May 29, 2026

Defunding Deception: Economic Disruption as a Proactive Weapon Against Information Manipulation

Information manipulation should be approached as part of a broader hybrid-threat environment. It interacts with cyber operations, political coercion, economic pressure, and the exploitation of social divisions. European institutional actors increasingly treat information manipulation operations as closely linked to cybersecurity and hybrid threats, and as tools used by both state and non-state actors for political and strategic gain.

That framing changes what an “effective response” means. In a hybrid-threat context, the key question is not only whether harmful narratives exist. It is under what conditions they gain traction and scale, and how those conditions can be disrupted. Hybrid pressure tends to be most effective where democratic legitimacy is contested, trust in institutions and media is weak, and polarisation is high. Resilience is not just detecting, exposing and debunking. It’s changing the conditions that enable scale and disrupting the infrastructure that keeps information manipulation activities operational.

From this perspective, defunding information manipulation and harmful content belongs within a broader resilience and deterrence agenda. The online advertising and platform economy does not merely enable information manipulation networks, it may inadvertently fund them. When sensationalism, harmful content, and outrage reliably generate clicks and revenue, hostile actors can build and sustain such networks cheaply and at scale. The problem is therefore partly one of market design.

Why monetisation matters in a hybrid-threat context

Information manipulation operations rely on an operational environment: websites, pages, ad accounts, amplification networks, and, crucially, the ability to replace assets when individual nodes are removed. Monetisation matters because it helps sustain that operational environment. Even where campaigns are not primarily profit-driven, monetisation can function as an enabling layer. It lowers operating costs, extends reach, and supports persistence across crises, elections, and policy debates.

The stronger concern is that commercial digital systems can provide paid reach, visibility, and resilience to coordinated manipulation efforts. Research has documented how weak enforcement of political advertising rules enabled the circulation of undeclared political ads and pro-Russian propaganda ads at scale in the EU ahead of the 2024 European elections, reaching tens of millions of accounts. Different investigations also reported that Meta earned US$338,000 between August 2023 and November 2024 by hosting at least 8,000 sponsored content pieces linked to the Russia-linked “Doppelganger” operation. The EEAS similarly documented the use of inauthentic accounts and paid amplification tactics as part of broader information operation activity targeting European audiences.

The point here is operational. Harmful actors can exploit advertising infrastructure and recommendation systems to distribute harmful content more efficiently, especially at politically sensitive moments (see our latest Germany Report).

The monetisation chain is the vulnerability

A second layer of the problem sits in the broader advertising market. Research shows that digital advertising systems routinely, and often without advertisers' knowledge, place major brands ads on low-integrity information sites, helping finance them at scale. Other research shows how opaque ad-tech practices, such as ad inventory pooling, allow publishers and information manipulation actors to use low-quality or disinformational content to hide inside legitimate market infrastructure and circumvent brand-safety protections.

This is where “defunding disinformation” becomes a concrete resilience lever: it targets the monetisation chain that sustains manipulation ecosystems, not just individual posts, channels or domains.

Exploiting opacity in the advertising supply chain

Research on the political economy of online disinformation shows that malicious actors routinely exploit opacity in three repeatable ways: they pool advertising inventory with legitimate publishers; they obscure ownership through intermediary networks; they use domain switching and mirror sites to evade brand-safety enforcement. The result is structural resilience of information manipulation networks.

Even when specific channels are exposed or removed, the broader financial infrastructure sustaining them often remains intact. Individual nodes can be replaced while the monetisation pipeline continues functioning. For policymakers concerned with hybrid threats, this matters because it shows that the sustainability of information manipulation networks is partly embedded in the architecture of the digital advertising market itself.

One system: algorithms, monetisation, and platform incentives

These issues are often discussed separately, recommenders, advertising, and platform governance, but in practice, they form a single economic and technological environment. Recommender systems optimise for engagement and time spent. Monetisation programmes reward high-traffic creators and publishers. Advertising systems allocate revenue based on attention metrics.

