Skip to main content

The Account Was Real

Manipulation Breakdowns · 9 min read · By D0

The Post the Journalist Didn’t Write

“Someone got into my account and posted some story about France and Ukraine.”

That’s how Wall Street Journal reporter Alex Ward described discovering that a Kremlin influence operation had used his Bluesky account to spread pro-Russian propaganda. He noticed. He deleted the post. He regained control.

Most victims didn’t notice as quickly. Some may not have noticed at all.

What Happened

In late May 2026, researchers at Clemson University and the Institute for Strategic Dialogue documented a Russian influence campaign operating on Bluesky. The campaign was linked to the Moscow-based Social Design Agency — a firm sanctioned by the United States, the European Union, and the United Kingdom for information warfare operations. Researchers named the campaign Matryoshka, after the Russian nesting doll, for its practice of hiding disinformation in layers, each concealing the next.

The campaign’s accounts were not fake. They were real accounts belonging to journalists, academics, a Texas pollster, an anime artist, and a Hollywood filmmaker. Their credentials had been compromised in data breaches — not a Bluesky breach, but the accumulated wreckage of years of password leaks from other platforms. The operation matched those credentials against Bluesky accounts, identified dormant profiles whose owners were unlikely to notice activity, and used them to post pro-Kremlin content.

The Hollywood filmmaker’s account posted an AI-doctored video impersonating a Canadian police official criticizing Macron. Ward’s account posted content about France and Ukraine. The accounts distributing this content belonged to real people with real posting histories and real followers.

The content was fabricated. The account was not.

Why This Is Different

Fake account operations have a fundamental problem: the account is new, or newly active, or its behavioral patterns don’t match a real person. Researchers look for these signals. Platforms run automated systems that model normal human behavior and flag deviations. Coordinated inauthentic behavior — networks of accounts posting the same content at similar times — leaves detectable patterns.

Hijacked real accounts don’t have this problem.

A real journalist’s account has years of posts. It has followers who engaged because they wanted to follow that journalist. It has an established behavioral fingerprint — what they post about, when they post, how they write. All of that existing infrastructure transfers to whoever is holding the password. The operation doesn’t build credibility from scratch. It inherits it.

When a reader sees a post from a journalist they follow, the credibility question is already answered. The reader decided, at some prior point, that this account is worth reading. The normal skeptical response — “who is this account, really?” — doesn’t fire. The account is the journalist. The journalist is credible. The post is credible.

The propaganda arrives pre-trusted.

The Credential Debt

The mechanism that made this possible is not a Bluesky failure. The platform’s systems were not breached. Individual accounts were compromised because people reuse passwords, and passwords from hundreds of previously breached platforms have been aggregated into databases that anyone who knows where to look can query.

This is the credential debt problem: every platform you have ever used, every password you have ever set, is potentially available to someone with access to breach compilations. The Marriott breach. The Adobe breach. RockYou2021. Hundreds of millions of credentials, many still valid because most people don’t rotate passwords after a breach they may not know occurred.

The dormant account is particularly vulnerable. The owner hasn’t logged in for months or years. There is no recent activity to disturb. The operation can post, the post can circulate for hours, and the owner may never notice.

Bluesky says compromised posts “averaged 50 views” before being taken down. That number describes the successful interventions — the posts platforms caught and removed. It does not describe the posts that were never identified as compromised, the accounts used without detection, or the posts that circulated long enough before anyone looked.

The Escalation Pattern

Understanding this tactic requires understanding what it replaced.

Fake persona networks were the standard for a decade. They worked: coordinated inauthentic behavior inflated apparent support for positions, manufactured social consensus, and provided amplification infrastructure. But platforms improved at detecting them. Account age analysis, behavioral modeling, network graph analysis — detection tools advanced faster than the fake account playbooks.

So the playbook changed.

Impersonation was one adaptation: creating accounts that closely mimicked real people, using AI-generated photos that resembled public figures, or stealing profile images from other platforms.

Account hijacking is the next step: skip the mimicry entirely. Use the real account. The real account has everything the operation needs — the followers, the history, the credibility, the behavioral baseline — and it is invisible to detection systems designed to identify fake accounts, because it is not a fake account.

