European fact-checking and media-monitoring organizations are sounding the alarm over a confluence of threats aimed at European democracy ahead of the June elections. In the latest issue of the Disinfo Bulletin, released by the European Digital Media Observatory (EDMO) network, three separate developments illustrate the intensifying pressure: the continued expansion of a Russian-run disinformation network even after it was publicly exposed; a steady and measurable rise in disinformation targeting the European Union itself; and an ongoing campaign of cyberattacks against critical European infrastructure, including repeated attempts to destabilize the Czech railway system. Together, these findings paint a picture of a comprehensive and multi-layered threat landscape in which foreign manipulation, digital interference, and cyber sabotage are increasingly intertwined. The bulletin, which aggregates material from the EDMO fact-checking network, national hubs, and the newly launched EFCSN Elections 24 Check database, is intended to provide a daily update for decision-makers, journalists, and the public. Its latest edition highlights not only the persistence of known propaganda structures but also the ability of hostile actors to adapt after being exposed, reaching into smaller European language communities as a way of bypassing scrutiny. As the European Parliament elections approach, the findings underscore the need for continuous vigilance, cross-border cooperation, and a deeper understanding of how information operations are actually reaching audiences.

At the centre of this latest warning is the Russian-backed operation known as “Portal Kombat,” first identified in a February 2024 report by Viginum, the French agency responsible for detecting and combatting foreign digital interference. Viginum, operating under the Secretariat-General for National Defence and Security (SGDSN), documented a large-scale disinformation infrastructure designed to spread pro-Russian narratives across Europe in multiple languages, including French, German, Spanish, and English. The network reportedly functioned through a series of copycat websites using the historic name “Pravda,” which were activated in the second half of 2023. According to Viginum’s analysis, the primary goal appeared to be influencing public discourse by flooding European information spaces with pro-Kremlin content, a classic example of what is now commonly referred to as foreign information manipulation and interference (FIMI). What makes the case particularly troubling, however, is that the exposure of the network did not stop it. Despite the French agency’s report, the proliferation of these Pravda-branded websites has continued across Europe. The latest discovery came from Greece Fact Check, a Greek fact-checking organization and member of the EDMO network, which detected new activations in April in Greek, Italian, Bulgarian, Danish, and Dutch. These additions mean the operation now covers an even broader linguistic front, allowing it to target audiences that may have previously been less exposed to such direct propaganda. The decision to expand into smaller European languages appears tactical: it is easier to operate under the radar in less-monitored language communities, where fact-checking resources are thinner and where false narratives may be met with less immediate scrutiny.

The EDMO fact-checking network has now launched an investigation to better understand the reach, characteristics, and impact of this expanding network. The results are expected to be published in the coming weeks, and will likely offer crucial insight into how these websites are being promoted, whether through social media amplification, paid advertisement, or organic sharing via messaging apps. The investigation will also seek to determine the actual audience size of the Pravda sites, a question that remains unresolved in many previous analyses of Russian influence operations. Experts in disinformation often caution that the existence of a fake website does not automatically translate into influence, especially if the site receives little traffic. But the deliberate expansion into multiple languages and the use of a recognizable brand like Pravda suggests a level of sustained investment and ambition. The case also highlights the growing complexity of the information environment facing Europe. It is no longer enough to track individual false claims; fact-checkers must now map entire networks of coordinated websites, understand how they mirror or recycle content from Moscow-backed outlets, and determine how they are embedded in the wider digital ecosystem. This is precisely the kind of cross-border effort that EDMO was created to facilitate, bringing together national hubs, independent fact-checkers, and academic researchers. Still, the bulletin makes clear that these investigations are slow and resource-intensive, while hostile actors can change domains, languages, and platforms quickly. The challenge, therefore, is not only exposing the networks but also developing early-warning mechanisms that can detect new versions and disruptions before they take root.

