Moscow’s largest achievement against Israel, keeping it out of the coalition arming Ukraine, was won with diplomacy over Syrian airspace rather than with code. The half of the Russian threat that does reach Israel is the cognitive half, and it is the half no Israeli institution owns.
ENSI research — built on a library of 164 primary documents and 52 company dossiers, compiled 23 September 2026.
The argument, before the list
Microsoft’s 2025 Digital Defense Report counts 603 observed nation-state events against targets in Israel over a twelve-month window — the highest figure in the Middle East and Africa, and second in the world only to the United States at 623. Israel takes 3.5% of all attacks Microsoft observes anywhere, behind the US at 24.8% and the UK at 5.6%, ahead of Germany and ahead of Ukraine (Microsoft 2025, pp. 8, 43–44). By any reasonable measure Israel is one of the two most-attacked countries in the world.
Now look at who is doing it. Israel accounts for 64% of all Iranian nation-state targeting — “Iran views Israel as its top regional rival,” the report notes drily. And Israel does not appear at all in the top ten regions targeted by Russian state actors. That list reads: United States 20% · United Kingdom 12% · Ukraine 11% · Germany 6% · Belgium 5% · Italy 3% · Estonia 3% · France 3% · Netherlands 3% · Poland 3% (Microsoft 2025, pp. 46, 48). Outside Ukraine, every country on it is a NATO member, and the set grew 25% year on year. Russian state cyber power is pointed at the alliance that arms Kyiv. Israel is not on the list because Israel is not in that coalition.
That absence is the finding this report is built around, and it is not an accident of telemetry. It is the visible output of a policy. Michelle Grisé and Alexandra Evans, writing for RAND on the Russian–Iranian relationship, list among the indicators an analyst should watch the possibility that Israeli action in Syria might “strain Iranian patience with Russian efforts to preserve positive relations with Israel and minimize Israeli support to Ukraine“ (RAND 2023, p. 15). Moscow’s Israel policy has an explicit objective, it is stated in the open literature, and it has been achieved. Israel has declined to send air-defence systems to Ukraine, and its Defense Export Controls Agency blocked Ukraine from buying Pegasus and barred Estonia from using it against Russian targets (Feldstein and Kot, Carnegie 2023, p. 23). The most effective Russian operation against a first-rank cyber power was a diplomatic one, and no amount of technical resilience defends against it.
But the absence from the Russian state top ten is not the same as absence of Russian pressure, and this is where the picture gets interesting. Recorded Future’s thirteen-month telemetry on NoName057(16) — the pro-Russian DDoS crowd-sourcing operation that is Europe’s most persistent nuisance actor — shows attacks on 3,776 unique hosts, with the burden distributed by share of attack days as: Ukraine ~29.5% · France 6.09% · Italy 5.39% · Sweden 5.29% · Germany 4.60% · Israel 4.50% · Czech Republic 4.00% · Poland 4.00% (Insikt Group 2025, p. 12). Israel is the fifth most-targeted country by the most industrialised pro-Russian proxy operation in existence, ahead of Czechia, and the only non-European state in that tier. Nataliya Tkachuk, a senior official of Ukraine’s National Cybersecurity Coordination Centre, supplies the mechanism: “Since late 2022, Russian intelligence has taken full command of all pro-Russian hacktivist groups… following the 7 October 2023 terrorist attack in Israel, dozens of new pseudo-hacktivist groups were launched to attack Israeli infrastructure. During this period, Ukraine saw its lowest number of cyber incidents in years” (CCDCOE Tallinn Paper 15, 2025, p. 18). The same deniable capacity, redirected by geopolitical requirement.
So the Russian vector reaches Israel — but it arrives through proxies, through capability transfer to Iran, and through a third channel that cyber telemetry cannot see at all. Since April 2023 a Kremlin-steered Hebrew-language operation codenamed “Normal Israel” has been running inside Israel: media clones of N12, sponsored articles bought in Walla, The Jerusalem Post and Channel 13, a costed proposal to found a political party of Russian-speaking immigrants targeting three or four Knesset seats, and a proposal to spray provocative graffiti in Arab neighbourhoods while posing as Jewish right-wing extremists (Rakov, JISS 2025, pp. 7, 31–32).
This is where Russian doctrine stops being an academic point. Michael Connell and Sarah Vogler open their CNA study with the observation that ought to reorganise every European cyber agency: “The Russians generally do not use the terms cyber (kiber) or cyberwarfare (kibervoyna), except when referring to Western or other foreign writings on the topic” (CNA 2017, p. 11). What Moscow operates is informatsionnoe protivoborstvo — information confrontation — with an information-technical limb and an information-psychological limb under one chain of command, which Mandiant draws as an actual organisation chart: GRU Information Operations Troops (Unit 55111) above Unit 26165 and Unit 74455, with espionage, attack and influence as three columns of one unit’s mission (Mandiant 2024, pp. 5–6). A state that buys cyber defence from one agency and counter-disinformation from another is fighting a single adversary with two disconnected halves.
Israel has the best of the first half and almost none of the second. Colonel (res.) Daniel Rakov — a former Israeli intelligence officer writing for the Jerusalem Institute for Strategy and Security — states the position without varnish: “Israel lacks a national strategy for dealing with such foreign interventions: the Israeli Security Agency has insufficient legal powers to act, and the government’s cooperation with civil society bodies on this issue is in its infancy” (JISS 2025, p. 9). The February 2025 national cyber strategy does list a public mindspace resilient to foreign influence among its objectives (Shabtai, BESA 2025). It names no owner, and no law gives anyone the power to act on it.
The reframe, then, is this. Israel treats Russia as a diplomatic problem that occasionally expresses itself in cyber, not as a cyber adversary — and on the technical evidence that reading is correct. The cost is that Israel is superb at the half of the Russian threat its system was designed for, and institutionally absent for the other half. That other half is also, uncomfortably, the half where Israel is a documented actor: Citizen Lab assesses that an Israeli state agency or a subcontractor under its supervision published an AI-generated video of the strike on Evin Prison while the bombs were still falling, a minute ahead of the first real footage, and international outlets republished it as fact (Citizen Lab 2025, pp. 6–8).
For a mid-sized European state — the Czech Republic is our default home example — the practical consequence is a split verdict, and it is the cleanest one in this whole series. On the technical half, copy Israel. On the cognitive half, do not: copy Sweden, France and the EEAS, because Europe is ahead of Israel here and knows it. Report 1 in this series ranked the fifty companies Israel’s machine produced; Report 2 distilled sixteen principles a state can act on; Report 3 specified the twenty-four features of the most advanced defence anyone could assemble; Report 5 sorted the 2026 threat claims by the evidence behind them. This one asks a question none of them asked: what happens when the world’s second cyber power meets an adversary it has decided not to treat as an adversary.
Summary of main points
Russia does not target Israel at state level, and the data is unambiguous. Israel is absent from the top ten regions targeted by Russian state actors, all of which outside Ukraine are NATO members, while it absorbs 64% of Iranian nation-state targeting and 603 observed nation-state events overall (Microsoft 2025).
Russian pressure still reaches Israel, by three indirect routes. Pseudo-hacktivist proxies redirected after 7 October 2023 (Israel is fifth at 4.50% of NoName057(16) attack days); capability transfer to Iran, including a reversal of Moscow’s prior prohibition on sharing offensive cyber (RAND 2023); and a Hebrew-language Doppelgänger campaign running since April 2023.
The doctrine makes the split between “cyber” and “disinformation” a Western administrative artefact. Russian theorists do not use the word kiber. Mandiant reads APT44 as “a characteristic representation of the information confrontation concept”, with espionage, technical attack and psychological influence as three columns of one mission.
Ukraine proved Russian cyber power is real but not decisive above the threshold — and that resilience, not security, is what blunted it. Ukrtelecom lost 87% of network capability and restored it in 15 hours; Kyivstar recovered from a GRU attack in a week; Viasat was not repaired but discarded and replaced with something better (Kott et al 2024). Below the threshold is where Russia is genuinely good: 63% of all ransomware attacks come from Russian-affiliated groups that are only 26% of publicised strains, and 99.52% of their located victims are outside Russia (Brantly and Mason 2026).
Israel’s technical answer is excellent and was built for a different enemy. Three layers, a civilian authority deliberately denied police powers, sector SOCs, binding regulation of named entities, and an industry that doubles as a national sensor network. It works against Russian-aligned proxies as a by-product.
Moscow’s biggest win over Israel required no operation. RAND names the objective — “minimize Israeli support to Ukraine” — and Israel duly withheld cyber assistance, air defence and, through its export authority, Pegasus from Ukraine and Estonia. Deconfliction over Syria is the price Israel pays and Russia collects.
The cognitive half is unowned. No national strategy, a security service without the legal powers, civil-society cooperation “in its infancy”, and an Israeli protest to Moscow in July 2023 that changed nothing (Rakov 2025). Israel is also unusually permissive: a large Russian-speaking population, heavy air links and no published restrictions on Russian intelligence officers, who retain diplomatic immunity where Europe has expelled them.
Israel is an actor as well as a target, and that costs it standing. PRISONBREAK, the STOIC/”Zero Zeno” network disrupted by OpenAI, Team Jorge and Archimedes Group are all documented. A state that runs deniable synthetic-media operations cannot credibly ask allies to treat synthetic media as illegitimate.
