
What France is now confronting in the run-up to its presidential election is not a handful of stray online hoaxes, but a sustained, externally driven influence architecture in which Russian-linked networks use AI, forged media, and impersonated news brands to test the resilience of a mature democracy’s information defenses.
Key Points
- French security services have linked a recent smear campaign against Raphaël Glucksmann to Storm‑1516, a Russian influence network already active against other French political figures.
- The operation relied on fabricated documents, AI-generated audio and video, and spoofed media identities, illustrating how cheap, scalable tools can be weaponized against elections.
- This episode sits in a broader pattern: Russia has repeatedly targeted French politics and major national events, from the 2017 presidential race to the Paris Olympics and municipal contests.
- France has responded with dedicated monitoring agencies, legal and diplomatic countermeasures, and practical lessons on how to blunt foreign disinformation without undermining open debate.
France’s Newest Warning Sign: A Targeted Smear in a Familiar Playbook
According to French security sources, the latest disinformation campaign surfaced in the final week of July, when doctored content began to circulate online targeting Raphaël Glucksmann, a prominent social‑democratic figure widely viewed as a serious contender for the next presidential election. Investigators traced the operation to Storm‑1516, an influence network already associated with Russia’s military intelligence, the GRU, in prior European campaigns. What distinguished this episode was less the volume of the material than its sophistication: the network deployed forged documents, AI‑reproduced voices, and a fabricated video that attempted to entangle not only Glucksmann but also high‑profile journalists and media personalities around him.
Security officials described the campaign’s visibility as relatively limited, a reminder that not every operation aims for viral reach; some are designed to probe, to test reactions, or to seed doubt among narrower audiences before larger contests arrive. Glucksmann, a long‑standing critic of the Kremlin, responded publicly by framing the attack as part of Vladimir Putin’s effort to destabilize European democracies and fracture the EU’s stance on Ukraine, explicitly aligning his own political identity with opposition to Russian and Chinese authoritarianism. In the same period, specialist observers such as Nathalie Pailleux of the disinformation‑tracking firm Check First emphasized that Storm‑1516 relies on paid operatives to drive clicks and amplification, treating even limited traction as validation of its tactics.
Storm‑1516 and the Mechanics of Modern Election Interference
Storm‑1516 is not an isolated creation; it belongs to a family of Russian‑linked influence infrastructures that marry traditional propaganda with contemporary digital tools. Investigations by NewsGuard and French authorities describe the network as a composite operation involving actors such as John Mark Dougan, a former American law enforcement officer now in Moscow, who uses AI systems to craft and disseminate false narratives. Between late 2024 and early 2025, Storm‑1516 pushed at least five major fake stories into French‑language spaces, drawing tens of millions of views across platforms. Those narratives ranged from fabricated corruption scandals to invented geopolitical threats, often tailored to France’s domestic debates about security, migration, and foreign policy.
Technically, Storm‑1516 operates through a mix of freshly registered websites that mimic mainstream outlets, cloned logos and typography, and social‑media accounts that impersonate journalists or media brands. Deepfakes—synthetic videos generated by machine‑learning models trained on existing footage—play a central role. By copying a target’s voice and likeness closely enough to pass a quick glance, they exploit the speed at which online audiences consume information and the limited time editors have to verify unexpected material. Parallel networks such as Doppelganger and CopyCop, documented by watchdogs like Recorded Future, extend the same toolkit to other elections, relying on coordinated posting, language‑specific narratives, and careful timing around news cycles.
A Pattern, Not a One‑Off: From Macron 2017 to the Olympics
To understand why French officials treat the Glucksmann case as more than a niche cyber incident, you have to situate it in nearly a decade of cumulative experience with Russian meddling. In 2017, during Emmanuel Macron’s first presidential campaign, hackers linked to the group APT28 (also known as Fancy Bear) penetrated his team’s systems and leaked data in an effort to shape the race’s final days. The attempt ultimately failed to shift the outcome, in part because French media respected a pre‑election silence period and because the campaign moved quickly to frame the leak as a foreign operation.
Since then, the rhythm has accelerated. French officials and international cybersecurity experts describe a steady stream of Russian‑origin campaigns targeting not only elections but symbolic national events such as the Paris Olympics. Operations have included manipulated images of Holocaust memorials, forged threats supposedly issued by armed groups, and videos presented as investigative journalism that turn out, on inspection, to be entirely fabricated. VIGINUM, France’s dedicated agency for monitoring foreign digital interference, has documented how these stories are crafted to exploit existing social fractures—over immigration, Islamist terrorism, or relations with the United States—rather than inventing entirely new grievances.