Parallel to this Russian network, EDMO’s quantitative monitoring reveals a slower but steady increase in disinformation specifically targeting the European Union. For the past ten months, EDMO has been tracking EU-related disinformation as part of its monthly briefs, which also cover topics such as Ukraine, the pandemic, and climate change. The latest data, anticipated in the 34th brief scheduled for publication on 17 April, shows that in March the percentage of EU-related disinformation among all detected disinformation items reached 8 percent. That number may sound small, but it represents a significant upward trend over time. In the first five months of EDMO’s monitoring, the average share of EU-related disinformation was 4.4 percent. In the most recent five months, that average has climbed to 7 percent. In other words, the proportion of misleading and manipulative content aimed at the European Union as an institution, its policies, and its upcoming elections has almost doubled over the course of the monitoring period. The bulletin predicts that this percentage will continue to increase as the June elections draw nearer, and there are several reasons for that expectation. Elections provide a clear inflection point for information operations, because the potential to affect political outcomes is greatest when citizens are making decisions about who will represent them. Moreover, EU-related disinformation often overlaps with debates on sovereignty, migration, security, and economic policy, making it a useful vehicle for narratives that portray the EU as distant, undemocratic, or on the verge of collapse. The monitoring data does not attribute all EU-related disinformation to Russian actors; domestic political actors, fringe media, and conspiracy networks also contribute. But the overall direction is clear: as election day approaches, the volume and intensity of anti-EU content is likely to grow.

The third major issue highlighted in the bulletin is cyberattacks targeting European critical infrastructure, with a specific focus on the Czech Republic. Czech transport authorities have detected thousands of attempts to destabilize the country’s rail system since Russia launched its full-scale invasion of Ukraine in 2022. These efforts have included denial-of-service attacks on ticketing systems and, even more worryingly, attempted signal interference that could have caused accidents. The fact that such attempts have been repeated thousands of times suggests a sustained and deliberate campaign rather than isolated hacktivist activity. Although the bulletin does not explicitly attribute every single attack to the Russian state, the timing and pattern point towards a wider strategy of undermining European stability and creating an impression of vulnerability. The reference to signal interference is particularly alarming because it moves beyond the usual realm of information manipulation and into the physical world, raising the potential for real harm to passengers and infrastructure workers. The bulletin also notes that, generally speaking, this kind of attack appears to target European energy infrastructure, with the broader aim of making the EU look weak in the face of external cyber threats. The implication is that adversary states are using cyber tools not only to spy or steal data, but also to test the resilience of essential services and to create a climate of fear. In response, the European Union has been developing a range of measures, including the so-called “Cyber solidarity package,” which is designed to strengthen collective preparedness, detection, and response to significant cyber threats. Such mechanisms include the creation of national and cross-border cyber hubs, a cybersecurity reserve of incident response services, and a review mechanism for coordinated risk assessments. These efforts are welcome, but the bulletin warns that the threat environment remains acute, especially with the June elections approaching. Cyber operations can be used as part of broader hybrid campaigns, combining network attacks, disinformation, and political pressure in a way that makes attribution and response extremely difficult.

Taken together, the three stories published in this edition of the Disinfo Bulletin illustrate the full spectrum of challenges facing the European Union in the coming weeks. The Russian-run Portal Kombat network shows that information manipulation remains persistent and adaptive, expanding into new linguistic territories even after exposure. The EDMO statistics on EU-related disinformation demonstrate a clear trend upward, one that is likely to intensify as citizens prepare to vote. And the Czech rail cyberattacks are a reminder that the digital battlespace is not confined to social media narratives; it also includes critical infrastructure that millions of people rely on every day. What connects these threats is the underlying goal: to weaken trust in European institutions, erode social cohesion, and make the European Union appear vulnerable, divided, and incapable of protecting its citizens. The response, accordingly, must be equally integrated. Fact-checkers need greater support, funding, and cross-border coordination to counter networks like Portal Kombat. Platforms must become more transparent about the distribution and amplification of foreign-controlled content. Governments need to invest in cyber resilience and regular testing of critical services. And the public must develop the critical literacy skills to recognize false narratives and avoid sharing them further. The EDMO network, with its combination of fact-checking organizations, national hubs, and a growing body of publicly accessible data, is a central part of this effort. But as the latest bulletin makes clear, the threat is not static. Every investigation published and every cyber defense established will likely be met with new tactics, new languages, and new targets. The June elections are not the finish line; they are simply the next major battleground. Sustained vigilance, transparent reporting, and collective action will be essential in the months ahead.

Share.
Leave A Reply

Exit mobile version