Platform Collection & ArchivesNarrative DetectionNetwork IntelligenceCoordination DetectionInvestigation WorkbenchDeployment & API
Products Narrative IntelligenceExecutive IntelligenceVerifyResolve
Solutions Counter-FIMI & Information OperationsExecutive & VIP ProtectionSynthetic Media IntelligenceScam & FraudCrisis CommunicationsCritical Infrastructure
Government Counter-FIMI IntelligenceCriminal InvestigationsTrafficking & Organized CrimeSovereign Deployment
SignalsCompanyRequest a Briefing
OUTSPUN SIGNALS

Current intelligence. Every signal carries its evidence.

Follow synthetic media, influence activity and digital threats from the first observed source through distribution, consequence and analyst assessment.

PUBLIC-SOURCE INTELLIGENCE / SELECTED INCIDENTS / UPDATED AS SOURCES DEVELOP / NO CLASSIFIED OR CUSTOMER DATA

SIGNAL ID / SIG-2026-0713-SG-TKHIGH ON PATTERN; ATTRIBUTION UNRESOLVED
HIGHSingapore / MalaysiaPrimary reportingSynthetic Media

AI-generated presenters repeat Singapore and Malaysia narratives at scale

A CNA investigation found a factory-like system using synthetic, manipulated or copied presenters, reused voices and repeated scripts across TikTok accounts.

01Observed

CNA examined 30 TikTok accounts and more than 550 videos published between October 2025 and June 2026.

02Pattern

The investigation reported that 98% of the presenters were synthetic, manipulated or copied and nearly nine in ten videos pushed false or misleading claims.

03Distribution

Twenty-four accounts repeated talking points over time. Reused audio, burst posting and similar naming patterns indicated a shared production process.

04Consequence

The videos accumulated more than three million views and targeted trust, social cohesion and perceptions of regional stability.

05Assessment

The production and distribution pattern is strongly supported. CNA could not identify an operator or determine whether the activity was commercial or state-linked.

Analyst Assessment

A strong example of why media detection alone is insufficient. The consequential object is the repeated narrative, its interchangeable presenters, shared scripts and distribution system.

Unresolved

  • Operator and funding source
  • Commercial versus state-linked intent
  • Full cross-platform extent
SIGNAL ID / SIG-2026-0728-SG-YTHIGH ON OBSERVED NETWORK; ATTRIBUTION UNRESOLVED
HIGHSingapore / YouTubePrimary reportingSynthetic Media

Fake Jack Ma presenters distribute false Singapore claims across YouTube channels

CNA identified 32 YouTube channels publishing 300 videos that used an AI-generated version of Jack Ma to deliver Singapore-related claims and conspiracies.

01Observed

The investigation identified 32 channels and 300 videos published between September 2025 and June 2026.

02Pattern

The videos reused the likeness and voice of a recognized authority figure while blending accurate details with unsupported or false claims.

03Distribution

Five channels were created within five days and posted on synchronized schedules, with some uploads occurring seconds apart.

04Consequence

The videos exceeded one million views and used an authority figure to make geopolitical and infrastructure narratives appear credible.

05Assessment

Identity misuse, content similarity and synchronization support a coordinated production hypothesis. Public evidence does not establish the operator.

Analyst Assessment

This incident connects executive likeness abuse with narrative operations. Verify should detect the synthetic asset; Narrative Trace should connect variants, channels, scripts and consequence.

Unresolved

  • Who operated the channels
  • Whether one organization controlled every cluster
  • Extent of activity outside YouTube
SIGNAL ID / SIG-2025-1219-US-VOICEOFFICIAL ADVISORY
HIGHUnited StatesOfficialExecutive Threat

FBI updates warning on AI voice impersonation of senior U.S. officials

The FBI reported malicious messaging campaigns using text and AI-generated voice messages to impersonate senior officials and target professional or personal contacts.

01Observed

The FBI described activity dating back to 2023 involving impersonation of state, White House, Cabinet and congressional figures.

02Pattern

Actors used smishing and AI-generated voice messages to establish rapport with people familiar with the claimed official.

