For 20 years, ISD has delivered field-leading threat detection, analysis and real-world strategies to combat terrorism, extremism and authoritarianism - in all their ideological forms.

Home / Digital Dispatches / Louder and Louder on the Western Front: Key Takeaways from the Authoritarian Interference Tracker

Digital Dispatches

July 29, 2026

ISD-US

Information Warfare and Online Manipulation

Louder and Louder on the Western Front: Key Takeaways from the Authoritarian Interference Tracker

Louis Savoia and Krysia Sikora

In February 2025, Germany faced a wave of car vandalism ahead of the country’s federal elections. More than 270 vehicles across the country were found with expanding construction foam sprayed into their exhaust pipes, rendering them unusable, and defaced with stickers promoting the Greens, a prominent left-wing political party. The operation, initially blamed on climate activists, was later revealed to be the work of saboteurs whom Russian government operatives hired on social media in a campaign intended to influence the election results.  

Earlier this year, the Iranian proxy group known as Harakat Ashab al-Yamin al-Islamiya (HAYI) committed more than a dozen arson attacks targeting Jewish communities and American diplomatic and financial institutions in the UK, the Netherlands, Belgium, Canada, Germany, France and North Macedonia. In May, the mayor of Arcadia, California, pled guilty to acting as an illegal agent of a foreign government after the US Department of Justice unsealed a plea deal detailing her efforts to circulate Beijing-approved propaganda at the behest of Chinese officials.   

These are just some of the incidents which show a pattern of authoritarian state-sponsored interference activities targeting Europe and North America online and offline. Over the past decade, Russia, China and Iran have deployed an ever-evolving set of hybrid tactics to advance specific strategic objectives, erode trust in democratic institutions, and exacerbate political and social fissures in targeted societies. While elections are still frequent targets of interference operations (as seen recently in Moldova and Armenia), authoritarian states have a much wider range of targets. 

To help capture this reality, the Institute for Strategic Dialogue (ISD) is releasing its Authoritarian Interference Tracker (AIT). The tool catalogues instances of authoritarian interference by Russia, China and Iran to target democracies in Europe and North America since the start of 2022 across five incident types: cyber operations, kinetic operations, information operations, malign finance, and political and civic subversion. Building on a database previously maintained by the Alliance for Securing Democracy at the German Marshall Fund of the United States, this updated version now includes activity linked to Iran, a redesigned user interface, and new features to monitor and identify trends across countries and incident types.

A screenshot showing the interface of the AIT.

Building an exhaustive picture of the threat landscape is challenging due to various factors, including differences in public reporting and attribution by the governments of targeted countries. Nonetheless, the more than 290 catalogued incidents that have taken place from 2022 onward highlight several concerning trends. 

Key takeaways include: 

