Skip to main content
Election Security9 min read

Iran, Bots and Disinformation: How Foreign Influence Can Target an Israeli Election

A foreign influence operation does not need to touch a ballot box. What Israeli official sources actually say about Iran, bots and AI, and the verification habits that break the amplification chain.

#Foreign Influence#Iran#Disinformation#Bots#Elections 2026

Most people picture election interference as someone changing votes. It is the most alarming version of the story, and for an Israeli general election also among the least likely, because ordinary polling stations run on paper slips counted by hand. An actor who wants to damage an election need not solve that problem at all. It can aim at something softer and far more reachable: what voters believe is happening around them.

In July 2026 the State Comptroller published a special report on Israel's national response to foreign influence in the digital space. Its headline finding was blunt: national readiness is materially deficient. The report warns that an election period is especially sensitive, that the potential damage from foreign influence attempts intensifies during it, and that such attempts can shift the public agenda and undermine confidence in the result. That assessment belongs to the Comptroller rather than to NetFortress. It is quoted here because it sets the frame for everything below.

This is the second article in our election security series. The first part maps what a cyberattack around an Israeli election can realistically reach. This one covers the other half, where nothing is breached at all and the target is attention rather than infrastructure.

Three different things people call election interference

  1. Cyber intrusion: someone compromises an account, device, website or system. This is a technical event with a technical fix, and it either happened or it did not.
  2. Information operation: someone creates or amplifies a narrative, a false claim or a fake identity. Nothing has to be breached, and most of it happens in the open, on public platforms.
  3. Influence outcome: attention moves, confidence rises or falls, people behave differently. The hardest of the three to measure, and the easiest to assert without evidence.

The three are often combined and routinely collapsed into one word. They are not synonyms. A stolen mailbox is not proof of an influence campaign, an aggressive online argument is not proof of a foreign operation, and neither tells you a single voter changed their mind.

What a foreign influence operation actually tries to achieve

The realistic objectives are more modest, and more achievable, than deciding an election.

  1. Deepen a division that already exists rather than invent one. The Comptroller's report notes that hostile actors identified polarisation in Israeli society as an opportunity.
  2. Amplify fear or distrust at a moment when people are already anxious.
  3. Damage confidence in institutions, so that an official announcement carries less weight than a rumour.
  4. Confuse or suppress participation through false logistical or security information.
  5. Embarrass a campaign, or force it to spend critical hours disproving something fabricated.
  6. Create pressure through leaked or stolen material.
  7. Make the information environment so noisy that accurate information stops feeling reliable.

None of that requires persuading a majority. A tactical win can be as small as a false claim looking popular for six hours on the day it matters. This article does not claim any particular party, candidate or bloc is being targeted in 2026: no official source reviewed here says so.

A six-stage influence chain

Official reporting and published research describe a recognisable sequence. Several of its stages are visible from the outside once you know what you are looking at.

  1. Reconnaissance and audience mapping: which communities exist, what vocabulary they use, which tensions are already live. Nothing is faked yet.
  2. Persona creation: fake identities, copied or generated profile photographs, invented biographies, accounts built to look unconnected. The Comptroller's report describes hostile actors spreading messages while posing as a local voice, so the audience never learns the source is foreign.
  3. Content creation: misleading posts, forged screenshots, generated images or audio, or real material edited until its meaning changes.
  4. Seeding: placing the claim somewhere small first, such as a group chat, a channel or an obscure website, so it acquires a plausible origin story.
  5. Amplification and laundering: coordinated or automated accounts make a claim look like organic interest, and it travels from the fringe toward influencers, journalists and ordinary conversation. By then the original source is gone.
  6. Exploitation of a real event: attaching a false claim to a genuine incident, outage or breaking-news moment, when everyone is watching and nobody can verify quickly.

This is deliberately a map rather than a manual: the operational detail is left out.

Why Iran is part of the 2026 discussion

Two Israeli official publications carry the concrete claims here, and it is worth being precise about each.

