Wien · Counter-DisinformationVienna · Counter-Disinformation

Das goldene Zeitalter der DesinformationThe golden age of disinformation

Und wer hält dagegen?And who pushes back?

Ein einziges Pravda-Netzwerk publiziert bis zu 23.000 Artikel pro Tag, kaum für Menschen, sondern um KI-Systeme zu vergiften.[6] Das heldin resilience lab baut die operative Antwort: eine Plattform, die koordinierte Kampagnen in Echtzeit aufdeckt, verhältnismäßige und rechtlich saubere Gegenwehr ermöglicht und misst, ob sie wirkt. Aus Wien.A single Pravda network publishes up to 23,000 articles a day, barely for humans, but to poison AI systems.[6] heldin resilience lab builds the operational answer: a platform that exposes coordinated campaigns in real time, enables proportionate, legally sound countermeasures, and measures whether they work. From Vienna.

Zwei interaktive Knowledge Graphs · die Täterseite (149 Akteure) und die Aufklärerseite (186 Knoten) desselben ÖkosystemsTwo interactive knowledge graphs: the attacker side (149 actors) and the attributor side (186 nodes) of the same ecosystem

Ein Venture von heldin · Unterschätzte Frauen. Unterschätzte Bedrohungen. Eine Antwort. A venture of heldin · Underestimated women. Underestimated threats. One answer.

#2
Globales Kurzfrist-Risiko (WEF 2026)Global short-term risk (WEF 2026) [1]
70+
Länder seit 2013 Ziel von Einfluss-Operationen (Princeton ESOC)Countries targeted by influence operations since 2013 (Princeton ESOC) [2]
3.006
KI-Content-Farmen (bis März 2026)AI content farms (as of March 2026) [3]
27 %
Anteil KI-gestützter FIMI-Vorfälle 2025, fast Verdreifachung ggü. Vorjahr (EEAS)Share of AI-enabled FIMI incidents in 2025, nearly triple the prior year (EEAS) [4]
Das ProblemThe problem

Desinformation ist ein industrielles System.Disinformation is an industrial system.

Desinformation ist kein Kommunikationsproblem mehr. Moderne Einflussoperationen arbeiten arbeitsteilig: Auftraggeber definieren Narrative, Verstärker verleihen Reichweite, Bot- und Clickworker-Netzwerke erzeugen künstliche Masse. Generative KI senkt zusätzlich die Kosten für Content-Produktion, Übersetzung, Persona-Aufbau und Skalierung.Disinformation is no longer a communications problem. Modern influence operations run on a division of labor: clients define narratives, amplifiers lend reach, bot and clickworker networks manufacture artificial volume. Generative AI further lowers the cost of content production, translation, persona-building and scaling.

Demokratische Institutionen reagieren oft erst, wenn Kampagnen bereits sichtbar sind. Dann ist der Schaden häufig schon verteilt: Vertrauen sinkt, Debatten kippen, Betroffene müssen rechtfertigen statt gestalten.Democratic institutions often react only once campaigns are already visible. By then the damage is usually done: trust erodes, debates tip over, and those affected are forced to justify themselves instead of shaping the agenda.

Tier 1 · Strategist & AuftraggeberTier 1 · Strategist & client

PR-Firma, politischer Auftraggeber oder staatlicher Akteur. Definiert Narrativ, Zielgruppe und Zeitfenster der Kampagne.A PR firm, political client or state actor. Defines the narrative, audience and timing of the campaign.

Tier 2 · AmplifierTier 2 · Amplifier

Influencer mit großer Reichweite verleihen dem Narrativ organische Glaubwürdigkeit, ohne Transparenz über Auftrag und Herkunft.High-reach influencers lend the narrative organic credibility, with no transparency about who commissioned it or where it comes from.

Tier 3 · Clickworker-ArmeenTier 3 · Clickworker armies

Fake-Account-Netzwerke erzeugen Masse, künstliche Reichweite und Trending-Effekte, die das Narrativ in die Algorithmen drücken.Fake-account networks manufacture volume, artificial reach and trending effects that push the narrative into the algorithms.

Der KI-HebelThe AI multiplier

KI hebt die alten Grenzen auf: Massenproduktion zu nahezu null Grenzkosten.AI removes the old limits: mass production at near-zero marginal cost.[5]

Die SchutzlückeThe protection gap
LLM Grooming

Die neue Front verläuft durch die KI selbst.The new front line runs through AI itself.

Netzwerke fluten gezielt Trainings- und Suchdaten von Chatbots. In Tests wiederholten KI-Assistenten in bis zu einem Drittel der Antworten Kreml-Narrative als Fakt.Networks deliberately flood the training and search data of chatbots. In tests, AI assistants repeated Kremlin narratives as fact in up to a third of their answers.[9]

WahlenElections

Vier Wahlen gestört. Eine annulliert.Four elections disrupted. One annulled.

Slowakei 2023, Rumänien 2024 (Wahl annulliert), Moldau 2024/25, Deutschland 2025: KI-gestützte Einflussoperationen sind in Europa angekommen.Slovakia 2023, Romania 2024 (election annulled), Moldova 2024/25, Germany 2025: AI-enabled influence operations have arrived in Europe.[10]

Das fehlende PlaybookThe missing playbook

Kein MITRE ATT&CK für Desinformation.No MITRE ATT&CK for disinformation.

