Skip to content
All posts

PRODUCT

Pickerman: media intelligence for a flood that is aimed at the checkers

7 min read

On 12 August, Germany’s BfV publicly named the Matryoshka network flooding four September elections with fake broadcaster clips — the same day a deepfake report counted 15,736 victims in six months, half of video fakes built to wreck reputations. Operation Overload’s real target is the verifier’s time. Pickerman is our media-intelligence radar built to invert that price: rank by independent agreement, check claimed sources against real ones, keep a human in command.

On 12 August, Germany’s domestic intelligence agency did something security services rarely do: it named the operation. The BfV publicly warned that the Russian-directed Matryoshka network — the infrastructure behind the campaign researchers call Operation Overload — is targeting four September ballots: the state elections in Saxony-Anhalt on the 6th, Berlin and Mecklenburg-Western Pomerania on the 20th, and local elections in Lower Saxony. The payload is short clips dressed in the layouts of well-known German outlets, pushed under hashtags like #TimeToDivideGermany, aimed — in the agency’s words — at polarising East and West and discrediting politicians whose positions do not suit the strategic interests of the Russian Federation. The same day, the H1 2026 Deepfake Threat Report from the detection firm Resemble AI put numbers under the genre: some 3.46 million synthetic files across 821 documented attacks and at least 15,736 confirmed victims in six months, with 87% of traceable attack files coming from a single tool — xAI’s Grok. The statistic that matters most here is quieter: of the video deepfakes, 51% were built for reputational attacks. Not steal-the-money fakes — destroy-the-name fakes. If your job is to watch the public web for a brand, a newsroom or an institution, this was the week the weather report changed.

Overload is a strategy, not a metaphor

Operation Overload was named by the research outfit CheckFirst in June 2024, and its mechanics needed a new mental model, because the operation does not try to sneak past the people whose job is verification — it mails them. More than 800 newsrooms, fact-checkers and research organisations were hit with some 2,400 coordinated posts and hundreds of targeted emails, each pointing at fabricated clips and screenshots dressed in the branding of real outlets — Deutsche Welle among the first, the BBC, The Economist and Euronews among the twenty-plus since — with a polite request to please investigate. The goal, CheckFirst concluded, is to divert the resources of the people doing the checking, and it worked well enough to generate more than 250 debunk articles: each one an analyst-day the operation bought for the price of a render. By July 2025 the Institute for Strategic Dialogue had measured the pivot — media impersonation up from half to 70% of the operation’s output, 96% of it in English, with researchers now emailed directly to burn their time. The BfV warning is the same playbook pointed at elections, at national scale, named by a counterintelligence service.

The flood, dated · June 2024 → August 2026
Jun 2024Operation Overload namedCheckFirst: 800+ organisations hit with ~2,400 coordinated posts and targeted emails — fake clips in real outlets’ branding, sent to the fact-checkers themselves
Jul 2025The pivot to impersonationISD: media impersonation reaches 70% of the operation’s posts, 96% in English; researchers now emailed directly to burn their time
12 AugBfV names MatryoshkaGerman counterintelligence warns publicly: four September ballots targeted with clips dressed as established broadcasters
12 AugH1 2026 deepfake ledger3.46M synthetic files, 821 attacks, 15,736 confirmed victims in six months — 51% of video deepfakes built for reputational attacks
The honest counterweight: platforms removed 73–90%+ of sampled Overload posts and what survived often averaged under one like. The operation exhausts verifiers far more effectively than it persuades voters — the target is capacity, not conviction.
Twenty-six months from research footnote to counterintelligence warning — with the honest counterweight in the footer.

The ground your monitoring reads is tilting

Under the targeted operation sits a structural shift. NewsGuard, which counted 49 AI-generated “news” sites when it started tracking in spring 2023, counted 3,006 this March — when it launched a dedicated detection datastream with the AI-detection firm Pangram — and 3,749 by late June: sixteen languages, growing by 300 to 500 sites a month, a mix of made-for-advertising slop and state-tied propaganda dressed as local journalism. Zoom all the way out and Graphite’s analysis of a Common Crawl sample found AI-written articles crossed the 50% line back in November 2024 and have hovered around half of new articles since. Then add the caveat the honest version of this post requires: the same study found human-written pages still make up 86% of what Google actually surfaces. The open web is not lost — ranked, filtered and curated, it still works. But a monitoring pipeline does not read the web through a search engine’s ranking. Collectors drink from the raw feeds, and the raw feed is where the 52% lives — next to the 3,749 farms and the clips wearing stolen logos.

