CBRNE and Disinformation (CBRNED) 

Published:

By: Julian H. Neylan and Timothy B. Erickson 

Accurate, timely information is the backbone of any chemical, biological, radiological, nuclear or explosive (CBRNE) response. This is why disruptions to the accuracy of information can be devastating whether intentionally done or otherwise. Manipulation of the information environment can happen at any stage of the response to a CBRNE incident. Disinformation planted before a CBRNE incident can erode trust in responders before anyone has been exposed or injured.  False claims during a response can misdirect resources and delay evacuation.  Post-incident narratives can shield perpetrators and block accountability for CBRNE attacks. Most preparedness guides still treat disinformation as a comms problem, something to address with fact sheets and rumor-control hotlines. However, this is no longer adequate especially as technology used in influence operations develops. 

The public’s reliance on social media for real-time information during emergencies has been clear at least since the 2013 Boston Marathon bombing, where Twitter was many people’s primary news source (Tran et al., 2020). The same dynamic plays out in conflicts, public health crises, natural disasters, and industrial accidents. When Hurricane Helene hit the US Atlantic Coast, false rumors about FEMA including calls for armed militias to confront agency workers, which forced teams to pull back from affected areas (The Guardian, 2024; InfoEpi Lab, 2024). While this was not a CBRNE incident, but the lesson transfers directly. 

The standard playbook for spreading false information in an emergency involves flooding the zone with inauthentic accounts spreading false content. Five hundred accounts pushing the same claim do not necessarily reach more people, but they make the claim look like settled consensus. After the Salisbury UK Novichok attack in 2018, Whitehall tracked a 4,000% spike in suspected Russian bots and automated accounts amplifying disinformation (de Mos, E., 2025). In 2023, a freight train carrying highly toxic chemicals derailed in Ohio.  In the aftermath, pro-Russian accounts spreading conspiracy theories about the US government covering up information about the train were released. (Klepper, 2023). 

We have also seen CBRNE accusations as a key part of hybrid warfare tactics. Russia used claims that Ukraine was going to use chemical weapons in the Donbas region as a pretext to its invasion of Ukraine (EUvsDisinfo, 2024). Other Russian disinformation was that Ukraine was hosting US biolabs (Parachini, 2022) or trying to create radioactive bombs (EUvsDisinfo, 2024). These types of CBRNE related narratives can readily generate fear in the target audience and be used to justify offensive actions. 

Agentic artificial intelligence (AI) makes these disinformation threats cheaper and faster. These AI systems that can pursue a goal across dozens of steps without human direction. If the goal is running a disinformation campaign this can become a problem. The workflow includes various steps such as generate AI content, post it, create new accounts when old ones get banned, and adapt messaging based on what disinformation is getting traction. The commercial guardrails on these tools get malfunction regularly (Akheel, 2025), and open-source versions can be run locally on private hardware with little oversight. 

Similarly, sophisticated attacks such as website impersonation are becoming easier to do with AI. Actors can simply copy the HTML code of a target website; clone it, and they have a credible looking fake version of any authoritative source online. From there, they can easily tweak the text content of the website; as seen in prior information manipulation (Lim et al., 2019; VIGINUM, 2023). Present day emergency responders are not prepared for the degree and sophistication of these modern-day attackers. The need for preparedness goes well beyond rumor control. Instead, CBRNe experts and responders need to understand the various attack vectors and how to prepare both themselves and the public. 

Disinformation also makes it more challenging to establish what actually happened after an incident. CBRNE events often occur in places where timely and proper on-site testing is not possible such as with insecure locations or those in active conflict. This is where open-source investigation has stepped in. For example, Bellingcat’s work on chemical weapons use in Syria showed that digital evidence can establish facts about on the ground reality (Higgins, 2020). However, that kind of intervention becomes much harder when the information environment has been deliberately muddied. When every piece of digital evidence must be treated as potentially fabricated, investigations are delayed and conclusions become easier to dispute. 

AI-generated images, audio, and video have become so convincing that detection by humans or software is an increasingly unreliable strategy (Köbis et al., 2021; Ahmed et al., 2024). A more practical approach is verifying where content came from rather than trying to determine whether it looks real. Provenance is the process of tracing the origin and chain of custody of a piece of media. Standards like C2PA (Coalition for Content Provenance and Authenticity) are attempting to build this chain of custody to analyze how media gets created and shared, but uptake is still limited. While other initiatives like the Saufex project are trying to build community level approaches to build resilience against these types of attacks. 

How Should We Respond? 

For CBRNE communication professionals, the first shift is cerebral. The threat is more than the existence of disinformation; it is the adversarial nature of it. Attackers study the response playbooks. Fact-checking sites should compete with fake fact-checking sites that are created by adversaries. Official channels can be cloned and impersonated. Rumor-control efforts are anticipated and subverted before they are launched.  CBRNe practitioners need to think not only about their response, but about the response to their response (EUvsDisinfo, 2025; IFRC, 2025). 

The evidence on what works best suggests using a prebunking process rather than just debunking. Trying to correct false claims after they have spread is an uphill battle as people who already accepted a narrative are often resistant to correction, and retractions often have lower visibility than the original claim. Warning people in advance through prebunking describing how disinformation campaigns operate is more effective. If your audience already knows what coordinated inauthentic behavior looks like, they’re more likely to recognize it when it appears. Prebunking needs to happen before the incident, not during it. 

