Subscribe to the Non-Human & AI Identity Journal

Disinformation

Disinformation is false or misleading content created with the intent to deceive. Unlike accidental misinformation, it is designed to manipulate beliefs or behaviour, making it a common tool in social engineering, fraud, and influence operations.

Expanded Definition

Disinformation is not simply wrong information. It is intentionally fabricated or selectively framed content designed to mislead a target audience, shape decisions, or trigger harmful action. In security contexts, the term covers messages, documents, media, and synthetic content that are crafted to look credible while supporting a deceptive objective. That makes it distinct from misinformation, which may be inaccurate without malicious intent, and from ordinary persuasion, which may be biased but not necessarily deceptive. For practitioners, the relevant question is not only whether content is false, but whether it is being used as part of a broader attack or influence campaign.

Industry usage is still evolving because disinformation now appears across phishing, business email compromise, fraud, and influence operations, as well as AI-generated content pipelines. For governance purposes, NIST guidance on access control, awareness, and system integrity in NIST SP 800-53 Rev 5 Security and Privacy Controls is often the closest operational anchor, even though it does not define disinformation as a standalone control term. The most common misapplication is treating all false content as disinformation, which occurs when teams ignore intent and fail to distinguish malicious fabrication from unintentional error.

Examples and Use Cases

Implementing disinformation controls rigorously often introduces verification overhead, requiring organisations to balance speed of communication against the cost of validation and escalation.

  • A fake invoice email uses believable vendor language and altered payment instructions to redirect funds through social engineering.
  • A deepfake voice message imitates a senior executive and creates urgency for a transfer or credential reset, a pattern that often intersects with agent-driven fraud.
  • False incident updates are seeded into internal chat channels to distract responders while an attacker maintains access or exfiltrates data.
  • Manipulated product or policy information is posted publicly to damage trust, influence customers, or amplify a coordinated narrative.
  • During election or crisis events, hostile actors use coordinated content bursts to distort public perception, making provenance checks and source validation essential.

For teams building defensive workflows, the practical value of NIST SP 800-53 Rev 5 Security and Privacy Controls lies in mapping the problem to controls for monitoring, response, and integrity rather than treating it as a pure communications issue. In modern environments, disinformation can also target identity systems by prompting users to approve fraudulent MFA requests, expose secrets, or trust counterfeit service notices.

Why It Matters for Security Teams

Disinformation matters because it converts human judgment into an attack surface. Once false narratives are believable, they can bypass technical controls by convincing people to authorize access, disclose secrets, or ignore warnings. This is especially dangerous in identity-led attacks, where the message itself becomes the delivery mechanism for credential theft, consent phishing, and fraudulent onboarding. The security impact extends beyond reputation: disinformation can create incident confusion, delay containment, and corrupt decision-making at the moment speed matters most.

Security teams should treat disinformation as a governance and resilience issue, not only a media literacy problem. That means pairing user awareness, verification steps, and source validation with logging, escalation paths, and incident communications discipline. The same applies to AI-generated content, where synthetic text, images, or voice can lower the cost of deception and increase scale. Organisations typically encounter the operational damage only after a false message has already altered behaviour, at which point disinformation becomes unavoidable to investigate and contain.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AT-1 Awareness training helps users spot deceptive content used in social engineering.
NIST SP 800-53 Rev 5 SI-4 System monitoring supports detection of malicious content and abuse patterns.
NIST AI RMF AI RMF applies when synthetic content increases deceptive scale and reach.
OWASP Agentic AI Top 10 Agentic systems can propagate deceptive instructions or synthetic impersonation.

Govern AI-generated outputs to reduce misuse, provenance loss, and deceptive amplification.