When the flood is the attack, collection is complicity

This is the uncomfortable conclusion for media intelligence, and the reason Pickerman is built the way it is. A monitoring tool that treats every inbound item as signal does the attacker’s work for them: it ingests the fake, matches the keyword, fires the alert, and puts the fabricated clip in front of your analyst with your own tool’s authority behind it. Overload’s economics only function while each fake costs the defender more than it cost the attacker — so the job is to invert the price. Three disciplines do it. Independence: cluster the same event across feeds and rank it by how many genuinely independent sources agree, because a hundred echoes of one origin corroborate nothing — we wrote a whole post about that discipline in July. Identity: an item claiming to be a broadcaster’s reporting gets checked against the one feed that settles the question — the broadcaster’s own; a stolen logo survives every visual inspection and fails that single lookup. And an editorial human: the operation’s target is your team’s time, so triage has to run at machine scale precisely so that judgment can stay at human scale.

The source check · claimed vs actual

Inbound: clip in a broadcaster’s branding

“EXCLUSIVE — candidate scandal”, logo and lower-third of a well-known outlet
the outlet’s own feed no such story
independent sources 0 corroborate — echoes of one origin
provenance none recorded
impersonation — flagged, not amplified

Inbound: story from the same outlet

same branding — but this one the newsroom actually published
the outlet’s own feed published, matches
independent sources 4 independent feeds corroborate
provenance recorded where present
corroborated — one story out
A stolen logo survives every visual inspection and fails the cheapest check in intelligence: the outlet’s own feed. Independence does the rest — a hundred echoes of one origin corroborate nothing.
Same branding, two verdicts: the fabricated clip fails the cheapest check in intelligence — the outlet’s own feed — and independence does the rest.

Where Pickerman stands

Pickerman is our OSINT and media-intelligence product, and it is that inversion productised. It collects across news, RSS, APIs, video, public Telegram channels, social, galleries and sitemaps, in twelve languages — including the English the Matryoshka clips arrive in and the Russian, Arabic and Farsi where regional narratives start. It extracts named entities and IOCs from everything it ingests, clusters the same event across feeds with embeddings, and synthesises a story only when three or more independent sources support it — provenance recorded where it exists, and the unverifiable flagged as exactly that instead of laundered into a confident summary. The last mile is deliberately human: a real-time operator console and an editorial workflow, so the machine does the triage and a person makes the call.

  • Multi-source collection: news, RSS, API, video, public Telegram, social, gallery, sitemap — in 12 languages
  • Named-entity (NER) and IOC extraction on everything ingested
  • Same-event clustering across feeds (embeddings + kNN) — a hundred echoes collapse into one cluster
  • AI synthesis only from 3+ independent sources; the unverifiable stays flagged, not summarised
  • Real-time operator console and editorial workflow — self-hosted, no Docker required
Many sources in, one story out: entities and same-event clusters across feeds, ranked by independent agreement.

What we will not claim

Honesty about limits is a house rule, so here are three. First, the panic has a ceiling: ISD found platforms had removed 73% to over 90% of the Overload posts it sampled, and what survived often averaged less than one like per post. This operation exhausts verifiers far more effectively than it persuades voters, and anyone selling you “AI disinformation is deciding elections” is ahead of the evidence — the BfV took it seriously anyway, and that is the right read, because the cost in verification capacity is real even where the persuasion is not. Second, Pickerman is not a deepfake detector, and corroboration is not a truth machine — three independent sources can still share a wrong assumption. What corroboration buys is a priced, auditable reason to trust one story more than another, and a flag on everything that could not earn it. Third, this is open-source intelligence — brand, event and threat monitoring on sources that are already public. That boundary is the product’s design, not a disclaimer: monitoring the public conversation is not surveilling the people in it.

The flood is aimed at your verification budget. Corroboration flips the price: echoes collapse into one cluster, and a stolen logo fails the cheapest check there is — the source itself.

In Türkiye the frame is familiar and written down. Article 217/A, added to the Penal Code by Law No. 7418 in 2022, made publicly spreading misleading information a distinct offence, and the Directorate of Communications’ Centre for Combating Disinformation publishes regular debunk bulletins. The EU side is not far away either: the AI Act’s Article 50, applicable since 2 August, requires deepfakes to be labelled and reaches Turkish operators serving European audiences under its extraterritorial Article 2 — but a label binds the honest, and Matryoshka does not label its work. What an institution can actually control is its own reading apparatus: whether the thing that watches the public web on its behalf ranks by independence, checks claimed sources against real ones, records provenance, and keeps a human in command of the editorial call. Pickerman self-hosts without Docker, so the collection, the source list and the editorial record live inside your own perimeter, behind your own SSO — and for the institutions the 2019/12 Presidential Circular expects to keep critical data in the country, that is the shape of the obligation, not a preference. Pickerman, from Arpanet Bilişim A.Ş., was engineered for the KVKK from its first line. Pricing depends on your deployment and scale — contact us and we will scope it with you.