  1. Iran is intensifying its interference efforts, although Russia remains the most eminent threat actor across all incident types. The AIT documents at least 188 unique incidents attributable to Russia since 2022, compared to 57 and 49 linked to Iran and China, respectively. However, the Iranian regime has been intensifying its hybrid activities. In 2024, it employed a diversified range of brazen operations targeting US elections, including an assassin-for-hire plot against then-presidential candidate Donald Trump, a hack-and-leak operation against the Trump campaign, and the creation of a network of inauthentic websites targeting different voter demographics. Iranian hybrid threats against the West have escalated amid intensifying military conflict in the Middle East. The AIT documents 18 incidents traced to Iran in the first half of 2026 alone. These include attacks targeting Jewish communities and American institutions in Europe and North America in what appears to be a direct response to US-Iran hostilities. 
  2. Foreign threat actors are increasingly targeting energy and water infrastructure with disruptive, and potentially destructive, cyberattacks. Cybercriminals linked to Russia and Iran are increasingly conducting cyberattacks beyond website defacement, which have long been the norm. Instead, they are targeting critical infrastructure in ways that threaten severe consequences: the AIT records 15 cyber incidents involving energy and water disruption since 2022, 10 of which have taken place since the start of 2025. There are likely many cases that have not been disclosed. Targeting critical infrastructure is not new: Western intelligence services have ample evidence that adversaries have long been probing and mapping out critical infrastructure networks mostly to signal capability and to be primed in the event of escalating military hostilities. However, this activity is already escalating in ways that could significantly impact citizens and communities even in the absence of direct military conflict. In late 2024, Z-Pentest, a hacking group founded, funded and directed by Russia’s military intelligence agency (GRU), targeted a water facility in a town outside Copenhagen. They were able to successfully alter water pressure, causing three pipes to burst. Around 500 homes were impacted, 50 of which lost water supply for seven hours. Sweden and Poland faced unprecedented cyberattacks by Russia-backed groups targeting their energy sectors in 2025, which could have halted the supply of heat for hundreds of thousands. US officials suspect Iran was behind several breaches of US critical infrastructure just this year, including one on California’s largest water utility, which serves 500,000 customers. While most of the intrusions have not caused significant damage, they reveal significant vulnerabilities and raise concerns about future, more destructive intrusions. Cyberattacks on critical infrastructure also frequently impart a sense of insecurity across society. State-aligned cyber groups often also release media evidence of their infiltration of critical infrastructure networks. The cognitive dimension of these corresponding information operations is intended to cause panic and fear in targeted societies. 
  3. Russia and Iran are increasingly executing on-the-ground kinetic attacks in Europe and North America. These include sabotage, vandalism and targeted assassinations. As the AIT documents, the number of kinetic operations carried out by Russia against Western countries (particularly in Europe) has spiked since the start of Russia’s full-scale invasion of Ukraine. There were just 2 documented incidents in 2022 but 60 since the start of 2024. These attacks range from vandalizing city streets to acts of terrorism, such as sabotaging train lines or sending explosives through courier or postal services. The latter, worryingly, suggests that Russia is becoming increasingly reckless and cavalier about potential civilian casualties. Since the start of 2024, most of Russia’s kinetic attacks documented in the AIT have targeted Poland (13), followed closely by Germany (11), Lithuania (8), France and Moldova (7 apiece), and Latvia (6). There are likely more kinetic incidents that have yet to be publicly disclosed or attributed. Iran has also increasingly resorted to kinetic operations; the AIT records at least 30 Iran-linked kinetic incidents since 2022. These incidents mostly take the form of intimidation campaigns and assassination plots targeting dissidents, regime critics or members of Jewish communities. The objective of Russia and Iran’s kinetic operations is often psychological: to spread a sense of insecurity among society and undermine public trust in government. A recently leaked trove of Kremlin documents revealed Russian intelligence agencies’ thinking. They referred to a series of kinetic attacks in France and Germany as “cognitive strikes” intended to stoke tension between religious groups and weaken support for certain parties. Attacks included placing pig heads in front of mosques in Paris. To strengthen their psychological effect, Russian and Iranian operatives often ask saboteurs to film kinetic attacks for later use in online information campaigns. 
  4. Russia and Iran rely on disposable agents and criminal syndicates to carry out their kinetic operations. Many are recruited and hired on commercially accessible online platforms. Nearly all Russia-linked kinetic incidents captured in the AIT since 2022 involved recruiting saboteurs on social media platforms such as Telegram. These individuals, some recruited from as far away as Colombia, were offered payment in the form of cryptocurrency. A recent investigation by the Polish Russian-language outlet Vot Tak uncovered a vast network of recruiters linked to Russian intelligence services that posted more than 20 million ads in Telegram job-search chats in more than 20 countries to hire saboteurs to attack Ukrainian-linked organizations across Europe. The Kremlin also reportedly held sabotage training camps in the Balkans and Russia to teach recruits how to conduct destabilization tactics: for example, how to handle incendiary devices or provoke protests in service of operations in countries like Moldova, Armenia and France. Iran has similarly leveraged connections with criminal organizations in Europe and used online platforms to recruit assassins-for-hire. In 2024, Iran hired members of two different Swedish crime groups to carry out a series of attacks on the Israeli embassies in Sweden and Denmark. Financial motivations are the most common incentive for these contracted agents; only a small minority appear ideologically motivated. 
  5. China’s most physically aggressive acts of interference center on transnational repression targeting diaspora communities or its critics in the West. The AIT logs 17 incidents of China-linked transnational repression that occurred in 2022 or beyond. Late that year, NGO Safeguard Defenders revealed that China’s Ministry of Public Security had been operating more than 100 illegal police stations worldwide to surveil and intimidate Chinese nationals and citizens living abroad. China’s transnational repression campaigns frequently traverse into the online realm. The AIT documents multiple Chinese state-sponsored online harassment campaigns targeting vocal critics of Beijing. One incident in 2025 involved the creation and spread of AI-generated sexually explicit deepfakes of a Canada-based YouTuber who comments on contemporary Chinese politics. Other significant examples of attempting to control or manipulate Chinese communities abroad include attempts to hinder the election campaigns of multiple perceived Canada-based critics of China, and a massive cyberattack against Italian law enforcement that attempted to exfiltrate information about the country’s Chinese diaspora.  

Conclusion 

Foreign interference is not a new phenomenon, but it is constantly evolving. New technologies provide Russia, China, Iran, and others the tools to conduct more sophisticated and more harmful campaigns at comparatively low cost. Generative AI and increasingly targeted social media manipulation have indeed lowered the entry cost and expanded the reach of influence operations: this allows both state and state-aligned actors to blur the line between authentic and inauthentic discourse. Meanwhile, multiple geopolitical flashpoints provide ample motivation for authoritarian regimes to expand their risk tolerance. This makes the potential for more innovative and destructive campaigns, including acts of sabotage and attacks on critical infrastructure, a real and growing risk.  

The AIT helps to paint a better picture of this evolving threat landscape, tracking not just isolated incidents but the broader patterns and tactics that recur across borders and over a period of time. No single database can capture the full scope of this activity, some of which remains undetected or undisclosed. But by building a rigorous, cumulative record of authoritarian interference, the AIT aims to equip researchers, policymakers and journalists with the foundation needed to address it.

You can access the AIT here. 

ISD Contributors