Die Cybersecurity hat seit Jahren eine gemeinsame Sprache für Angriffe. Für koordinierte Einflussoperationen im deutschsprachigen Raum fehlt sie. heldin baut sie: das Adversary Playbook.Cybersecurity has had a shared language for attacks for years. For coordinated influence operations in the German-speaking world it does not exist. heldin is building it: the Adversary Playbook.

Das ProjektThe project

Das heldin resilience lab.The heldin resilience lab.

Wir entwickeln eine KI-gestützte Counter-Disinformation-Infrastruktur, die antizipiert statt reagiert: verhaltensbasiert, lückenlos belegt und im Dienst demokratischer Resilienz. Ein F&E-Projekt aus Wien, für den deutschsprachigen Raum.We are building an AI-powered counter-disinformation infrastructure that anticipates instead of reacts: behavior-based, fully evidenced, and in service of democratic resilience. An R&D project from Vienna, for the German-speaking world.

Ziel ist eine Plattform, die nicht nur einzelne Falschinformationen widerlegt, sondern die Produktionslogik dahinter erkennt: Akteure, Taktiken, Narrative, Zielgruppen, Verstärkungsmuster und mögliche Gegenmaßnahmen.The goal is a platform that does not just debunk individual falsehoods but recognizes the production logic behind them: actors, tactics, narratives, audiences, amplification patterns and possible countermeasures.

Wir bauen eine Gegenstruktur zur industriellen Desinformation. Der Kern ist ein Adversary Playbook für Desinformation: eine formale Wissensbasis darüber, wie koordinierte Einflussoperationen aufgebaut sind, und wie demokratische Akteure vorbereitet, schnell und evidenzbasiert reagieren können.We are building a counter-structure to industrial disinformation. At its core is an Adversary Playbook for disinformation: a formal knowledge base of how coordinated influence operations are built, and how democratic actors can respond in a prepared, fast and evidence-based way.

Das heldin resilience lab ist die Forschungs- und Entwicklungsinitiative innerhalb von heldin, dem Wiener Startup für sichere Softwareentwicklung und Cybersecurity. Die heldin academy bildet unterschätzte Frauen zu Security Engineers aus und liefert sichere Software für europäische Unternehmen; das resilience lab wendet dieselbe KI-native Engineering-Kompetenz auf die Sicherheit des Informationsraums an. Unterschätzte Frauen, unterschätzte Bedrohungen: eine Antwort. Mehr über heldin → heldin.ioThe heldin resilience lab is the research-and-development initiative inside heldin, the Vienna-based startup for secure software engineering and cybersecurity. The heldin academy trains underestimated women into security engineers and delivers secure software for European enterprises; the resilience lab applies that same AI-native engineering capability to the security of the information space. Underestimated women, underestimated threats: one answer. More about heldin → heldin.io

90-Sekunden-Erklärvideo · Ton über den Voiceover-Schalter im Video aktivieren. 90-second explainer · turn on sound via the voiceover toggle in the video.
Video in voller Größe öffnen ↗ Open the video full-size ↗
Die PlattformThe platform

Drei Layer. Eine operative Antwort.Three layers. One operational answer.

The three layers as a closed loop: detect, counter, measure, built on the Adversary Playbook. DIE DREI LAYER THE THREE LAYERS 01 02 03 Aufdecken Detect LAYER 01 · THREAT INTELLIGENCE Bekämpfen Counter LAYER 02 · COUNTER-ENGINE Messen Measure LAYER 03 · IMPACT MEASUREMENT GESCHLOSSENER LOOP CLOSED LOOP Adversary Playbook KERN-IP · EIGENE FORSCHUNG CORE IP · ORIGINAL RESEARCH
Layer 01 · Threat Intelligence

Aufdecken, was koordiniert istExpose what is coordinated

Beobachtet öffentliche Quellen und die technische Infrastruktur der Angreifer. Erkannt wird koordiniertes Verhalten, nicht „Wahrheit“ von Inhalten.[17] Jeder Fund trägt eine lückenlose, offline prüfbare Belegkette.Monitors public sources and the attackers' technical infrastructure. What gets detected is coordinated behavior, not the “truth” of content.[17] Every finding carries a complete evidence chain that can be verified offline.

Kern-IP · Eigene ForschungCore IP · Original research
Layer 02 · Counter-Disinfo Engine

Verhältnismäßig bekämpfenCounter proportionately

Aus einer einzigen, menschlich freigegebenen Entscheidung entstehen viele belegte Meldungen an Registrare, Plattformen und Behörden (Fan-out), plus Vorab-Aufklärung (Prebunking) über ein Partnernetz.[22] Grundsatz: Kennzeichnen statt Gegen-Wahrheit.[21] Gegen-Bots sind bindend ausgeschlossen.A single, human-approved decision fans out into many evidenced reports to registrars, platforms and authorities, plus prebunking through a partner network.[22] Principle: label the campaign rather than post counter-truths.[21] Counter-bots are ruled out, bindingly.

