# Storm-1516 is a Russia-linked disinformation operation that manufactures fake videos and cloned news sites to smear Western and Ukrainian figures

**Verdict: Proven.** This is not a theory the site is debunking: it is a documented influence operation. Microsoft's Threat Analysis Center, France's VIGINUM, EU DisinfoLab, NewsGuard, Recorded Future, Bloomberg, and multiple Western governments have all tracked Storm-1516, catalogued its fabricated stories, and attributed it to Russia-linked actors. What is firmly established is the operation itself: the staged whistleblower videos, the fake local-news websites, the coordinated laundering of hoaxes into real feeds. Precise chain-of-command details (which GRU unit, which named individuals) rest on intelligence assessments and sanctions designations reported by these sources rather than on any Russian admission, which is why the file attributes those specifics to the researchers and governments that make them.

Category: Government & Intelligence · Era: 2020s · First circulated: The tactics grew out of the 2022 "Doppelganger" campaign; Storm-1516's own fabricated stories began appearing around August 2023, and Microsoft assigned the "Storm-1516" label in April 2024 · Believed by: Treated as a documented operation by Microsoft (MTAC), France's VIGINUM, EU DisinfoLab, NewsGuard, Recorded Future, Clemson University's Media Forensics Hub, and major newsrooms; the Russia attribution is shared by these researchers and by EU and other Western governments
URL: https://theconspiratory.com/theory/storm-1516

## Summary
Storm-1516 is the tracking name for a prolific Russia-linked disinformation operation that mass-produces fabricated content: staged videos of supposed whistleblowers and pseudo-journalists, cloned pages dressed up as local TV stations, and AI-generated "scandals" aimed at discrediting Ukraine and Western leaders. Researchers first mapped its output in late 2023, Microsoft assigned the Storm-1516 label in April 2024, and by early 2026 the Microsoft Threat Analysis Center was counting more than a thousand synthetic videos in a single quarter. Its hoaxes are engineered to launder from anonymous "burner" accounts through fringe sites and paid influencers until real politicians and mainstream outlets repeat them. Unlike most files in this archive, the rated claim here is true: the operation is real, extensively documented, and attributed to Russia-linked actors by reputable researchers and Western governments.

## The claim
That a coordinated, Russia-linked operation, tracked under the name Storm-1516, deliberately fabricates videos, impersonates news outlets and journalists, and seeds false scandals about Ukrainian and Western public figures in order to erode support for Ukraine and inflame divisions in the United States and Europe.

## Origin and timeline
- 2022: In the months after Russia's full-scale invasion of Ukraine, the "Doppelganger" campaign begins cloning European and Ukrainian news brands (outlets such as Bild, Le Parisien, The Guardian, and 20 Minutes) on look-alike domains. EU DisinfoLab and the digital-forensics group Qurium expose it in September 2022 and tie it to the Russian firms Social Design Agency and Structura. Doppelganger establishes the playbook Storm-1516 later builds on.
- 2023-08: The earliest fabricated stories that Bloomberg and other researchers later attribute to Storm-1516 begin circulating. The operation leans on staged "whistleblower" clips and impersonated journalists rather than only cloned websites, a shift toward video-first fakes.
- 2023-11: A false report claims Volodymyr Zelensky's associates bought two yachts worth roughly $75 million with money stolen from Western military aid. Fact-checkers debunk it, but the claim spreads widely; per Bloomberg's reporting, then-Senator JD Vance publicly repeated the yacht story while explaining his opposition to further US aid to Ukraine, an early illustration of a fabricated narrative reaching mainstream American politics.
- 2023-12: Researchers at Clemson University's Media Forensics Hub publicly identify the coordinated network behind a run of these hoaxes, an early step in mapping the operation as a distinct actor.
- 2024-04: Microsoft's Threat Analysis Center assigns the label "Storm-1516" (Microsoft uses "Storm" plus a number for developing threat clusters) and warns that US audiences are reposting Russia-origin disinformation about Ukraine, often unaware of its source. Microsoft later classifies the group as a Russian nation-state actor and renames it "Neva Flood."
- 2024-09: Days before the US election, a fabricated video alleges that Kamala Harris left a teenager disabled in a 2011 hit-and-run. It surfaces on a site masquerading as a San Francisco TV station, "KBSF-TV." Microsoft attributes the hoax to Storm-1516 and reports the woman on camera was a paid actor; CBS News and others find no record of any such incident. The same month, the US Justice Department seizes 32 domains tied to the related Doppelganger operation.
- 2024-12: The European Union imposes sanctions targeting the operation, including on John Mark Dougan, a former Florida deputy sheriff who moved to Moscow in 2016; EU and researcher assessments describe him as running a network of fake-news sites used to spread Storm-1516 content. NewsGuard separately names Dougan its "Disinformer of the Year."
- 2025-05: France's state agency VIGINUM publishes a technical report analyzing 77 Storm-1516 information operations through March 2025, concluding the campaign's principal aim is to discredit the Ukrainian government and erode Western aid, while also targeting European leaders around elections in France, the United States, and Germany.
- 2026: The operation's tempo climbs sharply. Microsoft's Threat Analysis Center reports it mapped more than 1,000 synthetic videos produced for the network in the first quarter of 2026 alone, and Bloomberg counts more than 190 fabricated stories since August 2023 with hundreds of millions of views. In July 2026, a fake video of masked "Hezbollah" fighters threatening a Bastille Day attack on France is traced by AFP and others to the same pro-Russian ecosystem.