The sceptical literature is the most important input and the least quoted. Eady et al find no measurable effect of Internet Research Agency exposure on attitudes or votes, with 1% of users absorbing 70% of exposures. EU DisinfoLab calls Doppelgänger “a failure”. OpenAI reports that the most-reached deceptive activity of 2024 was a hoax about AI, not AI.
The serious answer is to attack the enablers, not the narratives. Registrars, hosting, tracker software, bulletproof ASNs, contractors and payment rails — with sanctions, law enforcement, the DSA and trademark and data-protection law. That is the EEAS FIMI Deterrence Playbook, and it is available to a Czech-scale state today.
The targeting follows domestic politics, which should frighten a Czech reader more than any wiper. NoName057(16) stopped attacking Austria once the Freedom Party was excluded from coalition, and stopped attacking Czechia in January 2025 after reporting suggested the government would lose the October 2025 election (Insikt Group 2025, p. 15). The tap is a reward-and-punishment signal, not a weapon.
How this report is organised
Twenty-four numbered points in six sections, then the transfer. I sets out what the Russian threat actually is, doctrine first, because the doctrine determines the shape of everything else. II traces how it reaches Israel, and what conspicuously does not. III describes how Israel treats it across four layers — technical, intelligence, private and diplomatic. IV is the gap. V turns the mirror round and looks at Israel as an actor. VI is the sceptical literature on effects, which should discipline everything proposed here. VII is what a mid-sized European state does on Monday morning: eight concrete moves, and a plain statement of what to copy and what to refuse. Sources are cited inline by institution or lead author and year, and all of them sit in the library behind this series. Where the evidence is circumstantial or contested — on Russian sponsorship of criminal groups it always is — we say so.
I · What the Russian threat actually is
Four things have to be established before Israel can be judged: what Moscow thinks it is doing, who does it, what the largest live test of it proved, and where the capability has actually migrated.
1. The doctrine is one confrontation with two limbs, and it never stops
The conceptual point is the load-bearing one in this entire report, so it is worth stating precisely. Connell and Vogler record that Russian writers reserve the word kiber for describing Western thinking; their own category is informatsionnaya voyna, “a holistic concept that includes computer network operations, electronic warfare, psychological operations, and information operations” (CNA 2017, p. 11). Bilyana Lilly and Joe Cheravitch supply the authoritative definition from the Russian Ministry of Defence’s own 2011 Concept on the Activities of the Armed Forces in the Information Space: information warfare is the confrontation between states in the information space “with the purpose of inflicting damage to information systems, processes and resources, critical and other structures, undermining the political, economic and social systems, a massive psychological manipulation of the population to destabilize the state and society, as well as coercing the state to take decisions for the benefit of the opposing force” (CCDCOE 2020, p. 133).
Read that sentence as an organisational design brief. Damaging information systems and manipulating a population are not two missions requiring two ministries; they are one sentence describing one campaign. A GRU training official wrote after the 2008 Georgian war that modern information confrontation is directed “at both information-technical systems… as it is on human psychology. Activity against an enemy is organized and conducted in two aspects (directions): technological and psychological” (quoted in CCDCOE 2020, p. 143).
Two operational consequences follow. First, the threshold for action is permanently low, because the confrontation is doctrinally constant: it “is more or less constant and unending… It knows no boundaries, physical or temporal” (CNA 2017, p. 13). There is no peacetime in which nothing is happening. Second, the doctrine is declaratively defensive and operationally offensive on purpose. Official documents omit offensive cyber entirely while the military-scientific journals debate it openly; Lilly and Cheravitch judge that “the continuous omission of an official endorsement of offensive cyber capabilities in its doctrine allows the Russian government to claim plausible deniability and maintain a narrative… of a defensive power under threat by an aggressive West” (2020, p. 139).
There is also a stated theory of why it is worth the money. Russian military scientists estimated in 2012 that “total defeat of the information infrastructures of major powers such as the United States or Russia could be conducted by up to 600 ‘information warriors’… about two years and cost no more than 100 million dollars” (Bazylev et al, cited at CCDCOE 2020, p. 138). Whether or not the number was ever plausible, it explains the investment logic: information confrontation is the asymmetric equaliser that lets an economically weaker state neutralise a stronger one. That is why a state with Russia’s GDP behaves this way — and why it will not stop when the war in Ukraine does.
2. The services, the units and the journal that says the quiet part
Structure explains behaviour, and Russian cyber structure is a product of one institutional accident. FAPSI, the Russian analogue of the NSA, was dissolved in 2003 and its parts absorbed into the FSB, MVD, FSO and SVR (CNA 2017, p. 15). For two decades afterwards the FSB, not the military, held the commanding heights — and the FSB’s Center for Information Security covered its own staffing gaps by co-opting criminal hackers, with attacks on Western banks helpfully alleviating financial shortfalls (CCDCOE 2020, p. 139). The proxy model was not a clever innovation. It was a workaround that became doctrine.
The GRU’s rise was partly a reaction to Western posture: US Cyber Command in 2009, Stuxnet, and the collapse of cyber arms-control talks “necessitated that Moscow redouble efforts” inside its military (CCDCOE 2020, p. 140). The units that resulted are now named in indictments: Unit 26165 (85th Main Special Service Center, APT28/Fancy Bear), descended from late-Cold-War military cryptography; Unit 74455 (Main Center for Special Technologies, APT44/Sandworm), built for computer-based operations; and Unit 54777 (72nd Special Service Center), the psychological arm, which had 80 specialists in five sections before 2014 and has moved “in lock-step with GRU hackers since at least 2014” (CCDCOE 2020, pp. 144–146).
Mandiant’s 2024 report on APT44 closes the argument. It places Unit 74455 and Unit 26165 together under the GRU’s Information Operations Troops (VIO, Unit 55111) and diagrams the mission as three limbs of one body: KRIKS (cryptographic reconnaissance, espionage), ITV (information-technical effects, attack) and IPV (information-psychological effects, influence). In Mandiant’s words: “We therefore view APT44 as a characteristic representation of the information confrontation (IPb) concept that underpins Russia’s present-day cyber forces” (pp. 5–6). Unit 74455 is linked to the 4th Central Scientific Research Institute, whose officers publish in the journal Information Wars — including a 2018 paper titled “Threat Models of Joint Information-Technical and Information-Psychological Effects in Hybrid Wars” (CCDCOE 2020, pp. 145–146). The adversary publishes its integration doctrine in a peer-reviewed journal. Western defenders keep the two halves in different buildings.
One unglamorous constraint is worth recording, because it dates in the right direction. In 2017 the Russian military could not recruit for its cyber units, because “recruits have better and more lucrative prospects in the private tech sector” and conscripts serve only one year (CNA 2017, p. 16, fn. 18). Human capital, not intent, was the binding constraint — the same constraint NÚKIB reports for Czechia today, from the other side of the line.
3. What Ukraine proved, and what it disproved
The largest live test of Russian cyber power produced two findings that are usually reported as if only one of them were true.
The activity was enormous. Google measured a 250% increase in Russian phishing against users in Ukraine in 2022 against a 2020 baseline, and an over-300% increase against users in NATO countries, the latter driven primarily by a Belarusian group (Google TAG and Mandiant 2023, p. 6). Preparation began in 2021. “We observed more destructive cyberattacks in Ukraine during the first four months of 2022 than in the previous eight years,” with at least six unique wiper families. Jaclyn Kerr’s CNA assessment adds nine new wiper families and two new ransomware types against more than 100 Ukrainian organisations, Russian espionage in at least 17 European countries in 2023, and a new GRU actor, Cadet Blizzard, aimed specifically at NATO states supplying military aid (CNA 2023, p. 20).
The impact was not decisive. No nationwide blackout, no banking collapse, and — the most important negative finding in the library — “in contrast to NotPetya, we’ve seen little evidence of a spillover effect outside Ukraine” (Google TAG 2023, p. 6). Kerr’s framing resolves the apparent contradiction: “Prominent arguments about the role of cyberspace in the Ukraine war mostly focus on the domain’s impact, not its activity level… It may very well have been immensely active, but it has not been decisive.” Technical analysts measure activity, strategic analysts measure effect, and both are right about different things. The bluntest datum is substitution: “When Russia wanted to shut off internet services, troops took over internet service provider facilities… When they wanted to take down the power grid or affect other critical infrastructure, they used shelling and explosives” (pp. 22–23).
Why did it underperform? Kerr offers explanations that may prove temporary and should not be banked: inadequate planning for a long war, over-estimation of pre-war capability, poor deconfliction between GRU, SVR and FSB, and the fact that Russia’s best offensive capabilities sit in agencies built for intelligence and subversion rather than combined-arms warfare.
And she attaches the warning that must travel with every optimistic reading. There are two symmetrical errors. The first is assuming “too close a relationship between adversarial cyber activity and strategically relevant effect”. The second, worse one, is “assuming that ineptitude demonstrated above threshold must necessarily translate to a similar weakness in below-threshold showing” (CNA 2023, pp. 29–30). Russia’s craft depends on implausibly deniable volume, proxies and slow salami-slicing. That fails against a galvanised, warned wartime society. It works very well against a distracted peacetime one — which is precisely the condition of every EU member state, and of Israel before 7 October.