Mensch entscheidet · 4-Augen-PrinzipHumans decide · four-eyes principle
Layer 03 · Impact Measurement

Messen, ob es wirktMeasure whether it works

Verfolgt jede Maßnahme nach: Reagiert der Empfänger? Geht die Kampagnen-Aktivität zurück? Ausgewiesen wird zunächst zeitliche Korrelation; Kausalaussagen folgen erst mit belastbarer Methodik.[16]Tracks every measure: does the recipient act? Does campaign activity decline? What gets reported first is temporal correlation; causal claims follow only with robust methodology.[16]

Causal Inference · F&E-KernCausal inference · R&D core

Stand Juli 2026: Ein erster Prototyp schließt den Kreislauf, ein Lagebild-Dashboard mit ersten Echtdaten existiert. Die Streaming-Detektoren sind spezifiziert, aber noch nicht gebaut. Status July 2026: a first prototype closes the loop, and a situation dashboard with first real data exists. The streaming detectors are specified but not yet built.

Plattform vertiefenExplore the platform
DifferenzierungDifferentiation

Alle messen Lärm. Wir messen verhinderten Schaden.Everyone measures noise. We measure prevented harm.

Nach unserer Marktprüfung (Juli 2026) bietet kein kommerzieller Anbieter und kein operatives Produkt kausale Wirkungsmessung; alle messen Aktivität: Alarme, Reichweite. Die Wissenschaft dafür existiert bereits[16], sie ist nur noch nicht in ein Produkt überführt. Genau diese leere Spalte besetzt heldin.Per our market review (July 2026), no commercial vendor and no operational product offers causal impact measurement; everyone measures activity: alerts, reach. The science for it already exists[16]; it just has not been turned into a product yet. That empty column is exactly where heldin plays.

Lead time: the span between detection and the viral tipping point is the room for action. NORDSTERN-METRIK · VORLAUFZEIT (LEAD-TIME) NORTH-STAR METRIC · LEAD TIME Handlungsraum Room for action VORAB AUFKLÄREN · MELDEN · VORBEREITEN PREBUNK · REPORT · PREPARE t_detect KAMPAGNE ERKANNT CAMPAIGN DETECTED t* VIRALER KIPPPUNKT VIRAL TIPPING POINT Lead-Time = t* − t_detect

Mehr Vorlaufzeit = mehr Handlungsraum: vorab aufklären, bevor die Kampagne ihre Welle reitet. Die Lehre aus den Einflussoperationen rund um die Bundestagswahl 2025[10]: Der verteidigbare Wert ist Frühwarnung, nicht „virale Treffer stoppen“. More lead time = more room for action: prebunk before the campaign rides its wave. The lesson of the influence operations around the 2025 German federal election[10]: the defensible value is early warning, not “stopping viral hits”.

Der verifizierte FreiraumThe verified open space

EU-souverän, deutsch-nativ, offen.EU-sovereign, German-native, open.

Nach unserer Wettbewerbsprüfung (Juli 2026) kombiniert kein Anbieter EU-Souveränität, deutsch-native Erkennung und offene Standards. Der Markt bestätigt das Zeitfenster: Gartner führt „Narrative Intelligence“ seit Juni 2026 als eigene Kategorie (erwartete Ausgaben über 30 Mrd. USD bis 2028)[15], und der Digital Services Act wird durchgesetzt (erste Strafe: 120 Mio. € gegen X).[14]No vetted competitor combines EU sovereignty, German-native detection and open standards. The market confirms the window: Gartner has listed “narrative intelligence” as its own category since June 2026 (expected spend above USD 30bn by 2028)[15], and the Digital Services Act is being enforced (first fine: €120m against X).[14]

Der strukturelle SchutzwallThe structural moat

Provenienz als Produktkern.Provenance as the product core.

Jede Aussage trägt eine Belegkette, die Gerichte, Redaktionen und Partner ohne heldin offline prüfen können. Dazu der geschlossene Kreislauf, dessen Interventions-Messdaten mit jedem Vorgang wachsen – ein Datenbestand, den kein Wettbewerber kaufen kann.Every claim carries an evidence chain that courts, newsrooms and partners can verify offline, without heldin. On top: the closed loop, whose intervention data grows with every case – a dataset no competitor can buy.

Die roten Linien – bindendThe red lines – binding

Keine Gegen-BotsNo counter-botsVerdeckte Gegen-Kampagnen sind ausgeschlossen – bindend.Covert counter-campaigns are ruled out – bindingly.

Nichts unter fremder FlaggeNothing under false flagAlles, was das Haus verlässt, trägt Absender und Beleg.Everything that leaves the house carries a sender and evidence.

Keine rohen BeobachtungslistenNo raw watchlistsKonfidenz entsteht nur durch menschliche Prüfung.Confidence is assigned only through human review.

Keine Plattform-FinanzierungNo platform fundingUnabhängigkeit von denen, die gemeldet werden.Independence from those being reported.

