Interference targets minds and machines, rarely the tally
"Foreign interference" sounds like a single dark act — a switch flipped somewhere to change who wins. The documented reality is more mundane and more useful to understand: interference is a small toolkit, used over and over, that mostly works on the environment around a vote rather than the count inside it.
The reason is structural. As how votes are counted shows, the tally is defended in depth — by paper records, chain of custody, reconciliation, and audits — so changing it undetectably from outside is extraordinarily hard. What is far easier to reach is everything around the vote: what people read, whom they trust, and what dominates the last news cycle before they decide. That is where interference concentrates its effort.
The toolkit
Almost every documented operation is a combination of five techniques:
| Technique | What it does | Documented example |
|---|---|---|
| Cyber intrusion | Break into election, party, or campaign systems | Probing of U.S. state voter systems, 2016 |
| Hack-and-leak | Steal private material and release it for effect | DNC/Podesta emails (2016); MacronLeaks (2017) |
| Information operations | Coordinated inauthentic content to shape opinion | Internet Research Agency troll farm (2016) |
| Impersonation / forgery | Spoof real outlets and institutions | Ghostwriter; Doppelganger cloned news sites |
| Covert finance | Move money secretly to favoured actors | Alleged across multiple European contests |
Cyber intrusion and hack-and-leak
The two cyber techniques usually work together. First, intrusion: attackers get into email or document systems belonging to a party, campaign, or election body. Then, hack-and-leak: the stolen material is released — often selectively, and timed for maximum damage.
The 2016 U.S. presidential election is the reference case. U.S. intelligence assessed that Russian military intelligence (the GRU) hacked Democratic Party systems and released the material through intermediaries, while separately probing state voter-registration systems. Crucially, the same assessment found the systems that actually tally votes were not altered — the intrusion reached the environment, not the count.
France, 2017 shows the same playbook against a different target: the eventual winner's campaign was hacked and a large cache of emails dumped online barely a day before the vote, inside the legal reporting blackout. The timing was the weapon. But French media and voters largely declined to amplify it, and the leak landed with little effect — a reminder that these operations depend on a receptive audience they do not always get.
Information operations and impersonation
If hack-and-leak supplies ammunition, information operations supply the crowd. The clearest example is the Internet Research Agency, a St Petersburg "troll farm" that ran large-scale inauthentic social-media activity impersonating American voters and groups — later detailed in a U.S. criminal indictment naming the organisation and its financiers.
The frontier since then has been impersonation: making foreign content look like trusted local sources. Two operations catalogued in this database show the range. Ghostwriter fabricated content and planted it via compromised sites and spoofed identities, targeting audiences across Poland, the Baltics, and Germany. Doppelganger went further, cloning the actual domains and layouts of real Western news outlets to publish fake articles under a borrowed masthead. Both are examples of coordinated inauthentic behaviour — the tell is not the content of any single post but the hidden coordination behind many of them.
What interference can and cannot do
Holding the toolkit in view makes the limits clear:
- It can flood the last news cycle, launder a narrative into trusted-looking outlets, steal and time-release embarrassing material, and deepen existing divisions.
- It struggles to change a properly run count, because the tally is protected by layers that an outside actor cannot easily reach or hide within.
This is why lumping interference together with a falsified count — the mistake the five meanings of "fraud" warns about — gets the threat exactly wrong. Treating a genuine influence operation as proof the count was faked both overstates one problem and distracts from the other.
How interference is attributed
Naming the state behind an operation is its own discipline. Investigators combine technical forensics — shared infrastructure, malware, language and timing patterns — with intelligence reporting and, in the strongest cases, criminal indictments that name specific officers. International bodies such as the EU's diplomatic service now publish structured threat reports under the label FIMI (foreign information manipulation and interference).
The result is always a graded judgement, not a binary. A careful record states the confidence level — from tentative technical overlap up to a formal indictment — rather than asserting a certainty the evidence does not support, exactly as the interference-is-not-fraud framework insists.
Reading an interference claim
When you meet a claim that a foreign power "interfered," turn it into specific questions:
- Which technique is alleged — intrusion, leak, information operation, forgery, finance?
- What did it target — the count, or the environment around it?
- Who attributed it, and at what confidence — a named agency, an indictment, a platform report, or an anonymous assertion?
- What effect is actually claimed — that minds were influenced, or that votes were changed?
Answer those, and a vague fear of "meddling" resolves into something you can weigh — which is the only way to take real interference seriously without being manipulated by the fear of it.