03Distribution

Targets were encouraged to move quickly to secondary encrypted messaging applications.

04Consequence

The technique creates fraud, account compromise, intelligence and personal-safety exposure around high-value individuals and their associates.

05Assessment

The official warning confirms the threat class. Individual messages still require case-specific media, identity and infrastructure analysis.

Analyst Assessment

Executive Intelligence must include associates, communication patterns and response workflows. A voice score alone cannot determine whether the surrounding contact and request are legitimate.

Unresolved

  • Campaign-specific actor attribution
  • Number of successful compromises
  • Full set of targeted organizations
SIGNAL ID / SIG-2025-1203-UK-RAILOFFICIAL CONSEQUENCE CONFIRMED
ELEVATEDLancaster, United KingdomOfficialCritical Infrastructure

AI-generated bridge-damage image triggers precautionary rail suspension

An AI-generated image appeared to show damage to Carlisle Bridge after a real earthquake. Network Rail stopped movements while staff inspected the structure.

01Observed

A public image appeared to show serious bridge damage after a magnitude 3.3 earthquake affected the region.

02Pattern

The earthquake was real, but the depicted bridge damage was not. The combination increased plausibility and urgency.

03Distribution

The image circulated online and reached rail operators as an unsolicited, unconfirmed safety report.

04Consequence

Train movements were suspended while staff used inspection, CCTV, driver reports and other tools to verify the bridge condition.

05Assessment

The operational response is officially confirmed. Public sources do not establish the image creator or intent.

Analyst Assessment

A high-value example of narrative risk becoming physical disruption without requiring broad belief. Critical-infrastructure workflows must prioritize consequence and verification speed.

Unresolved

  • Image creator and intent
  • Original distribution path
  • Whether the disruption was a deliberate objective
SIGNAL ID / SIG-2026-0615-US-CYCUISSUER-REPORTED; DETERMINATION UNRESOLVED
ELEVATEDUnited States / NASDAQIssuer-reportedMarket Integrity

Issuer reports fabricated acquisition release and alleges coordinated market activity

Cycurion stated in an SEC-filed shareholder letter that an unauthorized acquisition release was followed by abnormal trading and alleged coordinated manipulation.

01Observed

The issuer reported that a fabricated release announcing a fictitious acquisition was distributed on 16 March 2026.

02Pattern

The shareholder letter described an immediate price decline, elevated short selling and order-cancellation activity.

03Distribution

The false release entered a recognized news-distribution channel, increasing the appearance of authenticity.

04Consequence

The issuer alleged market and reputational harm and reported litigation and evidence collection.

05Assessment

The filing proves that the issuer made these statements. It is not an SEC finding that every allegation or attribution is established.

Analyst Assessment

Financial Markets Intelligence must classify the evidence owner. Issuer allegations, regulator findings, court decisions and independent analysis cannot be collapsed into one certainty score.

Unresolved

  • Final actor attribution
  • Court findings
  • Regulatory conclusions
  • Causal relationship between narrative and trading activity
SIGNAL ID / SIG-2026-0521-MY-TKREGULATORY ACTION REPORTED
ELEVATEDMalaysiaPrimary reportingPlatform Response

Malaysia orders TikTok to address fake content targeting the royal institution

Malaysia required TikTok to explain its response to false and offensive content, including AI-generated video and manipulated images linked to an impersonating account.

01Observed

The Malaysian regulator identified false, menacing and insulting content targeting the royal institution.

02Pattern

Reported media included AI-generated video, manipulated images and an account falsely claiming association with the king.

03Distribution

The material circulated on TikTok despite prior notifications and engagement described by the regulator.

04Consequence

The regulator issued a legal notice and requested stronger moderation and enforcement.

05Assessment

Regulatory action and the cited content types are supported by reporting. TikTok had not publicly commented in the AP report.

Analyst Assessment

Resolve needs a full record of notification, platform response, authority, policy basis, escalation and outcome. Removal is a third-party decision, not a detector output.

Unresolved

  • Final TikTok response
  • Removal and recurrence outcome
  • Account operator

Need a monitored intelligence stream for your people, assets or markets?

Request a Briefing