Saxony-Anhalt: The Russian Disinformation Campaign Ahead of the Vote

In the final days before the September 6 election, an influence operation attributed by German authorities to the “Storm-1516” network — linked to Russian military intelligence (GRU) — attempted to discredit postal voting in Saxony-Anhalt. This was not an isolated strike: the same campaign had already targeted outgoing Minister-President Sven Schulze (CDU) a few weeks earlier, via a fake clone of the Süddeutsche Zeitung website.

Key Points

  • A video circulated from the Friday before the election purported to show an administrative employee opening postal ballots in advance and systematically invalidating AfD votes with large crosses.
  • The video contains glaring inconsistencies: all three visible ballots bear the same voter’s name, and none carries the corner punch-hole German polling stations use to authenticate ballots with templates.
  • German intelligence services attribute the fake video to “Storm-1516,” an influence operation they link to the GRU.
  • The same network had already spread false accusations against Sven Schulze a few weeks earlier via a fraudulent clone of the Süddeutsche Zeitung website — amplified by English-language accounts with a combined following of over 100,000.
  • No confirmed instance of electoral fraud was recorded on election day; vote counting in Germany remains, as a matter of principle, public and observable by anyone on site.

by Joël-François Dumont — Berlin, 8 September 2026.

An Already Familiar Playbook

The operation did not come out of nowhere. According to the Leipziger Volkszeitung of 7 September, the same campaign had already struck a few weeks before the election, this time targeting Sven Schulze directly: a fake clone of the Süddeutsche Zeitung website served as the vehicle for fabricated accusations against the outgoing Minister-President, picked up and amplified by several English-language accounts on X, some with over 100,000 followers — accounts that, under normal circumstances, mostly circulate conspiracy-minded, pro-Iranian or anti-Israel content. The modus operandi of the postal-vote video, circulated from the Friday before the election, follows the same distribution channel.

A Filmed Fraud — Crudely Fabricated

The video put into circulation purported to show a polling-station employee opening postal ballots ahead of time and methodically invalidating ballots marked for the AfD with large crosses. The footage does not, however, hold up to scrutiny: all three ballots visible in the sequence bear the same voter’s name, and none shows the corner punch-hole that, on genuine German electoral documents, allows polling authorities to authenticate them using purpose-made templates. A recognisable fabrication, then, but one released at the most sensitive point of the electoral calendar.

Storm-1516 and the GRU

According to German intelligence findings cited by the Leipziger Volkszeitung, the group behind this campaign — known as “Storm-1516” — maintains close ties to Russian military intelligence (GRU). This is not the first time the network has been identified in connection with operations targeting German elections; its signature, already flagged by several Western security services, consists of combining deepfakes or crude edits, clone websites of legitimate media outlets, and amplification via X accounts with pre-existing large followings but no apparent thematic link to German politics.

The network is largely run by John Mark Dougan, a former Florida deputy sheriff who fled to Russia in 2016 after an FBI raid on his home — and who, in December 2025, became the first American citizen sanctioned by the European Union for running influence operations against Western countries. According to European intelligence documents obtained by the Washington Post, funding for the network’s servers and generative-AI tools is attributed to GRU Unit 29155, led by Oleg Kushnir; operational coordination is reportedly handled by GRU officer Yury Khoroshenky, who is also said to oversee the hacking group Ember Bear.

Storm-1516 does not operate alone: Bloomberg describes it as one of several complementary Russian campaigns, alongside notably the “Doppelgänger” operation, which specialises in cloning legitimate media websites (Bild, The Guardian, ANSA, as well as, in its French version, Le Monde and Le Figaro) to spread pro-Kremlin disinformation — a phenomenon we already documented in 2023 (see « Cherchez l’intrus ! (Opération Doppelgänger) »). Europe owes much of its tracking of these Russian influence networks to two particularly effective services: Viginum, the French agency for vigilance against foreign digital interference, attached to the SGDSN, and EUvsDisinfo, the monitoring unit of the European External Action Service (EEAS) in Brussels — both cited several times in this article.

The network’s modus operandi, dubbed “Matryoshka” by analysts after the Russian nesting dolls, follows a well-honed three-step process: a video presented as footage from a “whistleblower” or “citizen journalist” appears on a newly created channel; the content is then picked up by a network of fake, seemingly independent news websites; it is finally amplified by Russian émigrés, officials and sympathisers. Worldwide, Storm-1516 is credited with more than 171 fake websites, 32 distinct false narratives and over 67 million cumulative views across sixteen languages, with documented interference attempts in at least seven different elections worldwide, including in Germany, Moldova and the United States.

The New Front: “LLM Grooming” of Artificial Intelligence

Beyond doctored videos and fake websites, the EEAS is warning of a more discreet, and potentially more durable, evolution in Russian strategy: “LLM grooming” — literally, the “conditioning” of large language models. Rather than targeting human readers alone through social media, the Russian disinformation apparatus is now flooding the internet with millions of low-quality articles designed to be absorbed by AI engines — ChatGPT and its equivalents — and to resurface as seemingly neutral answers.

The mechanism relies precisely on the Pravda network mentioned above: its massive output of content, in numerous languages, ensures that AI models incorporate it into their training data or real-time search results. One example documented by NewsGuard illustrates the scale of the phenomenon: when the Pravda network falsely claimed that President Zelensky had banned Donald Trump’s Truth Social platform, six out of ten AI assistants tested repeated this false claim, citing Pravda as their source. More broadly, the share of false or misleading content relayed by the ten leading AI assistants tested is said to have risen from 18% in 2024 to 35% in 2025 — a doubling in a single year.