French Political Figures Under Sustained Information Fire
Glucksmann is not the first French politician to find himself the target of a Russian‑linked disinformation network, and he is unlikely to be the last. Storm‑1516 previously focused on former prime minister Édouard Philippe, spreading false claims about his health in a manner designed to cast doubt on his fitness for office and, by extension, his suitability as a presidential candidate. Similar tactics have been used against other figures such as Gabriel Attal and Nathalie Loiseau, sometimes by overlapping but distinct pro‑Kremlin groups, with varying levels of intensity.
What these episodes share is a strategic logic: rather than attempting to swing a national electorate wholesale, the operators identify individuals who embody key policy stances—on Ukraine, NATO, EU integration, or relations with Russia—and try to erode their credibility through targeted scandal narratives. Analysts from think tanks such as IFRI and CSIS point out that this mirrors the pattern seen in the United States in 2016, where the objective was less to elect a specific candidate than to depress trust in the democratic process and amplify polarization. In France, that polarization often runs along axes of foreign policy and identity politics, giving outside actors obvious fault lines to manipulate.
Why Attribution Is Difficult—and Why It Still Matters
One of the paradoxes in modern information warfare is that the most sophisticated attribution work is rarely fully visible to the public. Technical evidence—IP address clustering, infrastructure overlaps with known GRU assets, and forensic analysis of malware or AI generation techniques—often remains classified or buried in specialist reports. In the French case, journalists rely on briefings from security sources, official communiqués, and independent monitors like NewsGuard or Check First to connect operations such as Storm‑1516 to Russian state or para‑state actors.
This opacity is not, in itself, evidence against the reality of interference; deniability is a design feature of such campaigns. Networks use cut‑out operators, disposable domains, and content that can always be framed after the fact as “just one more opinion online.” Attribution therefore operates more like intelligence work than courtroom proof: it combines multiple indicators, historical patterns, and the strategic context of Moscow’s broader information efforts. For readers and voters, the key is not memorizing the technical detail but recognizing when narratives appear suddenly, rely on unverifiable alleged leaks, and spread primarily through fringe or anonymous channels that mimic legitimacy without earning it.
France’s Counter-Disinformation Toolkit: Learning by Doing
France’s response to Russian information operations has evolved from ad hoc crisis management to a more structured, institutional approach. Agencies such as VIGINUM, situated within the government’s broader digital security apparatus, now monitor foreign disinformation flows systematically, issuing public alerts when specific narratives or operations cross defined thresholds of risk. Fact‑checking units at outlets like AFP, France 24, and TF1 have developed routines for rapid verification of suspicious stories, often in coordination with international partners and civil‑society organizations focused on media literacy.
Policy responses have followed. French authorities have expelled individuals accused of acting as conduits for Russian disinformation, tightening the link between information manipulation and threats to public order. Legal frameworks governing online platforms and political advertising have been updated to reflect the reality that foreign actors can now target domestic audiences directly without traditional intermediaries. Diplomatic messaging—from the Foreign Ministry’s public briefs on Russian disinformation to coordinated EU initiatives—has sought to name and shame specific operations, reducing the benefit of deniability. The Glucksmann case, in this sense, is both another challenge and another opportunity to demonstrate how such countermeasures can limit the impact of a hostile campaign.
What It Means for Voters and Democratic Resilience
For French voters, the practical implication of this landscape is straightforward but demanding: the information environment around major elections is now a contested space in which foreign actors are active participants. That does not mean every sharp critique or controversial revelation is disinformation; democratic politics require vigorous argument and investigative exposure. The problem arises when content rests on anonymous leaks, unverifiable audio or video, or websites whose provenance is unclear, and yet is presented as definitive proof about a candidate’s character or actions.
The evidence from the past decade suggests that Russia’s campaigns have rarely succeeded in deciding French elections outright. They have, however, imposed costs: they consume journalistic bandwidth, force candidates to spend time rebutting fabrications, and contribute to a general sense that “no one knows what’s true anymore.” Learning to distinguish between sincere political disagreement—such as the arguments over Ukraine policy voiced by figures like Philippe de Villiers—and engineered narratives is now part of the civic skill set expected of citizens. France’s experience shows that with alert institutions, strong media, and a public accustomed to interrogating sources, even sophisticated operations like Storm‑1516 can be blunted. But it also underscores that the battle over democratic legitimacy increasingly begins not at the ballot box, but on the screen.
Sources:
insiderpaper.com, euronews.com, lemonde.fr, ifri.org, politico.eu, ua.news, afpc.org, disinfo.eu, apnews.com, ground.news, csis.org, quointelligence.eu, idmo.it, youtube.com, consilium-europa.libguides.com, gmfus.org, abc.net.au, congress.gov, facebook.com, ghrd.org, uk.news.yahoo.com, diplomatie.gouv.fr, dw.com