Kein Verzicht, sondern die Geschäftsgrundlage: Vertrauen ist das Produkt. Ein einziger aufgedeckter Gegen-Bot würde den wichtigsten Schutzwall vernichten – und die Architektur erzwingt diese Differenzierung strukturell: Belege vor Meldungen, Mensch vor Maschine.Not renunciation but the business foundation: trust is the product. A single exposed counter-bot would destroy the most important moat – and the architecture enforces this differentiation structurally: evidence before reports, humans before machines.

Wissenschaftliche FundierungScientific foundation

Verhalten verrät Kampagnen. Nicht der Inhalt.Behavior gives campaigns away. Not content.

heldin baut auf peer-reviewter Forschung auf, unter anderem des Behavioral Data Science Lab um Marian-Andrei Rizoiu (University of Technology Sydney): Koordinierte Operationen verraten sich durch ihre Handlungsmuster, gerade dort, wo generative KI die inhaltsbasierte Abwehr aushöhlt. Wie wir diese Erkenntnisse operativ umsetzen, legen wir bewusst nicht offen.heldin builds on peer-reviewed research, including work by the Behavioral Data Science Lab around Marian-Andrei Rizoiu (University of Technology Sydney): coordinated operations give themselves away through their patterns of action, precisely where generative AI is hollowing out content-based defense. How we translate these findings into operations is deliberately not published.

Verhalten schlägt TextBehavior beats text

94,9 % – aus Handlungsspuren allein.94.9% – from behavioral traces alone.

Aus reinen Verhaltens-Policies von 12.064 Reddit-Konten (darunter 99 der russischen Internet Research Agency) werden Akteure zuverlässiger identifiziert als mit dem besten textbasierten Verfahren: Macro-F1 94,9 % gegenüber 91,2 % – schon aus kurzen Spuren.From pure behavioral policies of 12,064 Reddit accounts (including 99 run by Russia's Internet Research Agency), actors are identified more reliably than by the best text-based method: macro-F1 94.9% versus 91.2% – even from short traces.[17]

Früh genug für FrühwarnungEarly enough for early warning

Prognose nach 15–30 Minuten.Prediction after 15–30 minutes.

Das State-Space-Modell IC-Mamba prognostiziert das Engagement eines Beitrags bereits im kritischen Fenster der ersten 15 bis 30 Minuten nach Veröffentlichung – genau die Vorlaufzeit, die Gegenwehr vor der Welle braucht.The IC-Mamba state-space model predicts a post's engagement within the critical window of the first 15 to 30 minutes after publication – exactly the lead time that countermeasures need to act before the wave.[18]

Warum Tempo zähltWhy speed matters

Halbwertszeit auf X: ≈ 24 Minuten.Half-life on X: ≈ 24 minutes.

Wie stark Moderationsverzug die erreichbare Schadensreduktion bestimmt, ist hergeleitet (PNAS 2023): Innerhalb der 24-Stunden-Frist des DSA bleibt sie auf schnellen Plattformen begrenzt; erreichbar ist Wirkung vor allem bei den schädlichsten, langlebigsten Inhalten.How strongly moderation delay determines the achievable harm reduction has been derived (PNAS 2023): within the DSA's 24-hour deadline it remains limited on fast platforms; impact is achievable above all for the most harmful, longest-lived content.[19]

Kein reines FaktenproblemNot just a facts problem

Desinformation wirkt auch mit „korrekten“ Fakten.Disinformation works even with “correct” facts.

Fringe-Ideologien verbreiten sich gerade über konsensfähiges, „faktisch korrektes“ Material – treibend sind Themenauswahl und Stil, nicht die Unwahrheit einzelner Aussagen. Wer nur Falschbehauptungen prüft, verfehlt den Mechanismus. Deshalb: Erkennung am Verhalten, Kennzeichnen statt Gegen-Wahrheit.Fringe ideologies spread precisely through consensus-friendly, “factually correct” material – driven by topic selection and style, not the falsity of individual claims. Checking only false claims misses the mechanism. Hence: detect by behavior, label rather than counter-truth.[20]

Peer-reviewt und teils gemeinsam mit Verteidigungsforschung entstanden – überwiegend an australischen Daten. Die Validierung an EU-/DACH-Daten ist Teil des Fahrplans, keine erledigte Aufgabe.Peer-reviewed, partly developed with defense research – mostly on Australian data. Validation on EU/DACH data is part of the roadmap, not a finished task.

Threat News

Die Bedrohung, dokumentiert.The threat, documented.

Was gerade passiert, ausgewählte, belegte Entwicklungen aus dem Desinformations-Ökosystem. Kuratiert vom heldin resilience lab.What is happening right now: selected, evidenced developments from the disinformation ecosystem. Curated by heldin resilience lab.

