The Conspiratory
Case File No. 9732-Q● Declassified · Confirmed

Storm-1516 is a Russia-linked disinformation operation that manufactures fake videos and cloned news sites to smear Western and Ukrainian figures

Where the evidence lands: Supported
That a coordinated, Russia-linked operation, tracked under the name Storm-1516, deliberately fabricates videos, impersonates news outlets and journalists, and seeds false scandals about Ukrainian and Western public figures in order to erode support for Ukraine and inflame divisions in the United States and Europe.
First circulated
The tactics grew out of the 2022 "Doppelganger" campaign; Storm-1516's own fabricated stories began appearing around August 2023, and Microsoft assigned the "Storm-1516" label in April 2024
Era
2020s
Sources
9

Believed by: Treated as a documented operation by Microsoft (MTAC), France's VIGINUM, EU DisinfoLab, NewsGuard, Recorded Future, Clemson University's Media Forensics Hub, and major newsrooms; the Russia attribution is shared by these researchers and by EU and other Western governments

The full story

A factory for fake outrage

Most of the files in this archive weigh a claim and, more often than not, find it wanting. This one is different. Storm-1516 is not a theory to be debunked; it is a documented operation, and the thing being confirmed is that a coordinated campaign really does manufacture fake news on an assembly line.

The output has a recognizable shape. A grainy clip shows an unidentified person speaking gravely about a “leaked document” or a hidden scandal. A web page carries the logo and layout of a local television station or newspaper you have never quite heard of. An AI-generated “report” surfaces a lurid allegation about a president, a first lady, or a candidate. None of it happened. The person on camera is often a paid actor; the outlet is a shell; the scandal is invented. What is real is the machine that produces them, and by early 2026 the Microsoft Threat Analysis Center was counting its output in the thousands of videos per quarter.

The name is a tracking label. Microsoft tags emerging threat clusters as “Storm” plus a number before it has finished attributing them, and Storm-1516 stuck. (Microsoft later reclassified the group as a nation-state actor and renamed it Neva Flood.) This file rates the operation substantiatedbecause the evidence is not a single leak but a stack of independent investigations: Microsoft, France's VIGINUM, EU DisinfoLab, NewsGuard, Recorded Future, and newsrooms including Bloomberg have each mapped it from a different angle and arrived at the same picture.

The case for it

How the machine works

The operation's cleverness is less in any single fake than in how the fakes travel. Researchers describe a laundering pipeline designed to strip a story of its origins before it reaches a real audience.

It begins with disposable accounts. According to VIGINUM, operators seed content through anonymous “burner” accounts spread across platforms including YouTube, X, Instagram, Facebook, TikTok, and Rumble, sometimes primed weeks in advance with plausible biographies and reposted legitimate content so a profile looks lived-in before it is used. A staged video of a supposed whistleblower goes up first here, where it can be dismissed as fringe.

Next comes the coat of respectability. The claim is “reported” by a website built to look like a genuine local outlet, part of networks such as the AI-generated CopyCop cluster that Recorded Future has traced to hundreds of fake sites. NewsGuard catalogued 139 such French-language sites in one sweep. A hoax that started on an anonymous account now carries a dateline and a masthead.

The goal is to erase the fingerprints. By the time a fabricated clip reaches an ordinary feed, it looks like independent reporting, not a press release from Moscow.

Finally, sympathetic or paid influencers amplify it, and if the operation succeeds, a mainstream commentator or politician repeats it, completing the journey from burner account to real headline. The Harris hit-and-run video of 2024 ran this exact route, surfacing on a fake San Francisco “TV station” before spreading; Microsoft later reported the woman on camera was an actor.

The greatest hoaxes

The catalogue of specific fabrications is what makes the operation concrete, and nearly all of them have been individually debunked by fact-checkers who traced them back to the network.

Ukraine and its president are the recurring targets. Stories tied to the operation have falsely alleged that Zelensky's circle bought two yachts worth some $75 million with stolen aid money, that Olena Zelenska spent millions on a Bugatti and on jewelry, and that the family secretly owns luxury property abroad. Each was invented; each was designed to make Western voters feel their aid was being squandered. The yacht claim is the clearest example of the operation's reach: as Bloomberg reported, it was repeated in American politics by a sitting senator arguing against further support for Kyiv.

The operation also aims at Western domestic politics. Ahead of the 2024 US election it produced the false Harris hit-and-run video. Around the February 2025 German federal election, researchers documented deepfake videos and fake sites smearing German politicians. In the run-up to the 2024 Paris Olympics and the French and European votes, it pushed viral fakes on immigration and terrorism. In July 2026, a staged video of masked men posing as Hezbollah fighters and threatening a Bastille Day attack on France was traced by AFP and other fact-checkers to the same pro-Russian network; analysts noted the speakers' Arabic did not match a genuine Lebanese accent.