## The evidence, claim by claim
- Claim: Storm-1516 is a real, coordinated operation producing fabricated media at industrial scale, not a handful of scattered fakes.
  Evidence: Documented in detail. Microsoft's Threat Analysis Center reported more than 1,000 artificially generated videos produced for the network in the first quarter of 2026 (over ten a day), and Bloomberg identified more than 190 fabricated stories tied to the operation since August 2023, collectively drawing hundreds of millions of views. France's VIGINUM analyzed 77 distinct information operations through March 2025. The convergence of independent counts from a major software company, a national government agency, and a newsroom establishes the operation as a single, sustained campaign.
- Claim: Its purpose is to discredit Ukraine and weaken Western support, and to inflame divisions during elections.
  Evidence: This is the assessment of the researchers who mapped it. VIGINUM concluded the operation's main objective is very likely to discredit the Ukrainian government in order to erode Western aid, while also targeting European leaders during election periods. The timing of its surges (the June 2024 European Parliament vote, the July 2024 French snap election, the February 2025 German federal election, and the 2024 US campaign) matches that goal, as does the recurring focus on Ukrainian figures.
- Claim: Specific viral hoaxes have been traced to the operation and shown to be fabricated.
  Evidence: Repeatedly documented. Microsoft attributed the 2024 Kamala Harris hit-and-run video to Storm-1516 and reported the woman in it was a paid actor; CBS News found no record of the alleged crash. Fact-checkers debunked a cluster of Zelensky-family claims tied to the network, including a $75 million pair of yachts, a $4.5 million Bugatti and $1.1 million in jewelry attributed to Olena Zelenska, and alleged luxury property purchases. Each was traced to the same laundering pattern rather than to any real event.
- Claim: The operation is linked to the Russian state.
  Evidence: Attributed to Russia-linked actors by multiple reputable sources, though the finest details rest on intelligence assessments rather than a Russian admission. Microsoft classifies the group as a Russian nation-state actor. Western officials and a Ukrainian intelligence assessment reviewed by Bloomberg point to Russia's military-intelligence service, the GRU, and specifically its Unit 29155, as financing the network's servers and AI tooling. The EU cited Russian military-intelligence links when it sanctioned individuals connected to the operation. The state attribution is the consensus of these bodies, not a claim the file asserts on its own authority.
- Claim: Storm-1516 relies on a network of fake local-news websites to make hoaxes look like reporting.
  Evidence: Documented by NewsGuard and Recorded Future. NewsGuard catalogued 139 fake French-language "news" sites tied to the Kremlin and a run of Storm-1516 hoaxes in France that drew tens of millions of views. Recorded Future traced the "CopyCop" network of hundreds of AI-generated fake outlets used to publish and dress up the content, which researchers and EU sanctions associate with John Mark Dougan. These sites give a fabricated clip the surface appearance of a genuine local news story.
- Claim: Storm-1516 is an evolution of the earlier Doppelganger campaign, not an unrelated effort.
  Evidence: Supported by the tracking research, with an important nuance. Analysts including DFRLab and EU DisinfoLab treat Storm-1516 and Doppelganger as related but distinct "information manipulation sets" within the same Russian ecosystem: Doppelganger pioneered the cloning of real news brands from 2022, while Storm-1516 specializes in staged videos and whistleblower fakes. VIGINUM notes close coordination and occasional overlap between Storm-1516 and other Russian operations, including CopyCop and Project Lakhta.

## Why people believe it
- The fakes are built to launder into trusted channels. A hoax starts on anonymous burner accounts, gets "reported" by a fake local outlet, is amplified by paid or sympathetic influencers, and only then reaches ordinary users, who see it arriving through seemingly independent sources rather than from an obvious propaganda site.
- Video feels like proof. A person on camera claiming to be a whistleblower, or a clip stamped with a broadcaster's logo, carries an intuitive credibility that a block of text does not, and cheap AI tools now make such clips fast and plausible enough to fool a scrolling viewer.
- The stories are engineered to confirm what target audiences already suspect: that aid to Ukraine is wasted on corruption, that a disliked politician is secretly venal, that immigration brings danger. A fabrication that flatters an existing grievance travels faster and meets less resistance.
- The sheer volume overwhelms correction. When an operation ships more than ten fresh fake videos a day, fact-checkers cannot debunk each one before it spreads, and even a corrected hoax leaves a residue of doubt that serves the operation's real aim: not to be believed in full, but to make audiences unsure what to trust.

