FIMI & Cognitive Warfare Monitor — 30 July 2026

EEAS and Ukraine CCD joint report quantifies systematic Russian FIMI campaign against Ukraine EU accession across 244000 publications and 1.39 billion views

Lead Signal

A joint report from the European External Action Service and Ukraine Center for Countering Disinformation, titled Beyond the Battlefield, documents the most quantitatively substantiated case this monitor has logged this year, attributed on the basis of disclosed methodology to a layered Russian information apparatus. The apparatus, combining official state voices, state media, anonymous Telegram networks, and pseudo-local websites, generated 244000 publications and 1.39 billion views while working to erode support for Ukraine accession to the European Union. Over 2600 sources displayed signs of coordinated inauthentic behaviour within this apparatus. The attribution rests on quantitative content analysis and known infrastructure lineage, but the joint authorship of the report by two state-interested bodies warrants continued caution against treating it as fully independent corroboration.

The actor risk matrix records an overall risk rating of HIGH for Russia this cycle, an assessment tied directly to the Beyond the Battlefield findings and carrying the same attribution caution. Set against an information integrity composite score of 0.47, assessed as deteriorating, the picture shows strong attribution capacity concentrated on a small number of well documented actors coexisting with weaker platform transparency and enforcement dimensions elsewhere in the same composite.

Other Developments

Meta publishes its first semiannual Adversarial Threat Report, disclosing multi-actor disruptions while narrowing disclosure frequency. The Meta H1 2026 Adversarial Threat Report, published March 11 2026, disclosed disruption of networks linked to Iran, Russia, and China. The report reaffirmed and updated attribution of the long running Endless Mayfly operation to Iran International Union of Virtual Media. The same cycle marked a shift by the Meta Transparency Center from quarterly to semiannual reporting cadence, a change assessed as lengthening the interval between detection and public disclosure.

Chinese Spamouflage network activity spans two distinct regional targets in the same reporting window. DFRLab identified 27 Facebook pages belonging to Filipino activists targeted in part by a network attributed, at High confidence, to the Spamouflage and Dragonbridge ecosystem. Separately, a network of 90 Facebook profiles and 13 Instagram profiles was documented targeting the Tibetan Parliament in Exile elections. The Philippines finding carries an MF3 flag reflecting single-source Tier 3 sourcing this cycle.

European Commission intensifies DSA enforcement against Meta and X even as it acknowledges methodological gaps. The Commission issued preliminary findings that Meta Facebook and Instagram addictive design elements breach DSA obligations, and its Article 35(2) systemic-risk report, published July 2 2026, admits that no best practices have yet been identified for systemic-risk mitigation. X submitted a compliance plan on paid verification changes while contesting a 120 million euro DSA fine across three cases filed February 16 2026. Separately, Google TAG disclosed takedowns of China-linked YouTube channels targeting Canada and Bangladesh-related channels.

Structural attribution gaps persist for Gulf states, the United States, and Israel. No new attribution surfaced this cycle for Gulf states or for the United States as an originating FIMI actor, a status the interpreter marks as possible rather than confirmed absence of activity. Israel public posture this cycle was a defensive warning on Iranian cyber-disinformation threats rather than any offensive disclosure. Separately, European Parliament members pressed the European Commission on an unresolved question concerning alleged former United States intelligence staffing of Meta election operations centres.

Cross-Monitor Connections

This cycle findings connect to several sibling monitors. The democratic-integrity monitor is directly implicated by the Russian attribution documented in the Beyond the Battlefield report, given its direct bearing on Ukraine EU accession process, a connection the interpreter flags at High confidence. The conflict-escalation monitor should track the assessed pattern in which the Gulf and Iran conflict has become, per EDMO preliminary assessment, the dominant driver of AI-generated European disinformation activity this cycle. The european-strategic-autonomy monitor intersects with this cycle High-confidence Beyond the Battlefield finding and with the European Commission ongoing DSA enforcement actions against Meta and X, both bearing directly on European institutional integrity and enlargement-process protection. The ai-governance monitor is relevant to the EEAS 4th FIMI Threat Report finding that 27 percent of 2025 attributed FIMI incidents involved AI-generated content, a High-confidence figure that the Meta H1 2026 Adversarial Threat Report corroborates through its own disclosure of multi-actor network disruptions.

Outlook

Looking to next cycle, several open items merit continued attention. Independent technical infrastructure corroboration connecting Belarusian security services with the documented Russian FIMI apparatus would upgrade the Belarus transnational-repression case beyond its current Assessed confidence rating. A platform-disclosed coordinated-inauthentic-behaviour report naming a Gulf-state or United States linked network with technical fingerprint evidence would begin to close the structural six-actor parity gap that currently leaves attribution capacity concentrated on Russia, China, and Iran. Resolution of the unresolved question regarding alleged former United States intelligence staffing of Meta election operations centres, which European Parliament members have pressed without a concrete answer, would also meaningfully clarify a persistent governance blind spot.

The recurring overlap between narrative persistence in the Russian infrastructure documented against Ukraine EU accession and the accelerating integration of generative AI across nearly every tracked actor cluster suggests these two risk vectors are converging into a single structural pattern rather than remaining separable indicators. Whether the European Commission own acknowledged methodological gaps in systemic-risk mitigation narrow or widen against this backdrop will be a key marker of whether DSA enforcement activity translates into measurable governance improvement.

Sources Inauthentic Behavior | Transparency Center → T3 Meta’s threat disruptions | Transparency Center → T3 CIB Detection Tree: 2nd Branch - EU DisinfoLab → T3 Coordinated Inauthentic Behaviour detection tree - EU DisinfoLab → T3 CIB Detection Tree: Third Branch - EU DisinfoLab → T3 CIB Detection Tree: 4th Branch - EU DisinfoLab → T3 Visual assessment of CIB in disinformation campaigns - EU DisinfoLab → T3 Analysis of coordinated inauthentic behavior in Moldova: 23 days before the elections - EDMO → T3 How Coordinated Inauthentic Behavior continues on Social Platforms | FSI → T3 Integrity Reports, Third Quarter 2025 | Transparency Center → T3 EUvsDisinfo | Detecting, analysing, and raising awareness about disinformation - EUvsDisinfo → T3 Russia’s information war against Ukraine’s European future is a threat to Europe itself - EUvsDisinfo → T3