4. Resilience, not security, is what actually blunted it
The most transferable idea in the Russian angle is not a threat finding at all. It comes from a paper co-written by Ukraine’s deputy minister of digital transformation and US Army engineers, and its argument is a distinction: “cyber security is about risk avoidance — preventing threats from affecting the system — while cyber resilience deals with response and recovery… Employing cyber security strategies is ineffective once a breach has occurred” (Kott, Dubynskyi, Paziuk et al, Computer 2024, p. 2). Against a peer adversary you cannot buy your way out with prevention alone.
The evidence is four named paradigms. Discard and replace: Viasat’s KA-SAT modems were bricked by AcidRain an hour before the invasion, and the network was not repaired but abandoned for Starlink, which turned out to be better than what was destroyed, enabling aerial and maritime drone control. Deflect and absorb: a “diverse and decentralized patchwork” of hundreds of independent telecom operators plus universal national roaming, so the network “inherently lacks centralized chokepoints”. Reconfigure and relocate: legislated pre-war authority to migrate critical state and private data to foreign clouds. Dynamically regenerate: a new secret secure link between the Ukrainian military and US European Command, stood up just before the invasion (pp. 3–6).
The recovery numbers are the ones to quote in a budget meeting. Ukrtelecom, March 2022: a cyberattack eliminated 87% of its network capability, and full connectivity was restored within 15 hours. Kyivstar, December 2023: a GRU attack devastated thousands of virtual servers, and pre-planned resilience strategies restored full operations within a week (p. 5). Security still mattered at the decisive moment — in April 2022 Ukrainian defenders neutralised malware aimed at electrical substations that could have cut power to roughly two million people — but the survival mechanism was recovery, not prevention.
Two details deserve underlining for a European reader. Decentralisation is a defensive asset that cannot be retrofitted in a crisis, and consolidated European telecom markets do not have it. And the Viasat collateral is the escalation model European utilities should plan against: an attack aimed at Ukrainian command and control “impacted tens of thousands of other fixed broadband customers across Europe”, with Enercon reporting a massive disruption of satellite connections affecting the operation of 5,800 wind turbines in central Europe (Google TAG 2023, p. 12). A targeted operation against a third country degraded a NATO member’s energy sector within the hour, and nobody had to decide to attack it.
5. The deniable layer is now the main instrument against Europe — and it is centrally run
The single most consequential change in Russian cyber behaviour since 2022 is not a new wiper. It is the professionalisation of the proxy layer. Connell and Vogler predicted in 2017 that the crowd-sourced model “is likely to be replaced by more tailored approaches, with the FSB and other government agencies playing a more central role” (CNA 2017, pp. 27–28). Half of that came true. The state did move to the centre — but the proxy layer did not disappear. It was absorbed.
Tkachuk states the position from inside Ukraine’s coordination centre in terms no threat report can match: “There are no independent ‘hacktivists’ in Russia and any illegal activity in cyberspace is strictly controlled by the state,” and since late 2022 Russia “has developed a ‘turnkey’ methodology for creating, disguising and managing these pseudo-hacktivist groups, deploying them strategically based on geopolitical goals” (CCDCOE 2025, pp. 16, 18). Mandiant documents the same relationship technically for APT44’s fronts — XakNet Team, CyberArmyofRussia_Reborn (CARR) and Solntsepek. Google’s Threat Analysis Group saw CARR’s YouTube channel created from APT44 infrastructure; Mandiant saw APT44 infrastructure exfiltrate data that later appeared on the CARR channel; and in one case CARR’s Telegram claim preceded the attack it referenced (Mandiant 2024, pp. 14–15). The fifth and final phase of APT44’s playbook is not an intrusion technique. It is Telegraphing “Success” — amplifying the operation through hacktivist personas “regardless of the actual impact of the operation”. The influence limb is wired into the attack chain by design.
Recorded Future’s thirteen-month study of NoName057(16) shows the industrialised version in daily operation. Across 3,776 unique hosts the group ran a median of 50 unique targets per day, peaking at 91, with government and public sector taking 41.09% of attacks, transport and logistics 12.44%, technology, media and telecoms 10.19%, and finance and insurance 8.88% (Insikt Group 2025, pp. 2, 12–14). The DDoSia client is written in Go, distributed through Telegram, requires a per-volunteer “User Hash”, needs no technical skill and pays contributors in cryptocurrency. Behind the volunteers sits real infrastructure engineering: 275 unique Tier 1 command-and-control IPs with a mean lifespan of 9.33 days and a median of about two, 38% alive for a single day, fronting static Tier 2 servers protected by access-control lists. The hosting is a sanctioned economy in itself — BL Networks/BitLaunch at 8% of autonomous systems, the sanctioned Russian Aeza International at 7.5%, and Global Connectivity Solutions, “the UK front for Russian hoster 4vps”, at 6% (pp. 18–19).
Two further findings are the report’s most useful and least technical contribution. The first is attribution by timesheet: new targets are added in two daily waves peaking at 05:00–07:00 and around 11:00 UTC on weekdays, the second wave largely absent at weekends — “strongly indicating operations from within a Russian time zone” and a manual target-selection process on a standard Russian working week (pp. 2, 17). The second is what that working week is used for. Austria was hammered before its September 2024 election, and activity “abruptly halted following the election and only resumed in mid-November, once it became clear that the Freedom Party would be excluded from the governing coalition”. And the targeting of Czechia throughout 2024 “notably ended in January 2025 after public reporting indicated that the ruling government was expected to lose the October 2025 election to the ANO party”, whose leaders had said they would halt ammunition transfers to Ukraine (p. 15).
The DDoS tap is a reward-and-punishment signal keyed to the target’s domestic politics, not a weapon aimed at its networks. That is a category error most national threat pictures make, and correcting it changes what you do about it: the countermeasure to a political signal is political inoculation and public explanation, not more scrubbing capacity.
6. The criminal layer, and the merger nobody has priced in
Aaron Brantly and Ryan Mason built an open-source dataset of 19,128 ransomware incidents across more than 110 groups over two years, and the directional finding is the strongest quantitative evidence of state–criminal symbiosis anyone has published. Russian-affiliated strains are the top three by victim count, five of the top ten and 26 of the top 50. “While Russian-affiliated groups only make up 26% of the total publicised ransomware strains since 2020, they account for 63% of all attacks“ (ACIG 2026, p. 8). The top six Russian groups alone produced 7,142 victims, 56% of the global total.
Then the smoking gun. Of Russian-affiliated incidents with an observed victim location (n = 2,508), 99.52% targeted entities outside Russia and 0.48% inside. In the complete-case sample of 6,339 incidents, the United States has 2,793 identified victims and Canada 586; the Russian Federation has 17, of which 15 came from a single short-lived group active for three months (p. 18). The Czech Republic appears in the second tier of sustained victims, alongside Australia, Brazil, Canada, France, Germany, India, Italy and Spain, each with more than 50 attacks from Russian-affiliated groups (p. 19).
The mechanism the authors propose is not command but selective non-enforcement: Russia polices its domestic internet ferociously for content and dissent while placing “little in the way of limitations on their activities that extend beyond their borders” (p. 8). They frame this as a failure of the international-law duty of due diligence over one’s own networks — a legal hook a European state can actually use, and a better one than attribution. The bargain itself was stated on a dark-web forum after a round of Western seizures: “Mother Russia will help… Love your country and nothing will happen to you.” To the authors’ credit they publish their own limitation: “All analyses of Russian involvement in its prolific ransomware industry are based largely on circumstantial evidence.” The contribution is the convergence of independent strands, not any single proof.
Microsoft closes the loop from telemetry. Russian state actors “appear to have reduced their efforts to develop bespoke operations in favor of leveraging the cybercriminal ecosystem”, which Microsoft reads as a response to public exposure of their tooling — and warns that it “could make it more difficult for network defenders to attribute simple operations to sophisticated threat actors and recognize the implications of a breach” (Microsoft 2025, p. 48). Commodity malware on your network no longer implies a commodity adversary. Tkachuk adds the reverse flow: Russian intelligence services provide criminal groups with “access to advanced technologies, vulnerabilities and cyberattack tools, including those targeting mobile devices”, raising the risk of uncontrolled proliferation of what used to be state-only capability (CCDCOE 2025, p. 16). Mandiant reaches the same judgement about APT44 itself, calling it “a significant proliferation risk” that has “lowered the barrier of entry for other state and non-state actors”. And the fuel supply for all of it is the credential economy: Russia is the world’s second-largest source of infostealer infections, at 40,868 encounters behind India’s 44,197 (Microsoft 2025, p. 22). Hence Microsoft’s summary line for 2025 — “adversaries aren’t breaking in, they’re logging in”.
7. The information apparatus is industrial, and its budget is public
The psychological limb is not a side project run by trolls. It is a funded industry with a published state budget line. The European External Action Service detected 540 FIMI incidents in 2025 involving 10,500 unique channels and websites and about 43,000 observables across 19 platforms, with 29% attributed to Russia, 6% to China and 65% unattributed but showing coordination indicators with Russian or Chinese infrastructure. More than 100 countries, around 200 organisations and roughly 140 named individuals were targeted. Russian state-media funding rises to 146.3 billion roubles (about €1.56bn) in 2026, 7% up on 2025 (EEAS 2026, pp. 5, 9–11).