1,39 Mrd. Aufrufe · eine Kampagne, 5 Monateviews · one campaign, 5 months 244.000 Publikationen · > 2.600 Quellenpublications · > 2,600 sources 23.000 Artikel/Tag · Pravda-Netzwerkarticles/day · Pravda network 27 % FIMI-Vorfälle mit KIFIMI incidents using AI 120 Mio. € erste DSA-Strafe · gegen Xfirst DSA fine · against X

Kennzahlen belegt im Quellenverzeichnis:Figures documented in the source list: [4] [6] [11] [14]

High Juli/August 2026 · Fallbericht F-2026-01July/August 2026 · Case report F-2026-01

Ceuta: Als eine Kampagne Tausende ins Wasser schickteCeuta: when a campaign sent thousands into the water

Im Juli 2026 schwammen binnen weniger Tage Tausende von Marokko in die spanische Exklave Ceuta – mobilisiert über koordinierte TikTok-Videos und +213-Gruppen, mit Toten an der Küste und Nachwirkungen bis zur Schengen-Debatte. Der heldin-Fallbericht rekonstruiert Ablauf, Akteure und DISARM-Techniken auf offener Quellenbasis: das erste dokumentierte Beispiel, wie Desinformation eine Massenbewegung physisch auslöst.In July 2026, within days, thousands swam from Morocco into the Spanish exclave of Ceuta – mobilized via coordinated TikTok videos and +213 groups, with deaths along the coast and aftershocks reaching the Schengen debate. The heldin case report reconstructs the sequence, actors and DISARM techniques from open sources: the first documented example of disinformation physically triggering a mass movement.

High Juni 2026 · Industrielle SkalierungJune 2026 · Industrial scale

Eine Kampagne: 244.000 Publikationen, 1,39 Mrd. AufrufeOne campaign: 244,000 publications, 1.39bn views

Die russische Kampagne gegen den EU-Beitritt der Ukraine (Januar–Mai 2026) lief über mehr als 2.600 unauthentische Quellen – mit länderspezifischen Erzählungen: wirtschaftliche Ängste für Deutschland, Korruptions-Frames für Frankreich. Kampagnen werden industriell produziert und zielgruppengenau lokalisiert.The Russian campaign against Ukraine's EU accession (January–May 2026) ran across more than 2,600 inauthentic sources – with country-specific narratives: economic fears for Germany, corruption frames for France. Campaigns are industrially produced and precisely localized.

High Juni 2026 · Dezentrale NetzeJune 2026 · Decentralized networks

„Roska Bridge“: Sanktionsumgehung ins Fediverse“Roska Bridge”: sanctions evasion into the Fediverse

Die Operation spiegelt Inhalte EU-sanktionierter russischer Medien automatisiert auf Mastodon und Bluesky – Deutschland ist Zielraum; dezentrale Netze haben keine Sanktions-Compliance. Am 25. Juni kehrte RT über ein neues Konto auf X zurück: 6 Mio. Aufrufe in fünf Tagen.The operation automatically mirrors content from EU-sanctioned Russian media onto Mastodon and Bluesky – Germany is a target; decentralized networks have no sanctions compliance. On 25 June, RT returned to X via a new account: 6m views in five days.

Medium Mai 2026 · Gegenwehr wirktMay 2026 · Pushback works

Erste Doppelgänger-Verhaftungen – Belege tragenFirst Doppelgänger arrests – evidence holds up

In den Niederlanden wurden erstmals Mittelsmänner des Doppelgänger-Netzwerks verhaftet; parallel sanktioniert die EU 2026 laufend wegen Informationsmanipulation. Der Wirkpfad ist real: belastbare Belegkette → Meldung an Behörden → Sanktion oder Strafverfolgung. Genau diese gerichtsfesten Belege produziert heldin.In the Netherlands, intermediaries of the Doppelgänger network were arrested for the first time; in parallel, the EU keeps sanctioning for information manipulation in 2026. The impact path is real: robust evidence chain → report to authorities → sanction or prosecution. That court-proof evidence is exactly what heldin produces.

High April 2026 · LLM GroomingApril 2026 · LLM grooming

Pravda-Netzwerk: bis zu 23.000 Artikel pro TagPravda network: up to 23,000 articles per day

Das pro-russische Pravda-Netzwerk publiziert bis zu 23.000 Artikel täglich, kaum für menschliche Leser, sondern um Trainings- und Suchdaten von KI-Chatbots zu vergiften. DFRLab findet erste Belege für Pravda-Inhalte in KI-Trainingsdaten.The pro-Russian Pravda network publishes up to 23,000 articles a day, barely meant for human readers but to poison the training and search data of AI chatbots. DFRLab finds first evidence of Pravda content in AI training data.

Medium März 2026 · FIMI-LagebildMarch 2026 · FIMI landscape

EEAS: 27 % aller FIMI-Vorfälle 2025 nutzten KIEEAS: 27% of all FIMI incidents in 2025 used AI

Der 4. FIMI Threat Report des EU-Außendienstes dokumentiert eine fast Verdreifachung KI-gestützter Vorfälle gegenüber dem Vorjahr, Foreign Information Manipulation and Interference industrialisiert sich.The EEAS's 4th FIMI Threat Report documents a near-tripling of AI-enabled incidents over the prior year. Foreign Information Manipulation and Interference is industrializing.

