False stories rarely spread by accident. Behind many of them sit hired accounts and automated networks pushing the same narrative across platforms before most people notice anything unusual. For researchers, security teams and businesses, this makes disinformation detection a growing challenge – one the World Economic Forum has now ranked among the top short-term global risks for the second year running. Detection itself has changed in response, paying less attention to wording and more to the behaviour around it.
What is disinformation detection?
Disinformation detection is the work of identifying coordinated efforts to spread false or misleading narratives online. It draws signals from social platforms, websites, news feeds and other public sources, which analysts and software then comb for patterns of organised manipulation.
Rather than fact-checking every post, the aim is to find the coordination behind a story. That focus is what separates modern detection from a simple keyword filter.
What disinformation detection is really up against
The real adversary is the influence operation, not the isolated rumour. These campaigns target people rather than systems, and they set out to shape trust, emotions and decisions.
Analysts often describe this contest over perception as cognitive warfare, a framing that treats public opinion as contested space. This breakdown of modern influence operations explains how campaigns try to bend human judgement – and understanding that goal helps teams read the signals around a campaign.
How big is the disinformation problem?
Disinformation now runs at industrial scale. Oxford researchers have documented organised social media manipulation in 81 countries, much of it carried out by so-called cyber troops – accounts that push scripted messages in bulk. The European External Action Service tracks the same trend: it recorded 540 coordinated incidents during 2025, involving roughly 10,500 channels and websites.
The industry has professionalised too. The same Oxford research found private firms offering disinformation-for-hire, which turns coordinated manipulation into a service clients can simply buy.
Why text alone no longer works
Generative AI can produce polished, varied messages at scale, and that is why text alone misses too much. Older tools leaned on spelling quirks, repeated wording and other textual clues – signals that matter far less now that low-cost models turn out convincing posts in seconds. The EU found that one in four incidents in 2025 used AI tools, and the same technology generates synthetic audio and manipulated video.
False posts no longer have to look like spam, so systems that judge one message at a time can miss the wider campaign entirely.
How disinformation detection shifted to behaviour
Modern disinformation detection watches behaviour as closely as content. Individual users post at odd hours, vary their wording and follow personal habits, while coordinated networks tend to leave more regular traces.
Detection systems watch for a few clear signals:
- Timing – many accounts share the same link within seconds of each other.
- Repetition – profiles push identical talking points across unrelated topics.
- Clustering – groups of accounts amplify the same content together, again and again.
These patterns are hard to disguise across a large network, and they stay visible even when the wording keeps changing.
How network analysis catches coordination
Network analysis maps how accounts connect, share and react to one another. Treat a social platform as a graph of users and interactions, and detection tools can surface clusters that ordinary content review misses – suspicious accounts gathering around the same posts, say, or appearing early in the same viral chains. One peer-reviewed study used graph learning to flag these operations, and the model found coordinated accounts that content filters had missed.
Newer research follows these networks across platforms, because campaigns rarely stay on one app. A claim may start on one platform and pick up support elsewhere. Analysts call this coordinated inauthentic behaviour.
How modern detection tools work together
Effective detection combines several methods rather than trusting one signal. Teams pair open-source intelligence with media monitoring, language analysis and network analysis, and narrative intelligence platforms such as Repsense bring these signals into one view.
That combination lets a team follow how a story moves and who amplifies it. One unusual post proves little; a repeated pattern across accounts, channels and platforms can reveal coordinated activity.
What disinformation detection cannot do
The limits are real. A coordination signal can show how content spreads, but it cannot prove a claim false – human analysts still have to weigh intent, context and accuracy.
Automated systems can also flag innocent communities, since fans, activists and grassroots groups sometimes act in sync. Strong teams treat detection scores as leads rather than verdicts, and they review the network before taking any action.
Why disinformation detection matters beyond elections
Disinformation reaches well past politics. Businesses, hospitals and public agencies all face coordinated narrative attacks, and false claims can damage trust, move markets or trigger a reputational crisis.
A manufactured backlash may look like genuine public anger at first. Behavioural detection helps teams separate organic criticism from coordinated amplification, which supports faster and more proportionate responses.
The bottom line on disinformation detection
Disinformation will keep getting harder to judge from text alone. Wording changes cheaply, but coordinated behaviour is much harder to hide at scale. Detection works best when it follows timing, networks, amplification and cross-platform movement, because that is what shows analysts the campaign behind the content.
