Terminology
A shared vocabulary for understanding information manipulation, AI security, and online fraud.
Fraud and scams
7 terms
How people are deceived into giving up money, information, or access.
- Phishing:
- Deceptive communication, often through email or text messages, that impersonates a trusted source to trick someone into sharing sensitive information, transferring money, opening a malicious file, or visiting a harmful site.
- Spear phishing:
- A targeted phishing attempt tailored to a specific person or organization using information about them to appear credible. Targets do not have to be high-profile individuals.
- Pig butchering:
- A commonly used term for long-term relationship-based investment fraud. Scammers build trust through friendship, romance, or purported investment expertise before steering a person toward fraudulent investments or platforms.
- Account takeover (ATO):
- Gaining unauthorized control of a legitimate user’s account, often to steal information, commit fraud, impersonate the owner, or access other services.
- Spoofing (voice, email):
- Falsifying an identity or the apparent source of a communication to impersonate someone trusted. Examples include forged email sender details, manipulated caller ID, lookalike domains, spoofed IP addresses, and voice impersonation.
- Scam / spam:
- Spam is unsolicited, often bulk-distributed messaging. A scam is a deceptive scheme intended to obtain money, information, or another benefit. Spam can carry scams, but the terms are not interchangeable.
Information manipulation
6 terms
How false, misleading, or harmful information is shared and made to look credible.
- Misinformation:
- False or inaccurate information shared without knowing it is false or intending to deceive. Example: A relative shares an outdated emergency warning on Facebook, believing it describes a current event.
- Disinformation:
- False or misleading information deliberately created or shared to deceive or cause harm. Example: An account knowingly publishes a fabricated evacuation notice to cause panic.
- Malinformation:
- Genuine information used with the intention of causing harm, such as exposing private information to enable harassment. It can also involve using true information out of context to mislead. Example: Someone publishes a person’s real home address to encourage others to harass them.
- Information laundering:
- Moving false, misleading, or strategically planted material through other outlets and accounts to obscure its origin and make it appear more credible or independently corroborated.
- Synthetic media manipulation:
- Creating or altering audio, video, images, or other content using AI or other technology to deceptively misrepresent reality. Synthetic media itself also has legitimate uses.
- Deepfake:
- AI-generated or AI-manipulated audio, video, or imagery that realistically depicts a person saying or doing something they did not actually say or do. Deepfakes can be deceptive, but can also be clearly labeled creative works.
Influence operations
6 terms
How coordinated activity manufactures the appearance of support and shapes public opinion.
- Coordinated influence operations:
- Organized efforts to shape public opinion or behavior through coordinated use of information channels. Deceptive operations conceal their origins, identities, or coordination; their operators may be states, commercial firms, or other groups.
- Astroturfing:
- Manufacturing the appearance of independent, grassroots support when the activity is actually centrally organized or funded.
- Sockpuppetting:
- Using fake online identities, often with one operator controlling multiple accounts, to deceive audiences into believing independent people share a view or endorse a claim. Also spelled sockpuppeting.
- Troll farms:
- Organized operations in which people, often supported by automation, produce and amplify deceptive, inflammatory, or divisive online content to influence audiences, harass targets, or sow discord.
- Computational propaganda:
- Using algorithms, automation, and data analysis to produce, target, or amplify political messaging and manipulate public opinion at scale.
- LLM grooming:
- An emerging term for attempts to make large language models repeat selected narratives by flooding the information sources they may learn from or retrieve. This can target web search and retrieval as well as potential training data; repetition in a chatbot answer alone does not prove its training data was poisoned.
AI systems
4 terms
How AI models are attacked, manipulated, or produce unreliable output.
- Jailbreak:
- A technique or crafted input intended to bypass an AI model’s safety restrictions and elicit content or actions it would otherwise refuse.
- Prompt injection / adversarial prompting:
- Prompt injection embeds instructions in input, such as a user message, document, or website, to redirect an AI system away from its intended task or rules. Adversarial prompting is a broader term for inputs designed to induce unwanted behavior, including jailbreaks and prompt injection.
- Data poisoning:
- Deliberately introducing corrupted, biased, or malicious data into a model’s training or fine-tuning pipeline to manipulate its future outputs or behavior.