## Open questions
- How much of the operation's output actually changes minds, as opposed to briefly going viral before being debunked, is hard to measure; view counts are not the same as persuasion, and researchers disagree on real-world impact.
- The precise chain of command, including exactly which Russian entities and individuals direct, fund, and execute each stage, is drawn from intelligence assessments and sanctions filings rather than any public Russian record, so specifics remain contested at the edges.
- As detection improves, it is unclear how quickly the operation will shift tactics, formats, and platforms, and whether AI-generated fakes will grow harder or (through better provenance tools) easier to catch.
- The role and autonomy of named intermediaries associated with the fake-site networks, versus direct state operators, is still being pieced together by investigators and is not fully settled.

## Latest developments
- 2026-08-15T00:40Z: A fabrication with this operation's exact signature circulated this week, and the honest thing to say up front is that nobody has attributed it. On 13 August an X account posted what it presented as breaking news: four dead after a shooting at NATO's Baltic Trust 26 exercise in Latvia, with a Ukrainian gunman said to have opened fire on NATO servicemen, killing three before taking his own life. The report was credited to Euronews. Lead Stories rated it false on 14 August. There is no such report on the Euronews website or on its X and Facebook accounts, searches of Google and Google News turned up no credible journalism on any such shooting, and the Latvian army posted an explicit denial on 14 August stating that no such incident had occurred and the exercises were proceeding without incident. What makes it worth recording here is how precisely it matches the method catalogued in this file. The exercise is real: Baltic Trust 26 ran in Riga from 3 to 14 August. The outlet is real, a pan-European network headquartered in Lyon. Only the incident inside them was invented, and the credibility came from borrowing an institution's name rather than from any account anyone would otherwise trust. The framing points the same way as the operation's documented output, since it places a Ukrainian as the killer of NATO troops at a NATO exercise. But no researcher, government or fact-checker has tied this specific item to Storm-1516 or to any named actor, and this file will not do it for them. It is logged as an instance of the pattern, not as an attributed operation. (source: https://leadstories.com/hoax-alert/2026/08/fact-check-euronews-did-not-publish-report-saying-ukrainian-gunman-shot-dead-3-nato-soldiers-in-latvia.html)

## Sources
- Storm-1516: Technical report on a pro-Russian information manipulation set, VIGINUM / SGDSN (French government) (2025): https://www.sgdsn.gouv.fr/files/files/Publications/20250507_TLP-CLEAR_NP_SGDSN_VIGINUM_Technical%20report_Storm-1516.pdf
- Russia's Disinformation War Floods Social Media With Dangerous False Claims, Bloomberg (2026): https://www.bloomberg.com/graphics/2026-russia-disinformation-storm-1516-videos/
- Storm-1516, the pro-Russian disinformation operation threatening the public debate, EDMO (European Digital Media Observatory) (2025): https://edmo.eu/publications/storm-1516-the-pro-russian-disinformation-operation-threatening-the-public-debate/
- Russian Propaganda Campaign Targets France with AI-Fabricated Scandals, Drawing 55 Million Views on Social Media, NewsGuard (2025): https://www.newsguardtech.com/special-reports/russian-propaganda-campaign-targets-france-with-ai-fabricated-scandals/
- NewsGuard Rates Network of 139 Fake French News Websites with Ties to the Kremlin, NewsGuard (2025): https://www.newsguardtech.com/press/newsguard-rates-network-of-139-fake-french-news-websites-with-ties-to-the-kremlin/
- Bogus hit-and-run story about Vice President Kamala Harris created by Russian troll farm, Microsoft says, CBS News (2024): https://www.cbsnews.com/news/bogus-story-kamala-harris-paralyzed-teen-russia-disinformation-microsoft/
- Doppelganger: How Russia mimicked real news sites and created fake ones to target US audiences, DFRLab (Atlantic Council) (2024): https://dfrlab.org/2024/09/18/doppelganger-us-election/
- CopyCop Deepens Its Playbook with New Websites and Targets, Recorded Future (Insikt Group) (2025): https://www.recordedfuture.com/research/copycop-deepens-its-playbook-with-new-websites-and-targets
- Storm-1516: Fake Hezbollah video threatening Bastille Day attack possibly Russia linked, Euronews (2026): https://www.euronews.com/my-europe/2026/07/16/storm-1516-fake-hezbollah-video-threatening-bastille-day-attack-possibly-russia-linked

Rated by The Conspiratory, a neutral, sourced encyclopedia of conspiracy theories. Full page: https://theconspiratory.com/theory/storm-1516