Alberto Fittarelli
@fittarelli.com
Sr. Researcher @citizenlab.ca, Disinformation & Harassment. Fmr. Meta. Trainer: find & expose covert influence. I like doers.
16/ Read @haaretzcom.bsky.social ‘s own investigation on PRISONBREAK and other influence operations with an Israeli nexus here.
Reporting by Gur Megiddo and Omer Benjakob.
/END
Reporting by Gur Megiddo and Omer Benjakob.
/END
The Israeli influence operation in Iran pushing to reinstate the shah monarchy
Citizen Lab Found That an Online Network Pushed Out Deepfake Videos During Israel's Airstrikes on Tehran's Evin Prison. An Investigation by TheMarker and Haaretz Reveals the Persian-language Online Ca...
www.haaretz.com
October 3, 2025 at 3:32 AM
16/ Read @haaretzcom.bsky.social ‘s own investigation on PRISONBREAK and other influence operations with an Israeli nexus here.
Reporting by Gur Megiddo and Omer Benjakob.
/END
Reporting by Gur Megiddo and Omer Benjakob.
/END
15/ At the moment of publishing this, several PRISONBREAK profiles continue to be active. We notified X prior to publication - but got no reply.
October 3, 2025 at 3:32 AM
15/ At the moment of publishing this, several PRISONBREAK profiles continue to be active. We notified X prior to publication - but got no reply.
14/ So - who’s behind PRISONBREAK? We analytically weighed multiple hypotheses. The one most consistent with the available evidence is that the Israeli gov, directly or through a contractor, conducted the operation. Alternatively, but less likely, the US gov could be responsible for it.
October 3, 2025 at 3:32 AM
14/ So - who’s behind PRISONBREAK? We analytically weighed multiple hypotheses. The one most consistent with the available evidence is that the Israeli gov, directly or through a contractor, conducted the operation. Alternatively, but less likely, the US gov could be responsible for it.
13/ Finally, we noticed PRISONBREAK consistently promoting and interacting with an account named “تلآویو تهران” (Tel Aviv Tehran), which used an AI-generated persona to spread content very similar to the IO’s one. Including another AI-made “Evin Prison” video.
October 3, 2025 at 3:32 AM
13/ Finally, we noticed PRISONBREAK consistently promoting and interacting with an account named “تلآویو تهران” (Tel Aviv Tehran), which used an AI-generated persona to spread content very similar to the IO’s one. Including another AI-made “Evin Prison” video.
12/ Another tactic used by PRISONBREAK was the creation of fake content (and fake links) attributed to inexistent news reports, claiming that the outlets had removed them quickly after posting them. This echoed something we @citizenlab.ca had already seen as used… by Iran. Remember Endless Mayfly?
Burned After Reading: Endless Mayfly’s Ephemeral Disinformation Campaign - The Citizen Lab
Using Endless Mayfly as an illustration, this highlights the challenges of investigating & addressing disinformation from research & policy perspectives.
citizenlab.ca
October 3, 2025 at 3:32 AM
12/ Another tactic used by PRISONBREAK was the creation of fake content (and fake links) attributed to inexistent news reports, claiming that the outlets had removed them quickly after posting them. This echoed something we @citizenlab.ca had already seen as used… by Iran. Remember Endless Mayfly?
11/ We have many more examples in the report. But one that’s worth highlighting here is the creation of a whole videoclip for “Baraye”, an Iranian protest anthem. The catch? The lyrics were changed to a direct call for uprising; and the video is a (poorly made) deepfake of 3 known Iranian singers.
October 3, 2025 at 3:32 AM
11/ We have many more examples in the report. But one that’s worth highlighting here is the creation of a whole videoclip for “Baraye”, an Iranian protest anthem. The catch? The lyrics were changed to a direct call for uprising; and the video is a (poorly made) deepfake of 3 known Iranian singers.
10/ The use of AI in the campaign is *pervasive*. An attentive reader could have spotted the botched artifacts that often come with AI-generated videos, like the one claiming to show a crowd withdrawing their money from a bank in apparent panic. Just check the distorted human figure in yellow.