- Model hallucination:
- An AI reliability failure in which a model generates plausible-sounding content that is false, fabricated, or unsupported by the available evidence or context. It can have safety consequences, especially when people rely on the output.
Investigation and analysis
4 terms
How researchers gather intelligence, track adversaries, and map the stages of an attack.
- Open-source intelligence (OSINT):
- Intelligence produced by collecting and analyzing publicly available information, such as social media, news reports, websites, and public records.
- Human intelligence (HUMINT):
- Intelligence obtained from human sources through interpersonal contact, including interviews, informants, and undercover engagement.
- Nation-state actor tracking:
- The intelligence discipline of identifying, attributing, and monitoring cyber or influence activity conducted by or on behalf of governments.
- Killchain:
- A structured, stage-by-stage model of an attack, used to understand how an adversary progresses and where that activity could be detected or disrupted. Also written as kill chain.
Actors and operations
13 terms
Names and classifications used in public reporting for groups, networks, campaigns, and companies. These are not all equivalent kinds of organizations; attribution and naming can differ between researchers.
- Spamouflage / Dragonbridge:
- A persistent, China-linked influence network using large volumes of inauthentic accounts and repetitive content to promote pro-Beijing narratives and criticize opponents. Google tracks it as Dragonbridge; Meta has linked activity to individuals associated with Chinese law enforcement.
- Doppelganger:
- A Russian influence campaign known for imitating legitimate news outlets through lookalike domains and copied branding to distribute pro-Kremlin narratives. The U.S. Justice Department attributed the operation to Russian government direction in its 2024 domain-seizure announcement.
- Matryoshka / Operation Overload:
- A Russian disinformation campaign that sends fabricated media and coordinated verification requests to journalists and fact-checkers, seeking to exhaust their resources and gain attention for false narratives. Overlap in tactics with other campaigns does not by itself establish a shared operator.
- Portal Kombat / Pravda network:
- A network of pro-Russian aggregation sites documented by France’s VIGINUM, republishing content across domains aimed at different countries and languages. NewsGuard later documented its narratives appearing in AI chatbot responses; this does not by itself establish that a model’s training data was altered.
- Ghostwriter:
- An influence campaign associated with fabricated stories, compromised websites, and impersonation. Mandiant linked supporting cyber activity tracked as UNC1151 to Belarus. Related actor labels in public reporting include Storm-0257, UAC-0057, and FrostyNeighbor; campaign names and actor identifiers do not always describe exactly the same activity.
- Secondary Infektion:
- A Russia-origin influence operation documented by Graphika, known for forged documents, fabricated stories, and disposable accounts across many platforms. Its extensive use of single-use accounts made links between assets difficult to trace.
- Internet Research Agency (IRA):
- A St. Petersburg-based Russian organization widely known as a troll farm. A 2018 U.S. indictment alleged that it used false American personas and coordinated online activity to interfere in U.S. politics, including the 2016 presidential election.
- Storm-2035:
- An Iran-linked influence network using websites posing as news outlets to publish political and social commentary. In 2024, OpenAI reported disrupting accounts that used ChatGPT to produce material for the operation, while finding little meaningful audience engagement.
- STOIC:
- An Israeli commercial firm linked in 2024 platform investigations to covert influence activity, including pro-Israel messaging about the Gaza war. OpenAI described the operation it disrupted as “Zero Zeno.”
- Team Jorge:
- The name used by an Israel-based contractor group exposed in the 2023 Story Killers investigation. Undercover reporting documented offers of hacking, fake online personas, and disinformation services intended to influence elections and other public affairs.
- Rally Forge:
- A U.S. marketing firm banned by Facebook in 2020 after an investigation linked it to coordinated inauthentic behavior, including fake accounts used on behalf of clients such as Turning Point USA.
- Domestic hate groups (SPLC):
- In the Southern Poverty Law Center’s classification, groups whose statements or activities attack or vilify a class of people, typically because of characteristics such as race, religion, or sexual orientation. This is a civil watchdog classification, rather than a government designation or a finding that every listed group commits violence.
- Disinformation Dozen:
- A label coined by the Center for Countering Digital Hate for 12 prominent anti-vaccine figures. Its 2021 report attributed up to 65% of the anti-vaccine content in its analyzed sample to them. Facebook disputed the methodology and generalization; the figure should not be treated as a measured share of all vaccine misinformation across social media.