen Abbott Pugh built the free OpenCheck platform for researching company data, and he closely tracks developments in beneficial ownership access. He reported that “Bermuda has strengthened its beneficial ownership rules and introduced legitimate interest access to beneficial ownership information for the first time.” Read more in our recent guide, “Finding the real owner of a company: a guide to beneficial ownership in the EU, UK, and beyond.”
📍 Google made updates to Pinpoint, its free tool for analyzing large collections of documents and other files. It expanded access to Extract Table, a cool feature that enables you to extract structured data from a table contained in a PDF. It also increased the amount of audio you can transcribe and added a feature that “automatically distinguishes between different speakers for audio files up to 10 minutes long across a select set of supported languages.” (The information is from an email that didn’t contain a link to a web version.)
📍 The OSINT Newsletter published, “Company Research: Using OSINT to Look Behind the Marketing.”
📍 Azutech wrote, “Dark Web OSINT: A Practitioner’s Guide to Safe, Legal Hidden-Service Intelligence.”
📍 Henk van Ess and Julius Fitzke wrote, “Inside Russia's Recruiting Machine with AI & OSINT.”
📍 Jake Godin of Bellingcat wrote, “Viral Google Maps Images Shared Widely This Week Show Gaza Ruins. We Obtained More Recent Satellite Imagery.”
Events & Learning
📍 SkopeNow is hosting the 2026 edition of its free virtual OSINT Live event on Oct. 15. Speakers include Micah Hoffman and Griffin Glynn of My OSINT Training, Dr. Manisha Ganguly of The Guardian (and soon-to-be at TIME magazine), and Tom Vaillant, our partner for OSINT Navigator and the Indicator Lab.
Reports & Research

Screenshot from an AI-dubbed video of Donald Trump that ran as a Meta ad for a fake concealed carry permit
📍 ISD found “more than $3.1 million worth of ads urging Meta users to purchase a nonexistent concealed carry permit, with at least 24.8 million impressions in total.” One popular ad included a synthetic video of President Donald Trump discussing a nonexistent concealed carry law.
📍 Trisha Thadani, a former health reporter for The Washington Post, wrote a moving essay about her father’s battle with cancer and the lure of unproven treatments by alternative medicine clinics. “My dad was fixated on Envita’s online testimonials from patients who claimed to have beaten aggressive cancers with the clinic’s help,” Thadani wrote.
📍 A paper in Nature Human Behavior studied the effect of a “write with AI” feature introduced by the petitioning platform Change.org. It found that “in-platform AI access substantially altered the lexical features of petitions and increased petition homogeneity but did not improve petition outcomes.”
📍 Peter Cunliffe-Jones published an analysis with Full Fact examining the potential impact of 112 instances of AI-generated or altered misinformation and disinformation. The report found that more than 40% met the study’s criteria to cause or contribute to serious harm.
One More Thing
A viral ChatGPT-generated cartoon portraying Dolly Parton in a style that evokes The New Yorker went so far as to add the signature of a real cartoonist. Nieman Lab found that at least 15 other cartoonists’ signatures had been added to similar synthetic images posted online or created in its tests.

Indicator is a reader-funded publication.
Please upgrade to access all of our content, including our how-to guides and Academic Library, and to our live monthly workshops.