The through-line is not a single message but a mood. Whether the subject is Ukrainian corruption, a disliked candidate, or the threat of terrorism, the fabrications are chosen to deepen anxiety and distrust in the countries supporting Ukraine.

The case for it

Who is behind it, and how we know

It is worth being precise about what is proven and what is assessed, because they sit on slightly different footings. That the operation exists and is Russia-linked is the shared conclusion of Microsoft, VIGINUM, EU DisinfoLab, NewsGuard, Recorded Future, and Western governments. The finer chain-of-command details come from intelligence assessments and sanctions filings rather than from anything Moscow has admitted.

Microsoft classifies Storm-1516 as a Russian nation-state actor. A Ukrainian intelligence assessment reviewed by Bloomberg, along with Western officials, points to the GRU (Russia's military-intelligence service) and specifically its Unit 29155 as financing the network's servers and AI tools. VIGINUM, a French state agency, reached compatible conclusions from its own analysis of 77 operations.

Researchers and the EU also point to intermediaries who give the operation reach in the West. NewsGuard and Recorded Future identify John Mark Dougan, a former Florida deputy sheriff who relocated to Moscow in 2016, as running a network of fake-news sites used to distribute the content, and the EU imposed sanctions on him citing links to Russian military intelligence. These are the findings of the investigators and governments named here; the file reports their attribution rather than asserting the specifics in its own voice, and it does not treat any individual's role as a proven criminal fact beyond what those bodies have formally alleged.

The honest summary is that the operation is understood and attributed, not confessed. That is a strong footing: multiple independent bodies, using different methods, converged on the same actor. But the very last details of who does what inside the Russian apparatus rest on assessment, which is why the file attributes them carefully.

Why people believe

Why the fakes keep working

A reasonable question is why an operation whose stories are so often debunked keeps succeeding. The answer is that being believed in full was never entirely the point.

Part of it is form. A face on camera and a broadcaster's logo feel like evidence in a way that text does not, and cheap generative tools now make such clips quick to produce and just convincing enough to survive a scroll. Part of it is content: the fabrications are tuned to confirm suspicions the audience already holds, so they meet less resistance than a claim that has to overcome a reader's priors.

And part of it is sheer volume. When a network ships more than ten fresh fakes a day, debunking cannot keep pace, and each correction arrives after the story has already done its work. The deeper aim is corrosive rather than persuasive: to flood the space with enough plausible-looking claims that audiences stop trusting anything, including the genuine reporting that would expose the operation. A public that shrugs and says “who can tell what's true anymore” is, for a disinformation campaign, a public that has already been won.

The point is doubt

Storm-1516 matters beyond any one hoax because it marks how cheap and fast industrial-scale fabrication has become. The Doppelganger campaign of 2022 still had to painstakingly clone real news brands; its successor churns out synthetic whistleblowers and fake stations by the thousand, adapting within days to whatever election or tragedy is in the news.

That is why the documentation is a public service rather than an amplification. Naming the operation, tracing its pipeline, and pinning specific viral lies to it is how the fakes lose their power: a clip that a viewer recognizes as a known Storm-1516 product is a clip that no longer works. The researchers and agencies cited here have done the tracing so that the next fabricated scandal can be met with a source rather than a shrug.

The durable lesson is uncomfortable. The operation does not need most people to believe most of its stories; it needs enough people to doubt enough of the truth. Understanding it as a system, rather than reacting to its outputs one at a time, is the only way to blunt it, which is the whole reason this file confirms the operation instead of relaying its claims.

Advertisement
Open questions

What's still unexplained

  • How much of the operation's output actually changes minds, as opposed to briefly going viral before being debunked, is hard to measure; view counts are not the same as persuasion, and researchers disagree on real-world impact.
  • The precise chain of command, including exactly which Russian entities and individuals direct, fund, and execute each stage, is drawn from intelligence assessments and sanctions filings rather than any public Russian record, so specifics remain contested at the edges.
  • As detection improves, it is unclear how quickly the operation will shift tactics, formats, and platforms, and whether AI-generated fakes will grow harder or (through better provenance tools) easier to catch.
  • The role and autonomy of named intermediaries associated with the fake-site networks, versus direct state operators, is still being pieced together by investigators and is not fully settled.

Point by point

The claim: Storm-1516 is a real, coordinated operation producing fabricated media at industrial scale, not a handful of scattered fakes.

