The concern in Rome is shifting from traditional cyberattacks to a broader hybrid threat: deepfakes, cloned news websites, manipulated videos and coordinated influence campaigns designed to exploit political divisions and undermine trust in institutions.
Why it matters: Italy has already been exposed to fabricated political content, while European cases suggest that AI is expanding the toolkit available for foreign interference.
- Fake videos targeting Prime Minister Giorgia Meloni have circulated online, including manipulated footage involving Ukrainian President Volodymyr Zelensky.
- Another fabricated video depicted the prime minister praising a Russian commander.
- Similar techniques have appeared elsewhere in Europe, combining cloned media sites, synthetic content and coordinated distribution.
- Italian authorities are treating cyber and information operations as an increasingly important part of Russia’s broader hybrid strategy.
The big picture: The playbook is not entirely new. Russian-linked influence operations were already visible around Italy’s 2018 general election, when narratives favorable to Moscow circulated through parts of the Italian information ecosystem.
- What has changed is the technology. Artificial intelligence can now generate convincing audio and video at scale, while fake websites can imitate established media brands. That lowers the cost of producing material intended to look credible — and increases the volume that authorities, platforms and news organizations have to monitor.
Germany offers a recent European example. During its federal election, an information operation known as “Doppelgänger” involved fake websites designed to resemble established outlets including Der Spiegel, alongside fabricated stories and AI-generated material.
Zoom in: Rome. Italy has already seen politically sensitive deepfakes.
- A manipulated video involving Meloni and Zelensky circulated online, while another showed the Italian prime minister apparently praising Russian commander Robertus Vannacci. Both were false.
- The concern is that similar material could become part of a much larger information campaign as Italy moves toward its next national vote.
- The threat is not limited to fabricated statements by politicians. AI-generated “news” can also imitate legitimate reporting, allowing false stories to spread through an information environment in which the original source may be difficult for users to identify.
The Russian toolkit. Italy’s National Cybersecurity Agency (ACN) raised the alarm in July over activity linked to Russia’s foreign intelligence service, the SVR.
- The warning focused on the legacy of the FSB-linked “Berserk Bear” group and sectors considered particularly exposed: communications, the defense industrial base, energy, financial services, IT services, healthcare and public health.
- The broader ecosystem includes a series of Russian-linked cyber espionage groups identified in the material, including Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly, Ghost Blizzard, Static Tundra and others.
By the numbers: Italy’s cyber threat is already operating at significant scale.
- The National Cybersecurity Agency registered 2,171 attacks in the first six months of 2026 , while the Cyber Crime Observatory puts the amount of data exposed on the dark web at2.5 billion records .
- Those figures cover a wider cyber landscape than election interference alone, but they illustrate the environment in which political influence operations could unfold.
What we’re monitoring: The key question is how cyberattacks and information manipulation converge.
- AI adds a new layer to an established strategy: not simply hacking institutions or stealing information, but producing synthetic material that can circulate rapidly through the political debate.
- For Italy, that means the next election-security challenge may play out as much on voters’ screens as inside government networks.