Cyabra Named Innovation Leader by Frost & Sullivan

The Bot Network Collapse That Exposed Iran’s Influence Operation

As social media conversations around Scottish independence and Brexit spiked this summer, Cyabra found that the heated discourse suspiciously synchronized. On June 13, proof of those findings emerged: For 16 days, hundreds of fake accounts went completely dark.

Cyabra’s latest investigation revealed a state-run Iranian influence campaign, exposed mid-operation, attempting to manipulate public discourse in the UK.

A Disinformation Campaign Hidden in Plain Sight

Between May and June 2025, Cyabra scanned thousands of profiles discussing Scottish independence and Brexit on X, uncovering a coordinated and inauthentic influence operation driven by fake accounts linked to Iran.

The dominant narrative promoted by these fake profiles championed Scottish independence, framing the United Kingdom as a force of oppression from which Scotland must break free. This messaging strategically tapped into themes of democratic rights, national identity, and historical grievances. A parallel narrative portrayed Brexit as a decision imposed on Scotland against its will, emphasizing the economic, social, and political fallout – particularly its disproportionate impact on Scottish communities. A third narrative accused the BBC and the Labour Party of deliberately spreading dis- and misinformation and maintaining an institutional bias against Scottish interests.

In the picture: Fake profiles spreading Scottish independence narratives

This fake campaign was remarkably sophisticated in its tactics:

  • Mimicking local slang and expressions
  • Using AI-generated profile images
  • Repeating emotionally charged slogans like “Another very good reason for #ScottishIndependence” and “Brexit betrayal”
  • Amplifying coordinated hashtags such as #ScottishIndependence, #FreeScotland, #ScottishIndependenceASAP, #BrexitBetrayal, #Brexit, #BetterTogetherLied, #BBCLies, #BoycottTheBBC, and #LabourLies,
  • Disseminating identical or near-identical posts across multiple fake accounts
  • Mutual retweeting to manufacture consensus.
  • Fake accounts engaging with each other to boost credibility.

The coordinated campaign’s success was striking: content from fake profiles generated over 224 million potential views and more than 126,000 user engagements.

In the picture: Fake profiles (red) interacted with one another, but also integrated into authentic communities and engaged with authentic profiles (green) to spread and amplify their messages.

The 16-Day Silence That Blew the Cover

On June 13, following an attack that knocked out Iran’s power grid, the coordinated bot networks abruptly went silent. All at once, the fake profiles stopped posting. For more than two weeks, they vanished – no posts, no noise, just digital silence. When power returned, the same fake network came back online, using the same personas and behaviors, but with a new mission: promoting pro-Iran messaging and mocking the West.

This coordinated blackout – followed by a synchronized return and sudden messaging shift – left little room for doubt. It was clear: this was a state-controlled operation caught mid-glitch.

The Pivot: Iran vs. the West

After the power outage, the bot network’s new objective – amplifying pro-Iranian narratives – was immediately deployed. Fake profiles portrayed Iran as a strong, moral actor standing up to the United States, emphasizing its resistance to Western hegemony and support for regional liberation movements. The narratives painted U.S. foreign policy as hypocritical, contrasting it with Iran’s supposed moral clarity and historical victimhood. Posts leaned heavily on both historical grievances and current events to legitimize Iran’s actions and accuse the West of double standards.

In the picture: Fake profiles comparing the Scottish nation with Iran, presenting Iran as a winner in this conflict.

Multiple Narratives, One Goal: Destabilize the West

Cyabra’s findings serve as a strong reminder of the role disinformation plays in shaping public opinion. This campaign marks a shift: where fake profiles were once just amplifiers of outrage – now they are the architects of the narratives. They seed division, amplify existing tensions, and hijack political discourse – and they do all of this while maintaining a credible, authentic-looking image. In this case, the minor goal was to legitimize Iran’s geopolitical stance. But the major goal in those long-game influence operations is always the same – to divide Western societies, discredit democratic institutions, and manipulate public perception by creating a distorted reality.

Download and read Cyabra’s full report

____________

Cyabra’s AI platform exposes coordinated bot activity, identifies fake profiles in real time, detects GenAI content and deepfakes, and gives democratic institutions and companies the tools to fight disinformation and counter its spread. Contact us to learn more.

Related posts

Brand Disinformation: When Bots Attack

Here’s a fact: fake profiles are expanding - not only in volume but in impact. While in the past, creating a fake profile required manual...

Rotem Baruchin

July 18, 2024

1 in 4 Profiles Are Pro-Hamas Fake Accounts: The Online Battlefront

Hamas' assault on Israel is aided by a coordinated influence operations campaign involving tens of thousands of fake profiles. In their efforts to gain worldwide...

Rotem Baruchin

October 11, 2023

How Individuals Can Identify and Protect Themselves From Fake News on Social Media

Fake news refers to fabricated information that’s spread with the intent to deceive the population. Although false stories have been disseminated throughout human history, the...

Rotem Baruchin

July 9, 2024