The State Comptroller's July 2026 special report states that since the start of the war, Iran and other hostile states and actors increased their efforts to influence public opinion in Israel and abroad, using broad networks of bots and fake profiles to spread content intended to raise public anxiety and deepen division in Israeli society. It gives a documented example: in September 2024, Iran and Hezbollah sent roughly five million SMS messages to Israeli citizens carrying a false emergency instruction to enter a protected space, in order to provoke panic. The same report records that 58 percent of Israelis regularly follow the news through social networks, which is much of why such a message travels.

Separately, Shin Bet and the National Cyber Directorate reported hundreds of cyber attempts against Israeli public figures over the preceding year, including attempts attributed to Iranian intelligence actors to break into email and messaging accounts through targeted phishing. That is where the two halves of this article meet. A journalist's mailbox is not election infrastructure, and compromising one changes no votes. It does supply an influence operation with authentic material, a trusted voice, or both.

The limits of these sources deserve as much attention as their content. They attribute specific, documented activity to named actors. They do not license anyone to call every anonymous account, unwelcome argument or false political post Iranian.

Bots are useful, but a bot is not a foreign agent

At least four different things get called bots, and the differences matter.

  1. Automated accounts that post or repost on a schedule, with no person behind each message.
  2. Coordinated human accounts, run by real people working to a shared brief.
  3. Fake personas, which may be driven by a person, by software, or by both in turn.
  4. Genuine users who believe a false claim and pass it on. They belong to no operation, and usually do most of the work.

The Comptroller's report is unusually candid about how hard attribution is. Influence attempts happen in the open civilian space of social networks, where Israeli and foreign participants mix freely, and it is genuinely hard to trace who published something or to tell a hostile foreign actor from ordinary local discourse. Posting volume is not evidence. A new account is not evidence. An opinion you find offensive is not evidence. When a national audit body calls attribution hard for the state, it is not something a reader settles from a profile page.

AI changes cost and scale more than motive

The Comptroller's report sets out what generative tools change. A hostile actor can produce credible, audience-tailored text, images and video at volume, for little money, in a short time; get past language and cultural barriers; and create many fictitious identities that echo the same messages consistently, which both strengthens their apparent authenticity and makes exposing them harder.

That is a change in economics, not in intent. The motive long predates the tools, and cheaper content is no guarantee of success: it still has to reach people, be believed, arrive when it matters and land on a division that already exists. Treating AI as automatically decisive gives an adversary credit it has not yet earned.

Hack and leak: when real and fake material mix

A hack and leak follows a recognisable pattern. An account or mailbox is compromised, usually through ordinary phishing or business email compromise rather than anything exotic. Authentic documents are then released selectively, at a chosen moment and inside a chosen frame. Selection and timing do most of the work: real material stripped of its context can mislead more effectively than an invention, and forged items can in principle be mixed in among genuine ones, which makes any single document harder to check.

The useful instinct is to ask what a leak leaves out, and to notice material timed too conveniently to examine properly.

The most dangerous message may look ordinary

Influence content that works rarely looks like propaganda. It looks like something a neighbour forwarded. The examples below are hypothetical rather than confirmed incidents, with one noted exception.

  1. A forwarded message saying a polling location has moved.
  2. An emergency alert that came from no official system. The September 2024 SMS episode above is the documented version of this one.
  3. A screenshot presented as a headline from a trusted news outlet that never published it.
  4. A voice note attributed to a public figure.
  5. A post from a local-sounding account whose history, on inspection, is not there.

How to avoid becoming part of the amplification chain

Amplification is where ordinary people are genuinely involved, and the only stage a reader can personally interrupt. None of the advice below depends on your politics.