What the record shows: Documented in detail. Microsoft's Threat Analysis Center reported more than 1,000 artificially generated videos produced for the network in the first quarter of 2026 (over ten a day), and Bloomberg identified more than 190 fabricated stories tied to the operation since August 2023, collectively drawing hundreds of millions of views. France's VIGINUM analyzed 77 distinct information operations through March 2025. The convergence of independent counts from a major software company, a national government agency, and a newsroom establishes the operation as a single, sustained campaign.

The claim: Its purpose is to discredit Ukraine and weaken Western support, and to inflame divisions during elections.

What the record shows: This is the assessment of the researchers who mapped it. VIGINUM concluded the operation's main objective is very likely to discredit the Ukrainian government in order to erode Western aid, while also targeting European leaders during election periods. The timing of its surges (the June 2024 European Parliament vote, the July 2024 French snap election, the February 2025 German federal election, and the 2024 US campaign) matches that goal, as does the recurring focus on Ukrainian figures.

The claim: Specific viral hoaxes have been traced to the operation and shown to be fabricated.

What the record shows: Repeatedly documented. Microsoft attributed the 2024 Kamala Harris hit-and-run video to Storm-1516 and reported the woman in it was a paid actor; CBS News found no record of the alleged crash. Fact-checkers debunked a cluster of Zelensky-family claims tied to the network, including a $75 million pair of yachts, a $4.5 million Bugatti and $1.1 million in jewelry attributed to Olena Zelenska, and alleged luxury property purchases. Each was traced to the same laundering pattern rather than to any real event.

The claim: The operation is linked to the Russian state.

What the record shows: Attributed to Russia-linked actors by multiple reputable sources, though the finest details rest on intelligence assessments rather than a Russian admission. Microsoft classifies the group as a Russian nation-state actor. Western officials and a Ukrainian intelligence assessment reviewed by Bloomberg point to Russia's military-intelligence service, the GRU, and specifically its Unit 29155, as financing the network's servers and AI tooling. The EU cited Russian military-intelligence links when it sanctioned individuals connected to the operation. The state attribution is the consensus of these bodies, not a claim the file asserts on its own authority.

The claim: Storm-1516 relies on a network of fake local-news websites to make hoaxes look like reporting.

What the record shows: Documented by NewsGuard and Recorded Future. NewsGuard catalogued 139 fake French-language "news" sites tied to the Kremlin and a run of Storm-1516 hoaxes in France that drew tens of millions of views. Recorded Future traced the "CopyCop" network of hundreds of AI-generated fake outlets used to publish and dress up the content, which researchers and EU sanctions associate with John Mark Dougan. These sites give a fabricated clip the surface appearance of a genuine local news story.

The claim: Storm-1516 is an evolution of the earlier Doppelganger campaign, not an unrelated effort.

What the record shows: Supported by the tracking research, with an important nuance. Analysts including DFRLab and EU DisinfoLab treat Storm-1516 and Doppelganger as related but distinct "information manipulation sets" within the same Russian ecosystem: Doppelganger pioneered the cloning of real news brands from 2022, while Storm-1516 specializes in staged videos and whistleblower fakes. VIGINUM notes close coordination and occasional overlap between Storm-1516 and other Russian operations, including CopyCop and Project Lakhta.

