AIPolicyTracker

AI incident ·

Iranian Hacker Group Cotton Sandstorm Reportedly Integrating AI into Cyber Influence Operations

13 news reports Snapshot 7 Sep 2026

In brief

An AI system built by Islamic Revolutionary Guard Corps (Irgc), Government Of Iran and 2 others and deployed by Islamic Revolutionary Guard Corps (Irgc), Government Of Iran and 1 other allegedly harmed Political Candidates, Media Organizations and 3 others.

Risk domain
Malicious Actors & Misuse Disinformation, surveillance, and influence at scale
Occurred
Coverage
13 reportsMay 2023 - Dec 2024

What happened

The Iranian state-sponsored group Cotton Sandstorm, linked to the IRGC, has integrated generative AI into cyber influence operations. In December 2023, it launched Operation “For Humanity," using AI-crafted messaging to hijack a U.S.-based IPTV streaming service with propaganda about the Israel-Hamas conflict. The group also engages in election-related reconnaissance, which suggests they used AI-enhanced influence efforts ahead of the 2024 U.S. election.

Laws that address this harm

Policy angle: Classified under Malicious Actors & Misuse (Disinformation, surveillance, and influence at scale) in the MIT AI Risk Repository taxonomy; 5 recorded instruments address this use case.

Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).

News reports (13)

Titles link to the original publisher; report text is not reproduced here.

  1. Report: Iran Accelerates Cyberattacks
    iranprimer.usip.org · United States Institute of Peace

Who was involved

Alleged harmed party
Political Candidates, Media Organizations, General Public Of The United States, American Voters, Democratic Integrity

Classification (MIT AI Risk Repository taxonomy)

Causal entity
Human
Intent
Intentional
Timing
Pre-deployment
Harm level
—
Sectors
—
Countries
—

Risk entries describing this failure mode

Entries from the MIT AI Risk Repository coded to subdomain 4.1.

  • Political manipulation

    "Political manipulation - Use or misuse of personal data to target individuals’ interests, personalities and vulnerabilities with tailored political messages via micro-advertising or deepfakes/synthetic media."

    A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms (Abercrombie2024)

  • Coercion/manipulation

    "Coercion/manipulation - Use of a technology system to covertly alter user beliefs and behaviour using nudging, dark patterns and/or other opaque techniques, resulting in potential erosion of privacy, addiction, anxiety/...

    A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms (Abercrombie2024)

  • Political and Economic

    "Political and Economic - Manipulation of political beliefs, damage to political institutions and the effective delivery of government services."

    A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms (Abercrombie2024)

  • Electoral interference

    "Electoral interference - Generation of false or misleading information that can interrupt or mislead voters and/or undermine trust in electoral processes."

    A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms (Abercrombie2024)

  • Political

    "In the UK, a form of initial computational propaganda has already happened during the Brexit referendum1 . In future, there are concerns that oppressive governments could use AI to shape citizens’ opinions"

    The Rise of Artificial Intelligence - Future Outlooks and Emerging Risks (Allianz2018)

  • Biased influence through citizen screening and tailored propaganda

    "AI-powered chatbots tailor their communication approach to influence individual users' decisions. In the UK, a form of initial computational propaganda has already happened during the Brexit referendum. In future, there...

    The Rise of Artificial Intelligence - Future Outlooks and Emerging Risks (Allianz2018)

  • Surveillance and Censorship

    "Content moderation has emerged as one of the key use-cases of LLMs (Weng et al., 2023), indicating the potential of LLMs for surveillance and censorship as well (Edwards, 2023). Surveillance and censorship are one of th...

    Foundational Challenges in Assuring Alignment and Safety of Large Language Models (Anwar2024)

  • Disinformation and manipulation of public opinion

    "AI, particularly general- purpose AI, can be maliciously used for disinformation (351), which for the purpose of this report refers to false information that was generated or spread with the deliberate intent to mislead...

    International Scientific Report on the Safety of Advanced AI (Bengio2024)

Incidents in the same risk subdomain

All incidents in this subdomain

Source record: incident #971 on the AI Incident Database · all 13 reports