  1. Go to the original source, not a screenshot of it. A screenshot is a claim about a source, not the source.
  2. Check whether the institution named has published the notice on its own channel. For polling locations, hours or procedures, that means the Central Elections Committee's own voter information, not a forwarded image.
  3. Cross-check urgent claims against more than one reputable outlet before treating them as fact.
  4. Slow down when something makes you angry or frightened. That reaction is the delivery mechanism, and a few minutes removes most of its value.
  5. Treat follower counts, likes and reply volume as weak evidence of authenticity: they are the easiest part to manufacture.
  6. Report impersonation and suspicious cyber activity through the platform and the relevant official channels. The Comptroller's report notes that Israel has no single official body the public can approach about suspected foreign influence, which is one of the gaps it raises.

What businesses should learn from election influence operations

None of this is only an election problem. These techniques are already used against Israeli businesses every week, pointed at a different target.

  1. Impersonation works on companies for the same reason it works on voters: people trust a familiar name faster than they check it.
  2. A compromised executive account is a reputational problem as well as a security one: it hands an attacker a trusted voice inside your relationships.
  3. Suppliers, customers and employees amplify whatever looks legitimate, with no intent to do harm.
  4. Awareness training that stops at do not click links teaches nothing about verification, the skill that breaks the chain.

The practical response is unglamorous and the same on both sides of this article: phishing-resistant multi-factor authentication on the accounts that carry authority, security awareness training that teaches people how to verify a request rather than only how to fear one, and managed cybersecurity that keeps identity, email and endpoint controls working rather than documented.

NetFortress helps Israeli SMBs put those controls in place. No provider can make anyone immune to a convincing lie, and nobody should promise otherwise. What is achievable is accounts that are harder to take over and people who are harder to rush.

Frequently asked questions

What is foreign influence in an election?

Foreign influence is a coordinated attempt by a foreign actor to shape public opinion or behaviour in another country while concealing its own involvement. Israel's State Comptroller describes it as illegitimate action by a foreign party intended to harm the state's interests in a hidden way, typically by spreading messages while posing as a local voice, so the audience never learns the source is foreign. Around an election the aim is usually to move attention, deepen an existing division or damage confidence in institutions, rather than to alter the count itself.

Does foreign election interference always involve hacking voting systems?

No. An influence operation can work entirely in public, on social networks and messaging apps, without compromising a single system. Cyber intrusion and information operations are separate things that are sometimes combined: a hacked mailbox can supply authentic material or a trusted voice for an influence campaign, but most influence content is simply posted, forwarded and amplified in the open. Treating the two as one word is how people end up asserting far more than the evidence supports.

How can bots affect political discussion online?

Automated and coordinated accounts mainly manufacture the appearance of consensus. Volume makes a claim look popular, apparent popularity makes it look credible, and credibility earns it attention from real people and occasionally from journalists. Israel's State Comptroller reported that broad networks of bots and fake profiles were used to spread content intended to raise public anxiety and deepen division in Israeli society. Bots rarely persuade anyone directly. They change what looks worth paying attention to.

How can I tell whether a political account is a foreign influence account?

Usually you cannot, and it is worth being honest about that. Israel's State Comptroller describes attribution as a genuine difficulty even for the state, because influence attempts take place in the open civilian areas of social networks where Israeli and foreign participants mix, and tracing who actually published something is hard. Posting volume, a recently created account, imperfect Hebrew or an opinion you dislike are not evidence of foreign coordination. The practical response is to verify the claim rather than to diagnose the account, and to report suspected impersonation to the platform instead of accusing people publicly.

What should I do before sharing urgent election information?

Find the original source rather than a screenshot of it, and check whether the institution named has published the same notice on its own official channel. Cross-check urgent claims against more than one reputable outlet. If a message is built to make you act immediately, that urgency is the technique, so waiting a few minutes costs you almost nothing and removes most of its value. Anything about polling locations, hours or procedures should come from the Central Elections Committee rather than from a forwarded image.

Ready to secure your business without building an internal IT team?

Book a free consultation and get a practical first look at your IT and Microsoft 365 security posture.