Timeline

  1. 2022In the months after Russia's full-scale invasion of Ukraine, the "Doppelganger" campaign begins cloning European and Ukrainian news brands (outlets such as Bild, Le Parisien, The Guardian, and 20 Minutes) on look-alike domains. EU DisinfoLab and the digital-forensics group Qurium expose it in September 2022 and tie it to the Russian firms Social Design Agency and Structura. Doppelganger establishes the playbook Storm-1516 later builds on.
  2. 2023-08The earliest fabricated stories that Bloomberg and other researchers later attribute to Storm-1516 begin circulating. The operation leans on staged "whistleblower" clips and impersonated journalists rather than only cloned websites, a shift toward video-first fakes.
  3. 2023-11A false report claims Volodymyr Zelensky's associates bought two yachts worth roughly $75 million with money stolen from Western military aid. Fact-checkers debunk it, but the claim spreads widely; per Bloomberg's reporting, then-Senator JD Vance publicly repeated the yacht story while explaining his opposition to further US aid to Ukraine, an early illustration of a fabricated narrative reaching mainstream American politics.
  4. 2023-12Researchers at Clemson University's Media Forensics Hub publicly identify the coordinated network behind a run of these hoaxes, an early step in mapping the operation as a distinct actor.
  5. 2024-04Microsoft's Threat Analysis Center assigns the label "Storm-1516" (Microsoft uses "Storm" plus a number for developing threat clusters) and warns that US audiences are reposting Russia-origin disinformation about Ukraine, often unaware of its source. Microsoft later classifies the group as a Russian nation-state actor and renames it "Neva Flood."
  6. 2024-09Days before the US election, a fabricated video alleges that Kamala Harris left a teenager disabled in a 2011 hit-and-run. It surfaces on a site masquerading as a San Francisco TV station, "KBSF-TV." Microsoft attributes the hoax to Storm-1516 and reports the woman on camera was a paid actor; CBS News and others find no record of any such incident. The same month, the US Justice Department seizes 32 domains tied to the related Doppelganger operation.
  7. 2024-12The European Union imposes sanctions targeting the operation, including on John Mark Dougan, a former Florida deputy sheriff who moved to Moscow in 2016; EU and researcher assessments describe him as running a network of fake-news sites used to spread Storm-1516 content. NewsGuard separately names Dougan its "Disinformer of the Year."
  8. 2025-05France's state agency VIGINUM publishes a technical report analyzing 77 Storm-1516 information operations through March 2025, concluding the campaign's principal aim is to discredit the Ukrainian government and erode Western aid, while also targeting European leaders around elections in France, the United States, and Germany.
  9. 2026The operation's tempo climbs sharply. Microsoft's Threat Analysis Center reports it mapped more than 1,000 synthetic videos produced for the network in the first quarter of 2026 alone, and Bloomberg counts more than 190 fabricated stories since August 2023 with hundreds of millions of views. In July 2026, a fake video of masked "Hezbollah" fighters threatening a Bastille Day attack on France is traced by AFP and others to the same pro-Russian ecosystem.
The primary sources

From the case file

The actual records: declassified, released, or leaked. We link straight to each document in its official archive, so you never have to take our word for it. Read the originals yourself.

Where the evidence lands

Supported. This is not a theory the site is debunking: it is a documented influence operation. Microsoft's Threat Analysis Center, France's VIGINUM, EU DisinfoLab, NewsGuard, Recorded Future, Bloomberg, and multiple Western governments have all tracked Storm-1516, catalogued its fabricated stories, and attributed it to Russia-linked actors. What is firmly established is the operation itself: the staged whistleblower videos, the fake local-news websites, the coordinated laundering of hoaxes into real feeds. Precise chain-of-command details (which GRU unit, which named individuals) rest on intelligence assessments and sanctions designations reported by these sources rather than on any Russian admission, which is why the file attributes those specifics to the researchers and governments that make them.

Reviewed by The Conspiratory Editors · Last reviewed July 20, 2026 · How we rate

Sources

  1. 1.Storm-1516: Technical report on a pro-Russian information manipulation set, VIGINUM / SGDSN (French government) (2025)
  2. 2.Russia's Disinformation War Floods Social Media With Dangerous False Claims, Bloomberg (2026)
  3. 3.Storm-1516, the pro-Russian disinformation operation threatening the public debate, EDMO (European Digital Media Observatory) (2025)
  4. 4.Russian Propaganda Campaign Targets France with AI-Fabricated Scandals, Drawing 55 Million Views on Social Media, NewsGuard (2025)
  5. 5.NewsGuard Rates Network of 139 Fake French News Websites with Ties to the Kremlin, NewsGuard (2025)
  6. 6.Bogus hit-and-run story about Vice President Kamala Harris created by Russian troll farm, Microsoft says, CBS News (2024)
  7. 7.Doppelganger: How Russia mimicked real news sites and created fake ones to target US audiences, DFRLab (Atlantic Council) (2024)
  8. 8.CopyCop Deepens Its Playbook with New Websites and Targets, Recorded Future (Insikt Group) (2025)
  9. 9.Storm-1516: Fake Hezbollah video threatening Bastille Day attack possibly Russia linked, Euronews (2026)

Help us investigate

This is a living case file. If you spot an error or know evidence we missed, tell us, and weigh in on where you land.

Where do you land?

Cast your read on this one.

What did we miss?

Spotted an error or know a source worth chasing? Every note is read by a human.

Comments

Add your take. Comments are read and approved by a human before they appear, so keep it on topic and civil. Please do not accuse named, living people of crimes.

Saved on this device so you keep the same name next time. No account needed.

Related case files

Related topics

Advertisement
Written by The Conspiratory Editors · Published July 20, 2026. The Conspiratory lays out the claim, the case on every side, and the sources, so you can weigh it yourself. Spotted a stronger source? Corrections are welcome.