The architecture is deliberately covert. Of the 3,000 most recurrent channels, only 9.5% are overt state-controlled or official outlets; 90.5% are covert state-linked or state-aligned assets (p. 9). This is the structural reason why sanctioning RT and Sputnik achieved so little: the overt tenth was never where the work happened.
Two case files show the production model. Doppelgänger cloned at least 17 authentic media brands — Bild, 20minutes, Ansa, The Guardian, RBC Ukraine — across more than 50 typosquatted domains bought between May and September 2022, carrying about 80 identified pieces of disinformation in seven languages (EU DisinfoLab 2022, pp. 2, 6). Critically, it ran inside Europe: registrars GoDaddy, NameCheap and Panamanames; hosting at Webzilla in Luxembourg, BlueVPS and Glesys in Estonia and Sweden, JavaPipe in the Netherlands; cloaking and geo-redirection through Keitaro, a tracker registered in Estonia. “They targeted European citizens through impersonating European media providers, hosted their operations on European servers and covered their traces using European software” (p. 4).
Storm-1516, documented by France’s VIGINUM in a TLP:CLEAR technical report, ran 77 information operations between August 2023 and March 2025: 35 against Ukraine and its leadership, 42 against Western personalities, events or elections, and 20 specifically denigrating candidates or attacking ballot integrity. The production line includes video and voice deepfakes, forged invoices, fabricated press articles and government documents, and recruited amateur actors in more than half of the operations, with narrators chosen to match the story — an Arabic speaker for “Ukraine recruits ISIS fighters”, surzhyk for a faked Zelensky phone call (VIGINUM 2025, pp. 3–10). The distribution chain is the real intelligence product: burner or paid accounts seed, foreign paid media launder the content into “news”, and a known network of Western pro-Russian influencers amplifies it in French, German, English, Finnish and Dutch. Seventeen of the outlets used had already been used by Prigozhin’s Project Lakhta — the tradecraft is inherited, not invented. And the state link is documented rather than assumed: John Mark Dougan, the Prigozhin ecosystem, Valery Korovin’s Centre for Geopolitical Expertise (sanctioned by the US Treasury on 31 December 2024 for directing and subsidising the creation of deepfakes) and Yury Khoroshenky, a likely officer of GRU Unit 29155.
The AI turn is measured rather than asserted. Twenty-seven per cent of 2025 EEAS incidents involved AI-related techniques, up from 41 cases in 2024 to 147 — a 259% rise (EEAS 2026, p. 13). Voice cloning and synthetic video are routine, and Portal Kombat is suspected of LLM grooming: flooding the web with low-quality multilingual content to poison model training data and retrieval. But the EEAS is honest about quality: “Threat actors prioritise quantity over quality, resulting in limited overall impact as organic engagement remains low… Storm-1516 and Overload use AI-generated videos easily identifiable as inauthentic by average viewers.” The aim is “not precision but presence”. That is what Goldstein and colleagues predicted in 2023: language models attack the three constraints on influence operations — resources, content quality and, most importantly, detectability, because copypasta is what usually gets a campaign caught (CSET, OpenAI and Stanford 2023, pp. 4, 13).
II · How it actually reaches Israel
With the adversary described, the question becomes empirical. Where does this machine point, and what arrives in Israel?
8. The targeting data: the world’s most-attacked country, and Russia is not the one attacking it
The numbers were given in the opening, but they deserve to be set out as a single scannable picture, because the asymmetry is the finding.
Israel’s total exposure · 603 observed nation-state events in Microsoft’s notification data, the highest in the Middle East and Africa and second worldwide only to the United States at 623 · 3.5% of all attacks Microsoft observes globally, third behind the US at 24.8% and the UK at 5.6% · in Microsoft’s own summary, “the primary geographical targets of nation-state activity this year were in Israel, the United States, and the United Arab Emirates” (Microsoft 2025, pp. 8, 43–44).
Who is producing it · Israel is 64% of all Iranian nation-state targeting · Israel does not appear in the top ten regions targeted by Russian state actors · Russian state targeting by sector runs government 25%, research and academia 13%, think tanks and NGOs 13%, IT 10%, energy 5%, defence industry 3%, and Ukraine alone absorbs 25% of all Russian cyber operations (Microsoft 2025, pp. 46, 48).
This is consistent with everything else in the library. In the six months before 7 October 2023, Iran accounted for about 80% of all government-backed phishing aimed at users in Israel (Google TAG and Mandiant 2024, p. 4). Chuck Freilich’s INSS assessment finds Israeli defences blocked most Iranian attempts on critical infrastructure, that Iranian hackers in 2015–16 “believed that they had succeeded” against the electric grid when they had in fact reached honeypot decoys, and that in the first six days of the October 2023 war DDoS against Israel reached one million attempted logons per second with no significant impact after three months (INSS 2024, pp. 5, 30). Carnegie’s earlier judgement still holds: “Given the sophistication of Israel’s cyber defense, Tehran has been forced to focus mainly on soft targets” (Anderson and Sadjadpour 2018, p. 48).
Israel’s threat picture is an Iranian threat picture with a Hezbollah and Hamas annex. It is not a Russian one, at the level of state operations. The rest of this section is about the three routes by which Russia reaches Israel anyway, none of which appear in a nation-state targeting chart.
9. Route one: proxies, and the redirection after 7 October
Israel sits fifth in the NoName057(16) targeting table at 4.50% of attack days, above Czechia and Poland, and it is the only non-European country in that band (Insikt Group 2025, p. 12). That alone would be unremarkable — a pro-Russian group attacking a country that is not pro-Russian. What makes it significant is the timing evidence.
Tkachuk’s account should be read twice: “following the 7 October 2023 terrorist attack in Israel, dozens of new pseudo-hacktivist groups were launched to attack Israeli infrastructure. During this period, Ukraine saw its lowest number of cyber incidents in years” (CCDCOE 2025, p. 18). Set beside her statement that there are no independent hacktivists in Russia and that the services run a turnkey methodology for deploying them by geopolitical requirement, this is not volunteer enthusiasm. It is capacity allocation — a resource Moscow controls, moved from one theatre to another within days of an event Moscow did not cause, and visible in the Ukrainian incident statistics as a trough.
Three implications follow for any state that is not Israel. First, the pseudo-hacktivist layer is a shared, reallocatable pool, so your quiet period may be someone else’s crisis rather than evidence that your defences improved. Second, the layer is monetising: by late 2023 some of these state-controlled groups had begun “monetising their cyberattack services” (p. 16), blurring the line with the criminal layer still further. Third, it does not only do DDoS. NÚKIB records a growing trend of Russian-speaking hacktivists attacking weakly secured operational-technology systems, especially in water management, filming their activity and posting it to Telegram — “there have been dozens of them, especially in Western countries, and NÚKIB registered one attack in the Czech Republic last year” (NÚKIB 2025, p. 50). That is the CyberArmyofRussia_Reborn pattern Mandiant documented in early 2024, when CARR posted videos claiming manipulation of human-machine interfaces at Polish and US water utilities and a French hydroelectric plant, and a local US official later confirmed a malfunction that overflowed a tank at one claimed victim (Mandiant 2024, p. 16).
A deniable, centrally tasked, low-skill layer that can be pointed at Israeli infrastructure one week and Czech water utilities the next is the operational reality of the Russian threat to countries outside the front line. It produces very little damage and a great deal of signal, which is exactly what it is for.
10. Route two: capability transfer to Iran
The second route is indirect in a more dangerous way, because it improves the adversary Israel actually has.
RAND’s 2023 assessment records that in exchange for Iranian drones, Russia has offered Tehran “an unprecedented level of military and technical support” including multi-role aircraft, air defence, intelligence, surveillance and reconnaissance, and cyber capabilities (RAND 2023, p. 1). The indicator list is more consequential than the headline: among the markers of expanding cooperation is “Russian provision of digital surveillance and censorship systems, reversing prior prohibition on sharing offensive cyber capabilities“ (p. 7). Moscow had a rule about not giving Iran offensive cyber tools. The rule went.
Transfers beyond cyber make the pattern legible. After Iran asked for help suppressing the Mahsa Amini protests, Russia supplied communication-surveillance capabilities, eavesdropping devices, advanced photography equipment and lie detectors, alongside a judicial-cooperation memorandum (p. 9). In August 2022 Russia launched an Iranian remote-sensing satellite, and IRGC affiliates publicly celebrated the improved ability “to monitor potential U.S. and Israeli military targets” (p. 8).
RAND’s restraint is itself part of the finding: “it is still too soon to declare that the Russian-Iranian relationship has undergone a fundamental transformation.” It remains a partnership of convenience with mistrust and competing interests — and the largest source of friction is named: “One significant fault line relates to Israel; Russia has historically cultivated a good working relationship with Israel, whereas Iranian rhetoric and national security policy characterizes Israel as one of the country’s primary enemies” (p. 19). Moscow has even “sought to distance itself from Iranian antagonism of Israel”.