Medium Oktober 2025 · InfrastrukturOctober 2025 · Infrastructure

Operation SIMCARTEL: 49 Mio. Fake-Accounts aus einer SIM-FarmOperation SIMCARTEL: 49M fake accounts from one SIM farm

Europol zerschlägt ein Cybercrime-as-a-Service-Netzwerk: 1.200 SIM-Boxen, 40.000 aktive SIM-Karten, 49 Millionen Fake-Online-Accounts, Infrastruktur, wie sie auch Desinformationskampagnen speist. Razzien u. a. in Österreich.Europol dismantles a cybercrime-as-a-service network: 1,200 SIM boxes, 40,000 active SIM cards, 49 million fake online accounts, the kind of infrastructure that also feeds disinformation campaigns. Raids included Austria.

Zum Threat News Feed →To the Threat News feed → täglich 06:00daily 06:00
Die Angreifer (Threat Actors)The attackers (threat actors)

Wer steckt dahinter?Who is behind it?

Der Threat-Actor Knowledge Graph kartiert Akteure, Cluster und Infrastruktur organisierter Desinformation. Er zeigt, wie staatliche Akteure, PR-Fronten, Troll-Farmen, Bot-Netzwerke, Disinfo-for-hire-Firmen und technische Enabler zusammenwirken.The Threat-Actor Knowledge Graph maps the actors, clusters and infrastructure of organized disinformation. It shows how state actors, PR fronts, troll farms, bot networks, disinfo-for-hire firms and technical enablers work together.

149Akteure · 8 Clusteractors · 8 clusters

Threat-Actor Knowledge Graph

Die kartierte FIMI-Produzenten- und Infrastruktur-Seite. Ein erster Baustein der offenen Wissensschicht von heldin: Forschung, die öffentlich nachvollziehbar ist und als Grundlage für das Adversary Playbook dient.The mapped FIMI producer and infrastructure side. A first building block of heldin's open knowledge layer: research that is publicly verifiable and serves as the basis for the Adversary Playbook.

Offene WissensschichtOpen knowledge layer Grundlage Adversary PlaybookBasis for the Adversary Playbook
Graph öffnenOpen graph
Wer hält dagegen? (Die Aufklärer)Who pushes back? (The attributors)

Und wer verteidigt?And who defends?

Das Gegenstück zum Threat-Actor-Graph: der Attributoren-Knowledge Graph kartiert die Verteidiger- und Aufklärer-Seite desselben Ökosystems. Staatliche Abwehr, Sanktionsbehörden, Plattform-Threat-Intelligence, Forschung, NGOs, Investigativ-Journalismus, Faktencheck-Netzwerke und Standards. Er zeigt auch, wo heldin andockt und welche Lücke es füllt: Die meisten erkennen und attribuieren, kaum jemand kontert operativ und misst Wirkung.The counterpart to the Threat-Actor graph: the Attributor Knowledge Graph maps the defender and attributor side of the same ecosystem. State defense, sanctions authorities, platform threat intelligence, research, NGOs, investigative journalism, fact-checking networks and standards. It also shows where heldin plugs in and which gap it fills: most detect and attribute, almost no one counters operationally and measures impact.

186Knoten · 10 Kategoriennodes · 10 categories

Attributoren Knowledge Graph

Die kartierte Verteidiger- und Aufklärer-Seite gegen FIMI: 185 Attributoren plus heldins Andockpunkt. Geografisch zweistufig markiert (DACH und Europa hervorgehoben) und mit dem Status 2026 versehen, inklusive reduzierter und eingestellter Stellen.The mapped defender and attributor side against FIMI: 185 attributors plus heldin's plug-in point. Marked geographically in two tiers (DACH and Europe highlighted) and annotated with 2026 status, including reduced and discontinued units.

Verteidiger-PendantDefender counterpart DACH & Europa markiertDACH & Europe marked
Graph öffnenOpen graph
WirkungImpact

Von Asymmetrie zu Resilienz.From asymmetry to resilience.

Von der strukturellen Asymmetrie zwischen industrialisierter Desinformation und fragmentierter Abwehr bis zur Stärkung demokratischer Resilienz, unsere Wirkungslogik in sieben Stufen.From the structural asymmetry between industrialized disinformation and fragmented defense to strengthening democratic resilience: our impact logic in seven steps.

↑ zunehmende Wirkungstiefe · klick eine Stufe↑ increasing impact depth · click a step

Grundlage · 1–2Foundation · 1–2 Output · 3–4 Wirkung & Impact · 5–7Effect & impact · 5–7
Das vollständige Wirkungsmodell ansehenSee the full impact model

Wirkungsmodell nach PHINEO-Wirkungslogik · Stand Mai 2026.Impact model based on PHINEO impact logic · As of May 2026.

Team

Wer wir sind.Who we are.

Porträt Mariebeth Aquino
Technische Gründerin · CEO/CTOTechnical founder · CEO/CTO

Mariebeth Aquino

Verantwortet Architektur, Adversary Playbook, KI-gestützte Entwicklung und Produktstrategie.Leads architecture, the Adversary Playbook, AI-augmented development and product strategy.

Porträt Katja Tschoepe
Kommunikation & WirkungCommunications & impact

Katja Tschoepe

Kommunikationswissenschaftlerin & Strategieberaterin. Verantwortet Kommunikationslogik, Gegenkommunikation, Wirkungsdesign und Stakeholder-Einbindung.Communications scientist and strategy consultant. Leads communications logic, counter-communication, impact design and stakeholder engagement.