October 3, 2025 at 3:32 AM
10/ The use of AI in the campaign is *pervasive*. An attentive reader could have spotted the botched artifacts that often come with AI-generated videos, like the one claiming to show a crowd withdrawing their money from a bank in apparent panic. Just check the distorted human figure in yellow.
9/ In fact, the network had only just started increasing pressure on the Iranian government by spreading claims of state bankruptcy, generalized lack of basic resources (water, for example), and broader societal unrest.
October 3, 2025 at 3:32 AM
9/ In fact, the network had only just started increasing pressure on the Iranian government by spreading claims of state bankruptcy, generalized lack of basic resources (water, for example), and broader societal unrest.
8/ We now know that that didn’t happen. Iranian security forces retook control of the prison later that same day, temporarily transferring prisoners to different facilities before returning them to Evin in August 2025. But PRISONBREAK was not done yet.
October 3, 2025 at 3:32 AM
8/ We now know that that didn’t happen. Iranian security forces retook control of the prison later that same day, temporarily transferring prisoners to different facilities before returning them to Evin in August 2025. But PRISONBREAK was not done yet.
7/ What was possibly even more fascinating was the quick pivot by the network, immediately after the bombings stopped, to encourage Iranians in reaching the Evin Prison and free the prisoners. “The area is now safe”, some of the accounts posted.
October 3, 2025 at 3:32 AM
7/ What was possibly even more fascinating was the quick pivot by the network, immediately after the bombings stopped, to encourage Iranians in reaching the Evin Prison and free the prisoners. “The area is now safe”, some of the accounts posted.
6/ The video initially tricked the international press into republishing it as real. Not only that: it was even reposted by the Israeli MoFA, Gideon Sa’ar. It was later spotted as AI-generated footage by several outlets.
October 3, 2025 at 3:32 AM
6/ The video initially tricked the international press into republishing it as real. Not only that: it was even reposted by the Israeli MoFA, Gideon Sa’ar. It was later spotted as AI-generated footage by several outlets.
5/ Among the targeted locations, on June 23, was the infamous Evin Prison in Tehran, where political detainees routinely suffer torture and deprivation. And guess what? PRISONBREAK posted an AI-generated video of Evin’s bombing *while the bombing was still happening*.
October 3, 2025 at 3:32 AM
5/ Among the targeted locations, on June 23, was the infamous Evin Prison in Tehran, where political detainees routinely suffer torture and deprivation. And guess what? PRISONBREAK posted an AI-generated video of Evin’s bombing *while the bombing was still happening*.
4/ As we know, in June 2025, tensions between Israel and Iran came to a head with the so-called “12-day War”, which saw targeted assassinations of key figures in the Iranian Islamic Republic, while the IDF bombed multiple Iranian locations.
October 3, 2025 at 3:32 AM
4/ As we know, in June 2025, tensions between Israel and Iran came to a head with the so-called “12-day War”, which saw targeted assassinations of key figures in the Iranian Islamic Republic, while the IDF bombed multiple Iranian locations.
3/ We started analyzing the network’s behavior. Created in 2023, it only began posting regularly in January 2025. What could have been the purpose for this IO?
October 3, 2025 at 3:32 AM
3/ We started analyzing the network’s behavior. Created in 2023, it only began posting regularly in January 2025. What could have been the purpose for this IO?
2/ A few months ago, Darren Linvill @ the Media Forensics Hub at Clemson University made us aware of a set of X accounts that they were tracking. The profiles appeared to be inorganic: artificially set up to spread disparaging narratives on the Iranian regime. Also, they were clearly coordinated.
October 3, 2025 at 3:32 AM
2/ A few months ago, Darren Linvill @ the Media Forensics Hub at Clemson University made us aware of a set of X accounts that they were tracking. The profiles appeared to be inorganic: artificially set up to spread disparaging narratives on the Iranian regime. Also, they were clearly coordinated.