Introduction
A propaganda flyer usually wants one thing from you: to believe something. It argues, exaggerates, cherry-picks, and occasionally lies outright, but it is always trying to change what’s in your head. In June and July 2026, a Chinese state-linked influence operation distributed flyers that didn’t do that. According to a report published by the threat-intelligence firm Graphika, the network known as Spamouflage spread manipulated versions of real event flyers — for real gatherings, organized by real human rights groups — not to convince anyone of anything, but to interfere with whether those events came off as planned.
That’s a small operational detail with a large implication. For seven years, Spamouflage has been one of the most prolific and least effective influence operations on the internet — a network Graphika itself describes as “active and prolific, but ultimately low-impact.” This year, for the first time on record, it stopped trying to win the argument and started trying to break the room instead.
What Spamouflage Actually Did
Graphika’s report, titled “Save the Date for Spamouflage,” documents a campaign run through inauthentic accounts on Facebook and X during June and July 2026. The targets were three overlapping sets of events: gatherings organized by Safeguard Defenders, a Madrid-based human rights organization, and protests convened by pro-Tibet and Uyghur civil society groups in the United States and Europe. The accounts distributed altered versions of the flyers advertising these events, paired with misleading information about them. Graphika’s own assessment is direct: the activity represented “likely attempts to hinder the proper execution of or participation in the events.”
Graphika calls this “a novel tactic for the operation” — the first documented instance of Spamouflage using manipulated event materials specifically to obstruct civil society gatherings, rather than to argue against the people organizing them. The firm also flags where this could go next: the tactic, in its assessment, “could likely be used for other attempts at transnational repression or election interference.”
That last phrase is doing real work. Transnational repression is the term researchers use for a state reaching beyond its own borders to intimidate, monitor, or silence its critics living abroad — surveillance of diaspora communities, pressure on relatives back home, and in documented cases, unofficial detention. A manipulated flyer is a strange-sounding addition to that toolkit. It’s also a logical one, once you look at who got targeted and why.
Why This Target, Specifically
Safeguard Defenders isn’t an arbitrary choice. The organization is best known for “110 Overseas,” a 2022 investigation that identified more than 100 illegal Chinese “police service stations” operating in over 50 countries — outposts run by Chinese public security bureaus, ostensibly for consular services, that researchers and multiple national governments concluded were being used to pressure and monitor Chinese nationals abroad. More than a dozen countries opened investigations after that report. Safeguard Defenders’ campaign director, Laura Harth, has been one of the more visible public voices describing how the Chinese state uses intimidation and entrapment to reach people who thought distance had made them safe.
An organization that made its name exposing a covert transnational-policing network is, unsurprisingly, a standing target for the same state’s influence apparatus. So are the pro-Tibet and Uyghur diaspora groups swept into the same campaign — communities that have been the subject of Chinese state pressure for considerably longer than Safeguard Defenders has existed. None of this needed a leaked memo to explain the motive. The targeting is the motive, stated in the choice of victims.
An Operation With a Track Record of Losing
What makes the pivot to flyer manipulation legible as a pivot — rather than just one more tactic — is Spamouflage’s own history, most of it self-defeating in a specific, measurable way.
The network, also tracked under the names Dragonbridge, Taizi Flood, and Empire Dragon, has been documented since at least 2019, when it used hijacked and fake accounts across YouTube, Twitter, and Facebook to amplify attacks on Hong Kong protesters. In April 2026, the Digital Forensic Research Lab documented a Spamouflage campaign against the Tibetan Parliament-in-Exile elections: 90 Facebook profiles and 13 Instagram accounts attacking the re-elected leader, Penpa Tsering, as corrupt and power-hungry, claiming the election itself had been rigged, and alleging that monks and the Dalai Lama controlled the exile government from behind the scenes. The accounts infiltrated genuine Tibetan Facebook discussions to inject that framing and used AI-generated imagery more polished than a comparable 2022 campaign, which had relied on more than 35 dormant accounts and cruder visuals.
DFRLab’s finding on both campaigns was the same: virtually no organic engagement. Real people did not pick up the narrative, share it, or argue about it. The accounts talked past each other and past everyone else — five years of volume, escalating production values, and approximately nothing to show for it in terms of anyone actually being persuaded.
That’s the baseline the July 2026 shift needs to be read against. If years of increasingly sophisticated argument-making produce no measurable persuasion, an operation under pressure to demonstrate results has a narrow set of options. One of them is to stop trying to change what people think and start trying to change what people can do — specifically, whether they show up to a room where the argument they weren’t winning was going to be made in person, in front of press, in front of allied governments.
The Mechanism: Coordination Sabotage, Not Belief Manipulation
This is where it’s worth being precise about what the Influence Tactics Protocol is actually built to catch, because this campaign sits slightly outside the category it usually classifies. Most manipulation this platform documents operates on the narrative layer — it wants you to believe a forged document is real, a fabricated quote was said, a staged scene actually happened. The defense against narrative-layer manipulation is verification: check the source, find the original, compare the claim to the record.
A manipulated event flyer aimed at hindering participation is doing something adjacent but distinct. It doesn’t need you to believe anything false about the world in general. It needs you to trust one piece of logistics information — a time, a location, a status update — for exactly as long as it takes for that trust to cost you the event. You don’t have to be persuaded that Safeguard Defenders is corrupt, or that the Tibetan government-in-exile is illegitimate, or that Uyghur advocacy is misguided. You just have to glance at the wrong graphic at the wrong moment. The manipulation isn’t targeting your worldview. It’s targeting your calendar.
