Executive Summary
Between June 24 and July 13, 2026, the Russian influence network known as CopyCop (Storm-1516) orchestrated a series of disinformation campaigns targeting the Firebird AI data center in Hrazdan, Armenia. These campaigns disseminated false narratives, including fabricated earthquake threats, doubts about the facility's economic viability, and claims that the data center was a legitimate military target. The reach of these narratives expanded significantly, culminating in over 1.6 million combined views by the third instance, indicating a growing audience engagement as the campaign progressed.
This incident underscores the increasing use of coordinated disinformation campaigns by state-affiliated actors to undermine strategic infrastructure projects. The targeting of a major AI initiative highlights the vulnerability of emerging technologies to such operations, emphasizing the need for robust information security measures and public awareness to counteract misinformation.
Why This Matters Now
The CopyCop disinformation campaigns against the Firebird AI data center illustrate the escalating threat of state-sponsored influence operations aimed at destabilizing critical technological advancements. As AI infrastructure becomes pivotal to national and economic security, safeguarding these assets from misinformation and propaganda is imperative to maintain public trust and operational integrity.
Attack Path Analysis
The Russian influence network CopyCop (Storm-1516) conducted a series of disinformation campaigns targeting the Firebird AI data center in Armenia. These campaigns involved fabricating imminent earthquake risks, questioning the facility's economic viability, and impersonating official Iranian military communications to justify treating the data center as a military target. The reach of these campaigns expanded significantly, indicating growing audience engagement.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
CopyCop initiated disinformation campaigns by fabricating imminent earthquake risks and questioning the facility's economic viability.
MITRE ATT&CK® Techniques
Impersonation
External Defacement
Compromise of Social Media Accounts
Acquire Infrastructure: Domains
Acquire Infrastructure: Virtual Private Server
Acquire Infrastructure: Server
Acquire Infrastructure: Web Services
Acquire Infrastructure: Botnet
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
CISA Zero Trust Maturity Model 2.0 – Identity Verification and Authentication
Control ID: Identity Pillar
DORA – ICT Risk Management Framework
Control ID: Article 5
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
PCI DSS 4.0 – Maintain a Policy That Addresses Information Security
Control ID: Requirement 12
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
AI data center infrastructure faces Russian disinformation campaigns targeting Western investments, requiring enhanced threat detection and egress security controls.
Investment Banking/Venture
Information operations targeting AI investments create market manipulation risks, demanding multicloud visibility and zero trust segmentation for portfolio protection.
Government Administration
Nation-state influence operations undermining geopolitical realignment require comprehensive threat detection capabilities and encrypted communications for diplomatic initiatives.
Defense/Space
Military targeting threats against civilian AI infrastructure necessitate robust east-west traffic security and anomaly detection for critical defense communications.
Sources
- CopyCop Targets AI Investment in Armeniahttps://www.recordedfuture.com/blog/copycop-targets-ai-investmentVerified
- Firebird and U.S. Government Announce Phase 2 of Armenia AI Megaproject, Scaling it to $4 Billion and 50,000 GPU in 2026https://www.prnewswire.com/news-releases/firebird-and-us-government-announce-phase-2-of-armenia-ai-megaproject-scaling-it-to-4-billion-and-50-000-gpu-in-2026--302683715.htmlVerified
- Armenian bank Ameriabank invests $60m in Firebird.ai’s planned 100MW data centerhttps://www.datacenterdynamics.com/en/news/armenian-bank-ameriabank-invests-60m-in-firebirdais-planned-100mw-data-center/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF is pertinent to this incident as it could likely limit the spread and impact of disinformation campaigns by enforcing strict segmentation and controlling communication paths.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The CNSF would likely constrain the initial dissemination channels, reducing the reach of fabricated information.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely limit the ability to impersonate official communications by enforcing strict identity verification.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely limit the spread of disinformation across platforms by controlling internal communication paths.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely limit the coordination of disinformation by providing oversight across multiple platforms.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit the unauthorized extraction and manipulation of information.
The overall impact of the disinformation campaigns would likely be reduced due to constrained dissemination and coordination efforts.
Impact at a Glance
Affected Business Functions
- Data Center Operations
- AI Research and Development
- Cloud Computing Services
Estimated downtime: N/A
Estimated loss: N/A
n/a
Recommended Actions
Key Takeaways & Next Steps
- • Implement robust monitoring of social media and online platforms to detect and counteract disinformation campaigns.
- • Establish partnerships with fact-checking organizations to quickly debunk false narratives.
- • Enhance public communication strategies to proactively address and dispel misinformation.
- • Develop and enforce policies for rapid response to impersonation and misuse of official communications.
- • Invest in cybersecurity awareness training for staff to recognize and report disinformation threats.



