The Post About Minneapolis
In early February 2026, a Minneapolis ICE officer shot and killed Renée Good during an enforcement operation. Protests followed. On social media, accounts responded quickly: images from the demonstrations, captions in Spanish, messages about justice and resistance. One post read: “Resistance is our only option when Justice fails.”
The account looked like what it sounded like. A Latina activist from Texas, posting about issues that mattered to her community. She had a profile photo. She had followers who agreed with her. She had a posting history — ICE, immigration, Latin American politics, the ongoing grind of life under uncertain documentation status.
She wasn’t real.
The Pivot
Twenty-four hours after the United States and Israel launched strikes against Iran, the account changed.
The ICE protest content disappeared. In its place: anti-war protest videos from outside Trump Tower, anti-American and anti-Israeli political cartoons, footage of an American pilot accidentally shot down by Kuwaiti air defenses.
The Latina activist from Texas was now posting Iranian war propaganda. The followers who came for immigration content were now receiving IRGC messaging. They hadn’t changed who they followed. The operation had changed what they were following.
The Study
Clemson University’s Media Forensics Hub documented what happened. Their report — “From Texas to Tehran: A Multilingual, IRGC-affiliated Influence Operation on X, Instagram, and Bluesky” — identified at least 62 accounts linked to Iran’s Islamic Revolutionary Guard Corps. The operation ran across three platforms and two languages. The accounts divided into two clusters:
Cluster One: The Americas. Profiles presenting as Latina women from Texas, California, Venezuela, and Chile. Posts in Spanish about ICE enforcement, immigration politics, and anti-Trump sentiment. Profile photos were AI-generated or stolen. Bios listed American cities.
Cluster Two: The British Isles. Profiles presenting as Scottish independence supporters, Irish nationalists, and English progressives. Posts in English about devolution, Brexit’s failures, and anti-establishment politics. Same playbook, different fault line.
Both clusters operated for months before the war. When the war started, both clusters pivoted in the same 24-hour window.
What Pre-Positioning Means
There is a category distinction between influence operations that react to events and those that prepare for them.
Reactive operations move quickly when news breaks. They flood trending hashtags, inject false information into breaking coverage, exploit an existing moment before it passes. They are improvised. Their quality degrades under time pressure.
Pre-positioned operations are something else. They require an investment of time — months of activity that builds no immediate operational value. You post about ICE protests because the account needs to look real when the war starts. You engage with Scottish independence discussions because you need followers who trust you before you ask them to share Iranian propaganda.
The Clemson study’s most important finding is not that 62 accounts posted pro-IRGC content. It is that those accounts existed before there was anything to post about. The operation was running in Minneapolis before Iran was attacked.
Why These Audiences
The account clusters were not chosen at random. Each targeted a political identity that already had reasons to distrust American institutions.
Latin American progressives in Texas and California have direct experience of ICE enforcement — family separations, deportation fears, community surveillance. Anti-ICE sentiment in these communities is earned, not manufactured. An account that speaks to those experiences builds trust quickly.
Scottish independence supporters and Irish nationalists carry historical skepticism of British and American institutional power. Anti-imperial narratives map onto existing political frameworks. An account that validates those frameworks accumulates credibility without argument.
Neither audience needs to be persuaded that American foreign policy can be wrong. They already have reasons to believe that. The operation did not implant a belief. It found pre-existing beliefs, built credibility around them, and planned to redirect that credibility when the time came.
This is the operational logic: identify audiences with fault lines that align with your future messaging objectives. Build trust by speaking to their actual concerns. Activate the trust for your actual objectives. The concerns are real. The account expressing them is not.
The Follower’s Experience
Consider what a real Latina activist in Texas experienced.
She sees an account posting about the Minneapolis shooting and the protests that followed. The posts are in Spanish. The account’s profile looks like someone like her. She follows. Over weeks, the account posts things she agrees with — criticisms of ICE, solidarity with detained immigrants, pushback on anti-immigration rhetoric. She shares some posts. Her followers see them.
Then the war starts.
The account she follows begins posting about Iran. The shift is jarring but explicable: a war is happening, of course people are reacting. She keeps following. Maybe she reads the Iranian propaganda. Maybe she shares it, because she trusts the account. Maybe she forms views about the conflict partly shaped by content produced by the IRGC.
At no point did she consent to become a node in an Iranian information operation. She thought she was following a Latina activist from Texas.
What Trust Transfer Does
The mechanism here is not persuasion. It is trust transfer.
Persuasion requires making an argument. You move someone from one position to another by presenting evidence, framing, and repeated exposure. It is slow and uncertain.