That is the whole strategic geometry in two sentences. Russia arms and equips Israel’s principal cyber adversary, while carefully preserving its relationship with Israel — because the relationship buys something the transfers cannot. What it buys is the subject of point 16.
11. Route three: the Hebrew-language campaign, running since April 2023
The third route is the one that does not appear in any cyber telemetry, and it is the most thoroughly documented Russian operation against Israel in the library.
Daniel Rakov’s JISS study is built on leaked internal documents of Russia’s Social Design Agency (SDA) and Structura, whose authenticity a US Department of Justice release of September 2024 later confirmed. It describes a Hebrew-language arm of Doppelgänger running since April 2023, codenamed “Normal Israel”, steered from Sergei Kiriyenko’s directorate in the presidential administration, with Putin “probably at least vaguely aware of it” (JISS 2025, pp. 7–8, 11).
The objectives are not ambiguous. Deepen Israeli polarisation in order to get Israel to withhold military aid to Ukraine; distance Israel from the United States; move Jerusalem toward Moscow; and swing American Jewry against the Democratic Party ahead of November 2024 (p. 7). The first fake, on 18 May 2023, was an article attributed to the well-known columnist Amnon Abramovich on a clone of the news portal N12, written in poor Hebrew.
What makes the file worth a European reader’s attention is that the plan was never confined to the digital domain. SDA proposed founding a political party of Russian-speaking immigrants, hoping for three or four of the Knesset’s 120 seats as a balancing faction; costed an “Israeli office” at roughly $1.2 million; proposed spraying provocative graffiti in Arab neighbourhoods while posing as Jewish right-wing extremists; and proposed distributing leaflets in synagogues and churches, with a separate messaging campaign aimed at Israeli Arabs designed to stir violence against Jews (pp. 8, 31). Penetration of the local information space used real Israeli intermediaries: sponsored “articles” appeared in Walla, The Jerusalem Post and Channel 13, commissioned through an Israeli media figure of Russian origin who declined to name his clients, and a Russian-speaking Israeli blogger’s YouTube videos were amplified by Doppelgänger (p. 32).
The scale claimed internally is industrial: 34 million comments and 40,000 “content units” plus thousands of videos and memes in January–April 2024 alone, produced by ten specialised teams — from media monitoring and research to “exclusive reporters in Israel”, translation and distribution — running a “Comments Machine” designed to fake authentic engagement signals (p. 36). After 7 October the campaign went global and turned antisemitic: Doppelgänger’s European arms amplified content including an AI-generated video of Jews in Auschwitz apologising to Palestinians for the IDF’s actions, alongside Russia’s promotion of the claim that the Holocaust was a genocide of “the Soviet People” generally rather than of Jews specifically (pp. 21, 24).
Why Israel, and why this method? Because the environment is permissive in ways Europe’s no longer is. Russia can combine provocations with media activity “in light of a large number of Russian speakers, a large number of flights to Russia, and the absence of published restrictions on the activity of intelligence agents. The latter enjoy diplomatic immunity in Israel, unlike in Western countries, where there have been large-scale expulsions of Russian spies disguised as diplomats over the past five years” (p. 50). Israel’s Russian-speaking population is usually put at around a million; the library contains no census, but it contains something more useful — the adversary’s own market sizing, which was three or four Knesset seats and a $1.2m office. Israel protested to Moscow in July 2023. Nothing changed.
12. The dog that did not bark, and why it matters
Now the negative findings, because a threat assessment that only lists what happened is an advertisement.
There is no documented Russian state intrusion campaign against Israeli critical infrastructure in this library — no Israeli Industroyer, no Israeli NotPetya, no Sandworm operation against an Israeli grid. Israel does not appear in Microsoft’s Russian top ten. It is not named in Tkachuk’s list of Russian APT tasking, which runs Gamaredon (FSB) against Ukrainian government, Sandworm (GRU) against energy, Turla (FSB) against defence enterprises. It is not in the EEAS top-targets list for FIMI incidents: Ukraine 112 · France 107 · Moldova 94 · Germany 71 · USA 51 · UK 36 · Armenia 18 · Poland 17 (EEAS 2026, p. 10). And Rakov’s own effect assessment is sober: direct political influence in Israel is “quite limited”, the campaign runs “on a low-intensity scale”, and SDA’s claim of half a million Israeli followers is doubtful (pp. 8, 35, 50).
Three conclusions follow, and they pull in different directions, which is why each has to be stated.
First, the restraint is real and it is a policy. Given Mandiant’s assessment that APT44’s reach is already global — North America, Europe, the Middle East, Central Asia, Latin America — the absence is a decision, not a limit.
Second, restraint is reversible in a way that resilience is not. Rakov warns that “the relatively limited scope of Doppelganger’s activity in Israel might change rapidly based on the campaign operators’ assessment of the situation”. A capability withheld for diplomatic reasons returns the moment the diplomacy changes, and the defender’s lead time is zero, because nothing had to be built.
Third, and most useful to a European reader: Israel is the closest thing available to a natural experiment on what a Russian information campaign does when the technical campaign is switched off. Israel gets the psychological limb alone. Czechia, Poland and the Baltics get both. The answer the control group gives is that the psychological half arrives regardless, costs almost nothing, and is the half nobody in Jerusalem is mandated to fight.
III · How Israel treats it
Israel’s response to Russia has four layers, and only three of them are visible in cyber policy documents. They are worth taking in order of how well they work.
13. The technical layer: a system built for Iran that happens to stop proxies
Israel’s national cyber defence is set out in Report 2 and specified as a system in Report 3, so the summary here is compressed. The architecture is three layers with responsibility escalating by severity: organisations own robustness, the national CERT and sector centres own resilience, the security bodies own national defence (INCD 2017). CERT-IL in Beersheba runs a 119 hotline open to any citizen, handled around 9,000 incidents and issued about 300 alerts in a single pre-war year, and works with more than 90 international partners; CyberNet links company security chiefs in a trusted national network (INCD 2021). Critical infrastructure is regulated at the level of named entities rather than whole sectors, a lineage running from Resolution B/84 in 2002. The February 2025 strategy adds “zero significant damage to critical infrastructure”, a National SOC combining the sectoral SOCs, and “Cyber Dome”, an AI-driven national active-defence concept (Shabtai, BESA 2025).
Against the Russian-aligned proxy layer this is close to ideal, and it is worth being precise about why. NoName057(16)-class operations are volumetric and application-layer denial of service against public-facing government, transport and finance targets. Israel has a national scrubbing posture, a sectoral SOC structure, a CERT with a public hotline, and a domestic industry that sells exactly this — Radware’s DefensePro appliances and cloud scrubbing service, whose own 2026 threat reporting counted web DDoS attacks up more than 110%, sit in banks, carriers and governments worldwide. The proxy campaign against Israel after 7 October produced noise, Telegram claims and overstated damage reports, and on the available record no significant effect.
The honest reading is therefore slightly deflationary: Israel is well defended against the Russian technical vector because it is extremely well defended against the Iranian one, not because it built anything for Russia. That is the correct design when 64% of your nation-state pressure comes from one adversary — but it means the defence is adaptive to volume, not to a Russian change of policy.
14. The intelligence layer, and what 7 October did to it
The second layer is the one that would have to notice a change of Russian policy, and it is the one with a documented failure mode.
The October 2023 surprise was not a cyber failure; it was a warning failure with a technological cause. Michel Wyss records “an overestimation of Israel’s technological capabilities” among the reasons, a shift of collection toward technical means as HUMINT coverage of Hamas’s intentions declined, and a Unit 8200 NCO’s July 2023 warning that Hamas exercises matched the captured “Jericho Wall” plan being dismissed as “aspirational” (CTC Sentinel 2024, pp. 4–6). Shmuel Bar is more specific: the intelligence community’s “love affair” with cyber intelligence and AI, automated processing “with little or no human intervention”, the dismantling of Unit 8200’s OSINT unit Hatzav in 2021 on the strength of machine translation, the disbanding of document exploitation, and the replacement of pushed analyst warning with an “intelligence pool” that analysts had to pull from — and did not pull from when the contents contradicted the prevailing conception (NIPP 2024, p. 5).
Every one of those failure modes is more dangerous against an information-confrontation adversary than against a kinetic one. A Doppelgänger campaign in Hebrew produces no SIGINT signature, no malware sample and no network indicator. It produces text, published by intermediaries who are legally resident Israelis and laundered through legitimate outlets. Detecting it requires exactly the capabilities Israel had been decommissioning: open-source collection, linguistic analysis, cultural intelligence and an analyst willing to push an unwelcome conclusion upward. The 2025 strategy responds with compensatory mechanisms against the cognitive biases that underestimate strategic surprise (Shabtai 2025) — the right lesson, drawn from the wrong war, and applied to the enemy Israel expects.
15. The private layer: an industry as a de facto national sensor network
The third layer is not a policy at all. It is an externality of the ecosystem the first three reports in this series described, and it does more against Russia than any Israeli government body does.