That structure tends to favour content that is emotionally charged, polarising, or sensational, the same properties frequently used in information manipulation campaigns. Although unintentional, this creates a systemic bias within the market design of platforms that can be easily exploited by coordinated actors to promote information manipulation and harmful content. For hybrid threat actors, that creates an asymmetric advantage: relatively small networks can achieve outsized reach by leveraging attention-optimisation logic built into digital platforms.

Why the incentive problem is getting sharper

Digital advertising, especially programmatic advertising, creates financial incentives that rewards engagement maximisation regardless of quality or truthfulness. At the same time, social media platforms are no longer just intermediaries in the advertising supply chain. They have launched revenue-sharing and content monetisation programmes, deepening platform-creator incentives around reach and engagement.

In other words, the market is not just distributing content. It is paying for it.

What can be done: market-based approaches

Several market-based approaches are emerging. They are not interchangeable, and they do not deliver the same type of leverage.

1) Ranking algorithms

Ranking systems can reduce the visibility of misleading content on platforms and in search results, and studies show reasonable performance across topics. In turn, they carry bias risks, tend to become an adaptation game in adversarial environments, and do not reliably disrupt the underlying economics.

2) Advertising demonetisation

Addressing advertising demonetisation requires platforms to act structurally, not just reactively. Platforms should strengthen monetisation eligibility criteria and consistently enforce them, removing or downgrading publishers that repeatedly host manipulative content.

More importantly, they should close the inventory pooling loopholes that allow low-integrity sites to shelter inside legitimate market infrastructure, a problem that individual advertisers have neither the visibility nor the leverage to solve unilaterally.

Regulatory pressure reinforces this: systemic risk obligations under the DSA create a basis for requiring platforms and ad exchanges to demonstrate that their monetisation infrastructure is not inadvertently funding manipulation networks. Advertisers retain a role in demanding supply-chain transparency, but the architecture of the problem sits with platforms, and that is where the primary obligation should lie.

3) Supply-chain transparency

Demonetisation without supply-chain transparency is enforcement without memory; it addresses individual content while leaving the underlying pipeline intact. Opacity is the core vulnerability: malicious actors can pool their ad inventories together with those of legitimate publishers, allowing revenue to flow through market infrastructure that looks clean on the surface. Research suggests a small number of major ad exchanges play an outsize role in enabling such behaviour, meaning the problem is structural even if it appears sporadic.

From a hybrid threat perspective, monitoring the advertising supply-chain is a critical capability. It reinforces existing threat intelligence toolkits, disrupting the infrastructure that gives manipulation networks persistence rather than the symptoms those networks produce.

4) Platform market design

Disinformation should also be understood through a market-shaping lens: platforms have built markets designed to monetise engagement, creating incentives to circulate engaging and enraging content.

Engagement-maximising systems persist because they are profitable. Any redesign that meaningfully reduces harmful amplification will, almost by definition, reduce the metrics platforms use to measure success. That is why voluntary change at scale is structurally unlikely and why regulatory pressure, including systemic risk obligations under frameworks like the DSA, is not optional but necessary.

From mapping to disruption

If the market is paying for manipulation, then accountability cannot stop at the content level. The practical question becomes: where can the flow be disrupted, and who has the visibility to do so across platforms, intermediaries, and shifting domains?

Building on this logic, two strategies emerge: demonetisation, which cuts off revenue streams at their origin, and supply-chain mapping, which clarifies the flow of funds to allow targeted interventions upstream. These methods address root causes rather than surface issues. GDI’s research centres on these approaches, analysing the monetisation strategies and revenue models that enable harmful online content, providing evidence to support regulatory action, and documenting the malicious practices of adversarial actors across platforms and media types.

This is what “raising the costs” of information manipulation looks like: fewer safe harbours in the advertising ecosystem, less paid reach for coordinated manipulation, and a narrower set of pathways for influence networks to sustain themselves. In the current hybrid-threat environment, this could mean deterrence and resilience in practice: making influence operations harder to finance, harder to amplify, and harder to reconstitute.

_

Photo by Fujiphilm

GDI
Accessibility:

© Copyright - Disinformation Index Ltd., All Rights Reserved GDI is a not-for-profit company; any surplus income generated will be 100% reinvested back into the organisation to further its mission.