Trust transfer is faster. If you trust someone on Issue A, you are more likely to listen to them on Issue B — especially during a crisis, when you are uncertain and looking for credible voices. The relationship established around ICE protests lowers resistance to Iranian war messaging. It does not eliminate critical thinking, but it reduces the friction that would otherwise prompt someone to ask: who is this account, really?
The accounts were not built to manufacture trust from nothing. They were built to borrow it. To attach themselves to existing trust relationships in specific communities, and then activate those relationships for different purposes. The trust was never meant to stay where it was built.
The Scope of the Problem
The Clemson study counted 62 accounts. That number describes what was caught and documented, not what existed. The researchers note that the accounts showed “signs of being affiliated” with the IRGC — identifying the network required documented links to known IRGC infrastructure. Networks not linked to identified IRGC accounts are, by definition, not in this count.
The number is also an operational floor. Pre-positioned networks are designed to be discovered eventually. The ones that get caught are the ones where forensic researchers found the thread to pull. The ones that operated without getting caught are, by definition, in no report.
What this study documented is one instance of a model. The model — build local identity, gain local trust, pivot to foreign objective — is not unique to Iran. Every state that runs information operations has variants of this approach. The specific accounts change. The architecture does not.
After the Removal
When platforms identify and remove influence operation accounts, the reporting focuses on the accounts: how many were removed, what platforms they used, what content they posted. This is the correct unit of analysis for platform enforcement.
It is not the correct unit of analysis for impact.
The followers who engaged with these accounts did not have their memories wiped. The woman who shared the ICE protest posts still shared them. The people who saw those shares still saw them. The views that formed during months of engagement — views the operation deliberately cultivated — persist after the account is gone.
The operation does not end at account removal. The network of real people who engaged with the fake accounts remains. Their trust was built by something that no longer exists. The beliefs that trust helped shape remain.
This is what makes pre-positioned influence operations different from acute disinformation campaigns. A fake news article that goes viral can be corrected with a follow-up. A relationship that developed over months, with an account that felt real, cannot be retroactively marked false. The follower trusted someone. That someone was never there.
The Timing Is the Tell
Post-facto analysis can detect pre-positioning by looking for accounts whose content strategy changes sharply at a geopolitical trigger — and then checking whether the pre-trigger content was qualitatively different from the post-trigger content, not just topically different.
The Latina activist accounts posted genuine-seeming content about real events: the Minneapolis shooting was real, the protests were real, ICE enforcement in those communities is real. The content was calibrated to be indistinguishable from organic activism. After the pivot, the content is clearly adversarial propaganda.
This content discontinuity — not the ideological shift, but the tonal and operational shift — is the forensic signature. Real accounts that shift focus in response to major events typically retain their voice. Operational accounts pivot their entire posture. The grammar changes. The emotional register changes. The account that posted with grief about an ICE shooting now posts with barely-concealed state-aligned talking points.
The identity does not pivot. It breaks.
Conclusion
The Clemson report’s title — “From Texas to Tehran” — describes a journey. The journey was always going to Tehran. The Texas detour was the cost of the ticket.
The followers were not the target. They were the infrastructure. Their trust in the account was the asset the operation was building. The ICE content was the investment. The war propaganda was the return.
Pre-positioning is harder to detect than active influence operations because it looks, for most of its operational life, like nothing unusual. An account that posts about ICE protests in Texas looks like an account that posts about ICE protests in Texas. You cannot distinguish it from a real Latina activist by examining the content alone. You need the network — the links to known IRGC infrastructure, the account creation patterns, the simultaneous pivot across dozens of accounts that have no visible connection to each other.
Most people do not see networks. Most people see posts.
The operation knew this. The operation prepared for this. The followers came first, before there was anything to recruit them for, because that is how you build a distribution network that no one can see until the moment you use it.
This article is part of Decipon’s Manipulation Breakdowns series, examining specific influence operations through the Influence Tactics Protocol.
Sources:
- From Texas to Tehran: A Multilingual, IRGC-affiliated Influence Operation on X, Instagram, and Bluesky — Clemson University Media Forensics Hub
- Iran shifts social media network from sowing Western discord to promoting war propaganda — The Jerusalem Post
- How Iran-linked social media accounts faked Irish and Scottish profiles to manipulate the public — Euronews
- Amid Iran war, trolls tied to Iran’s Revolutionary Guard launch propaganda campaign — Mississippi Now
- Iranian influence operation using fake personas to deceive US Instagram users disrupted, Meta says — The Record
- Inside Iran’s Information War on the US – AI, Propaganda, and Perception Management — RSIS