Strategic Security Advisor

GenMjr i. R. Thomas Starlinger, ehem. Bundesminister für Landesverteidigung, ehem. österr. Militärvertreter bei EU und NATO. Bringt die sicherheitspolitische Expertise für die FIMI-Dimension.Maj. Gen. (ret.) Thomas Starlinger, former Federal Minister of Defence and former Austrian military representative to the EU and NATO. Brings the security-policy expertise for the FIMI dimension.

heldin wird als FlexCo geführt (in Gründung); die Gründung erfolgt in Wien.heldin is being established as a FlexCo (in formation); incorporation will take place in Vienna.

Willst du uns unterstützen?Want to support us?

Gestalte demokratische Resilienz mit.Help shape democratic resilience.

heldin sucht Partner, Förderer und Institutionen, die Counter-Disinformation als öffentliche Infrastruktur verstehen. Die offene Wissensschicht stärkt Forschung, Medien, Bildung und Zivilgesellschaft; die operative Schicht schützt sensible Methoden vor Missbrauch.heldin is looking for partners, funders and institutions that see counter-disinformation as public infrastructure. The open knowledge layer strengthens research, media, education and civil society; the operational layer protects sensitive methods from misuse.

info at heldin dot io · WienVienna

QuellenverzeichnisSources

  1. World Economic Forum: Global Risks Report 2026: Mis-/Desinformation als zweitgrößtes globales Kurzfrist-Risiko.World Economic Forum: Global Risks Report 2026. Mis/disinformation ranked the second-largest global short-term risk. weforum.org · Global Risks Report 2026
  2. Empirical Studies of Conflict Project (Princeton University): Tracking Disinformation and Conflict: Online-Einfluss-Operationen in 70+ Ländern seit 2013.Empirical Studies of Conflict Project (Princeton University): Tracking Disinformation and Conflict. Online influence operations in 70+ countries since 2013. esoc.princeton.edu
  3. NewsGuard: AI Tracking Center: 3.006 KI-Content-Farm-Seiten in 16 Sprachen (Stand März 2026), Wachstum 300–500 Seiten/Monat.NewsGuard: AI Tracking Center. 3,006 AI content-farm sites in 16 languages (as of March 2026), growing 300–500 sites/month. newsguardtech.com · AI Tracking Center
  4. European External Action Service (EEAS): 4th Annual Report on FIMI Threats (März 2026), 27 % der FIMI-Vorfälle 2025 mit KI-Einsatz.European External Action Service (EEAS): 4th Annual Report on FIMI Threats (March 2026). 27% of FIMI incidents in 2025 used AI. eeas.europa.eu · 4. FIMI Threat Report
  5. National Endowment for Democracy: Manufacturing Deceit: How Generative AI Supercharges Information Manipulation. ned.org · Manufacturing Deceit
  6. DFRLab: Pravda in the pipeline: Early evidence of state-adjacent propaganda in AI training data (April 2026); Pravda-Netzwerk mit bis zu 23.000 Artikeln/Tag.DFRLab: Pravda in the pipeline: Early evidence of state-adjacent propaganda in AI training data (April 2026); the Pravda network with up to 23,000 articles/day. dfrlab.org · Pravda in the pipeline
  7. Institute for Strategic Dialogue (ISD): Link by link: Hundreds of webpages cite pro-Russia Pravda network. isdglobal.org
  8. Europol: Operation SIMCARTEL (Oktober 2025), SIM-Farm-Netzwerk mit 49 Mio. Fake-Accounts zerschlagen; Razzien u. a. in Österreich.Europol: Operation SIMCARTEL (October 2025). A SIM-farm network with 49M fake accounts dismantled; raids included Austria. europol.europa.eu · SIMCARTEL
  9. NewsGuard: KI-Audit (März 2025), führende Chatbots wiederholten in 33 % der getesteten Antworten Narrative des Pravda-Netzwerks; spätere Replikationen fanden niedrigere Werte (5–8 %), daher „bis zu ein Drittel".NewsGuard: AI audit (March 2025). Leading chatbots repeated Pravda-network narratives in 33% of tested answers; later replications found lower rates (5–8%), hence “up to a third”. newsguardtech.com · Special Reports
  10. VIGINUM (SGDSN, Frankreich): Storm-1516-Report (Mai 2025), 77 dokumentierte Operationen; Fälle: Slowakei 2023, Rumänien 2024 (Annullierung durch Verfassungsgericht), Moldau 2024/25, Deutschland 2025.VIGINUM (SGDSN, France): Storm-1516 report (May 2025), 77 documented operations; cases: Slovakia 2023, Romania 2024 (annulled by the constitutional court), Moldova 2024/25, Germany 2025. sgdsn.gouv.fr · VIGINUM