Check Point’s threat research runs on ThreatCloud across more than 100,000 customer organisations, and its prevention-first research output is among the most-cited early-warning sources in the industry. KELA, founded by Unit 8200 veterans in 2009 and profitable from inception, sells visibility into precisely the Russian-speaking criminal economy that Brantly and Mason quantified: dark-web forums, marketplaces, Telegram channels and infostealer logs, with 192 billion intelligence items collected and 34.1 billion compromised credentials indexed in 2026 alone. Its 2026 State of Cybercrime report counted 2.86 billion credentials stolen in 2025 and 7,549 ransomware victims, up 45%; its research fed the TeamPCP arrests through the Australian Federal Police and the FBI; and in October 2025 it launched a National Cyber Resilience Suite for governments, national CERTs and police. Sygnia, the Team8-founded incident-response firm now owned by Singapore’s Temasek, publishes attribution-grade investigations — Bybit, Velvet Ant, Fire Ant — that function as public goods. Alice, formerly ActiveFence, built an eight-year corpus of labelled real-world abuse content across languages by tracking how influence and abuse actors operate at platform scale, and now sells red-teaming and runtime guardrails to eight of the ten leading AI labs.
Two things follow. The first is a genuine national advantage: a mid-sized state with a domestic threat-intelligence industry gets a sensor network it does not have to fund, and KELA sells national CERTs and police the same tools it sells to banks. The second is a dependency. The layer of Israel’s Russian threat picture that works best is privately owned, commercially motivated and sells to everybody. Recorded Future belongs to Mastercard and Cybersixgill to Bitsight; Israeli threat intelligence is consolidating into global platforms on the same trajectory. A national capability that exists only as a by-product of an export industry is one the state does not control.
16. The diplomatic calculation: Syria, Ukraine, and the win that required no operation
The fourth layer is the real one, and it is not run by the INCD.
Israel’s posture toward Russia is set by a deconfliction problem. Russian forces and air defences in Syria sit between the Israeli Air Force and Iranian and Hezbollah targets, and the working relationship that permits Israeli operations there is the asset Jerusalem protects. RAND states the resulting Russian objective in the open: Moscow works to “preserve positive relations with Israel and minimize Israeli support to Ukraine“, and flags intensified Israeli activity in Syria as the friction that might strain Iranian patience with that policy (RAND 2023, pp. 15, 19).
The policy has been paid for, and one payment is documented precisely. Israel has withheld from Kyiv the cyber and intelligence assistance a country of its capability could have supplied, and its Defense Export Controls Agency blocked Ukraine from buying Pegasus and barred Estonia from using it against Russian targets in March 2022 (Feldstein and Kot, Carnegie 2023, p. 23) — a case that also shows, incidentally, that Israeli export licensing follows geopolitics rather than human-rights criteria, which is Report 2’s principle 15 failing in public.
Two conclusions, and they are the hinge of this report.
First, this is the most successful Russian operation against a first-rank cyber power on record, and it involved no operation. Moscow achieved the exclusion of one of the world’s best offensive and defensive cyber states from the coalition supporting Ukraine, at the cost of maintaining a phone line over Syria. No wiper, no intrusion, no attribution problem, no sanctions exposure. On Kerr’s distinction between activity and impact, it is the highest-impact, lowest-activity Russian success in the library.
Second, there is no technical defence against it, and pretending otherwise is how states waste money. A national SOC does not defend against a strategic bargain. The only defence is political: alignment declared publicly and in advance, so the adversary cannot buy neutrality cheaply or make each individual concession look like a reasonable act of prudence. Recorded Future’s Austrian and Czech findings show Moscow already running the same operation on a smaller budget, modulating pressure according to whether a target’s domestic politics look likely to move its way. Israel is what the finished version of that looks like.
IV · The gap: the cognitive domain
This is the section that a “learn from Israel” report has to write honestly or not write at all. On the psychological limb of information confrontation, Israel is not a model. It is a warning.
17. Nobody owns it, and the strategy says so by omission
Start with the sentence, because it comes from an Israeli institution and a former Israeli intelligence officer rather than from a foreign critic: “Israel lacks a national strategy for dealing with such foreign interventions: the Israeli Security Agency has insufficient legal powers to act, and the government’s cooperation with civil society bodies on this issue is in its infancy” (Rakov, JISS 2025, p. 9). And the comparative judgement in the same paragraph: “The threat of foreign interference… has not been given sufficient attention in Israel’s re-examination of its national priorities in the wake of the ‘Swords of Iron’ war. Israel differs in this respect from Western countries, which view the threat of disinformation and subversion with extreme severity.“
The February 2025 national cyber strategy does contain the objective — a public mindspace resilient to foreign influence sits among its eight chapters, beside “zero significant damage to critical infrastructure”, the National SOC and Cyber Dome (Shabtai, BESA 2025). What it does not contain is an owner, a legal power or a budget line — and the INCD, by design, is the wrong body to hold it. Report 2’s principle 3 explains why: the civilian authority created by Resolution 2444 was deliberately denied law-enforcement powers, “to prevent any ongoing suspicion of NSA-like practices, to build trust” (Tabansky 2020, p. 8). That choice is why Israeli companies share incident data with CERT-IL. It is also why the INCD cannot investigate a foreign influence operation, compel a platform, or act against an Israeli intermediary selling sponsored placements to an SDA front.
The Spanish military analysis of the Gaza information conflict reaches the same conclusion from outside, and its phrasing is unintentionally damning. Israel’s counter-narrative work is “likely coordinated by organizations such as the Israel Security Agency (ISA), the Ministry of Foreign Affairs, the National Security Directorate (NSD), or the government itself” (De Sebastián, IEEE 2025, p. 8). That is four candidates and a shrug — a function with no institution. Israel’s showcase response, the rapid technical rebuttal of the Al-Ahli Hospital claim with impact analyses, aerial imagery, audio and explanatory video within hours, demonstrates real capability. It also demonstrates its shape: reactive, source-based, tied to military events, and dependent on the credibility of the state making the claim.
18. Why a technically superb state is structurally blind here
Four mechanisms explain the gap, and each is a direct consequence of something that makes Israel good at the other half.
The threat model requires a named adversary and a measurable effect. Report 2’s principle 13 is that Israel specifies security against a “threat of reference”, which is why Israeli defence is concrete rather than compliance theatre. It is also why a campaign whose effects are diffuse, contested, small in any given month and unattributable to a single actor falls outside the frame. There is no threat of reference for a narrative.
The civil–military boundary that produces trust also produces a hole. The INCD cannot act; the Shin Bet lacks the powers; military intelligence is pointed outward; the Foreign Ministry does public diplomacy, not counter-interference. Every agency has a reason not to own it, and Israeli institutional design deliberately created those reasons.
The intelligence culture decommissioned the collection this problem needs. Hatzav, OSINT, document exploitation, linguistic and cultural analysis — reduced or dissolved in favour of automation before 7 October (Bar, NIPP 2024). Those are precisely the sensors that detect a Hebrew-language operation run through legally resident intermediaries.
And the political economy is hostile. Counter-disinformation in a polarised democracy is indistinguishable, to the losing side, from state regulation of domestic speech. Israel entered this period mid-way through the judicial-overhaul crisis — a fracture the campaign was explicitly designed to widen, and which Iranian operations also exploited (Freilich, INSS 2024). A government cannot credibly referee an information environment it is itself a combatant in. That is not an Israeli peculiarity; it is the general problem, and Israel is the case where it has not been solved.
19. The permissive environment, and the cost of protesting without cost
The last element is the one European states have already fixed without noticing. Rakov lists what makes Israel convenient for Russian information operations: a large number of Russian speakers, heavy air links, and “the absence of published restrictions on the activity of intelligence agents”, who “enjoy diplomatic immunity in Israel, unlike in Western countries, where there have been large-scale expulsions of Russian spies disguised as diplomats over the past five years” (p. 50). Europe’s post-2018 and post-2022 expulsions were not primarily counter-disinformation measures. They turned out to be the most effective ones available, because they removed the physical layer — the officers who stage provocations, pay intermediaries and run agents — that the digital campaign is designed to amplify.
Israel protested to Moscow in July 2023 and imposed nothing. Rakov’s recommendation is the sharpest line in the document and generalises to every European foreign ministry: “issuing warnings without imposing costs may be perceived in Moscow as positive feedback that the cognitive campaign is ‘painful’ and might portray Israel as weak” (p. 9). A démarche without a consequence is not deterrence; it is a delivery receipt.
V · Israel as an actor, not only a target
Candour here is not moralising. It is load-bearing, because it determines what Israel can credibly ask of others — and because a European state buying Israeli capability is buying from this industry.
20. The influence-for-hire industry and its lineage
The documentary record is specific. OpenAI’s October 2024 threat report discloses that “an Israel-origin commercial company we dubbed ‘Zero Zeno’ briefly generated social media comments about the elections in India, which we disrupted less than 24 hours after it began”; the earlier May 2024 disclosure attributed the network to the Israeli political-campaign firm STOIC, targeting Canadian, US, Israeli and then Indian audiences (OpenAI 2024, p. 6). Citizen Lab places this in a lineage: “both independent press and social media platforms’ investigations have previously exposed several highly sophisticated Israeli covert influence operators, and their alleged connections to the country’s government. Two notable examples are Team Jorge and Archimedes Group“ — firms that advertised prior connections to the Israeli intelligence community (Citizen Lab 2025, p. 6).
This is the flywheel Report 2 describes as the engine of Israeli cyber success, running in the other direction. Carnegie records that 80% of the 2,300 founders of Israel’s roughly 700 cyber companies served in IDF intelligence units, and the Atlantic Council’s global spyware dataset puts the Israeli cluster at 43.9% of all entities (Feldstein and Kot 2023; Atlantic Council 2024). The pipeline that produced Wiz and Check Point also produced NSO, Candiru, Intellexa — and Team Jorge. A state cannot design a pipeline that produces only the outputs it likes.
21. PRISONBREAK, and what it costs
The most consequential case is recent, forensic and hard to argue with. Citizen Lab documents a network of more than 50 inauthentic X profiles, created in 2023 and dormant until January 2025, pushing regime-change narratives at Iranian audiences and synchronised with the IDF’s June 2025 campaign. After reviewing alternatives the authors assess “that an unidentified agency of the Israeli government, or a sub-contractor working under its close supervision, is directly conducting the operation” (2025, p. 4).
The timeline is the finding. Evin Prison was struck between 11:17 and 12:18 Tehran time on 23 June 2025. A PRISONBREAK account posted about an explosion at 11:52. At 12:05, while the strikes were still under way, the network published an AI-generated video of the strike on the prison’s main entrance. The first genuine footage appeared one minute later. BBC Persian eventually flagged the video as fabricated — after international outlets had already republished it as real (pp. 6–8). The toolkit also included fabricated BBC Persian articles and bulletins the BBC confirmed it never produced, and a fully synthetic on-camera persona, “Sarina”.
The strategic cost is not squeamishness; it is operational. Israel is a documented victim of exactly this technique — the Auschwitz deepfake pushed by Doppelgänger’s European arms, the false claim on 7 October that Brigadier General Nimrod Aloni had been captured, Hamas hostage video used as an instrument of indoctrination (De Sebastián 2025, pp. 6, 15). A state that runs deniable synthetic-media operations against a foreign public forfeits the standing to demand that platforms, allies and its own citizens treat synthetic media as illegitimate — and Citizen Lab notes that attribution is already harder because platforms have restricted researcher access and cut trust-and-safety teams. Every state-linked deepfake republished by a real newsroom makes the next real atrocity easier to deny. Israel’s information operations degrade the commons that Israel’s information defence depends on. That is the sharpest available argument for the principle this library keeps arriving at: do not run covert influence operations you would condemn if aimed at you.
VI · What the evidence says about effects
Everything proposed in the final section has to survive the sceptical literature, which is the least-quoted and most important material here.
22. The effects are small, the exposure is concentrated, and the denominator is everything
The strongest study in the library is Eady and colleagues in Nature Communications, which linked a longitudinal YouGov panel of 1,496 respondents to their actual Twitter timelines during the 2016 US election. It finds no meaningful relationship between exposure to Internet Research Agency content and changes in issue positions, perceived polarisation or vote choice — coefficients near zero and, where signed, pointing the wrong way for the campaign’s aims (2023, pp. 1, 7).
Three structural facts explain it. Exposure was grotesquely concentrated: 1% of users accounted for 70% of exposures and 10% for 98%, while 1% of Russian accounts produced 89% of the content that reached timelines. The denominator is crushing: in the final month, respondents saw on average 4 IRA posts a day against 106 from national news media and 35 from politicians, and median weekly exposure was zero. And the campaign reached the least persuadable people: exposure rose monotonically with strength of Republican identification, which also sinks the “demobilise the left” theory.
The converging evidence is unusually broad. EU DisinfoLab, having discovered Doppelgänger, called it “undoubtedly a sophisticated operation, but… also a failure”, with most engagement purchased and fake pages drawing mockery of the operators’ 800-rouble bonus. OpenAI reports that “the deceptive activity that achieved the greatest social media reach and media interest was a hoax about the use of AI, not the use of AI itself”, and scored every election-related operation it disrupted at Category Two on Brookings’ six-point Breakout Scale. Elmas and colleagues, analysing 4.5 million tweets around 7 October, found 11 coordinated groups of 541 accounts whose campaigns “fail to deeply penetrate organic user networks” (2026, p. 3). Rakov puts Doppelgänger’s direct political influence in Israel at “quite limited”.
23. Coordination is not harm, and threat inflation is itself a Russian objective
Two corrections follow that matter more for institutional design than for rhetoric.
Coordination is a poor proxy for harm. Of 191 highly amplified coordinated posts in the Israel–Hamas dataset, only 12 were misleading, concentrated in 3 of the 11 groups; the rest were advocacy, religious solidarity and humanitarian mobilisation. “Treating coordination as a proxy for harm would misclassify the majority of components and risk suppressing legitimate collective action” (Elmas et al 2026, pp. 2, 28). Worse, no single signal works: claim-level integrity, toxicity and emotional tone are mutually uncorrelated. One group concentrated five misleading posts inside a fact-checking façade; another had the strongest toxicity and fear signals and zero misleading posts. Any automated early-warning or moderation system built on a single behavioural proxy fails in both directions.
Exaggeration is a deliverable. Rakov quotes Thomas Rid’s assessment that the Kremlin is Doppelgänger’s main target audience, that SDA’s activity is built around convincing the presidential administration that the campaign has serious impact, and that far more people read about Doppelgänger in the press than ever saw its content — with an explicit warning to researchers against exaggerating the significance of interference actors “and thus helping them to secure funding from their customers” (JISS 2025, p. 50). Goldstein and colleagues record the same pathology from the other side, noting that measurement ambiguity “has historically contributed to intelligence agencies inflating the impact of their influence operations for bureaucratic gain”. Eady’s residual claim closes the loop: Russia’s campaign “may have had its largest effects by convincing Americans that its campaign was successful” — the belief in interference, not the interference, is what corroded trust in the result.
Every over-stated national threat assessment is a line in a Russian contractor’s grant renewal, and a deposit in the account of domestic distrust.
24. So attack the enablers, not the narratives
None of this means doing nothing, and the deflationary findings sit beside genuinely large infrastructure numbers: 540 incidents, 10,500 channels, 34 million comments in four months, €1.56bn of state media funding, 77 Storm-1516 operations, and one deepfake of a US vice-presidential candidate viewed more than five million times on X in under 24 hours (VIGINUM 2025, p. 20). The resolution is the EEAS FIMI Deterrence Playbook, which targets three layers of the architecture — WHAT (content), HOW (digital infrastructure and supply chain), WHO (threat actors, intermediaries, contractors) — with four instruments: sanctions, law enforcement, digital regulation through the DSA and platform terms of service, and resilience-building. The logic is stated as a structural claim: “By striking at the key enablers of FIMI operations such as intermediaries, proxies and service providers the structure that sustains them can become progressively fragile” (EEAS 2026, p. 5).
The enablers are unusually European and unusually prosaic. Domain registrars where media brands are typosquatted. Hosting in Luxembourg, Estonia, Sweden and the Netherlands. A tracker registered in Estonia. Bulletproof ASNs behind DDoSia — the sanctioned Aeza International, and a UK front for a Russian host. Israeli media intermediaries selling sponsored placements. Recruited actors paid to read scripts. EU DisinfoLab’s four proposals are all of this type: protect media brands in the domain-name system, make EU-registered software and hosting liable when used for covert operations, actually enforce trademark law and the GDPR — the authors “cannot recall a single GDPR fine against the malicious actors depicted in our many investigations”, despite routine breaches — and give vetted researchers structured platform data including takedown archives.
Two operational notes complete the picture. Targeting beats volume: removing the top amplifiers of already-identified misleading posts suppressed 18.6% of misleading retweet actions at just 5% of coordinated accounts, while the naive heuristic of removing the most prolific amplifiers of all widely shared content suppressed none (Elmas et al 2026, p. 27). Prior identification of the false claims, by hand, is the binding constraint — not takedown capacity. And AI providers occupy a genuinely new vantage point in the middle of the kill chain, after an actor has accounts and access but before content is deployed; they should be treated as a reporting node, not only as a risk surface (OpenAI 2024, pp. 8–9).
VII · What this means for us
The Czech Republic is not Israel’s situation with a different flag. It is the inverse of it. Israel gets the psychological limb of Russian information confrontation without the technical limb, and has world-class technical defence and no cognitive institution. Czechia and its peers get both limbs, have a competent technical agency that is short of money and people, and have a cognitive function that has been created, abolished and relocated more than once. The transfer problem is therefore not “how do we become Israel”. It is “which half do we copy from Israel, and where do we copy the other half from”.
The Czech case is already documented, including the part that should worry most
The evidence base for Czechia is unusually complete, and it is worth setting out as one picture. The volume · 268 recorded incidents in 2024, the highest ever, but with severity falling for the third year — 1 very significant, 18 significant, 249 minor — and availability incidents alone at 43% (NÚKIB 2025, pp. 13–14). The actor · “the primary threat actor is the Russian-speaking NoName057(16), which was behind most of the DDoS attacks detected domestically”, peaking at 30 DDoS attacks in October alone, with all three Russian services present: APT29/Midnight Blizzard (SVR), COLDRIVER (FSB) and APT28 (GRU), the last with “a long-term focus on targets in the Czech Republic”. The position in the table · seventh globally at 4.00% of NoName057(16) attack days, and in the second tier of sustained ransomware victims with more than 50 attacks from Russian-affiliated groups (Brantly and Mason 2026, p. 19). The new vector · Russian-speaking hacktivists attacking weakly secured operational technology in water utilities, with one such attack registered in Czechia in 2024. The information side · the EEAS records that Russia targeted the Czech elections, with “hundreds of anonymous TikTok accounts spread[ing] pro-Kremlin narratives ahead of the parliamentary elections” (EEAS 2026, pp. 11, 14).