That distinction matters for detection. A platform’s misinformation systems are tuned to catch false claims about the world — fabricated events, doctored quotes, invented statistics. A flyer that gets a detail wrong about a real, upcoming, verifiably scheduled event doesn’t necessarily read as disinformation to an automated system in the same way a fake news article does. It reads as a flyer. The manipulation lives in a layer most classification tools aren’t built to inspect: not “is this claim true,” but “does this coordination artifact match the one the organizers actually issued.”
What This Is Not
This is not a claim that Spamouflage has become effective. Graphika’s report documents a new tactic, not a new result — there’s no public evidence yet that any of the targeted events were actually disrupted, and the operation’s entire history argues for skepticism about its execution quality. It’s also not evidence of a centrally choreographed, single-order campaign in the way a leaked directive would be; attribution here rests on infrastructure and pattern — inauthentic account clusters with a documented seven-year history of serving Chinese state interests — the same evidentiary tier this platform has applied to other decentralized-looking operations with a consistent throughline.
It’s also not the same mechanism as the ridicule-based operations or platform-seam exploits this platform has covered in Russian-linked campaigns. Those run on getting real people to laugh, share, or unknowingly bridge a moderation gap. This runs on getting real people to trust a piece of paper — or a PNG — that looks like it came from an organization it didn’t. The shared thread across all of these is simpler than the mechanisms: a state actor found a spot in the information ecosystem that either audiences or moderators weren’t checking closely, and built a tactic to live there until someone named it.
Key Findings
- Spamouflage deployed manipulated event flyers in June–July 2026 to target gatherings organized by Safeguard Defenders and by pro-Tibet and pro-Uyghur civil society groups, per a Graphika report — the first documented use of this tactic by the network.
- Graphika assesses the goal as disruption of participation, not persuasion — “likely attempts to hinder the proper execution of or participation in the events,” distributed via inauthentic Facebook and X accounts.
- The target selection is legible on its own: Safeguard Defenders authored the 2022 “110 Overseas” investigation exposing illegal Chinese police outposts in 50+ countries, making it a known adversary of the same state apparatus.
- Spamouflage’s track record is one of high volume and near-zero organic engagement — documented since 2019 (Hong Kong protests) through April 2026 (Tibetan Parliament-in-Exile elections, 90 Facebook profiles + 13 Instagram accounts) — a pattern of persuasion that consistently failed to land.
- Graphika explicitly flags escalation risk: the tactic “could likely be used for other attempts at transnational repression or election interference,” beyond this specific campaign.
- The mechanism targets coordination, not belief — a meaningful category distinct from narrative-layer disinformation, and one less likely to trip detection systems built to catch false claims rather than falsified logistics.
Implications
For the Influence Tactics Protocol, this campaign is a useful edge case precisely because it resists the framework built for narrative manipulation. Scoring a piece of content on whether its claims are true, sourced, and verifiable works well against a forged quote or a fabricated statistic. It works less cleanly against a flyer whose only lie is a detail about an event that is, in every other respect, completely real. The event exists. The organizers are real. The cause is genuine. The only manipulated element is a coordination artifact designed to misdirect the people trying to attend.
That has a practical implication for anyone monitoring civil society and diaspora organizing specifically: verification needs to extend past the claim and into the logistics. An event flyer circulating on social media is exactly as spoofable as a quote or a screenshot, and considerably less likely to be checked, because nobody fact-checks a time and address the way they fact-check a claim about the world. Organizations operating in this space — human rights groups, diaspora advocacy networks, anti-authoritarian civil society — may need to treat their own event logistics as a manipulation surface, publishing flyers through channels that are harder to spoof and treating unofficial copies with the same suspicion normally reserved for unverified quotes.
For readers further from this specific fight, the broader lesson generalizes past China and past this campaign. An influence operation that has spent years failing to win an argument doesn’t necessarily give up. It looks for a layer of the system nobody’s defending, because nobody thought to. Belief isn’t the only thing worth manipulating. Attendance, participation, and coordination are just as valuable to sabotage — and a good deal easier to fake, because almost nobody is checking.
Conclusion
Spamouflage spent five years arguing badly and losing consistently — its own documented record, campaign after campaign, is volume without persuasion. In the summer of 2026, it stopped arguing. The flyers it manipulated this time weren’t trying to change anyone’s mind about Safeguard Defenders, Tibet, or Xinjiang. They were trying to make sure fewer people showed up to say those names out loud in public, on the record, in front of people who might act on it. That’s not a more convincing version of the same operation. It’s a different operation wearing the same name — one that gave up on the argument it kept losing and went after the room instead.
This article is part of Decipon’s Manipulation Breakdowns series, examining specific influence operations through the Influence Tactics Protocol.
Sources:
- Save the Date for Spamouflage — Graphika
- China-linked Spamouflage targets Tibetan parliament-in-exile elections — DFRLab
- Spamouflage — Graphika
- 14 governments launch investigations into Chinese 110 overseas police service stations — Safeguard Defenders
- Cyber Based Influence Campaigns Report: Insights from 13th-19th July 2026 — Cyfluence Research