  11. Cyfluence Research Centre (Juli 2026): Wochenberichte zu cyber-gestützten Einflusskampagnen – Grundlage der Angaben zur Ukraine-EU-Kampagne (244.000 Publikationen, 1,39 Mrd. Aufrufe), „Roska Bridge“ und RT-Rückkehr auf X.Cyfluence Research Centre (July 2026): weekly reports on cyber-based influence campaigns – basis for the figures on the Ukraine-EU campaign (244,000 publications, 1.39bn views), “Roska Bridge” and RT's return to X. cyfluence-research.org
  12. EU DisinfoLab: Disinfo Update (27. Mai 2026), erste Verhaftungen von Doppelgänger-Mittelsmännern in den Niederlanden.EU DisinfoLab: Disinfo Update (27 May 2026). First arrests of Doppelgänger intermediaries in the Netherlands. disinfo.eu
  13. Rat der Europäischen Union (Januar–April 2026): Sanktionslistungen wegen Informationsmanipulation (hybride Bedrohungen Russlands).Council of the European Union (January–April 2026): sanctions listings for information manipulation (Russian hybrid threats). consilium.europa.eu
  14. Europäische Kommission (5. Dezember 2025): Erste Bußgeld-Entscheidung unter dem Digital Services Act – 120 Mio. € gegen X.European Commission (5 December 2025): first fine under the Digital Services Act – €120m against X. digital-strategy.ec.europa.eu
  15. Gartner (Oktober 2025 / Juni 2026): Enterprise-Ausgaben gegen Mis-/Desinformation > 30 Mrd. USD bis 2028; „Narrative Intelligence“ als Emerging-Market-Kategorie (Juni 2026). Prognosewerte, als Sekundärsignal gekennzeichnet.Gartner (October 2025 / June 2026): enterprise spend against mis/disinformation > USD 30bn by 2028; “narrative intelligence” as an emerging market category (June 2026). Forecast figures, treated as a secondary signal. gartner.com · Newsroom
  16. Tian, L. & Rizoiu, M.-A. (2026): Estimating Online Influence Needs Causal Modeling, AAAI-26; Ram, R. & Rizoiu, M.-A. (2024/2026): Empirically Measuring Online Social Influence, EPJ Data Science 13:53 und 15:56 – kausale Einfluss-Schätzung ist in der Forschung etabliert, aber in keinem operativen Produkt.Tian, L. & Rizoiu, M.-A. (2026): Estimating Online Influence Needs Causal Modeling, AAAI-26; Ram, R. & Rizoiu, M.-A. (2024/2026): Empirically Measuring Online Social Influence, EPJ Data Science 13:53 and 15:56 – causal influence estimation is established in research but not in any operational product. doi.org/10.1140/epjds/s13688-024-00492-z
  17. Schneider, P. J., Yuan, L. & Rizoiu, M.-A. (2026): Beyond Content – Behavioral Policies Reveal Actors in Information Operations, npj Complexity.Schneider, P. J., Yuan, L. & Rizoiu, M.-A. (2026): Beyond Content – Behavioral Policies Reveal Actors in Information Operations, npj Complexity. doi.org/10.1038/s44260-026-00085-z
  18. Tian, L., Booth, E., Bailo, F., Droogan, J. & Rizoiu, M.-A. (2025): Before It's Too Late – A State Space Model for the Early Prediction of Misinformation and Disinformation Engagement (IC-Mamba).Tian, L., Booth, E., Bailo, F., Droogan, J. & Rizoiu, M.-A. (2025): Before It's Too Late – A State Space Model for the Early Prediction of Misinformation and Disinformation Engagement (IC-Mamba). arxiv.org/abs/2502.04655
  19. Schneider, P. J. & Rizoiu, M.-A. (2023): The Effectiveness of Moderating Harmful Online Content, PNAS 120(34) – Halbwertszeiten: X ≈ 24 Min., Facebook 105 Min., Instagram 20 Std., LinkedIn 24 Std., YouTube 8,8 Tage.Schneider, P. J. & Rizoiu, M.-A. (2023): The Effectiveness of Moderating Harmful Online Content, PNAS 120(34) – half-lives: X ≈ 24 min, Facebook 105 min, Instagram 20 h, LinkedIn 24 h, YouTube 8.8 days. doi.org/10.1073/pnas.2307360120
  20. Lee, J., Booth, E., Farid, H. & Rizoiu, M.-A. (2025): Misinformation Is Not About Bad Facts: Production and Consumption of Fringe Content, EPJ Data Science 14:50.Lee, J., Booth, E., Farid, H. & Rizoiu, M.-A. (2025): Misinformation Is Not About Bad Facts: Production and Consumption of Fringe Content, EPJ Data Science 14:50. doi.org/10.1140/epjds/s13688-025-00567-5
  21. The Effects of Social Media Labeling of State-Controlled Media, Information Systems Research (2024): Herkunfts-Kennzeichen auf Facebook senkten Teilen um 34 % und Likes um 46 %.The Effects of Social Media Labeling of State-Controlled Media, Information Systems Research (2024): provenance labels on Facebook reduced shares by 34% and likes by 46%. pubsonline.informs.org/doi/10.1287/isre.2022.0305
  22. Roozenbeek, J. u. a. (2022): Psychological inoculation improves resilience against misinformation on social media, Science Advances 8(34).Roozenbeek, J. et al. (2022): Psychological inoculation improves resilience against misinformation on social media, Science Advances 8(34). science.org/doi/10.1126/sciadv.abo6254