Two findings should be read together, because they define the actual strategic problem. First, Czechia has already acted offensively and collectively, and it did not deter anything: Military Intelligence conducted an active intervention in cyberspace against APT28 in January 2024 as part of the US-led operation DYING EMBER, and Czechia co-signed the May 2024 EU/NATO attribution of the APT28 Outlook zero-day campaign — after which, Tkachuk notes, Russia ran its combined satellite-and-cyber operation against Latvia six days later. The attribution had no deterrent effect because nothing followed it.
Second, and more uncomfortable: “the targeting throughout 2024 of the Czech Republic, a major supplier of arms to Ukraine, notably ended in January 2025 after public reporting indicated that the ruling government was expected to lose the October 2025 election to the ANO party” whose leaders had said they would halt ammunition transfers (Insikt Group 2025, p. 15). Austria received the same treatment in reverse, with attacks halting after the September 2024 election and resuming once the Freedom Party was excluded from coalition. Moscow is running on Czechia, at low cost, the same operation it has already completed against Israel: buy a policy change with graduated pressure, and reward the outcome by switching the pressure off. The Israeli case is what success looks like after a decade. It is far cheaper to refuse the bargain than to unwind it.
Against that, the binding constraint is capacity, and NÚKIB says so itself: only 47% of organisations consider their cyber budget sufficient, unchanged since 2023, while the share naming insufficient remuneration as the barrier to hiring jumped from 54% to 77% in a single year, and 55% cope by outsourcing (NÚKIB 2025, pp. 17–19). The gap is not threat awareness. It is money and people.
The models to copy are European, and they are specific
Sweden built psychological defence in 1954 as part of total defence and — unlike Norway and Denmark, which created limited wartime information councils — made it a government body active in peacetime. It lapsed into the Civil Contingencies Agency in 2002 and was re-established as a standalone Psychological Defence Agency in 2022 (Ördén, Lund 2025, p. 2). France has VIGINUM, under the prime minister’s national defence secretariat, publishing attribution-grade TLP:CLEAR technical dossiers that feed sanctions — the single most copyable institutional model in this library for a mid-sized state. The EU supplies the shared vocabulary (Pamment’s four terms: misinformation, disinformation, influence operations, foreign interference), the shared analytic grammar (ABCDE, ABC, DISARM, STIX), the regulatory lever (the DSA and the Code of Practice) and an operational centre in EEAS StratCom with a deterrence playbook already written.
Copy the safeguards with the institution. Ördén’s genealogy is the necessary warning: once information influence is treated as a permanent everyday condition rather than a wartime exception, “foreignness” becomes the criterion that licenses state action, establishing it requires intelligence and signals access, independent journalists shift from scrutineers to students, and the agency must be simultaneously transparent (for trust) and secret (for sources) — which “runs the risk of undermining its moral authority as defenders of the open democratic society”. Her constructive proposal is a governance device, not nostalgia: keep an explicit war/peace line, confine exceptional measures to wartime, and spend peacetime on the demand side — media pluralism, domestic vulnerabilities, minority- and diaspora-language media. That is cheaper and more democratic than a permanent counter-propaganda apparatus, and it is what a Czech-scale state can actually afford.
Eight moves
Name the owner, and give it publication powers rather than speech powers. A small counter-interference unit under the head of government on the VIGINUM model, with a statutory mandate to investigate and publish TLP:CLEAR technical reports on foreign information manipulation — and no power to order content removed. Use Pamment’s diagnostic as the routing rule: misinformation and disinformation go to education, media policy and the courts; influence operations and foreign interference go to the new unit and the intelligence services. Fifteen to twenty-five staff, not a directorate.
One threat picture, one attribution process, one public voice. NÚKIB’s technical assessment and the cognitive-defence function must share a single situational picture and a single quarterly national assessment, because the adversary treats them as one mission and publishes papers saying so. Keep NÚKIB’s probabilistic confidence language (”very likely (70–85%)”) across the merged product — it is a cheap, high-value practice most national agencies still lack.
Stand up an enabler task force and publish its scoreboard. Registrar-level protection for Czech media brands with CZ.NIC; hosting and ASN action against the bulletproof providers behind DDoSia; data-protection and trademark enforcement against cloned outlets — EU DisinfoLab cannot recall a single GDPR fine against these operators despite routine breaches; and the financial-intelligence unit on the payment rails to contractors and paid amplifiers. Report the number of actions annually, by layer: WHAT, HOW, WHO.
Pair every attribution with at least one imposed cost. Czechia has already attributed publicly and been ignored. Rakov’s warning generalises: a warning without a consequence reads in Moscow as confirmation that the campaign hurts. Decide in advance which instrument accompanies which finding — an expulsion, a listing, a DSA referral, a registrar takedown, a prosecution under Operation Eastwood-style coordination.
Buy resilience before more prevention. The Ukrainian evidence is unambiguous about what survives: universal national roaming and a decentralised operator base; legislated pre-authorisation to migrate critical state and private data to foreign clouds; mandatory backups for all critical systems; pre-arranged secure links to allied commands; and a national protective DNS, after which Ukrainian losses from financial phishing fell by more than 30% in the first month with 300-plus providers joined (Tkachuk 2025, p. 18). Every one of those is procurable now.
Rehearse the election playbook you already have the script for. Ukraine’s December 2021 strategic command-and-staff exercise, built from intelligence on Russian plans, saw roughly 80% of its scenario materialise within months. Czechia’s scenario is written: DDoS timed to political milestones, hundreds of anonymous TikTok accounts, deepfaked candidate audio on the Storm-1516 model, and a documented pattern of pressure being switched off when polling moves Moscow’s way. Exercise it with the electoral commission, the platforms, the broadcasters and the parties in the room.
Fix pay, because it is the actual constraint. A government resolution exempting a defined number of NÚKIB, national CERT and counter-interference expert posts from standard civil-service pay tables — the clause Israel wrote into Resolution 3611 in 2011, when the whole bureau’s first-year budget was NIS 4.5M. Everything else in this list fails without it.
Rent the sensor network while you build one. Israel’s best Russian threat picture is privately owned. A mid-sized state should procure equivalent coverage of the Russian-speaking criminal economy — dark-web forums, Telegram, infostealer logs — on the national-CERT model that vendors such as KELA now package for governments and police, with fixed sovereignty terms: source-code escrow, local hosting, open data export and clean exit. Treat it as a lease, not a capability, and keep a state analytic team able to read it.
What to copy from Israel, and what to refuse
Copy · the three-layer model with responsibility escalating by severity · a civilian defender deliberately denied police powers, which is what makes no-fault reporting work · regulation of named entities rather than whole sectors · sector SOCs feeding a national SOC · specifying defence against a named threat of reference · the continuous below-threshold “campaign between wars” mindset · and treating the domestic security industry as national capability, deliberately, with procurement to match.
Refuse · the orphaned cognitive file, and the assumption that a technical agency can hold it · an intelligence culture that decommissions OSINT, linguistic and cultural analysis because machine translation looks cheaper · an export-control regime that follows geopolitics rather than published criteria, and which blocked Ukraine from buying Pegasus and barred Estonia from using it against Russian targets · the influence-for-hire industry and the state-linked covert operations that come with it, because they destroy the commons your own defence depends on · and, above all, the bargain itself: the purchase of quiet from Moscow by withholding support from a country under attack. That is the one Israeli decision in this entire series that a European state must not copy, and it is the one Moscow would most like it to.
Close
The Russian threat has two limbs and one command. Israel has built, against a different adversary, one of the two best technical defences in the world, and it works against the Russian technical limb largely by accident. Against the psychological limb it has a strategy objective with no owner, a security service without the powers, an intelligence culture that dismantled the sensors the problem requires, and a political environment in which no government can credibly referee. Moscow noticed, and spent its effort accordingly: since April 2023 a Kremlin directorate has been running a Hebrew-language campaign with ten specialised teams and a costed plan to seat a party in the Knesset, while Russian state cyber operations went to NATO and to Ukraine.
The larger lesson is about what cyber power cannot do. Israel’s technical excellence did not prevent, and could not have prevented, the outcome Moscow actually wanted: a first-rank cyber state kept out of the coalition arming Ukraine, at the price of a deconfliction line over Syria. That result cost Russia nothing, produced no indicators, and would not have appeared in any national SOC.
For a mid-sized European state the instruction is therefore double, and neither half is optional. Build the technical machine on the Israeli pattern, because it is the best there is and most of it is affordable. And build the cognitive institution on the European pattern — Swedish in its peacetime persistence and its safeguards, French in its publication discipline, EU in its vocabulary and its enabler-focused deterrence — because Israel does not have one and knows it. Then do the cheapest and least technical thing in this report: say publicly, in advance, where you stand, so that no one has to spend a single packet finding out what it would cost to move you.