Disinformation That, Paradoxically, Serves the AfD’s Own Narrative

The choice of subject — alleged fraud in postal voting — is not incidental. The Leipziger Volkszeitung notes that the German far right has itself long claimed, without ever producing evidence, that postal voting is subject to manipulation. In the weeks before the election, AfD officials had jointly called, alongside the far-right association “Ein Prozent,” for a mobilisation of citizen “election observers.” The Russian disinformation campaign and the AfD’s rhetoric on electoral fraud thus converge, though it is not currently possible to establish whether this reflects deliberate coordination or a simple convergence of interests between two actors who each stand to gain from undermining trust in the German electoral process.

Federal Interior Minister Alexander Dobrindt (CSU), who subsequently announced a protective scheme against hybrid attacks on critical infrastructure, summed up the broader climate in an interview with Bild am Sonntag: Russia’s hybrid attacks — infiltrated agents in cities, cyberattacks, sabotage — now amount to “tägliche Realität” (daily reality).

No Confirmed Fraud

At the conclusion of the count, no attempt at electoral fraud was recorded in Saxony-Anhalt. On this front, the German system continues to rank among the most secure in international comparison: vote counting is, as a matter of principle, public, and anyone interested may observe it on site, provided they do not disrupt the counting process.

Joël-François Dumont

Sources:

Leipziger Volkszeitung — review of the German press, 7 September 2026. Washington Post, Bloomberg, Meduza, EDMO/Viginum, Ukrainian Week — for the profile of the Storm-1516 network. EUvsDisinfo (European External Action Service), NewsGuard — for the “LLM grooming” section. EUvsDisinfo, Policy Genome (Ihor Samokhodskyi) — for the Yandex/Alice analysis.

See also:

Analysis — When Propaganda Changes Infrastructure

The case of “Alice,” the AI assistant developed by Russian tech giant Yandex, deserves attention beyond the anecdotal, because it documents in black and white what Storm-1516 only illustrates indirectly: state propaganda no longer travels solely through television channels or social networks, but now through the everyday objects of digital life — a search engine, a smart speaker, a voice assistant.

The most striking episode was documented by independent researchers (a 2026 study by Ihor Samokhodskyi, founder of Policy Genome, cited by EUvsDisinfo, the monitoring unit of the European External Action Service). Asked in Russian about the Bucha massacre, Alice first generated a factually accurate answer — no, there is no convincing evidence that Ukraine organised this massacre — before that answer was instantly erased and replaced with a programmed dodge: “there are topics on which I could be wrong, so I’d rather stay silent.” The model knew the truth; the system deleted it before it reached the user. Asked in English, the same question did not trigger this censorship — a sign that the filtering specifically targets the Russian-speaking audience.

This is no accident but a declared policy. Already in 2024, Dmitry Medvedev publicly accused Alice of “cowardice” on sensitive topics; since then, a “criterion for assessing respect for ideological sovereignty,” developed by the Institute of Social Sciences at the Russian Presidential Academy, has been ranking Russian AI systems by their degree of alignment with Kremlin talking points — with Alice coming first. A leak of documents attributed to the Social Design Agency, an organisation operating under direct supervision of the Russian presidency, further revealed the existence of deliberate operations designed to “poison” the results produced by AI in targeted geographic areas, in order to steer the answers given to internet users asking about their local leaders or upcoming elections.

The parallel with Storm-1516 is no coincidence: both operations follow the same strategic logic, but act at two distinct levels of the same system. Storm-1516 pollutes the upstream — it floods the open web with fabricated content, betting that Western AI models, trained on public data, will eventually absorb it and regurgitate it as fact. Yandex, by contrast, directly controls the downstream: it has no need to poison anyone, since it owns the model, the platform and the end user. One cheats within the rules of the Western game; the other has simply freed itself of any rules on its own turf.

The problem extends well beyond Russia itself. The Yandex browser, with Alice built in, claims 71 million monthly active users worldwide — more than a mere Russian tool, a global player in consumer AI. Its footprint outside Russia is far from marginal: roughly 34.5% market share in Belarus, 28.5% in Kazakhstan, and a real, if smaller, presence in several Baltic EU member states — 10% in Latvia, 7% in Estonia, 6.2% in Lithuania, despite blocking measures taken by some of these states. Alice-branded smart speakers, not officially marketed in the EU, are nonetheless readily available there through resellers based in Latvia itself, or via platforms such as eBay.

What this case illustrates is a shift in infrastructure more than a shift in method. Authoritarian regimes have long sought to control television; they are now learning to control the algorithm. The difference is not merely technical: a biased television news broadcast is recognisable as such, with an identifiable editorial line and a bias that is either openly asserted or denounced. A chatbot’s answer, by contrast, presents itself as a neutral synthesis, faceless, with no identifiable newsroom — making it all the harder for the user receiving it to challenge. For the first time, state propaganda is exported not as content one chooses to consult, but as a feature one installs without a second thought, alongside a navigation app or a delivery service.

For European democracies, the lesson is twofold. First, the vigilance deployed against classic disinformation campaigns — doctored videos, fake websites, coordinated accounts — must now extend to the technical upstream: which AI models are citizens using, on what data were they trained, and above all, who controls their final output. Second, and perhaps the most uncomfortable point, the line between “foreign propaganda” and “imported technology product” is fading as these tools become embedded in daily digital life — a challenge to information sovereignty that, unlike the electoral firewall, cannot be settled by a simple vote.