The problem central to all this disinformation matrix is trust. To be believed, you must be trusted. You cannot build credibility with a community while a crisis is unfolding. If people do not already have a reason to believe official sources, no amount of accurate information will cut through the noise. CBRNE practitioners need pre-existing relationships with local health authorities, community organizations, and leaders who already has standing with the populations they serve. They also need contacts inside the major platforms, because responding to harmful influence campaigns requires a relationship that exists before you need it. 

On the technical side, the reality is that deepfake detection is losing the race against disinformation generation. Understanding provenance tools matters more than knowing what C2PA-compliant media looks like and building authenticated channels whose integrity can be verified independently of their content. CBRNED experts also need to be in the room where policy on these technologies gets made. Agentic AI and synthetic media are moving faster than any regulatory framework, and the experts who understand how these tools can impact emergency response need to be included in the conversation of how these tools are developed. 

Table 1: Key Terms: 

Disinformation: Information that is false and deliberately created to harm a person, social group, organization or country. 

Misinformation: Information that is false, but not created with the intention of causing harm 

Deepfakes: A form of artificial intelligence used to create hyper-realistic, yet entirely fabricated, images, audio, or video 

Prebunking: A preventative strategy that equips people to recognize and resist false information and manipulative narratives before they encounter them. Also known as ” inoculation” it works like a psychological vaccine, by exposing audiences to a weakened dose of misinformation individuals build mental resilience to future manipulation. 

Automated accounts: Also called bots, these are computer algorithm-controlled entities that perform programmed actions and interact with systems (in this context mostly social media platforms) on the users’ behalf.  

References 

Ahmed, N. U. R., Badshah, A., Adeel, H., Tajammul, A., Daud, A., & Alsahfi, T. (2024). Visual deepfake detection: Review of techniques, tools, limitations, and future prospects. IEEE Access. https://doi.org/10.1109/ACCESS.2024.3523288 

Akheel, S. A. (2025). Guardrails for large language models: A review of techniques and challenges. Journal of Artificial Intelligence, Machine Learning and Data Science, 3(1), 2504–2512. https://doi.org/10.51219/JAIMLD/syed-arham-akheel/536 

de Mos, E. (2025). The impact of mis- and disinformation during CBRN incidents: Deep dive into past case studies (Ed. P. Skácelová). JCBRN Defence COE. https://www.jcbrncoe.org/app/uploads/2025/06/The-Impact-of-Mis-and-Disinformation-During-CBRN-Incidents-final_978-80-908964-9-9.pdf 

Edward Helmore (2024, October 14). North Carolina: Hurricane Helene, FEMA and the armed militia threat. The Guardian.  https://www.theguardian.com/us-news/2024/oct/14/north-carolina-hurricane-helene-fema-armed-militia-threat 

EUvsDisinfo. (2024, December 18) 1 000 and 4 000 days of Russia’s CBRN disinformation: sowing fear, undermining accountability. https://euvsdisinfo.eu/1-000-and-4-000-days-of-russias-cbrn-disinformation-sowing-fear-undermining-accountability 

EUvsDisinfo. (2025, January 6). Disinformation is not potatoes. https://euvsdisinfo.eu/disinformation-is-not-potatoes/ 

Higgins, E. (2020, April 21). The open-source hunt for Syria’s favourite Sarin bomb. Bellingcat. https://www.bellingcat.com/news/2020/04/21/the-open-source-hunt-for-syrias-favourite-sarin-bomb/ 

IFRC Community Engagement Hub. (2025, July). Managing misinformation, disinformation, and rumours in CBRN situations: Guidance for national societies and IFRC field staff. International Federation of Red Cross and Red Crescent Societies. https://communityengagementhub.org/wp-content/uploads/sites/2/2025/08/Tool-1-CBRN-Misinformation-Management.pdf 

InfoEpi Lab. (2024, October 7). How militia groups exploit disasters. https://infoepi.org/posts/2024/10/07-militia-groups-exploit-disaster-helene-milton-hurricane-fema.html 

Klepper, D. (2023, March 18). Pro-Moscow voices tried to steer Ohio train disaster debate. Associated Press. https://apnews.com/article/ohio-train-derailment-russia-disinformation-twitter-musk-49af27699727d6f4157a5d6d5f35819b 

Köbis, N. C., Doležalová, B., & Soraperra, I. (2021). Fooled twice: People cannot detect deepfakes but think they can. iScience, 24(11), 103364. https://doi.org/10.1016/j.isci.2021.103364 

Lim, G., Maynier, E., Scott-Railton, J., Fittarelli, A., Moran, N., & Deibert, R. (2019, May 14). Burned after reading: Endless Mayfly’s ephemeral disinformation campaign (Citizen Lab Research Report No. 118). University of Toronto. https://citizenlab.ca/research/burned-after-reading-endless-mayflys-ephemeral-disinformation-campaign/ 

Parachini, J. V. (2022). Debunking Russian Lies about Biolabs at Upcoming UN Meetings. RAND Corporation, 12. https://www.rand.org/pubs/commentary/2022/09/debunking-russian-lies-about-biolabs-at-upcoming-un.html 

Tran, T. T. T., Valecha, R., Rad, P., & Rao, H. R. (2020). Misinformation harms: A tale of two humanitarian crises. IEEE Transactions on Professional Communication, 63(4), 386–399. https://doi.org/10.1109/TPC.2020.3029685 

VIGINUM. (2023, July 19). RRN: A complex and persistent information manipulation campaign. Secrétariat Général de la Défense et de la Sécurité Nationale. https://www.sgdsn.gouv.fr/files/files/Publications/20230719_NP_VIGINUM_SYNTHESE_RAPPORT-CAMPAGNE-RRN_EN_0.pdf 

Related articles

Recent articles