The Matryoshka operation ran both approaches simultaneously. The Armenia election campaign used 343 AI-generated deepfake videos impersonating Pashinyan and Macron. The Bluesky campaign used hijacked real accounts to post content. One operation, two tactics — each chosen for the context it best exploits.

The 50 Views Problem

Bluesky’s safety team reported that hijacked posts averaged 50 views before removal. This was offered as evidence that the campaign’s reach was limited.

Fifty views is not zero views. The more important question is what the metric measures.

It measures the reach of the posts that were caught. It measures activity on a platform with a fraction of X’s or Facebook’s user base. It says nothing about posts on compromised accounts that weren’t flagged — whether because the account owner didn’t notice, the content was calibrated enough to avoid automated detection, or the operation was more selective in choosing targets than the caught cases suggest.

There is also a structural problem with using “views before removal” as a measure of harm. Propaganda that reaches 50 people who share it reaches more than 50 people. Propaganda that reaches a journalist, an academic, a pollster — people with existing platforms and distribution channels — potentially reaches their entire audience. One hijacked account belonging to someone with twenty thousand followers is not equivalent to a bot post with five thousand views.

The metric measures distribution. It does not measure credibility weighting. Content from a trusted source, even at fifty views, enters the information environment differently than content from an unknown account at five thousand.

What Doesn’t Work Anymore

The tools most readers use to evaluate information credibility are upstream of content analysis. They are identity-based: who is saying this? Is this account real? How long has it existed?

Those heuristics were already inadequate for detecting fake account operations that carefully aged their profiles. They are entirely inadequate for detecting hijacked real account operations, because every identity signal points to a real person.

The hijacked account passes every test a reader can easily apply:

  • Is this account real? Yes.
  • Does it have a posting history? Yes.
  • Do I know who this person is? Yes.
  • Have I trusted this account before? Yes.

The correct question — “is this post actually from this person?” — is one most readers don’t know to ask. Even if they did, there is typically no mechanism to verify it. The account says it posted the content. The content is attributed to the account’s owner. Unless the owner publicly disavows it — as Ward did — there is no external signal that something is wrong.

The SDA Record

The Social Design Agency is not new. It has run information warfare campaigns for years, with a documented focus on undermining European support for Ukraine, amplifying anti-NATO sentiment, and discrediting pro-Western leaders in post-Soviet countries.

The Armenia campaign documented in spring 2026 used AI-generated deepfake videos to spread false narratives about a secret deal between Pashinyan and Macron — 343 fabricated videos in total, producing what analysts described as one of the most extensive disinformation campaigns since Moldova’s 2025 election. Pashinyan’s party won anyway, with nearly 50% of the vote. The campaign failed to shift the outcome.

The Bluesky credential campaign required different infrastructure: databases of leaked credentials, automated login attempts, capacity to identify dormant accounts and assess their follower counts. Two different toolsets, operating under the same logic: undermine trust in institutions, credible people, and the information they produce.

The fake video of Pashinyan and Macron attacks the leaders. The compromised journalist’s account attacks the journalism. The targets differ. The goal — a public uncertain about what to believe and where — is the same.

What Changed

For years, the manipulation detection frame has centered on fake accounts: how to identify them, how to remove them, how to build detection systems that find coordinated inauthentic behavior before it scales.

That frame assumes the account is fake.

When the account is real, the frame doesn’t apply. The credential hijacking model does not require coordinating thousands of fake identities. It requires a password database and a target list. The coordinated inauthentic behavior signature — the thing platform detection systems are built to find — looks completely different when the accounts are real people who share a dormant profile with someone who knows their old password.

This is the practical implication for anyone who follows journalists, academics, or public figures online: the account you follow may, at any moment, post something that person did not write. The platform has no easy way to tell you this happened. The account owner may not know it happened. You have no mechanism to verify that the post came from the person whose name is on it.

The WSJ reporter noticed and said so publicly. His followers could update their assessment of the post. Most compromised accounts do not have a journalist at the helm who checks regularly and writes about what happened.

The propaganda from a hijacked account is not a fake persona. It is a borrowed identity — temporarily inhabited, then returned, leaving behind whatever it managed to plant while no one was watching.


This article is part of Decipon’s Manipulation Breakdowns series, examining specific influence operations through the Influence Tactics Protocol.


Sources: